Privacy Policy

How we handle your data at Plutus

Last updated: 20 September 2026

20 September 2026: Provider disclosures were reorganised by category and clarified; there was no change to the data we collect or why.

The short version

We know privacy policies can be long. Here are the key things you should know:

  • You choose how your data gets into Plutus — enter transactions manually or optionally connect your bank accounts via open banking. We never store your bank login details or banking access tokens.
  • We never sell your personal or financial data to anyone.
  • Payments are handled by Stripe, our payment processor. We never see or store your full card details.
  • Your data is encrypted in transit and at rest, including full-disk encryption on our database server.
  • You can export or delete your data at any time.
  • We do not use automated decision-making or profiling that produces legal or similarly significant effects.

1. What This Policy Covers

This Privacy Policy explains how Telotek Ltd, trading as Plutus Finance ("Plutus", "we", "us", or "our"), collects, uses, shares, and protects your information when you use our website, web application, and related services (collectively, the "Service").

Telotek Ltd is the data controller responsible for your personal data. Our registered address is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

By using Plutus, you agree to the collection and use of information as described in this policy. If you do not agree with any part of this policy, please do not use our Service.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and a securely hashed version of your password. If you sign in with Google, we receive your name, email address, and profile picture from your Google account. We never store your Google password. If you enable two-factor authentication, we store the encrypted TOTP secret associated with your authenticator app.

Financial Data

Plutus supports two ways of managing your financial data: manual entry and optional bank account connections.

Manual entry. You can enter all transactions, budgets, categories, and account balances directly. No bank connection is required to use Plutus.

Bank connections (optional). If you choose to connect a bank account, we use FCA-regulated open banking providers to securely retrieve your account balances and transaction history. When you connect an account:

  • Your banking credentials are entered directly into your bank's secure authentication flow — Plutus never sees or stores your bank login details
  • We receive read-only access to your account balances and transaction data via the open banking provider
  • We store the transaction data and balances provided in order to deliver the Service
  • You can disconnect a linked account at any time from within Plutus
  • Open banking consent is time-limited (typically 90 days) and you will be prompted to re-authorise when it expires

By connecting a bank account, you acknowledge that the open banking provider's privacy policy applies to their handling of your data during the connection process. All financial data — whether entered manually or imported via open banking — is stored securely and is only accessible to you (and any workspace members you choose to share it with).

Workspace Data

If you create or join a workspace, we store membership information, roles, and shared financial data associated with that workspace. All members of a workspace can see the shared budgets and transactions within it.

Usage Data

We collect information about how you interact with Plutus, including the features you use, pages you visit, actions you take, and the time and frequency of your activity. This helps us understand how people use Plutus and where we can improve.

Device & Technical Data

When you access Plutus, we automatically collect certain technical information, such as your IP address, browser type and version, operating system, device type, screen resolution, and referring URL.

Payment Data

Payments for Plutus are processed by Stripe, our payment processor. Stripe handles all payment processing, tax calculation, and invoicing. We receive your subscription status, plan details, and billing country from Stripe, but we never see or store your full credit card number, bank account details, or other sensitive payment information.

Communications

If you contact us for support, send us feedback, or respond to our emails, we collect the content of those communications along with your email address and any other information you choose to provide.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Plutus service
  • Process your subscription payments through Stripe
  • Send transactional emails such as password resets, billing receipts, and account notifications
  • Send marketing and onboarding emails where you have opted in to receive them (you can unsubscribe at any time using the link in any marketing email)
  • Provide customer support and respond to your requests
  • Send product updates, tips, and in-app notifications (which you can control via notification preferences in your settings). Security alerts and billing notifications are always sent regardless of your preferences.
  • Analyse usage patterns to improve features and user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our terms of service

We will not use your financial data — whether entered manually or imported via open banking — for any purpose other than providing you with the Plutus service. We do not use your data to build advertising profiles or serve ads.

5. How We Share Your Information

Service Providers and Partners

We share personal data with service providers that help us operate Plutus. Where they act as processors, they may use the data only on our instructions, under data processing agreements, and not for their own purposes. They fall into the following categories:

  • Hosting and infrastructure — operating our application, database, and financial-record storage in the United Kingdom.
  • Network delivery and security — delivering content, providing DNS, and protecting Plutus against attacks. These providers receive technical connection data needed to route and secure requests.
  • Transactional email — delivering account, security, billing, notification, and service messages. Our email delivery providers receive your email address and the content of the messages we send you. If you enable alerts or summaries, those messages can include account names, balances, transaction amounts, payees, thresholds and category totals. You control these messages through your notification settings.
  • Onboarding, marketing, and lifecycle communications — new verified users receive onboarding and service messages. Marketing lists and product updates depend on the applicable preference or consent. The provider receives your name, email address, user ID, and high-level account attributes such as whether a bank connection is active.
  • Monitoring and logging — detecting errors, measuring performance, securing the service, and investigating incidents. These systems are not designed to receive your financial records, but a diagnostic event may incidentally include details about the action that failed.
  • Product analytics — with your consent, understanding how Plutus is used and improving the product. The provider receives usage data and account identifiers. We configure product analytics so that on-screen text, element attributes, searches, filters, and URL parameters are not collected, and we do not record sessions.
  • Customer support — providing in-app live chat. The provider does not automatically receive your stored financial records, but processes your contact details and any information you choose to include in a support message.
  • Stripe — payment processing and invoicing. Your primary contracting party is Stripe Payments Europe Limited (Ireland). Stripe is PCI-DSS certified and processes payment data under its own regulatory obligations. We never see or store your full card details. Where Stripe transfers data to Stripe, LLC in the United States, that transfer relies on Stripe's certification under the EU-U.S. Data Privacy Framework and its UK Extension, with EU Standard Contractual Clauses and the UK International Data Transfer Addendum as a contractual fallback.
  • Finexer Ltd — Open Banking (Account Information Services) provider, authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 (Firm Reference Number: 925695) as an Authorised Payment Institution to provide account information services and payment initiation services. Plutus uses Finexer only to provide account information services. Telotek Ltd, the company that operates Plutus Finance, is registered on the FCA Register as an appointed agent of Finexer Ltd. Finexer processes bank account identifiers, account holder names, and transaction data in the United Kingdom.

Separately, we operate aggregate, cookie-free analytics on the UK infrastructure used to operate Plutus. That data is not shared with a third-party analytics provider. You can request a current list of the service providers that process your personal data by contacting privacy@plutusfinance.app.

When bank sync is enabled, your open banking connection is provided through Finexer Ltd, which is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 (Firm Reference Number: 925695) as an Authorised Payment Institution to provide account information services and payment initiation services. Plutus uses Finexer only to provide account information services. Telotek Ltd, the company that operates Plutus Finance (company number 17050370, registered at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ), is registered on the FCA Register as an appointed agent of Finexer Ltd. Finexer provides you with regulated account information services through Telotek Ltd as its agent, retrieving your account balances and transaction data from your bank to display them within Plutus. Finexer accesses your banking data only with your explicit consent, in accordance with open banking regulations, and processes it within the United Kingdom.

Workspace Members

If you belong to a shared workspace in Plutus, other members of that workspace can see shared budgets, transactions, and categories. Your personal account details (such as your email or password) are never shared with other workspace members.

Legal Requirements

We may disclose your information if required to do so by law or if we believe in good faith that such action is necessary to comply with a legal obligation, protect and defend our rights or property, prevent fraud, or protect the personal safety of users or the public.

Business Transfers

If Plutus is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

We Never Sell Your Data

To be completely clear: we do not sell, rent, or trade your personal information or financial data to third parties. Ever.

6. Data Security

We take the security of your data seriously and implement appropriate technical and organisational measures to protect it:

  • All data is encrypted in transit using TLS/SSL
  • Database storage is protected by full-disk encryption (LUKS2/AES-XTS)
  • Banking connections use consent-based access through FCA-authorised providers — no banking credentials or access tokens are stored by Plutus
  • Passwords are securely hashed and never stored in plain text
  • Two-factor authentication (2FA) is available for your account, using time-based one-time passwords (TOTP)
  • We use secure, HTTP-only cookies for session management
  • Access to production systems is restricted and monitored
  • We regularly review and update our security practices

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to keeping your data as safe as reasonably possible.

7. Data Retention

We retain your information for as long as your account is active or as needed to provide you with the Service.

If you choose to delete your account, we will remove your personal data and financial records within 30 days. Some information may be retained for longer if necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

Anonymised, aggregated data that cannot be used to identify you may be retained indefinitely for analytical and product improvement purposes.

8. Cookies & Tracking

Essential Cookies

We use essential cookies to keep you signed in and to maintain your session. These cookies are strictly necessary for Plutus to function and cannot be disabled:

  • plutus.session_token — Stores your authentication session token. HTTP-only, secure, same-site. Expires when you sign out or after 7 days of inactivity.
  • plutus.session_data — Caches session data to reduce database lookups. HTTP-only, secure, same-site. Refreshed every 5 minutes, cleared on sign out.

Additional cookies may be set temporarily during two-factor authentication flows.

Error & Performance Monitoring

We use an error and performance monitoring provider to identify and fix technical problems, not for advertising or behavioural analytics. It receives diagnostic information such as stack traces, browser type, page paths, account identifiers, and IP address. These systems are not designed to receive your financial records, but an error report may incidentally include details about the action that failed. If you choose to attach a screenshot to feedback, it may include information visible on screen; you can hide sensitive areas before submitting.

Aggregate Analytics

On our marketing website, Plutus operates aggregate analytics on the UK infrastructure used to operate the service. This measures traffic such as page views, referral sources, browser and device information, coarse location, and campaign source, medium, campaign, and content labels when those four standard campaign parameters are present. Before data is sent, we remove every other URL query parameter, advertising click identifier, URL fragment, and all query parameters from the referring URL. It does not use cookies, create persistent identifiers, receive Plutus account identifiers, or track you across sites or devices. An IP address may be used transiently to derive location and rotating session information, but is not stored. The data is not shared with a third-party analytics provider. Because this analytics is cookie-free and is not used to identify individuals, no analytics consent is required to browse our marketing website.

Product Analytics

Within the Plutus app, a third-party product analytics provider helps us understand how people use and improve the product. It collects usage data such as page views, feature interactions, and clicks, uses cookies for analytics sessions, and receives account identifiers such as your user ID, email, and name. We enable it only after you consent. We configure product analytics so that on-screen text, element attributes, searches, filters, and URL parameters are not collected, and we do not record sessions.

After you accept analytics consent in the Plutus app, our Plutus-operated aggregate analytics also measures page views, feature adoption, funnels, and short-term retention. It does not set cookies or receive account identifiers. We send general page paths with resource identifiers removed, and limited event information such as the feature used, a coarse free-or-paid plan category, the time of the event, and the four campaign labels described above on selected signup and activation milestones. After consent, these campaign labels may be kept in your browser for up to 30 days; they are not stored in your Plutus account. We do not send names, email addresses, account names, payees, notes, balances, transaction or budget amounts, URL query strings, URL fragments, or referrer values.

This aggregate analytics uses a rotating, cookie-free session identifier derived from technical request information to calculate aggregate visits and short-term retention. An IP address may be used transiently to derive location and session information but is not stored. We do not use this data to identify a Plutus account or track a person across devices.

Live Chat Support

We use a provider for in-app live chat support. When you use the chat widget, the provider sets a session cookie to maintain your conversation. This cookie is functional (not used for analytics or advertising) and expires after 6 months, renewed on each visit. If you do not start a conversation, the session expires after 30 minutes. Your IP address is stored server-side for active conversations as required by applicable law. The provider also processes your name, email address, and any information you choose to include in your messages.

What We Do Not Use

We do not use cookies for advertising purposes. We do not use third-party advertising or cross-site behavioural analytics services (such as Google Analytics). We do not allow third-party advertising networks to set cookies through our Service. Our monitoring and analytics tools are used only for the purposes described above.

Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing ones. Please note that disabling essential cookies may prevent you from using certain features of Plutus.

9. Your Rights

Under the UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Correction — Ask us to correct any inaccurate or incomplete data
  • Deletion — Request that we delete your account and personal data
  • Export — Download your data in a portable format (CSV export is available within the app)
  • Withdraw consent — Where processing is based on consent (such as bank connections or marketing emails), you may withdraw consent at any time without affecting the lawfulness of prior processing
  • Restrict processing — Ask us to limit how we use your data in certain circumstances
  • Object — Object to our processing of your data where we rely on legitimate interests
  • Data portability — Receive your personal data in a structured, commonly used, and machine-readable format

Right to Complain

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

Information Commissioner's Office

Website: ico.org.uk/make-a-complaint

Telephone: 0303 123 1113

For EEA Residents

If you are located in the European Economic Area, you have equivalent rights under the EU GDPR and may lodge a complaint with your local data protection authority.

For Other Jurisdictions

If you are located in another jurisdiction with data protection laws, you may have similar rights under your local laws. This includes, but is not limited to, residents of California (CCPA/CPRA), Canada (PIPEDA), Australia (Privacy Act 1988), and Brazil (LGPD). We are committed to honouring those rights. Please contact us at privacy@plutusfinance.app if you have questions about how your local laws apply to your use of Plutus.

To exercise any of these rights, please contact us at privacy@plutusfinance.app. We will respond to your request within 30 days.

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by Article 33 of the UK GDPR.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing details of the breach, its likely consequences, and the measures we have taken or propose to take to address it.

11. Children's Privacy

Plutus is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take steps to delete that information as quickly as possible. If you believe a child has provided us with their data, please contact us at privacy@plutusfinance.app.

12. International Data Transfers

Plutus is operated from the United Kingdom. Our core application, primary database, financial records, and aggregate analytics data that we operate ourselves are hosted in the United Kingdom.

Some service providers process limited contact details, email content, account identifiers, profile or uploaded-image data, and technical, diagnostic, support, or usage data in the European Economic Area or the United States. Transfers to the EEA rely on UK adequacy regulations. For transfers to the United States, we use the following safeguards as applicable:

  • EU-U.S. Data Privacy Framework and UK Extension. Where a provider has an active certification under the Data Privacy Framework and its UK Extension, we rely on that certification. Certification status can be checked on the Data Privacy Framework participant register.
  • Contractual safeguards. Where the framework does not apply, we use the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum, supported by a transfer risk assessment.

You can request further information about these safeguards, or a copy of the relevant contractual protections, by contacting privacy@plutusfinance.app. Stripe's specific transfer arrangements are described in the Stripe entry in Section 5.

13. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Features such as budget alerts, transaction categorisation, and spending summaries are tools to help you manage your finances — they do not make decisions about you or restrict your access to services.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting a notice within the Plutus app or by sending you an email.

We encourage you to review this policy periodically. Your continued use of Plutus after any changes indicates your acceptance of the updated policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please get in touch:

Email: privacy@plutusfinance.app

Data Controller: Telotek Ltd

Registered Address: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

We aim to respond to all enquiries within 30 days.