The short version: We store your financial data encrypted on our servers in the UK. We don't sell your data, we don't show you ads, and we don't train AI models on your data. The only third parties who ever see your data are the services listed below, each chosen carefully for a specific function.
👤1. Who we are
SoleDirector is a UK-based product currently operated by its founder. For any questions about this policy or your data, contact us at [email protected].
📋2. What data we collect
Account data: your name and email, collected via Clerk (our authentication provider). We never see your password.
Company & financial data: company name, director details, tax year settings, and transactions you enter manually.
Receipt images: files you upload for OCR scanning. Stored encrypted on our server. Not shared beyond what is described in section 4.
Chat messages: messages you send to the AI assistant and the responses generated. Stored in your encrypted account database.
HMRC credentials (sole traders, opt-in): National Insurance number, Unique Taxpayer Reference, and HMRC business ID. OAuth access and refresh tokens for the HMRC MTD API. Stored encrypted in your account database and used only to submit quarterly returns to HMRC on your explicit instruction. You can disconnect at any time from Settings.
Bank transaction data (opt-in): If you connect a bank account via Open Banking, transaction history (date, description, amount) and account names are synced and stored in your encrypted account database. This connection is entirely optional and can be removed at any time from Settings.
Usage logs: IP address, timestamp, and HTTP status code. Retained for 30 days for security purposes, then deleted.
⚙️3. How we use your data
To provide the SoleDirector service and generate AI-assisted financial guidance.
To process your subscription via Stripe.
To authenticate your account via Clerk.
To submit quarterly Making Tax Digital (MTD) returns to HMRC on your behalf, when you explicitly authorise each submission (sole traders only, opt-in).
To import bank transactions if you connect a bank account via Open Banking (opt-in).
To improve the product (aggregate, anonymised analysis only, never individual data).
To comply with our legal obligations.
We do not sell your data. We do not use your data for advertising.
We only process your data when we have a lawful basis to do so: mostly because it's necessary to provide the service you've signed up for, sometimes because we're legally required to (tax records, billing records), and occasionally with your consent, which you can withdraw at any time.
🤖4. AI providers
SoleDirector routes different tasks to different AI providers. Here is exactly what each one receives:
Anthropic (Claude) Receives your data
Your chat messages and relevant financial context are sent to Claude to generate responses.
Privacy policy ↗
Google (Gemini) Receives your data
Receipt images you upload are sent to Gemini for OCR extraction (vendor, amount, date).
Privacy policy ↗
Perplexity AINo personal data
Used for web searches on HMRC rules and UK tax guidance. Before any query is sent, the application strips all personal and financial details from your message. Perplexity only ever sees a generic tax question.
Privacy policy ↗
We have Data Processing Agreements in place with Anthropic and Google. Under these agreements, your data is used solely to generate a response and is not used to train their models.
These providers are based outside the UK, so using them means your data is transferred internationally. Our agreements with them include the standard safeguards UK GDPR requires for this, so your data stays protected to the same standard wherever it's processed.
🔐5. Authentication & payments
Clerk: handles sign-up, login, and session management. Your password is never stored by SoleDirector. Clerk privacy policy ↗
Stripe: processes subscription payments. We do not store your card details. Stripe privacy policy ↗
🏛️6. HMRC MTD connection (sole traders)
When you connect your HMRC Government Gateway account, SoleDirector acts as your agent for Making Tax Digital quarterly submissions. Here is exactly what that involves:
What we send to HMRC: quarterly income and expense totals, your NINO and UTR, and mandatory fraud-prevention headers (your client IP address, a fixed device identifier for our server, and browser metadata) required by the HMRC API specification. These headers are a legal requirement of the HMRC MTD API and cannot be omitted.
Tokens stored: HMRC OAuth access token and refresh token, stored encrypted in your account database. Used to authenticate API calls on your behalf without requiring you to log in each time.
Disconnecting: you can disconnect your HMRC account at any time from Settings. All stored tokens and your HMRC business ID are permanently deleted immediately on disconnect. Previously submitted data remains with HMRC as required by law.
Bank account connection is entirely optional. If you choose to connect a bank account via Open Banking:
Authentication: you authenticate directly with your bank through their own secure interface. SoleDirector never sees your bank username or password.
What SoleDirector stores: bank transaction history (date, description, amount) and account names, synced into your encrypted account database. An access consent token is stored and used to refresh the transaction feed. This consent expires after 90 days per FCA regulations.
Disconnecting: you can disconnect your bank account at any time from Settings. This revokes the consent token and removes it from your database. Previously synced transactions remain unless you delete them manually.
📅8. Data retention
Your account and financial data is retained for as long as your account is active.
If you delete your account, all data (transactions, receipts, chat history, settings) is permanently deleted within 30 days.
Server access logs are deleted after 30 days.
Stripe retains billing records as required by financial regulations.
⚖️9. Your rights under UK GDPR
Access: request a copy of your personal data.
Rectification: correct inaccurate data.
Erasure: delete your account and all data via Settings > Delete Account.
Portability: export your financial data as CSV via the Export section.
Object: object to processing of your personal data.
Deletion and export are self-serve. For all other requests, email [email protected]. We aim to respond within a few hours. For formal data rights requests we are legally required to respond within 30 days, but in practice we will be much faster.
Encryption in transit: all data between your browser and our servers is encrypted via HTTPS (TLS 1.2+).
Encryption at rest: all financial data is stored inside an AES-256 encrypted volume. The encryption key is stored on the server and never transmitted externally, protecting your data against physical disk theft or offline access to storage media.
Per-user isolation: each account has its own dedicated database. No user can access another user's data.
Encrypted backups: backups are encrypted independently before leaving our server and stored in a separate cloud region.
No routine access: no employee has routine access to your financial data.
Browser-level protections: we enforce a strict Content Security Policy and related browser security controls to reduce the risk of cross-site scripting and similar attacks against the app.
🍪11. Cookies
We use a single session cookie (__session) set by Clerk to keep you logged in. It is HttpOnly, Secure, and SameSite=Lax. We do not use tracking, analytics, or advertising cookies.
📢12. Changes to this policy
If we make material changes to this policy, we will post a notice inside the app and update the date at the top of this page. Continued use of SoleDirector after changes take effect constitutes acceptance of the updated policy.