Privacy Policy

How aihtax processes personal data

URL: /privacy · Last updated: 25 September 2026

This Privacy Policy explains how aihtax ("we", "us", or "our") collects, uses, stores, and shares personal data when you use our website and bookkeeping / Making Tax Digital (MTD) services (the "Service"). It is written for users in the United Kingdom and reflects the UK GDPR and the Data Protection Act 2018.

By creating an account or using the Service you acknowledge this policy. If you do not agree, please do not use the Service.

1. Who we are

The data controller for personal data processed through the Service is Sebastian Toke-Nichols, trading as aihtax. For privacy questions and requests, email [email protected].

If we appoint a Data Protection Officer or nominate a representative, we will update this policy and publish those details here.

2. Scope

This policy covers personal data relating to:

  • Account holders, invited users, and workspace members
  • Agents and client users who access shared workspaces
  • Visitors to our marketing or application sites who submit forms or create accounts

Business and financial records you upload may include personal data about third parties (for example tenants, suppliers, or employees). You are responsible for ensuring you have a lawful basis to provide that data to us for processing on your behalf as part of the Service.

3. Data we collect

Depending on how you use the Service, we may process:

  • Account identity: name, email address, password hash, optional two-factor authentication secrets, company / trading name, role within a workspace
  • Business and tax context: business sources, categories, VAT settings, tax-year preferences, and related configuration
  • Bookkeeping content: receipts and documents you upload, OCR / extraction results, bank transactions, matches, ledgers, notes, and exports you generate
  • HMRC / MTD data: OAuth tokens (encrypted), business identifiers you connect, obligations, and filings you initiate
  • Integrations: tokens and metadata for optional connections (for example Open Banking, accounting export, email ingest, or payment providers) when you enable them
  • Billing: subscription status, invoices, and payment-provider identifiers (card details are handled by our payment processor, not stored by us in full)
  • Technical and security data: IP address, device / browser metadata, session identifiers, approximate location derived from IP, audit logs, and error diagnostics when enabled
  • Communications: support messages, feedback, and emails we send or receive about your account

4. How we collect data

  • Directly from you when you register, configure settings, or upload content
  • Automatically from your browser or device when you use the Service
  • From integrations you connect (for example HMRC, banks, email, or Stripe)
  • From workspace owners or agents who invite you or share a workspace with you

5. Purposes and legal bases

We process personal data only where we have a lawful basis, including:

  • Contract: to create and manage your account, provide bookkeeping and MTD tooling, and deliver features you request
  • Legitimate interests: to secure the Service, prevent abuse, improve reliability, and understand product usage in a privacy-respecting way (balanced against your rights)
  • Legal obligation: where we must retain or disclose information to comply with applicable law
  • Consent: for optional diagnostics / cookies where required, and for any other processing we clearly ask you to opt into (you may withdraw consent at any time)

Do not upload documents or data you are not authorised to process. You remain responsible for reviewing figures before any HMRC submission.

6. AI and automated processing

Where enabled for your deployment, we may use automated tools (including OCR and optional AI models) to extract fields from receipts, suggest categories, or assist matching. These features support your bookkeeping workflows; they do not replace your review, and they are not used to make solely automated decisions that produce legal or similarly significant effects about you without human involvement.

7. Sharing and processors

We do not sell personal data. These processors handle it on our behalf, under written contracts, and only to provide the Service:

  • Fly.io

    Does
    Runs the aihtax application and its background processing
    Data
    Everything we process, while it is being processed
    Where
    United Kingdom (London)
  • Neon

    Does
    Our database
    Data
    Account, business and bookkeeping records
    Where
    European Union
  • Upstash (through Fly.io)

    Does
    Queue for background work
    Data
    References to work in progress, such as which document to read
    Where
    United Kingdom (London)
  • Cloudflare

    Does
    Delivers the website, stores the documents you upload, and forwards email sent to our privacy, security and accessibility addresses
    Data
    Documents you upload, emails you send us, and visitors’ IP addresses
    Where
    Documents: Western Europe. Website: Cloudflare’s global network
  • Google (Gmail)

    Does
    The mailbox our privacy, security and accessibility addresses forward to
    Data
    Emails you send to those addresses, and your email address
    Where
    Google’s global infrastructure, which includes the United States
  • Google (Gemini API)

    Does
    Reads the text of receipts and invoices to fill in supplier, date and amount, and suggests categories
    Data
    Text read from your receipts and invoices, and supplier names and descriptions of transactions — not the images themselves
    Where
    European Union
  • Resend

    Does
    Sends account emails, such as invitations and password resets
    Data
    Recipients’ email addresses and the message
    Where
    European Union (Ireland)
  • Sentry

    Does
    Error diagnostics
    Data
    Details of a request that failed, which may include an email or IP address. Error reports from your browser only if you allow them
    Where
    European Union
  • PostHog

    Does
    Product analytics, only if you accept analytics on the cookie banner
    Data
    A pseudonymous account identifier, pages visited and actions such as signing in — not your name, email address, receipts, transactions or filings
    Where
    European Union

We also share data with:

  • HMRC, when you connect Making Tax Digital and submit or retrieve information. HMRC is not our processor: it receives your filings as the tax authority, under its own responsibilities.
  • Optional integration providers you choose to connect (for example Open Banking, payment, or export tools)
  • Professional advisers or authorities where required by law, or to protect our rights, users, or the Service
  • Successors in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards

Workspace owners and authorised agents may access personal data within shared workspaces according to the permissions you configure.

8. International transfers

Your account, business and bookkeeping data, and the documents you upload, are stored and processed in the United Kingdom and the European Economic Area, which the UK recognises as giving adequate protection. Two things can go further: Cloudflare delivers the website from its global network, so your connection may be handled close to wherever you are browsing from; and emails you send to our privacy, security or accessibility addresses are kept in a Gmail mailbox, which Google may store in the United States. Where a processor stores or accesses personal data outside the UK or EEA, we rely on the safeguards in its terms.

9. Retention

We retain personal data for as long as needed to provide the Service and for a reasonable period afterwards to resolve disputes, enforce agreements, and meet legal or tax record-keeping needs. You may request deletion of your account; we will delete or anonymise personal data unless we must retain it (for example completed HMRC filings metadata, billing records, or security logs). Content you chose to keep for tax compliance may need longer retention under UK law — you should export records you are required to keep before closing an account.

10. Security

We implement technical and organisational measures appropriate to the risk, including encrypted transport (TLS), access controls, password hashing, and encryption of sensitive tokens (such as HMRC OAuth credentials) where the product implements encryption. No method of transmission or storage is completely secure; please use a strong unique password and enable two-factor authentication when offered.

11. Your rights

Under UK data protection law you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure in certain circumstances
  • Restrict or object to certain processing
  • Receive a portable copy of data you provided (data portability)
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk

To exercise these rights, email [email protected]. We may need to verify your identity before responding. HMRC filings you already submitted remain subject to HMRC rules and cannot be recalled through this product alone.

12. Cookies and similar technologies

We use essential browser storage to keep you signed in and operate the Service. Optional product analytics (PostHog) and error diagnostics (Sentry) run only if you accept them on the cookie banner, and neither is loaded if you choose essential only. Details are in our Cookie Notice.

13. Children

The Service is intended for business and adult users. We do not knowingly collect personal data from children under 16. If you believe a child has provided data, contact us so we can delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be notified in-product or by email. Continued use after an update constitutes acceptance of the revised policy where permitted by law.

15. Contact

Privacy questions and requests, including access, correction and deletion: email [email protected]. You do not need an account to write to us. Please include enough detail for us to locate your account (for example the email you registered with).

Security problems: email [email protected]. You do not need an account with us to report one. Our policy, and what we commit to in return, is published at /.well-known/security.txt.

See also our Cookie Notice and Terms and Conditions.

Back to signup