ReconcileCore
Privacy Policy
What we collect, why we hold it, who else touches it, how long it stays, and the rights you can exercise over it.
Effective . Last updated .
1Scope
This policy explains how ReconcileCore handles personal data in connection with ReconcileCore, covering the marketing site, the anonymous demo and the signed-in application.
It is written to be read rather than skimmed past. Where a statement describes a technical behaviour, that behaviour exists in the product today, and where something is not yet in place we say so rather than leaving it implied.
2Our two roles
We sit in two different positions depending on which data is in question, and the distinction matters because it determines who decides what happens to it.
For account data, such as your name, your email address and how you use the product, we are the controller. We decide why it is held and for how long, and this policy is the notice governing it.
For the financial records you upload, we are a processor acting on your instructions. You decide what goes in, what it is used for and when it is deleted. Where a bank statement names an individual, that person's relationship is with you, not with us.
As your processor we act only on your documented instructions, and using the product is how those instructions are given: uploading a file, running a reconciliation, saving a rule, exporting a result and deleting a record are each one. Everyone with access is under a written confidentiality obligation. We engage the providers listed in section 7 and remain responsible for their handling of your data. If a personal data breach affects your records, we notify you without undue delay after becoming aware of it, and in any event within 48 hours, with what we know at the time rather than waiting for a complete picture. If your own compliance review needs these terms on your paper, write to us and we will work from your template.
3What we collect
| Category | What it contains | Where it comes from |
|---|---|---|
| Account details | Name, email address, and a hashed password. Plain passwords are never stored. | You, at sign-up |
| Linked sign-in | The provider identifier and tokens returned when you choose to sign in with Google. | Your identity provider, with your consent |
| Session records | Session identifier, expiry, and the address and browser used to sign in. | Generated when you sign in |
| Workspace and membership | Workspace name and slug, member roles, and pending invitations. | You and your workspace owner |
| Client records | Client names, colour labels, bank account names and identifiers you enter. | You, inside the application |
| Uploaded files | The statement and ledger files themselves, with their filename, size, type and which side they belong to. | You, at upload |
| Parsed transactions | Date, amount, currency, description, reference and counterparty name extracted from each file. | Derived from your uploads |
| Reconciliation records | Matches, scores, exceptions and the reason given for each, plus the rules you save. | Produced by the matching engine and your decisions |
| Audit events | Who approved a match, created a rule or locked a period, and when each of those happened. | Recorded as you work |
| Billing records | Plan tier, billing period and usage counts measured against your plan limits. | Your subscription and your activity |
| Technical logs | Error traces and request diagnostics used to keep the service working. | Generated automatically |
We do not ask for and do not want special category data such as health, biometric or political information. Financial records occasionally carry such detail in an unrelated column. Section 6 of the Terms asks you to strip anything the match does not need before uploading.
4Why we use it
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and securing your account | Account details, linked sign-in, session records | Performance of a contract |
| Running reconciliations | Uploaded files, parsed transactions, client records | Performance of a contract |
| Keeping an audit trail | Audit events, account details | Legitimate interest in a verifiable record, and your own compliance needs |
| Enforcing plan limits and billing you | Billing records, usage counts | Performance of a contract, and legal obligation for tax records |
| Diagnosing faults and preventing abuse | Technical logs, session records | Legitimate interest in a secure and working service |
| Responding to a support request | Whatever the request concerns | Performance of a contract, and your consent where you send us more than we asked for |
| Service announcements | Account details | Legitimate interest in telling you about changes that affect you |
We do not run behavioural advertising and we do not profile you for marketing. Where we rely on a legitimate interest, we have weighed it against your interests and you can object at any time using the contact address in section 14.
5Automated processing and document extraction
Two parts of the product process your data automatically, and both deserve to be described plainly.
Matching
The matching engine scores candidate pairs on amount, date, reference and counterparty name, and applies a threshold. This decides what appears as an automatic match and what is routed to you for review. It produces no decision about any individual and has no legal effect on one.
Reading scanned documents
When you upload a PDF or a photograph rather than a structured file, the document is sent to Anthropic's Claude API so that the figures and dates can be read from it. Anthropic processes the document to return that result and, under its commercial terms, does not use it to train models. Structured formats such as delimited text, Excel and SWIFT MT940 are parsed entirely on our own infrastructure and are never sent to that API.
If you would rather no document reached a third party at all, upload structured exports instead of scans. The rest of the product works identically.
6The anonymous demo
The demo on the home page accepts a file without an account. It parses the file in memory, returns the result to your browser, and writes nothing to our database or to disk. Once the response has been sent, the upload is gone.
Because nothing is stored, there is nothing to export or delete afterwards, and no way for us to recover a demo run for you.
7Who else touches the data
We do not sell personal data, and we share it only with the providers needed to run the service. Each is bound by contract to process it on our instructions and to protect it.
| Provider | What it does | What it sees |
|---|---|---|
| Cloud hosting and database | Runs the application and stores the database | All stored data, at rest |
| Anthropic | Reads scanned and photographed documents | Only the PDFs and images you upload, at the moment of parsing |
| Inngest | Coordinates background parsing and matching jobs | Job metadata and record identifiers, not file contents |
| Optional sign-in, only if you choose it | Your email address and basic profile | |
| Payment processor | Takes payment for a paid plan | Your billing details, which do not reach our servers |
We may also disclose data where the law compels it, where it is needed to establish or defend a legal claim, or as part of a merger or sale of assets. In the last case you would be told before your data became subject to a different privacy policy. Where a legal demand permits us to notify you, we do.
8International transfers
Some of these providers operate outside the country where you are based, which means personal data may be transferred internationally.
Where data leaves the United Kingdom or the European Economic Area, the transfer is covered by an adequacy decision where one exists, and otherwise by standard contractual clauses together with any supplementary measures the transfer needs. A copy of the clauses relied on for a particular provider can be requested using the address in section 14.
9How long we keep it
| Data | Kept for |
|---|---|
| Demo uploads | Not kept. Held in memory for the duration of the request only |
| Account details | While the account is open, then up to 30 days after closure |
| Session records | Until the session expires or you sign out |
| Uploaded files, transactions and matches | Until you ask us to remove them, or up to 30 days after the workspace is closed. The product has no delete button yet, so removal is by written request and we action it within 30 days |
| Audit events | Kept for the life of the workspace, and not editable, because a record that can be rewritten afterwards serves no purpose |
| Billing records | As long as tax and accounting law requires, commonly six to seven years |
| Technical logs | Up to 90 days, then deleted on a rolling basis |
Backups follow their own cycle and are overwritten in the ordinary course. Data deleted from the live system may persist in a backup for a short period after deletion before it is cycled out.
10Security
Traffic is served over HTTPS. Passwords are hashed rather than stored. Every query against workspace data is scoped to a single workspace, so there is no path through the application that reads across tenants. Requesting a workspace you are not a member of returns a not-found response rather than a permission error, so that membership itself is not disclosed.
Sign-in and sign-up accept five attempts a minute, which is where credential stuffing stops being practical without getting in the way of someone who mistyped. The application holds no third party credentials on your behalf: there are no connected accounts to store tokens for. Approvals, rule creation and period locks are written to an audit log the application gives no way to edit, for any role, including the workspace owner.
Two things we do not yet have, since a security section listing only strengths is not worth reading: there is no SOC 2 or ISO 27001 certification, and no independent penetration test has been carried out. Two factor authentication is not available on accounts yet either. When any of that changes it gets named here with its date.
11Your rights
Subject to the conditions in the law that applies to you, you can ask us to give you a copy of your personal data, correct it, delete it, restrict how it is used, provide it in a portable format, or stop processing it where we rely on a legitimate interest. Where processing rests on consent, you can withdraw that consent at any time without affecting what was done beforehand.
Requests go through the contact page at reconcilecore.com/contact. We respond within the period the applicable law sets, which is one month under the United Kingdom and European regimes, and we may ask for information needed to confirm who you are before acting. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied with our response, you can complain to the data protection authority where you live or work. We would rather hear from you first, but that route remains open to you regardless.
12If your data reached us through an accounting firm
If you are an individual whose name appears on a bank statement uploaded by a firm, we process that record for the firm and not for ourselves. We hold no direct relationship with you and cannot verify your identity independently.
Please direct your request to the firm that holds the relationship. If you contact us instead, we will pass the request to that customer and tell you we have done so. Use the contact page at reconcilecore.com/contact to reach us.
13Children
The service is a professional accounting tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us through the contact page at reconcilecore.com/contact and we will remove it.
14Changes and contact
We update this policy as the product changes. The revision date at the top reflects the current version, and a material change is notified to account owners by email or in the application before it takes effect.
Every kind of question, whether about privacy, this contract or a suspected vulnerability, goes through the contact page at reconcilecore.com/contact. There is one address and it is watched.