Skip to content
Gemma Gemma
Features Pricing Privacy
Sign in Get started
Features Pricing Privacy
Sign in Get started
Privacy Policy Terms of Service Cookie notice

Privacy Policy

Last updated 8 September 2026

This policy explains what personal data Gemma holds, why we hold it, and the rights you have. Gemma is a personal household budget app. Bracketed fields such as Gemma are placeholders for the operator to complete.

Who we are

Gemma is operated by Gemma (“we”, “us”).

Registered office:
Company number:
Privacy contact: TBC

We are based in the United Kingdom. This policy is written for UK GDPR and the Data Protection Act 2018. We do not claim registration with the Information Commissioner’s Office on this page.

The data we hold

Depending on how you use Gemma, we may hold:

  • Account. Username, email address, hashed password (Argon2), date joined, last sign-in, and whether email is verified.
  • Profile. First and last name if you add them in Settings, optional authenticator-app MFA (the secret is encrypted at rest), and your default currency.
  • Email verification. A hashed 6-digit code, expiry time, and attempt count while you confirm a new account. Codes expire after about 20 minutes and are removed once verification succeeds.
  • Banking (TrueLayer). If you connect a bank, we store encrypted TrueLayer access and refresh tokens, connection status, provider name, linked account labels, masked account identifiers, balances, and imported payments.
  • Household money data. Transactions, categories, learned categorisation rules, budgets, spend-kind tags, recurring series, savings goals, notifications, and weekly digest summaries.
  • Agent. Chat messages live in your signed-in session (not a separate Gemma chat database). We also store a monthly token usage count for the spending Agent. Prompts and tool results are sent to Google Gemini so the Agent can answer. Weekly digest narratives also use Gemini.
  • Billing. If you start Gemma Premium, Stripe holds payment details. Gemma stores subscription status, period end, and Stripe customer/subscription identifiers so we can unlock Premium and cancel billing.
  • Technical. Server-side session records (including Agent chats while you are signed in), CSRF tokens, flash messages, and a gemma_cookie_consent cookie that records whether you accepted required cookies. We do not run advertising or analytics cookies. See the cookie notice.

We do not use your Gemma data to train a public AI model. Gemini processes Agent and digest requests in order to provide those features.

Why we use it

  • To create and secure your account, including email verification and optional MFA.
  • To import, categorise, and display your household finances.
  • To run Premium features you choose to use (Goals, Cashflow, Digest, Agent).
  • To take payment for Premium through Stripe and keep entitlement in sync.
  • To send transactional email (verification codes) via Amazon SES in production.
  • To convert amounts between currencies using published FX rates (Frankfurter / ECB), fetched server-side.

We rely mainly on contract (providing the service you signed up for) and, where needed, legitimate interests (keeping the service secure). Open Banking access is granted by you through TrueLayer. Stripe processes card details as an independent controller/processor under its own terms when you pay.

Processors and other services

  • TrueLayer — Open Banking connections and transaction import.
  • Stripe — Checkout, Customer Portal, invoices, and subscription webhooks.
  • Amazon Web Services — hosting. Production email uses Amazon SES (default region eu-west-2).
  • Google Gemini — spending Agent replies and weekly digest write-ups.
  • Google Fonts — the Inter typeface loaded on Gemma pages.

Gemini and some other providers may process data outside the UK. Where that happens we rely on the provider’s contractual safeguards. AWS email and typical Gemma hosting are configured for the UK (eu-west-2) unless the operator changes that.

Export

Signed-in users can download a JSON file from Settings → Your data (“Export personal data”). That file includes username, email, profile name, dates, whether MFA is enabled, default currency, a subscription status summary, linked bank labels, account names, and counts of household data. It does not include password hashes, MFA secrets, TrueLayer tokens, account numbers, sort codes, or Stripe IDs.

Full payment history is a separate CSV from the Transactions page. The JSON export points at that download; it does not dump every transaction row.

Retention and deletion

We keep account and household data while the account exists. Email verification challenges are short-lived. Sessions last until you sign out or they expire (Django’s default session lifetime is two weeks). Agent chats go with the session.

Settings → Your data → Delete account permanently removes your Gemma user and cascaded household data: bank connections (including encrypted TrueLayer tokens), transactions, categories, budgets, goals, digests, Agent usage counts, notifications, and the local billing record. Stored sessions for that user are flushed so an old login cookie cannot stay signed in. You are signed out and cannot sign back in with those credentials.

If a Stripe subscription is on file and Stripe is configured, Gemma asks Stripe to cancel it immediately so billing does not continue. The Stripe Customer may remain on Stripe so invoice history is not destroyed. Gemma does not delete that Customer. If Stripe is unreachable, local deletion still goes ahead; leftover Customers can be removed in the Stripe Dashboard.

Processed Stripe webhook event IDs may remain as technical idempotency records. They are not a copy of your household data.

Your rights

Under UK GDPR you can ask to access, correct, or erase personal data, object to or restrict certain processing, and complain to the ICO. In Gemma you can:

  • Edit your name and currency in Settings.
  • Export the JSON described above, and download transaction CSV from Transactions.
  • Delete your account from Settings, which erases Gemma-held household data as described.
  • Disconnect individual bank accounts from the Accounts tab without deleting the Gemma login.

For anything the product screens do not cover, email TBC. We may need to verify that the request comes from the account holder.

Children

Gemma is a household finance product. It is not aimed at children. Do not create an account for someone who cannot lawfully use Open Banking or enter a contract for this service.

Changes

We may update this policy when the product changes. The date at the top will change. Continued use after an update means the new policy applies to that use.

Gemma Gemma

Personal budget manager.

Features Pricing Privacy Sign up Sign in Privacy Policy Terms Cookies

© 2026 Gemma.