← Back to Home

Cozzy Security Policy

Version 2 · Effective 3 September 2026

Version: 2

Last Updated: September 3, 2026

Effective: September 3, 2026

This page answers one question: how safe is my data with Cozzy?

Our Privacy Policy covers what we collect and why. This page covers how we keep it safe, in ordinary language. You do not need to accept it, and it is not part of our Terms of Service.


1. The short version

  • We never see your bank login. You sign in with your bank, not with us.
  • We can look, not touch. Cozzy can see your balances and transactions. It cannot move your money.
  • Everything is scrambled. Your data is encrypted on its way to us and while we store it.
  • Kept in Europe. Your accounts, our servers and our AI run in Ireland, the Netherlands and Belgium. Section 3 has the detail.
  • Kept apart. Our systems are built so one person's data cannot be handed to another.
  • You are in charge. You can add a second sign-in step, lock the app, download your data, or delete your account.

2. Connecting your bank

Cozzy connects to your bank through Open Banking, the regulated system that lets you give an app permission to see your accounts. Our partner is Yapily Connect Limited, which is authorised by the UK's Financial Conduct Authority to do this (reference number 827001).

  • Your login stays with your bank. When you connect an account, we send you to your own bank to sign in and approve. Your bank username, password, PIN and security answers never reach us.
  • We can only look. The permission you give covers account information. Making a payment needs a different permission, and we never ask for it, so Cozzy cannot move your money.
  • What we hold. Your account name and number, your balances, and the transactions for the accounts you chose to connect.
  • Permission runs out. Your bank's permission expires unless you renew it: after 90 days for banks licensed in the UK, and after up to 180 days for banks licensed elsewhere in Europe (some are still set to 90 days). The app shows the date for your own connection and reminds you beforehand.
  • You can disconnect whenever you like, in Settings or through your bank. That cuts off access straight away.
  • The keys are locked up. The digital key that lets us read your accounts is stored scrambled, and tied to your connection alone, so it is useless anywhere else.

3. Where your data is kept, and how it is protected

Everything important runs inside Europe:

WhatWhere
Your accounts, sign-in details and filesDublin, Ireland
Our app serversAmsterdam, Netherlands
Our AI featuresBelgium
Crash reportsFrankfurt, Germany

How it is protected:

  • On the way to us, every connection is encrypted, the same protection your bank's website uses. Browsers are told never to connect to us any other way.
  • While we store it, our hosting provider encrypts everything on disk, and your bank keys get a second layer on top.
  • On your phone, sign-in details live in your phone's own secure storage, never in an ordinary file.
  • Between people, our database refuses to hand out your records to anything reaching it from outside our app, and whenever our app fetches something it checks the record is yours before showing it to you.
  • Inside our team, staff need a specific named permission for each thing they can do, and every action is written to a record that would show if anyone tried to alter it.

A few supporting services, such as subscriptions, email delivery and push notifications, run outside Europe under standard data-transfer contracts. The Privacy Policy lists each one.


4. Your account

  • Passwords are never stored in a readable form.
  • A second sign-in step using an authenticator app is available in Settings. We recommend turning it on.
  • An app lock can require Face ID, a fingerprint or a PIN every time you open Cozzy. It is off unless you switch it on.
  • Sessions end after 30 days, or after 14 days without use, whichever comes first.
  • The riskiest actions need you to sign in again, even if you are already signed in: downloading your data, deleting your account, and unlinking a bank.
  • Lost your phone? Sign out of all devices in Settings. That ends your session here and tells your other devices to sign out. Change your password too.

5. The app on your phone

  • If something is tampering with the app, it will not run. Cozzy checks for tools that try to alter how it behaves.
  • A jailbroken or rooted phone still works. We make a note of it so we can spot patterns, but we do not lock you out. It is your phone.
  • Your screen is hidden when you switch apps, so balances do not show in the app carousel. On Android this also blocks screenshots while Cozzy is not the app you are using.

6. Our own systems

  • Limits on requests stop any one user or machine from overloading the service for everyone else.
  • Our web pages carry the standard protections against being embedded in someone else's site or leaking where you came from. Our app connections only accept browser requests from addresses we have listed.
  • We watch our building blocks. The outside code we rely on is scanned for known weaknesses; a serious one stops the app and our servers from being built at all. The admin dashboard is scanned on a schedule.
  • Crash reports go to a European service. Personal details are stripped out first, your IP address is never sent, and your account is identified only by a scrambled code.
  • Backups of the database run automatically.

7. AI features

Cozzy's AI assistant and automatic categorisation are switched off unless you turn them on. When you do:

  • We take the identifying bits out first. Before anything goes to Google's AI service in Belgium, we remove names, account numbers, card numbers and other identifying details from your transaction descriptions. Where we can, we send totals instead of individual items.
  • We check what comes back before showing it to you.
  • Google works for us here, on our instructions only. It does not use your information for advertising.
  • You can switch it off in Settings at any time. Nothing more is sent once you do.

This is designed to keep identifying details away from the AI. We do not claim it is flawless. The Privacy Policy explains the AI in full, including your right to ask a human to look at anything the AI worked out about you.


8. Getting your data, or deleting it

  • Download it. You can get a copy of your data from Settings. The law gives you this right.
  • Delete it. You can delete your account in Settings, or follow the steps at cozzy.io/account-deletion. This removes your information from our systems, including bank connections, transactions and anything the AI worked out. A few internal records are kept, such as the log of how transactions were categorised, but your identity is permanently stripped out of them so they can no longer point back to you.
  • Both of these ask you to sign in again first.
  • How long we keep things is listed by category in the Privacy Policy.

9. If something goes wrong

  • If your personal data is ever exposed, we tell the Irish Data Protection Commission within 72 hours of finding out, unless it is clear the problem poses no real risk to anyone. If it could seriously affect you, we tell you directly and quickly as well.
  • Spotted a security problem? Email security@cozzy.io. We read every report and reply to genuine ones.

10. Version history

  • v2 (September 3, 2026): Section 3 shortened and sections renumbered.
  • v1 (September 2, 2026): First published.

11. Contact

  • Security: security@cozzy.io
  • Privacy: privacy@cozzy.io
  • Anything else: support@cozzy.io
  • Post: Cozzy Finance Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland

© 2026 Cozzy. All rights reserved.