How BankScan AI handles your data.
BankScan AI ("we", "us") provides an AI-powered tool that converts bank statements and receipts into spreadsheet formats, keeps simple GBP bookkeeping records for one owner-operated UK sole trade, individual property business, ordinary partnership or micro limited company (with company books using a narrow customer/supplier-document, bank-reconciliation, fixed-asset and reviewed-adjustment accrual workflow), manages basic sales and transaction-review tools, can import read-only bank-account data through Moneyhub, and may submit supported quarterly updates to HMRC only after HMRC Production access is granted and live filing is enabled. This policy explains what personal data we collect, how we use it, and who we share it with.
Data controller: Mitoba Consulting Ltd, trading as BankScan AI, is the data controller for account, billing, security and direct service data supplied by the individual subscriber for their selected owner-operated business records.
Contact: mitchellagoma@gmail.com for general queries and data subject requests; security@bankscanai.com for security incidents (see our security policy).
Supervisory authority: the Information Commissioner's Office (ICO) regulates data protection in the UK. You have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint if you believe we have mishandled your data.
The subscriber chooses an unpaid invoice and instructs BankScan to queue the reminder using the email on that invoice’s customer record. Delivery is best effort and a delivery event does not prove the intended person read it. The subscriber remains responsible for the accuracy of the address, debt and balance.
Under UK GDPR Article 6, every personal-data processing activity needs a lawful basis. Ours, by purpose:
| What we do | Lawful basis | Reason |
|---|---|---|
| Run your account (email + password) | Contract — Article 6(1)(b) | Necessary to provide the service you signed up for. |
| Parse uploaded bank statements / receipts | Contract — Article 6(1)(b) | You uploaded the file specifically for us to parse it. |
| Connect a read-only bank feed and import account data | Contract — Article 6(1)(b) | You request the connection and authorise it through Moneyhub’s standard consent journey and your bank. |
| Keep customers and current bookkeeping records for a supported sole trade, individual property business, ordinary partnership or micro limited company; provide hosted invoice and transaction-review tools | Contract — Article 6(1)(b) | Necessary to provide the bookkeeping tools requested by the individual subscriber. |
| Retain dormant legacy practice, advanced-accounting, API and integration records for read/export/deletion and cleanup | Contract — Article 6(1)(b), legal obligation — Article 6(1)(c), and legitimate interests — Article 6(1)(f) for security evidence | Retired functions do not accept new records. Processing is limited to authorised access, export, deletion, safe cleanup, legal retention and proportionate investigation of earlier access. |
| Send an unpaid-invoice reminder and record delivery status | Contract — Article 6(1)(b) | The subscriber specifically requests a transactional reminder about a recorded business invoice and must ensure the debt, balance and address are current. |
| Store HMRC NINO + OAuth tokens | Contract — Article 6(1)(b) | Necessary only when you explicitly connect an approved live account or, before Production access, choose a clearly labelled Sandbox test using synthetic details. |
| Submit to live HMRC on your behalf (after Production access) | Contract — Article 6(1)(b) | Each live submission will require an explicit user action. Sandbox test updates are not legal filings. |
| Retain HMRC audit evidence | Legal obligation — Article 6(1)(c), where applicable; legitimate interests — Article 6(1)(f) for proportionate Sandbox test and security evidence | Live submission records are retained for the applicable HMRC and tax-record period. Sandbox test evidence is not presented as a legal filing record. |
| Collect and send HMRC fraud-prevention headers | Legal obligation — Article 6(1)(c), and contract — Article 6(1)(b) | HMRC requires these technical fields from software making an API request. They are used to prevent fraud, sent only with the HMRC request and retained with its restricted audit evidence. |
| Process subscriptions and one-time AI credit packs (Stripe) | Contract — Article 6(1)(b) | Necessary to take and reconcile the requested payment, fulfil a paid credit pack once, and apply a confirmed refund or dispute to the corresponding balance. |
| Rate-limit, abuse detection, security logs | Legitimate interests — Article 6(1)(f) | Necessary to keep the service running for all users. Balanced against minimal-data collection. |
| Transactional email for BankScan account holders (verification, account and HMRC deadline alerts) | Contract — Article 6(1)(b) | Necessary to operate the account, including confirming your email and alerting you to a deadline reported by your connected HMRC account. You can stop HMRC reminders by disconnecting HMRC. |
For processing where BankScan AI is the controller, we do not rely on consent (Article 6(1)(a)) for any of the above — which means we are also not collecting any personal data for purposes that would require your opt-in. We do not run marketing email lists, advertising profiles, or third-party analytics. The express bank-account authorisation completed through Moneyhub and the bank is still required for Open Banking access; it is separate from the UK GDPR lawful basis described in this table.
BankScan AI uses third-party AI providers to read the content of your uploaded files. Every bank statement and receipt you upload is transmitted to our AI sub-processor to be parsed. We do not run our own computer-vision or OCR models — parsing is performed entirely by the sub-processor listed below.
| Service provider / recipient | Purpose | Data shared | Location |
|---|---|---|---|
| Anthropic PBC (Claude API) | AI parsing of statements & receipts | Full content of uploaded files | United States |
| Stripe, Inc. | Payment processing, subscription billing, one-time credit-pack checkout, refunds and disputes | Email, the selected pack and amount, BankScan purchase reference and billing identifiers; full card data is held by Stripe | United States / Ireland |
| Resend, Inc. | Transactional email delivery | Recipient email and the transactional message, including account verification, unpaid-invoice reminders and HMRC account-holder reminders; provider delivery events are returned to us | United States |
| Moneyhub Financial Technology Ltd | Regulated, read-only bank-account connection and account-information retrieval | Institution choice, connection and consent metadata, provider reference, account details, balances and transactions made available by the connected bank, and signed event notices for new, updated, deleted or restored transactions | To be confirmed from the executed Moneyhub agreement before live bank feeds are enabled |
| HM Revenue & Customs (HMRC) | MTD Income Tax authorisation, retrieval and filing; mandatory fraud prevention | NINO and business identifiers, tax-request values, OAuth-authorised request data and the required fraud-prevention device, network, user and MFA headers | United Kingdom |
| Turso / SQLite | Account database | Email, hashed password, usage metadata, customer records, current bookkeeping records for a supported sole trade, individual property business, ordinary partnership or micro limited company, reconciliation evidence and applicable HMRC data; dormant legacy supplier, purchase, practice, advanced-accounting, API and integration records only while needed for authorised read/export/deletion, cleanup, legal retention or security evidence | Configurable region |
| Vercel / Railway | Application hosting | HTTP traffic, ephemeral temp files during a parse | US / EU region of your deployment |
Moneyhub Financial Technology Ltd handles the regulated bank-facing Account Information Service and is FCA-authorised under FRN 809360. Its standard consent journey and handling of bank-connection data are governed by Moneyhub’s API Terms of Use and Privacy Policy. BankScan AI receives read-only data for bookkeeping and does not claim to be FCA-authorised or a registered agent. The BankScan integration cannot initiate payments. Moneyhub’s exact UK GDPR role and BankScan’s regulated operating model must match the executed agreement and be reflected in this notice before live customer bank feeds are enabled.
A seller may place its own payment provider’s HTTPS checkout URL on a hosted invoice page. That provider is selected by the seller, not by BankScan. If a visitor follows the link, the visitor leaves BankScan and deals directly with that provider under the seller’s and provider’s privacy terms. BankScan does not collect, hold or move the invoice payment, and does not receive the visitor’s card details or payment-account credentials. The seller is responsible for any personal data or reference it embeds in the external URL.
Anthropic's API terms state that API inputs are not used to train their models by default. See Anthropic's Commercial Terms and Privacy Policy for their full data handling commitments.
Business-mileage journeys are part of the structured bookkeeping record. A removed journey is hidden immediately but is not physically erased before the entity-specific statutory deadline; it remains available only in the restricted retention record and is deleted after that deadline unless an active enquiry or legal hold extends it.
Temporary parser working copies of uploaded bank statements and receipts are deleted after processing. The exact original PDF, CSV or image is stored separately in encrypted form as bookkeeping evidence. Downloadable Excel/CSV working files are also cleaned up on a schedule (typically within 1 hour).
We retain the exact original bank-statement or receipt file together with the structured values extracted from it—for example the source filename, transaction rows, receipt line items, totals and processing status—in separate saved-statement and saved-receipt records. The original and parsed records provide provenance for the business Ledger. They are not used to train BankScan or third-party AI models. For a sole trader or ordinary partnership we retain statutory bookkeeping evidence through at least five years after the 31 January Self Assessment filing deadline for the relevant tax year. For a micro limited company we retain it through at least six years after the relevant accounting period ends. An account-erasure request removes records that are no longer required, but an open HMRC enquiry, litigation or other legal hold can extend the retention period. Clearing the current upload workspace does not delete retained originals, saved parsed records or the book records formed from them.
Bank-feed data is different from an uploaded source file. Booked transactions imported through Moneyhub become structured accounting records in your business Ledger and follow the same entity-specific retention period described above. Disconnecting a bank stops future polling and asks Moneyhub to revoke the connection, but it does not erase transactions already imported. We retain only masked account identifiers in the user interface; BankScan never stores the bank username or password.
Moneyhub may send a signed event notice when a transaction is new, updated, deleted or restored. BankScan verifies and queues that notice, then retrieves the current transaction details from Moneyhub. If the bank reports an imported transaction as deleted, we preserve the existing accounting record, record the provider deletion and flag it for review rather than silently erasing it. A restoration is recorded and checked against the current provider data. After processing, the signed event payload is scrubbed from the queue; a one-way event key and processing outcome may be retained for duplicate prevention and operations.
Connection, consent and synchronisation metadata is kept while needed to operate or evidence the connection and is removed with the related business account, subject to legal or accounting-record retention duties. Short-lived callback state expires automatically and cannot be reused after a completed authorisation.
Dormant legacy records are not current features. Older supplier, purchase, bill, cash-flow, practice, staff, multi-client, return-workflow, advanced-accounting, asset, inventory, project, worker, payroll-record, currency, API-key, integration and webhook records may remain for existing accounts. They are not used to offer those retired workflows. We keep them only until the authorised account holder reads, exports or deletes them, cleanup completes, or a legal or security-evidence retention period ends. Legacy credentials and delivery configurations cannot be used to create new product activity.
Customer records, quotes, invoices, customer credit notes, allocations, repeating schedules and their audit history remain with your business account until you delete them or a legal or accounting-record retention policy requires removal. A hosted invoice link is represented in the database by a one-way token hash, expiry and revocation metadata; we do not store the raw secret link token. Revoking or expiring a link stops access through that token but does not delete the underlying invoice.
Confirmed payment and transfer matches and saved statement-balance checks remain with the accounting record so the controller can understand how a balance was proved.
The web-app manifest can let a supported browser place a BankScan icon on a device or open the website in a standalone window. It does not create a native mobile app or an offline accounting store, and BankScan does not use it to cache uploaded source files or bookkeeping records for offline use. The browser or operating system may retain ordinary site data according to the user’s device and browser settings.
For an unpaid-invoice reminder, we retain the schedule, attempts, status and available provider identifiers while needed to deliver, retry and evidence the instruction. The customer address remains part of the customer record and the transactional message is sent through Resend. These records follow your account deletion and retention instructions, subject to any legal or accounting-record duty. BankScan does not use invoice-reminder data for marketing.
The fraud-prevention header set actually sent with an HMRC request is retained with that restricted HMRC submission audit for the applicable tax/audit period (a conservative seven years after submission). It is not used for advertising or general device profiling and is deleted when the associated retained audit lawfully expires, unless an enquiry or legal hold extends it.
Annual declaration confirmations, calculation/final-quarter evidence and any linked post-filing correction instructions are retained for seven years from the instruction, or until the later statutory bookkeeping deadline. They are then deleted by controlled cleanup. An active HMRC enquiry, litigation or other legal hold pauses that deletion; release of the hold restores the stated deadline rather than making the record permanent.
You can delete your account at any time by contacting support. Deletion removes your user record, email, password hash, and user-owned usage metadata. Bank-feed connections owned only by that account are removed from BankScan; use Disconnect before account closure when you want BankScan to send Moneyhub a provider-revocation request. Current business records and dormant legacy data are deleted or queued for safe cleanup unless a legal, tax, accounting or security retention duty requires a limited record to remain. Before a ledger clear or private account closure, records still inside that period are copied into an integrity-hashed statutory archive. The direct sign-in email is replaced with a keyed, versioned one-way verification fingerprint, but transaction descriptions and supporting values remain confidential personal financial data—the archive is not anonymous or pseudonymised. Access requires the active owner account or a separately audited support identity-verification approval; knowing the historical email address alone is not sufficient. Stripe billing records are retained by Stripe in accordance with their own retention policies. BankScan retains the pseudonymous AI-credit purchase and fulfilment ledger for seven years from purchase so a charge, duplicate delivery, refund or dispute can be reconciled. An unresolved refund, dispute, recovery shortfall or legal hold can extend that period until it is resolved; after account closure the sign-in identity is removed but the minimum provider and integrity references remain protected until that deadline. Records of submissions made to HMRC through the service are retained for seven years. Annual declaration attestations and linked post-filing correction instructions are retained for seven years or the later applicable statutory deadline (see section 2 and the lawful-basis table in section 3a). Each is then deleted at its disclosed deadline unless an active legal hold temporarily suspends deletion.
If you are in the UK or EU, you have the following rights over your personal data. To exercise any of them, email mitchellagoma@gmail.com. We respond within 30 days (extendable to 90 for complex requests, with notice).
For an invoice reminder, contact the seller shown in the message to dispute the debt, correct the address or ask it to stop further reminders. Delivery remains best effort and a provider event does not prove that a recipient read the message.
We use the minimum cookies needed for the service to function:
bp_auth — your authenticated session, HttpOnly, Secure, SameSite=Lax. Strictly necessary; no consent banner required under PECR.bp_csrf — CSRF protection token (double-submit pattern). Strictly necessary.bp_active_client — a legacy-named cookie that remembers your selected business record for up to one year. HttpOnly, SameSite=Lax and Secure in production; strictly necessary for record selection.We do not use third-party analytics cookies, advertising cookies, or any non-essential tracking. There is no cookie banner because nothing we set requires opt-in consent under PECR / UK GDPR.
BankScan AI is not intended for users under 16. We do not knowingly collect data from children.
We will update this page whenever we change sub-processors or materially change how we handle your data. The effective date above will be updated accordingly.
Questions about this policy or your data: email mitchellagoma@gmail.com.