Legal

Privacy Notice

Last updated: 14 June 2026

This Privacy Notice explains how personal data is collected, used, stored, and shared in connection with the Nibella website, app, and related services.

1. Who we are

Nibella is a product operated by Formiti Data International UK Ltd. For the purposes of applicable data protection law, the operator of Nibella will usually be the controller of the personal data described in this notice.

Operator details
Formiti Data International UK Ltd
Grosvenor House, 11 St Pauls Square
Birmingham B3 1RB
United Kingdom
Email: hello@nibella.ai

If the final operator details or contact arrangements change before launch, this notice should be updated before publication.

2. What this notice covers

This notice applies to personal data processed through:

  • the Nibella website;
  • the Nibella app and user account area;
  • communications with users and prospective users;
  • marketing pages, blog pages, and waitlist or contact forms; and
  • connected product features that help users identify recurring bills, subscriptions, savings opportunities, and related alerts.

3. The personal data we may collect

Depending on how a person uses Nibella, the following categories of personal data may be processed:

A. Identity and account data

  • name;
  • email address;
  • login credentials or authentication identifiers;
  • account status and subscription plan;
  • support history and account preferences.

B. Contact and communications data

  • messages sent through contact forms or support channels;
  • email subscription preferences;
  • records of product, service, or support communications.

C. Technical and usage data

  • IP address;
  • browser type and device information;
  • approximate location derived from technical data;
  • pages viewed, app events, interaction patterns, and referral sources;
  • cookie, analytics, and session-related information where used.

D. Financial and account-information data

If a user chooses to connect a bank or payment account through an authorised account information provider, Nibella may process:

  • account identifiers and account type information;
  • transaction history made available through the connection;
  • merchant or payee information;
  • recurring payment patterns;
  • subscription, billing, and renewal signals inferred from transaction data;
  • estimated savings opportunities and coaching outputs derived from that data.

Nibella is intended to use read-only access for this purpose. It is not designed to move money or initiate payments unless separate functionality is expressly introduced and separately disclosed.

E. Consent and privacy-related data

Where relevant product features are used, Nibella may also process:

  • records of user consents or consent withdrawals;
  • privacy preference settings;
  • marketing-permission history;
  • related compliance and audit logs.

4. How personal data is used

Personal data may be used to:

  • provide and operate the website, app, and related services;
  • create and manage user accounts;
  • connect authorised financial accounts and retrieve account information with user permission;
  • detect recurring bills, subscriptions, and price-rise risks;
  • generate alerts, savings suggestions, and coaching outputs;
  • process subscriptions, billing, and account administration;
  • respond to enquiries and provide customer support;
  • improve service quality, security, reliability, and product design;
  • send service messages and, where permitted, marketing communications;
  • comply with legal, regulatory, tax, accounting, fraud-prevention, and security obligations;
  • establish, exercise, or defend legal claims.

5. Lawful bases for processing

Depending on the context, personal data may be processed on one or more of the following lawful bases:

  • Contract — where processing is necessary to provide the service requested or to take steps at the user's request before entering into a contract.
  • Consent — where the law requires consent, or where a user chooses to connect data sources, receive marketing, or enable optional features.
  • Legitimate interests — where processing is necessary for legitimate business interests such as operating and improving the service, preventing misuse, securing systems, understanding usage, and communicating with users, provided those interests are not overridden by data protection rights.
  • Legal obligation — where processing is needed to comply with legal or regulatory obligations.

Where consent is relied on, it can usually be withdrawn at any time, although withdrawal will not affect the lawfulness of processing carried out before withdrawal.

6. Open banking and connected account data

If Nibella uses an authorised open banking or account information service provider to retrieve transaction or account data, the provider will act under its own legal and regulatory framework and may provide its own privacy information.

When a user connects an account:

  • the connection is made with the user's express action and permission;
  • the user's bank or authorised provider controls the authentication journey;
  • Nibella receives data made available through that authorised connection;
  • access should remain read-only unless clearly stated otherwise;
  • consent and access periods may expire and require renewal.

Users should review both this notice and the relevant connected-provider information before authorising a connection.

7. Marketing and blog content

Nibella may send newsletters, product updates, educational content, or promotional messages where permitted by law. Marketing can be opted out of at any time by using the unsubscribe function or by contacting the operator.

Blog content may include analytics, page-performance information, and standard website interaction data to help understand readership and improve content quality.

8. Cookies and analytics

Nibella may use cookies or similar technologies for core site functionality, performance, analytics, security, and user experience. A separate cookie notice or cookie settings tool may be provided where required.

Where non-essential cookies or similar technologies are used, they should be activated only in line with applicable consent requirements.

9. Sharing personal data

Personal data may be shared with trusted service providers and partners where reasonably necessary, including providers of:

  • hosting and infrastructure;
  • analytics and monitoring;
  • authentication and user management;
  • email delivery and support operations;
  • payments and subscription billing;
  • open banking or account information connectivity;
  • security, fraud monitoring, legal, and compliance services.

Personal data may also be disclosed:

  • where required by law, regulation, court order, or competent authority;
  • in connection with legal claims or investigations;
  • as part of a business sale, merger, investment, restructuring, or acquisition, subject to appropriate confidentiality and lawful handling.

Nibella does not state in this notice that personal data is “sold” as a commercial data asset. If any data-sharing model materially changes, this notice must be updated before that change takes effect.

10. International transfers

Some service providers may process personal data outside the UK or EEA. Where that happens, appropriate safeguards should be used where legally required, such as adequacy regulations, standard contractual clauses, or equivalent mechanisms.

11. Data retention

Personal data is kept only for as long as reasonably necessary for the purposes described in this notice, including for service delivery, records management, security, dispute handling, and legal or regulatory compliance.

Retention periods may vary depending on:

  • the nature of the data;
  • whether an account remains active;
  • applicable financial, tax, or legal retention requirements;
  • security and audit needs;
  • whether deletion has been requested.

12. Security

Reasonable technical and organisational measures should be used to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. No internet-based system can be guaranteed completely secure, so users should also take care to protect their credentials and devices.

13. User rights

Depending on location and applicable law, users may have rights to:

  • request access to personal data;
  • request correction of inaccurate data;
  • request deletion of personal data;
  • object to certain processing;
  • request restriction of processing;
  • request portability of data provided by them;
  • withdraw consent where processing is based on consent;
  • complain to a supervisory authority.

Requests can be submitted by clicking here and completing the DSAR Form.

14. Children

Nibella is not intended for use by young children. If it becomes known that personal data has been collected from a child in a way that requires parental consent and that consent was not properly obtained, steps should be taken to delete or otherwise lawfully handle that data.

15. Changes to this notice

This notice may be updated from time to time to reflect legal, technical, operational, or product changes. The latest version should always be available on the Nibella website, with the revision date shown at the top.

16. Contact

Questions, complaints, or privacy requests should be sent to:

hello@nibella.ai

If a dedicated privacy contact address is introduced later, this section should be updated accordingly.