Privacy Policy
Last updated 1 August 2026.
The short version: we built Scrivenza Insights so we never have to be trusted with more of your data than the job requires. Your bank statement PDF is never stored — it's read in memory and discarded. What we do keep is deleted automatically after 7 days by default. We don't sell data, we don't run advertising, and we don't use tracking cookies. The rest of this page explains exactly what that means in practice.
Who we are
Scrivenza Ltd (company number 17375328, registered in England and Wales) operates this website and the Scrivenza Insights feature. We are the data controller for the personal data described on this page.
What we collect, and why
Using Scrivenza Insights
You don't need to create an account to use Insights. Here's what happens when you do:
- Your bank statement PDF is uploaded, read using Azure AI Document Intelligence to extract the transaction data, and then discarded. We never save the original file to disk or to a database.
- The extracted transaction data (dates, amounts, merchant descriptions) is sent to Anthropic's Claude API to categorise your spending, detect subscriptions, and produce a plain-language summary. The categorised results are stored so you can view them again and so History works.
- If you use the "Chat with your statement" box on your results page, your question is sent to Claude alongside that statement's own data, the same way as above, so it can answer from your real numbers. Unlike your transaction data, chat questions and answers aren't stored anywhere on our side — they exist only in your browser for that visit, and are gone the moment you leave or refresh the page.
- An anonymous session cookie ties your uploads to your results, so we can show you your own data without asking you to register. It's a random identifier, not linked to your name or email unless you separately contact us.
- If you turn on month-over-month comparison (off by default, a checkbox on the upload page), we additionally keep your income/spending totals by category — not individual transactions, not merchant names — for longer, so we can show you a trend against your next upload. Turning this off stops future uploads from creating new comparison data; anything already kept from earlier uploads still expires on its own 90-day schedule, or you can delete it immediately via the History page.
Occasionally a transaction description on your statement can indicate something sensitive — a payment to a healthcare provider, a religious organisation, or a trade union, for example. We don't do anything special with this beyond what's described above: it's processed and stored the same as any other transaction, for the same 7 days, and never used for anything other than showing your own results back to you.
Contacting us
If you use the contact form, we collect your name, email address, and message purely to reply to you. It's sent as an email to us and isn't added to a marketing list or database.
Using the website generally
We use Microsoft Application Insights to understand how the site is used — page views and counts of successful/failed uploads, for example. Our own tracking only ever records event names and counts, never the content of your transactions or the amounts involved. Standard technical data — like your IP address and browser type — is also logged automatically for all visitors, as with most websites, to help us diagnose problems.
Our legal basis for processing
Under UK GDPR, we rely on:
- Performance of a contract (Article 6(1)(b)) — processing your statement to give you the results you've asked for.
- Consent (Article 6(1)(a)) — for the opt-in month-over-month comparison feature, which you can withdraw at any time.
- Legitimate interests (Article 6(1)(f)) — for the anonymous session cookie and basic site analytics, both needed to run the service and keep it working.
How long we keep things
| Data | Retention |
|---|---|
| Your uploaded PDF | Never stored — discarded immediately after processing |
| Transaction, subscription and summary data | 7 days, then automatically deleted |
| Month-over-month category totals (opt-in only) | 90 days, then automatically deleted |
| Your comparison on/off preference | Kept until you change it or ask us to delete it |
| Contact form messages | Only as long as needed to respond to you |
You can also delete any upload and its data immediately yourself, at any time, from the History page — you don't need to wait for the 7 days or ask us.
Who we share data with
We use a small number of service providers to run Scrivenza, each only for the specific job described:
- Microsoft Azure — hosting, document processing (Document Intelligence), and database storage, all within the UK.
- Anthropic — processes your categorised transaction data to generate the spending summary and subscription detection. Anthropic is a US company, so this transfer is covered by Standard Contractual Clauses and the UK International Data Transfer Addendum, the standard UK GDPR safeguard for this kind of transfer. Anthropic doesn't use this data to train its models.
We do not sell, rent, or share your data for advertising or marketing purposes.
Cookies
We use one cookie: an anonymous session identifier that's strictly necessary for Insights to work (it's how the site knows which results are yours). We don't use advertising or cross-site tracking cookies.
Your rights
Under UK data protection law, you have the right to:
- Delete your data at any time via the History page, or by asking us.
- Ask what data we hold about you.
- Withdraw consent for the comparison feature at any time by turning it off.
- Complain to the Information Commissioner's Office (ICO) if you think we've got something wrong.
Because Insights doesn't use accounts, the History page is the fastest way to see and control your own data — it works in real time, without needing to ask us or wait for a response. If you contact us to ask what we hold, we'll need enough detail to find it — roughly when you uploaded and which bank — since all we have to identify you by is a browser cookie.
Security
Data in transit is encrypted. Our infrastructure uses managed identities rather than shared passwords wherever possible, and the credentials we do hold are kept in a secrets vault, not in our code.
Who this service is for
Scrivenza Insights is intended for adults (18+) managing their own personal finances. It isn't intended for use by children.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and change the date at the top.
Contact us
Questions about this policy or your data? Get in touch.