Privacy Policy

Last updated: April 2026

1. Data Controller

Crackle AI Limited ("we", "us") is the data controller for personal data processed through the Bank Account Analyser service. Contact: privacy@crackleai.co.uk.

2. Data We Collect

  • Account data: Name, email address, organisation (auto-detected from email domain)
  • Bank statement data: Transaction details (dates, descriptions, amounts, balances) extracted from uploaded PDFs. Documents are processed as uploaded — you are responsible for redacting any personally identifiable information before uploading.
  • Usage data: Job history, credit transactions, classification edits
  • Technical data: Authentication cookies (session management only)

3. Legal Basis

We process your data on the following legal bases:

  • Contract: Processing is necessary to provide the Service you have requested
  • Legitimate interest: Service improvement, fraud prevention, and security

4. Data Retention

Uploaded bank statements (PDFs) and the transaction data we extract from them are automatically deleted 90 days after the job completes (or 90 days after upload for jobs that failed to process). Account data — your profile, organisation membership, and the audit trail of your activity — is retained while your account is active.

Financial transaction records (Stripe payment IDs, amounts, and dates of credit purchases) are retained for 6 years to comply with UK HMRC business-records requirements (Article 6(1)(c) — legal obligation). Where a retained record relates to a deleted account, your user reference on the record is removed but the financial details are preserved.

You can download a copy of all your data, or permanently delete your account, at any time from Settings → Data & privacy.

5. Third-Party Processors

We use the following third-party services to deliver the Service. All processors are GDPR-compliant and process data within the EU or under adequate safeguards:

  • Supabase (EU region) - Database, authentication, file storage
  • Stripe - Payment processing
  • OpenRouter - AI/LLM processing for transaction classification
  • n8n Cloud - Workflow automation for PDF processing
  • Vercel - Application hosting
  • Resend - Transactional emails

6. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest

You can exercise your right of access (Article 15) and right of erasure (Article 17) directly from Settings → Data & privacy: the “Download my data” button produces a ZIP containing everything we hold about you, and the “Delete my account” button permanently removes your account and associated data. For other rights or queries, contact privacy@crackleai.co.uk.

7. Cookies

We use only essential cookies for authentication session management. We do not use tracking, analytics, or advertising cookies. See our Cookie Policy for details.

8. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS) and row-level security in our database. You are responsible for redacting any personally identifiable information from documents before uploading them to the Service.

9. Contact

For privacy-related queries, contact our Data Protection Officer at privacy@crackleai.co.uk.

Back to home