Privacy Policy
Last updated 11 September 2026 · Applies to the Duolign app and duolign.co.uk
Duolign is a trading name of JeffNet Ltd ("Duolign", "we", "us"), a company registered in England & Wales (company no. 16842613). We are the data controller for the personal data described in this policy. This policy explains what we collect, why, and the choices and rights you have — including how to delete everything, yourself, at any time.
1. What we collect
Account & household data, which you give us directly: your email address, a display name, your household's structure (you and your partner), how you split shared costs, your payday pattern, and the bills, pots, goals and debts you set up.
Financial data, from the bank accounts you choose to connect (see below): balances and transaction history for those accounts.
Device & usage data: a push-notification token (so we can notify you), basic device type, and app diagnostics (crash and error logs) so we can fix problems.
We do not collect your location, your contacts, or browsing history outside the app.
2. Open Banking data, specifically
When you connect a bank account, you are securely redirected to your bank to authorise access. That authorisation is brokered by our regulated Open Banking partner, an FCA-authorised Account Information Services Provider (AISP) — Duolign operates under their regulatory permissions rather than holding its own.
This access is read-only. Duolign can see the balance and transaction history of the accounts you authorise; it can never initiate a payment or move money. Duolign never sees or stores your online banking username, password, or PIN — those are entered on your bank's own site or app, never ours.
You can revoke this access at any time, either in your banking app or from Duolign's Settings — disconnecting stops all future access immediately.
3. Why we use it, and our legal basis
- To provide the service (performance of our contract with you): calculating your household's payday split, tracking bills and debts, running the projections you ask for, and the two-person approval workflow for shared changes.
- To connect your bank (your explicit consent, given at the point of connecting, separately from this policy): fetching balances and transactions via our AISP partner.
- To keep the service secure (our legitimate interest): detecting misuse, abuse, and unauthorised access attempts.
- To contact beta applicants (your consent): if you join our closed-beta waiting list on this website, we use your email address only to tell you when a place opens up.
We do not use your data for advertising, and we do not sell personal data to anyone, ever.
4. Who sees it
Your partner sees the data your household shares by design — that's the point of a joint budget. Anything you mark private stays private: it is stored in a separate partition your partner's account cannot read, enforced at the database level, not just hidden in the app's interface.
We share data with a small number of infrastructure providers who process it on our behalf, under contract, and only as needed to run the service:
- Supabase — our database and authentication provider, hosted in the EU (AWS, Ireland).
- Our Open Banking AISP partner — brokers the read-only bank connection described above.
- Google Firebase — delivers push notifications to your device.
None of these providers may use your data for their own purposes. We do not share data with data brokers, advertisers, or any other third party.
5. How long we keep it
We keep your household's data for as long as your household is active, so the app keeps working correctly. If you close your bank connection, the transaction history already fetched is kept (it's the record of what happened) unless you delete your account or household outright. Beta waiting-list emails are kept until the beta ends or you ask us to remove them.
6. Your rights — including deleting everything yourself
Under UK GDPR you have the right to access, correct, delete, restrict, or receive a copy of your personal data, and to object to certain processing. For most of these, you don't need to email anyone:
Settings → delete my account permanently erases your login and your private data; if your partner has joined the household, it stays for them.
Both take effect immediately and cannot be undone. We recommend exporting your data first — the same screen offers a download.
For anything else — a copy of your data, a correction, or a question about how we've used it — email privacy@duolign.co.uk. We'll respond within one month.
7. Security
See our Security & Encryption page for the detail: encryption in transit and at rest, how bank connections work, and biometric app protection.
8. International transfers
Your data is primarily stored within the EU. Google Firebase (push notifications) may process limited device data outside the UK/EEA; where it does, this happens under Google's standard contractual clauses and equivalent safeguards recognised under UK GDPR.
9. Cookies & this website
This marketing website (duolign.co.uk) does not use tracking or advertising cookies. If you join the beta waiting list, your email address is sent directly to our database provider to be stored; no analytics or third-party tracking scripts run on this page. The Duolign app itself is a native mobile app and does not use browser cookies.
10. Children
Duolign is intended for adults (18+) managing a shared household. We do not knowingly collect data from anyone under 18.
11. Changes to this policy
We'll update the date at the top of this page when this policy changes, and tell you in-app if a change is material.
12. Contact & complaints
Questions or requests: privacy@duolign.co.uk. If you're unhappy with how we've handled your data, you can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Duolign