Last updated: July 4, 2026
TaxSwipe helps UK sole traders manage Making Tax Digital compliance. We take the privacy of your financial data seriously. This policy explains exactly what we collect, why, and how it is protected.
1. Who We Are
TaxSwipe is developed and operated by FinMedTech. We are the data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Email: hello@finmedtech.co.uk
2. What Data We Collect
2.1 Personal Information
- Email address — for account creation and communication
- Full name — for profile identification
- Business name — for tax records
- National Insurance Number — required for HMRC Making Tax Digital submissions
- Password — stored as a one-way bcrypt hash; we cannot read your password
2.2 Financial Information
- Bank transactions — imported via PDF upload, CSV import, or manual entry
- PDF bank statements — uploaded files are processed using dual-engine verification for accuracy and temporarily stored; automatically deleted after parsing
- Transaction categorisations — business vs personal, HMRC expense categories
- Income and expense data — calculated from transactions
- Tax calculations — Income Tax and National Insurance contributions
2.3 HMRC Integration Data
- HMRC OAuth tokens — to submit quarterly returns on your behalf (encrypted)
- HMRC Business ID — fetched from HMRC Business Details API
- Submission records — quarterly MTD submission history and HMRC references
2.4 Technical Data
- Authentication tokens — stored securely on your device; cleared on logout
- Biometric preference — enabled/disabled flag stored in device secure storage only; we never receive biometric data itself
- Device information — operating system and app version
- Purchase status — whether you hold submission credits or an active subscription
2.5 HMRC Fraud Prevention Data (Legally Required)
UK law requires all Making Tax Digital software to send HMRC certain information about the device a submission comes from, as fraud prevention headers, with every request made to HMRC's APIs. When you connect TaxSwipe to HMRC, we collect and forward to HMRC:
- A unique device identifier generated by TaxSwipe (stored securely on your device)
- Your device's operating system, manufacturer and model
- Screen and window size, resolution and colour depth
- Your timezone
- Your device's local and public IP addresses and port
- Whether multi-factor authentication was used for your session
This data is sent to HMRC only, is not used by us for any other purpose, and is collected under our legal obligation to comply with HMRC's fraud prevention requirements.
2.6 What We Do Not Collect
- We do not access your device's GPS location
- We do not collect advertising identifiers
- We do not use analytics or tracking SDKs
- We do not store bank login credentials (you upload PDF statements directly)
- We do not permanently store PDF files (deleted after parsing)
3. How We Use Your Data
We use the collected data for the following purposes:
- Provide and maintain our service — account management, transaction import, categorisation
- Process bank statements — extract transactions from uploaded PDFs using dual-engine verification for accuracy (see Section 4.1 for how statements are processed)
- Calculate tax liability — Income Tax and National Insurance calculations based on UK tax rates
- Submit to HMRC — quarterly Making Tax Digital updates and your year-end Final Declaration, on your behalf
- AI categorisation — suggest expense categories using Anthropic Claude. For categorisation, we send transaction descriptions, merchant names, amounts and an internal reference ID — never your name, National Insurance Number, or bank account details
- Manage purchases — track your submission credits and subscription status
- Customer support — respond to your requests and provide assistance
- Comply with legal obligations — HMRC reporting and fraud prevention requirements, data protection laws
Our lawful bases
Under UK GDPR we rely on: contract (providing the service you signed up for), legal obligation (HMRC fraud prevention data, tax record-keeping), consent (connecting your HMRC account, which you can withdraw at any time by disconnecting), and legitimate interests (service security and support).
4. Third-Party Services
4.1 Statement Processing (Amazon Web Services & Anthropic)
- PDF bank statements are processed using dual-engine verification for accuracy
- Text extraction runs in an isolated serverless environment on Amazon Web Services (AWS). Privacy notice: aws.amazon.com/privacy
- Where a statement is scanned or cannot be read by text extraction alone, the statement document is processed by Anthropic Claude to read the transactions. This means the statement content (which typically includes your name, account number and transactions) is transmitted securely to Anthropic for processing. Anthropic does not use data submitted through its API to train its models
- Both engines are cross-checked against your statement balances; discrepancies are flagged for your review
- PDFs are temporarily stored during processing and automatically deleted after extraction
4.2 HMRC (Tax Submissions)
- UK Government tax authority
- Receives quarterly MTD submissions on your behalf
- We store OAuth tokens to submit on your behalf (encrypted)
- You can disconnect from HMRC at any time via Settings
- HMRC Personal Information Charter
4.3 Anthropic (AI Categorisation & Statement Reading)
- Provides Claude AI for expense categorisation suggestions and for reading scanned bank statements (Section 4.1)
- For categorisation, only transaction descriptions, merchant names, amounts and an internal reference ID are sent — never your name, National Insurance Number, or bank account details
- For statement reading, the uploaded statement document is processed by Claude (see Section 4.1)
- Anthropic does not use data submitted through its API to train its models
- Privacy policy: anthropic.com/privacy
4.4 Supabase (Cloud Infrastructure)
- Stores your profile, transactions, and submissions
- Manages user authentication
- Data encrypted at rest and in transit (HTTPS)
- Privacy policy: supabase.com/privacy
4.5 RevenueCat (Purchase Management)
We use RevenueCat to manage in-app purchases and subscriptions. RevenueCat receives an anonymised app user ID and your purchase history (products bought, subscription status) — never your payment card details or financial data. Privacy policy: revenuecat.com/privacy.
4.6 Apple / Google
If you make a purchase through the app, payment is processed entirely by Apple (App Store) or Google (Play Store). We do not receive or store your payment card details. We receive only confirmation of your purchase or subscription status.
5. Data Security
- Encryption in transit — all data transmitted via HTTPS/TLS
- Encryption at rest — database encryption via Supabase
- Passwords — stored using industry-standard one-way hashing (we cannot read your password)
- Biometric authentication — Face ID/Touch ID for app access
- Field-level encryption — your most sensitive data (National Insurance Number and HMRC connection tokens) is additionally encrypted at field level with AES-256-GCM, on top of database encryption
- Database isolation — strict access controls ensure users can only access their own data
- PDF processing security — uploaded PDFs are processed in an isolated serverless environment and automatically deleted after extraction
- No credential storage — we do NOT store bank login credentials; you upload PDF statements directly
6. Data Retention
- Active accounts — data retained while your account is active
- Deleted accounts — all personal data permanently deleted from our servers when you use Settings → Delete Account
- HMRC submissions — retained for 6 years to comply with UK tax record-keeping requirements
- PDF files — automatically deleted immediately after transaction extraction (not stored permanently)
- Subscription data — retained while subscription is active; deleted 30 days after cancellation
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Access — request a copy of all data we hold about you
- Rectification — correct any inaccurate data
- Erasure — delete your account and all associated data at any time via Settings → Delete Account, or by contacting us
- Restriction — request we limit how we process your data
- Portability — export your data in a machine-readable format
- Objection — object to processing of your personal data
- Withdraw consent — disconnect HMRC or cancel subscription at any time
To exercise any right, contact us at hello@finmedtech.co.uk. We will respond within 30 days.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk.
8. Purchases & Submission Credits
Core features of TaxSwipe are free to use. Submitting to HMRC requires either a one-off submission credit or an active subscription. To operate this, we track:
- Submission credits — credits purchased and used
- Subscription status — whether a monthly or annual plan is active, and its renewal date
We do not sell or share your usage data with third parties.
9. Children
TaxSwipe is not intended for use by individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. International Data Transfers
Your data is stored in the European Union (our database infrastructure is hosted by Supabase in Ireland and Germany), which the UK recognises as providing adequate data protection. Some third-party services (Anthropic, AWS) may process data outside the UK/EU with appropriate safeguards in place (Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions).
11. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify you via the app. Continued use of TaxSwipe after changes constitutes acceptance of the updated policy.
12. Contact
For any privacy questions, data requests, or concerns:
← Back to TaxSwipe