TheUp TheUp
Features How it works Privacy Terms
Legal Notice

Privacy Policy

Last updated: 10 August 2026

We are 7Stockapp OÜ (registry code 16976938), Lahtri tn 12, 15551 Tallinn, Estonia ("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose and safeguard information in connection with our mobile application TheUp, related website and backend APIs (together, the "Services"). We are the data controller for personal data processed to provide the Services.

Please read this Policy carefully. It describes the choices available in the app and the rights you may have under applicable data protection law.


1. Personal Data We Collect

Depending on the features you choose to use, we may process the following categories of personal data:

1.1 Account and Identification Data

  • Your email address and passwordless sign-in records. TheUp does not ask you to create an account password.
  • One-time verification-code metadata such as expiry, attempt count and status. Verification codes are stored as keyed hashes rather than readable codes.
  • If you use Google or Apple sign-in, the identity information needed to verify that sign-in through Firebase. We do not receive your Google or Apple password.
  • Basic profile data, including your encrypted first and last name, account status and account creation date.

1.2 Usage and Service Data

  • Feature interactions and operational events needed to run and troubleshoot the Services.
  • Your selected AI provider, AI token usage, subscription plan, entitlements, limits and related usage statistics.
  • Security and abuse-prevention data such as IP address, user agent, authentication events and blocked-request records.

1.3 Financial Data You Provide

  • Accounts and balances you create in the app, such as cash, bank, credit card, savings and investment accounts. We do not connect to your bank; you enter or import this information yourself.
  • Transactions, including amount, date, category, merchant, description, notes, tags, split details and recurring-payment settings.
  • Plans, including budgets, savings goals, debts, debt payments, payoff strategies and scenarios.
  • Subscriptions, including renewal dates, detected recurring charges and price history.
  • Investment holdings, including instrument, quantity and cost basis. We do not execute trades and are not a broker.
  • Currencies and exchange-rate choices, including manual rate overrides you enter.
  • Statements and receipts you upload in PDF, image or CSV form. See Section 6 for file retention.
  • Free-text notes, financial goals, AI chat messages, prompts and conversation history.

We do not ask for, and you should never enter, your full card number, online-banking password or one-time banking codes. Where an account number appears in an uploaded file, we take steps to mask it in extracted text before storage.

1.4 Device and Notification Data

  • Device identifiers, notification tokens such as FCM/APNs tokens, app version and language settings.
  • Your device time zone and country code, where provided, to schedule notifications in your local time and choose the language of service emails.
  • Your notification preferences, delivery window, frequency and delivery history.
  • Technical information sent by your device, such as operating system and diagnostic error data.

1.5 Support and Communication Data

  • Messages you send through in-app support or email, including their subject and content.
  • Contact details you choose to provide when requesting support.

1.6 Payment and Subscription Data

  • Purchases and subscriptions are processed by the Apple App Store or Google Play. We do not receive or store your full payment-card details.
  • From our billing provider, such as RevenueCat, we may receive subscription status, entitlements, product identifiers, country and purchase, expiry or renewal dates.

1.7 AI Skills and Connected External Tools

  • If you create an AI Skill, we store its name, settings and encrypted instructions. When you activate it, those instructions may be included in requests sent to your selected AI provider.
  • If you connect a compatible external tool server, we store its name, URL, declared tool definitions, your allowlist and connection-health metadata. Calls to that service are made from your device.
  • Credentials for a connected tool are kept in secure storage on your device and are not sent to or stored by TheUp’s backend.
  • When you allow a tool call, the request goes to the third-party service you configured. Its response returns through the app and may be sent to TheUp and your selected AI provider so the assistant can complete your request. That third party’s own terms and privacy policy apply.
  • Encrypted temporary state needed to continue an approved tool call is automatically expired after 10 minutes.

2. How We Use Personal Data

  • Provide and maintain the Services, including authentication, device sync and account management.
  • Run personal-finance features, including balances, budgets, subscription tracking, debt scenarios, goals, forecasts, safe-to-spend calculations and net-worth summaries.
  • Deliver AI assistance, including answering questions, suggesting categorisations and preparing actions for you to review. AI-created changes are not committed without the confirmation required by the app.
  • Process imports by converting statements and receipts into draft transactions for you to review. An imported row is not saved as a transaction until you confirm it.
  • Run the Skills and external tools you select and return their results to the assistant.
  • Send service notifications, reminders and insights in line with your preferences and local schedule.
  • Provide household sharing. Only data types you choose to share become visible to active household members. Leaving ends that sharing and does not move, copy or delete your own records.
  • Manage billing and access, including free or premium entitlements and usage limits.
  • Provide support, secure the Services and prevent misuse, including investigating errors, fraud and abusive traffic.
  • Improve the Services using troubleshooting information and aggregated usage patterns.
  • Meet legal obligations, respond to lawful requests and establish or defend legal claims.

3. Legal Bases for Processing (EEA/UK Users)

Where the GDPR or similar law applies, we rely on:

  • Performance of a contract to create your account and provide the features you request under our Terms.
  • Legitimate interests to secure, support and improve the Services, prevent abuse and send non-promotional service messages, balanced against your rights.
  • Consent where law requires it, such as for optional marketing or non-essential device permissions. You may withdraw consent without affecting earlier lawful processing.
  • Legal obligations where processing or retention is required by law.

4. Cookies and Similar Technologies

Our public website does not currently require non-essential advertising cookies. Essential session or security technologies may be used where a web service requires sign-in. The mobile app generally uses secure authentication tokens, device identifiers and notification tokens rather than browser cookies. If we introduce non-essential cookies, we will provide any notice and choice required by law.

5. Third-Party Services and International Transfers

We use service providers to operate the Services, including:

  • Cloud hosting and infrastructure providers for servers, databases and content delivery.
  • Firebase and notification providers for supported sign-in methods and device notifications.
  • RevenueCat and the App Stores for subscription status, purchases and billing.
  • AI providers, including OpenAI and Google, to provide the AI feature you request, categorise information and process statements or receipts. We send the content needed for that request. We do not use your financial content to train our own general-purpose AI model; third-party providers process request content under their applicable business/API terms.
  • Market and exchange-rate providers, such as Binance, Yahoo Finance, TEFAS and Frankfurter. Price requests use an instrument or currency symbol and do not include your identity, holdings or quantities.
  • External tool services you choose to connect. These are independent third parties, and you decide which tools may be used.
  • Security and operational providers that help us detect abuse and maintain stability.

Providers acting for us may process personal data only for the relevant service and under applicable data-protection requirements. Some providers may operate outside the European Economic Area. Where a restricted international transfer occurs, we use an appropriate legal mechanism, such as an adequacy decision or standard contractual clauses, as required by law. Services you connect independently process data under their own terms.

6. Data Retention

Original statements and receipts are automatically deleted within 24 hours, whether or not processing succeeds. We retain structured information you choose to confirm, rather than the original file.

Temporary encrypted state used to resume an external-tool request expires after 10 minutes. Household audit records identifying who changed a shared record and when, but not the record content, are retained for 90 days.

Other data is kept only for as long as needed for the purposes in this Policy, including:

  • account and financial data while your account remains active;
  • short-lived sign-in and invitation records until they expire or are no longer needed;
  • records required to answer disputes, protect the Services or comply with tax, accounting and other legal duties.

We may retain properly anonymised or aggregated information that no longer identifies you.

7. How We Protect Data

We use technical and organisational safeguards designed for the sensitivity of the data, including:

  • Encryption of sensitive text fields at rest, including account names, transaction descriptions, merchant names, notes and AI Skill instructions.
  • An optional biometric app lock to reduce access by someone holding your unlocked device.
  • Secure on-device storage for credentials used with external tools; those credentials are not stored by our backend.
  • Application logging designed to exclude transaction amounts, descriptions and email addresses.
  • Access controls, security-event records and abuse-prevention measures.

No system is completely secure. Keep access to your email, social sign-in account and device protected, and contact us if you suspect unauthorised access.

8. Your Rights and Choices

You can use Settings → Download my data to export your transaction data and Settings → Delete account to request permanent deletion of your account and financial data, subject to any legal retention requirement. Notification, household sharing, AI provider, Skill and external-tool permissions can also be changed in the app.

Depending on your jurisdiction, you may have the right to:

  • access, correct or delete personal data;
  • restrict or object to certain processing;
  • receive portable data where applicable;
  • withdraw consent where processing relies on consent; and
  • complain to a competent supervisory authority.

Contact us to exercise a right. We may need to verify your identity before responding.

9. Automated Processing

TheUp uses rules and AI to suggest categories, detect possible subscriptions, prepare insights and produce forecasts. These outputs are advisory and may be wrong. TheUp does not make solely automated decisions that produce legal or similarly significant effects for you.

10. Children’s Privacy

The Services are not directed to children under 16, or any higher minimum age required in their jurisdiction. If we learn that we collected a child’s personal data without the authorisation required by law, we will take appropriate steps to delete it and restrict or close the account.

11. App Store and Google Play

If you obtain TheUp through Apple App Store or Google Play, the store’s own terms and privacy policy also apply. The stores and our billing provider independently process information such as country, device information, purchase history and subscription status.

12. Changes to This Policy

We may update this Policy as the Services or legal requirements change. We will post the new version here, change the date above and provide an additional app or email notice where appropriate.

13. Not Financial Advice

TheUp is a personal budgeting and tracking tool. It is not a bank, broker, payment institution or investment adviser. Nothing in the app is investment, tax or legal advice. Market prices may be delayed, and decisions you make using the Services remain your own.

14. Contact Us

For questions or privacy-rights requests, contact:

7Stockapp OÜ
Lahtri tn 12
15551 Tallinn
Estonia
Email: [email protected]

TheUp TheUp

An AI budget assistant. Not a bank, broker or investment adviser — nothing here is financial advice.

Product

Features How it works

Legal

Privacy Policy Terms of Use EULA
© 2026 TheUp by 7Stockapp OÜ. All rights reserved.