Privacy notice
This notice explains what personal data BudgetUp collects, why, what we do with it and the rights you have. We've tried to write it in plain English. The short version: we collect as little as we can, we never sell your data, there are no ads inside BudgetUp, advertising tags only ever run on our public website pages and only if you say yes, and your institution only sees grouped results unless you say otherwise.
Using BudgetUp through a university, college, council, housing association or employer? Your organisation decides how your data is used and is the controller. We process it for them as their processor. Their own privacy notice applies too, and they're your first point of contact for data requests, though we'll help either way.
1. Who we are
BudgetUp is a trading name of Tamsar Global Ltd, a company registered in England and Wales (company number 17371733). Registered office: Unit 3, Office A, 1st Floor, 6-7 St Mary At Hill, London EC3R 8EE. We're registered with the Information Commissioner's Office (ICO) under registration number ZC269951.
For anything about your data, email [email protected]. Our data protection lead handles every request. We aren't required to appoint a statutory Data Protection Officer, but this person acts in that role.
2. Our role: controller or processor
| How you use BudgetUp | Who decides how your data is used |
|---|---|
| Without an account (guest play), or with your own account on the free plan or Plus | We are the controller. This notice is the main notice that applies. |
| Through an institution: you signed up with its code, single sign-on or virtual learning environment | Your institution is the controller and we're its processor under a written data processing agreement (UK GDPR Article 28). We only use your data on its instructions. |
| Optional research and outcomes surveys you agree to take part in | We act as controller for pseudonymised, aggregated research, and only with your separate consent. |
| Enquiries from organisations (our contact forms) | We are the controller. |
3. What we collect
Information you give us
- Account details: your email address, a display name or the random pseudonym we generate for you. If you join with an access code you don't have to give an email at all: the account is a pseudonym plus your age range, linked to your organisation, until you choose to add one.
- If you choose "Continue with Google": Google tells us your name, your email address, whether Google has verified it, and a Google account ID so we recognise you next time. We don't take your profile photo, contacts or anything else from your Google account, and we don't keep Google's access tokens after you've signed in. We only connect Google to an existing BudgetUp account with the same email if Google has verified that email and your BudgetUp email is already verified; if your university or college runs its own sign-in for your email domain, we ask you to use that instead.
- Plus billing (only if you buy Plus): your plan, subscription status and renewal date, a Stripe customer ID, and a record of your request to start Plus straight away and of any cancellation or refund. Stripe takes your card details; we never see or store your full card number.
- If you're 16 or 17 and ask a parent or guardian to unlock Plus: the date you asked (so we can limit asks to one a week) and, only if you type it in, their email address so we can send them the link. We don't ask for their name or anything else about them. If they pay, Stripe holds their payment details as the customer, and we record on your account that a parent or guardian confirmed who they are and consented, with the date. Their email is removed from the request once it has been paid or has expired.
- Onboarding answers: your goals (for example "stop running out before payday"), your situation (student, working, renting, parent or carer, from outside the UK, back in education later in life), topics you're interested in, how confident you feel, your preferred session length and notification choices.
- Wellbeing and confidence check-ins: short questions about how you feel about money, based on the public-domain CFPB Financial Well-Being Scale, plus knowledge and "where to get help" questions. You can skip any question.
- Institution access codes you enter, so we can connect you to your organisation's licence.
- Optional equality information, only where your institution uses it and only with your explicit consent: for example disability, ethnicity, care experience, estrangement or being first in your family to go to university. See section 6.
- Messages you send us, such as support requests, complaints or safeguarding concerns.
- Problem reports and feedback you send with "Report a problem": the category, your words and any description of the screen you add. We attach the page address (without any codes or links in it) and the app version, and, if you're signed in, your account so we can look into it. Nothing else is attached unless you type it.
- Data rights requests: what you asked for, when, and what we did, so we can show we answered on time.
- Enquiry form details from organisations: name, work email, organisation, role and message.
Information created as you play
- Learning activity: levels and games played, scores, stars, time taken, XP, streaks and streak freezes, daily quests, and in-game items and coins (BudgetUp's just-for-fun game currency, with no cash value).
- Signpost clicks: when you tap a link to a help service, so we and your institution can tell whether people are finding help. We don't see what you do on the other site.
Technical information
- Essential technical data: a session cookie to keep you signed in, your IP address (used briefly for security and rate-limiting), and basic device and browser information in server logs.
- Free-plan counts: which arcade games a free account opened each day, so the daily free game works fairly on every device. Guests may be given a random ID in an essential cookie for the same purpose; it isn't linked to you.
- Analytics and browser error reports, only if you've said yes in our cookie banner and you're not in under-18 mode: pages viewed, taps on buttons and links (their text is hidden), events such as "lesson finished, 3 stars" or "game abandoned", page speed, and for about 1 in 4 visits a session recording in which every word on screen and everything you type is masked. Recordings never cover Settings, admin pages, the AI coach or parent links. Product analytics is PostHog's EU Cloud (Frankfurt); error reports go to Sentry's EU region. See our cookie policy.
- Advertising measurement, only if you choose "Analytics + ads", you're not in under-18 mode and your browser doesn't send Global Privacy Control: Google Analytics 4, Google Ads and the LinkedIn Insight Tag run on our public pages (home, pricing, games overview, library, help, trust and the pages for organisations) to tell us which ads bring people to BudgetUp, and whether a visit led to a sign-up or an enquiry. They never run inside lessons, games, onboarding, your account, settings or admin pages, so nothing about your learning ever reaches an advertising platform. We send no name, email or answers, and switch off Google signals and enhanced conversions.
- Server error reports (Sentry, EU region) when something breaks on our side: the page address without any codes or links in it, and the technical error. We strip names, emails, IP addresses, cookies and anything you typed before the report leaves our servers.
If you play as a guest, your progress is stored only on your device (in your browser's local storage) until you create an account, when it's copied to your account.
4. Why we use it, and our lawful bases
Where we're the controller, we rely on these lawful bases under UK GDPR Article 6 (and Article 9 for special-category data):
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, saving progress, personalising which topics you see, streaks and quests | Contract: we need it to provide the service you signed up for |
| Taking payment for Plus and handling cancellations and refunds | Contract, and legal obligation (tax and accounting records) |
| Keeping the service secure, preventing abuse and fixing errors | Legitimate interests: keeping BudgetUp safe and working |
| Improving games and content using aggregated, de-identified statistics | Legitimate interests: making the learning better. You can object at any time |
| Optional product analytics (PostHog EU) and browser error reports (Sentry EU) | Consent (PECR regulation 6 and UK GDPR Article 6(1)(a)). Withdraw any time in the cookie settings |
| Measuring our advertising on our public pages (Google Analytics 4, Google Ads, LinkedIn Insight Tag) | Consent (PECR regulation 6 and UK GDPR Article 6(1)(a)), asked separately from analytics. Never asked for or used in under-18 mode |
| Marketing emails and news (adults only) | Consent. You can unsubscribe from any email |
| Research and outcomes surveys used beyond your own feedback | Consent, given separately and optional |
| Optional equality and diversity information | Explicit consent (Article 9(2)(a)) |
| Responding to organisation enquiries | Consent, given on the form, and legitimate interests in replying to business enquiries |
| Acting on safeguarding concerns | Vital interests or legitimate interests, and where relevant substantial public interest (safeguarding of children and individuals at risk, Data Protection Act 2018 Schedule 1) |
Where your institution is the controller, it chooses the lawful basis, usually public task (for public bodies such as universities and councils) or legitimate interests. Your institution's privacy notice will say which.
5. What your institution can see
- By default, institutions see aggregated results only: how many people have joined, completion rates, popular topics and average changes in confidence. Any group with fewer than 10 people is hidden, and percentages are rounded.
- They do not see your individual answers to wellbeing questions, your scores or what you've played, unless you've explicitly agreed to that for a specific purpose (for example, opting in to be contacted by your student money team).
- We never receive your student, tenancy or employment records unless your institution's data processing agreement with us specifically covers it.
6. Special-category information
Some institutions measure whether support reaches the people who need it most, for example care-experienced or disabled students, as part of their Access and Participation Plan. If yours does, we'll ask whether you want to share this information. It's always optional and separate from everything else. We keep it in a separately encrypted part of our database with restricted access, use it only in grouped reports with small numbers hidden, and you can withdraw consent and have it deleted at any time.
7. If you're under 18
BudgetUp is for people aged 16 and over. If you're 16 or 17, usually through a college, we follow the ICO's Age Appropriate Design Code (the Children's Code). That means:
- High-privacy settings by default
- No profiling, no marketing and no requests for marketing consent
- No public leaderboards with your name, no chat and no friends features
- No push or email nudges, weekly rather than daily streaks, and no AI coach
- No analytics, no browser error reports and no advertising tags, even if you accept them in the cookie banner
- No location tracking
Under-18s never see prices or purchase prompts. The only option shown is "Ask a parent or guardian", which you can use at most once a week, and we never remind you about it.
Under-18 mode switches on if you pick 16–17 (or "I'd rather not say") when we ask your age range, or if your college has under-18 learners and we don't know your age yet. You can see whether it's on in Settings.
You can download your data or delete your account yourself in Settings at any age, without asking anyone. In the app, "Report a problem" also shows who you can talk to straight away (such as Childline, 0800 1111) if something's worrying you.
If you're under 16 and have signed up, please tell us at [email protected] and we'll delete the account.
8. AI features (Ask Nana)
Ask Nana is an optional AI money coach for adults. It answers general money questions using only our reviewed lessons and official UK figures, and links you back to the lessons. It never recommends products or providers and never tells you what to do with your own money: it's general education, not advice.
- Who can use it: signed-in learners aged 18 or over, after reading a short notice ("AI can be wrong; this is general education, not advice"). It's always off in under-18 mode, and your college, university or employer can switch it off. If you tell Nana you're under 18, we switch on under-18 mode for your account (you can change your age band in Settings).
- Which AI: Google's Gemini models, through Google's paid Gemini API, as our sub-processor. Google processes your message only to produce the answer and, under its paid-tier terms, doesn't use it to train its models. Processing may happen outside the UK (United States or global), covered by the UK Extension to the EU-US Data Privacy Framework and the UK International Data Transfer Addendum. Your name, email address and any card or phone numbers are removed before anything is sent to Google. Before any university, college, council or employer switches the coach on for its learners, we move it to Google Cloud (Vertex AI) in London.
- What we keep: your messages, Nana's answers and the safety labels our checks add (for example "sent to helplines" or "answer made safer"), for 90 days. Then they're deleted automatically. You can delete them any time with "Delete my chats" in the chat panel.
- Who can see your chats: only you. Your institution can't read them, and neither can our staff in normal operation; institutions only see counts (such as how many questions were answered), hidden when fewer than 10 learners have used it.
- Safety: if a message suggests you might be at risk (for example thoughts of suicide, a scam in progress or a money emergency), Nana doesn't send it to the AI. She shows you people who can help straight away, such as Samaritans (116 123) and Shout (text SHOUT to 85258). Nobody is contacted on your behalf. See our safeguarding policy.
We don't make decisions about you that have legal or similarly significant effects using automated processing.
9. Who we share data with
We never sell personal data, and we don't share your learning data with advertisers, lenders, banks or data brokers. We share it only:
- with your institution, as described in section 5, if you joined through one;
- with service providers (sub-processors) who help us run BudgetUp, under contracts that require them to protect it (see below);
- with Google, only if you choose "Continue with Google": Google confirms who you are and we tell it nothing about your learning (Google's own privacy policy applies to your Google account);
- with Google and LinkedIn, only if you choose "Analytics + ads" and only from our public pages: their tags see the page address (with any codes removed), your browser and device, your IP address, their own cookies and whether you signed up or sent an enquiry. For that ad measurement Google and LinkedIn are independent controllers (their own privacy policies apply: policies.google.com and linkedin.com/legal/privacy-policy). Nothing from lessons, games or your account is sent;
- with Stripe, only if you buy Plus: your email and the payment details you type into Stripe's checkout;
- with authorities where the law requires it, or with emergency services where someone's life may be at risk.
| Provider | What for | Where | Status |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, database, object storage, backups | Germany (Nuremberg, Falkenstein) | In use |
| Cloudflare, Inc. | Secure tunnel, DNS, CDN, web application firewall and DDoS protection; encrypted off-site database backups in R2 (EU jurisdiction) | Global edge; backups stored in the EU | In use |
| Google LLC (Gemini API, paid tier) | Ask Nana, the optional AI money coach for adults (Gemini models). Processes questions only to generate answers; paid-tier terms, so no training on customer data; names, emails and card or phone numbers are masked before sending. Switched off for under-18s and per institution. Before any institution enables the coach we move it to Google Cloud Vertex AI in London (europe-west2) | United States / global | In use (adults, optional) |
| Stripe Payments Europe Ltd | Plus subscriptions (hosted checkout, card details never reach us), refunds and institution licence invoices. Only for people who buy Plus and for institutions we invoice | Ireland / United States | At launch |
| Google Ireland Ltd (Sign in with Google) | Optional "Continue with Google" sign-in: confirms your name and verified email. Google is an independent controller for your Google account; we receive no tokens we keep and send nothing about your learning | Ireland / United States | In use (optional) |
| Brevo (Sendinblue SAS) | Transactional email (sign-in links, receipts) | France | In use |
| Functional Software, Inc. (Sentry), EU region | Error monitoring. Server errors always; browser errors only with analytics consent and never in under-18 mode. Names, emails, IP addresses, cookies, request bodies and codes in links are removed before sending | Germany (Frankfurt, de.sentry.io) | Optional (not currently used; errors go to PostHog EU) |
| PostHog Inc, EU Cloud | Product analytics: pages viewed, masked button taps, lesson and game events, page speed, and masked session recordings for about 1 in 4 visits (all text and typing hidden; never on settings, admin, coach or parent pages). Only with analytics consent and never in under-18 mode. No cookies, no IP addresses stored; identity is a one-way hash of the account id. Reached through our own /ingest address | Germany (Frankfurt, eu.posthog.com) | In use (consent only) |
| Google LLC (Google Analytics 4, Google Ads) | Measuring our advertising on our public website pages only (never in the learning app), with Google Consent Mode v2 and only after marketing consent; never in under-18 mode. Google signals and enhanced conversions off; no names or emails sent. Google is an independent controller for its ad measurement | United States / global | When ads run (marketing consent only) |
| LinkedIn Ireland Unlimited Company (Insight Tag) | Measuring our LinkedIn adverts on our public website pages only (never in the learning app), only after marketing consent and never in under-18 mode. No names or emails sent. LinkedIn is an independent controller for its ad measurement | Ireland / United States | When ads run (marketing consent only) |
The full register, including transfer mechanisms, is in our trust centre.
10. Where your data is stored
Our main servers and database are hosted by Hetzner Online GmbH, Nuremberg and Falkenstein, Germany (EU). The UK recognises the EU as providing adequate protection for personal data, so these transfers are covered by UK adequacy regulations. Where a provider may process data in the United States (for example payment processing), we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified.
Product analytics is hosted in the EU (PostHog EU Cloud, Frankfurt), so it's covered by UK adequacy for the EU. The optional advertising tags send data to Google LLC and LinkedIn (LinkedIn Ireland Unlimited Company, with its parent LinkedIn Corporation in the United States). Data may be processed in the United States; both companies take part in the UK Extension to the EU-US Data Privacy Framework, and otherwise rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
11. How long we keep it
A scheduled job applies these periods automatically every day, except where the table says otherwise.
| Data | How long |
|---|---|
| Your account and learning data | For as long as you have an account. You can delete it yourself at any time in Settings |
| Inactive accounts | Deleted after 24 months with no sign-in and no play. If we have your email, we warn you 30 days before |
| Data held for an institution | Deleted or returned within 30 days of the end of its contract |
| Guest progress on your device | Until you clear your browser storage or create an account |
| Free-plan daily counts (guests and accounts) | 35 days |
| Reminder email log | 90 days |
| Sign-in sessions, sign-in links and institution sign-in state | Sessions end 30 days after you last use them; expired sessions, links and sign-in state are deleted a day after they expire |
| Rate-limit counters (hashed, no emails or IP addresses) | Deleted within an hour of their time window ending |
| "Ask a parent" requests | The parent's email: removed when the request is paid or expires (7 days). Unpaid requests: deleted 90 days after they expire. Paid requests and the consent record: kept with the payment records |
| AI coach conversations | 90 days, or straight away with "Delete my chats" |
| Problem reports and feedback you send in the app | 24 months |
| Our record of your data-rights requests (including account deletions) | 3 years after we complete the request |
| Security and audit logs | Up to 6 years. They hold an account number, never your name or email |
| Backups | Automatically overwritten within 35 days |
| Payment and invoice records (Plus) | 6 years after the end of the financial year, as required for tax, including after you delete your account |
| Organisation enquiries | 24 months, unless you become a customer |
| Complaints and safeguarding records | Complaints: 3 years after closure. Safeguarding: as long as necessary to protect people, reviewed at least yearly |
When you delete your account we delete or anonymise everything linked to it straight away (backups roll off within 35 days). We keep only what the table above says must stay: payment records for tax, our security audit log, which holds an account number but never your name or email, and a record that the deletion happened. Grouped statistics that can't identify you (for example "40 people finished the budgeting topic") may remain in reports already produced.
12. Your rights
Under UK data protection law you have the right to:
- access a copy of the personal data we hold about you;
- rectification of anything inaccurate or incomplete;
- erasure ("right to be forgotten"), for example by deleting your account;
- restrict how we use your data in some circumstances;
- data portability: get your data in a machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time, where we rely on consent. This doesn't affect anything we did before you withdrew it.
Do it yourself in the app. In Settings you can download everything we hold about you (a readable page and a machine-readable file), correct your name, email and age range, ask us to restrict or stop using your data, and delete your account. Deleting your account cancels Plus first, signs you out on every device and sends you a confirmation email. Anyone can delete their own account, including learners aged 16 or 17. If you joined through an institution, deleting removes your personal data from BudgetUp; the institution keeps only grouped statistics with groups under 10 people hidden.
Or, to use any of these rights, email [email protected]. We'll reply within one month (we may extend this by two more months for complex requests, and we'll tell you if so). It's free, though we may need to confirm your identity first. If you use BudgetUp through an institution, we'll pass your request to it and help it respond.
13. Keeping it safe
We encrypt data in transit and at rest, separate each institution's data at the database level, limit staff access to what's needed, and keep an audit log. Read more in our trust centre. If a breach puts your rights at high risk, we'll tell you without undue delay.
14. Complaints
If you're unhappy with how we've handled your data, please tell us first at [email protected] and we'll try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
15. Changes to this notice
We'll update this notice when we change how we use data, and show the date at the top. If a change is significant, we'll tell you by email or in the app before it takes effect.