Cozzy Security Policy
Version: 1
Last Updated: September 2, 2026
This page answers one question: how safe is my data with Cozzy? The Privacy Policy covers what we collect and why. This page covers how we keep it safe, in ordinary language. You do not need to accept it, and it is not part of our Terms of Service.
Connecting your bank
Cozzy connects through Open Banking, the regulated system that lets you give an app permission to see your accounts. Our partner is Yapily Connect Limited, authorised by the UK's Financial Conduct Authority (reference 827001). You sign in with your own bank, so your bank username, password and PIN never reach us. We can only look: making a payment needs a different permission that we never ask for, so Cozzy cannot move your money. Your bank's permission expires unless you renew it: after 90 days for banks licensed in the UK, and up to 180 days for banks licensed elsewhere in Europe (some are still set to 90 days). The app shows the date for your own connection. You can disconnect at any time in Settings. The digital key that lets us read your accounts is stored scrambled and tied to your connection alone.
Where your data is kept, and how it is protected
Your accounts and files are in Dublin, our servers in Amsterdam, our AI in Belgium, and crash reports in Frankfurt. Everything is encrypted on its way to us and while we store it, and sign-in details on your phone live in your phone's own secure storage. Our database refuses to hand out your records to anything reaching it from outside our app, and our app checks every record is yours before returning it. Staff need a specific named permission for each thing they can do, and every action is written to a record that would show if anyone tried to alter it.
We do not claim your data never leaves Europe. These smaller services run in the United States or worldwide: RevenueCat (whether you have a subscription, never card details), Resend (emails such as password resets), Firebase Cloud Messaging (push notifications; a balance or spending alert may include the amount it is about), Firebase Analytics (only if you opt in), Google Perspective (checks Education Hub comments for abuse), and Talsec (technical checks about the app itself, no account or money information, treated as anonymous while we review that judgement).
Your account
You can add a second sign-in step using an authenticator app, and lock the app with Face ID, a fingerprint or a PIN. Sessions end after 30 days, or 14 days without use. Downloading your data, deleting your account and unlinking a bank each need you to sign in again.
AI features
Switched off unless you turn them on. Before anything goes to Google's AI service in Belgium we remove names, account numbers, card numbers and other identifying details, and we check what comes back. You can switch it off at any time in Settings.
Getting your data, or deleting it
You can download a copy of your data from Settings. You can delete your account in Settings or at cozzy.io/account-deletion; this removes your information from our systems, apart from a few internal records such as the log of how transactions were categorised, which are kept with your identity permanently stripped out.
If something goes wrong
If your personal data is ever exposed, we tell the Irish Data Protection Commission within 72 hours of finding out, unless it is clear the problem poses no real risk to anyone. If it could seriously affect you, we tell you directly and quickly as well. Spotted a security problem? Email security@cozzy.io.
What we have not done yet
No security certificate: Cozzy does not hold ISO 27001, SOC 2 or Cyber Essentials, and our suppliers' certificates are theirs, not ours. No independent security test yet; one is planned. No paid reward scheme for reporting faults. We are a small team, so a named director handles anything that goes wrong rather than a round-the-clock security team.
Contact
security@cozzy.io, privacy@cozzy.io, support@cozzy.io