Your data
Privacy Policy
Sterling reads your business’s financial evidence for a living, so you deserve to know exactly what we hold, who sees it, and how you get it back or make it go away. This page says all of that plainly.
Who is responsible for your data
The proof-of-concept service presented under the placeholder display name below operates Sterling and is responsible for the personal data described here. For some processing we act on your instructions; for the pipeline that decides what is relevant to your accounts we act with you as a joint controller; and for your account, billing and security we decide things ourselves.
Proof-of-concept identity notice
These particulars are POC placeholders only. They must be replaced or omitted before charging customers or relying on these pages as final legal particulars.
- Display name: Sterling Trace (POC placeholder).
- Company number: 00000000 — POC placeholder; not a real company registration.
- Address: 1 Prototype Way, London, SW1A 1AA, United Kingdom — POC placeholder; not a registered office.
- Contact email: poc-contact@example.invalid — POC placeholder; non-deliverable placeholder.
- VAT number: GB000000000 — POC placeholder; not a VAT registration.
These fixtures do not establish that Sterling Trace is incorporated or VAT-registered.
You can contact us by messaging Sterling from your account, or on Telegram if you have it connected.
Not a customer? If you have dealt with a business that uses Sterling — as a supplier, customer or correspondent — some of your data may reach us through their records. We publish a separate notice for you: the third-party privacy notice, which also sets out the essence of the joint-controller arrangement between us and our customers.
What we hold
- Account data — your name and email address from Google sign-in, and your businesses’ details.
- The sources you connect — mail from a connected mailbox (read-only), transactions and balances from a connected bank account, public filings from Companies House, and your VAT obligations from HMRC if you connect it. You choose how far back Sterling reads when you connect each source, and you can disconnect any source at any time.
- What you send Sterling directly — messages, photos, documents and voice notes in chat.
- What Sterling produces — extracted text, categorisations, ledger entries, prepared filings and billing records.
Reading is narrowed before it happens. Before fetching a mailbox message, Sterling checks the sender and declines to read messages from senders it recognises as health or trade-union sources — the message is never retrieved at all. That check is deliberately narrow: it sees only the envelope, not the content, so it cannot catch everything (an ordinary supplier’s invoice that happens to reveal something sensitive would still be read).
Sterling only imports mail that carries a financial signal. A message is fetched only if it has an attachment, or matches wording like invoice, receipt, statement, payment, tax, payroll and similar bookkeeping terms — decided by Gmail’s own search against that message alone, without Sterling reading its content first. Ordinary personal or social correspondence, and anything else that shows no financial signal, is never retrieved.
What we use it for
To run the service you signed up for: reading the evidence you connect, deciding what is relevant to your accounts, keeping your ledger, preparing filings, answering you in chat, billing you for the items Sterling takes on, and keeping the service secure. We do not sell your data. We do not train AI models on your data. Neither do our AI providers: xAI’s and OpenAI’s business API terms bar training on API content by default, and we have not opted in to any data sharing. Both providers may retain API content for up to 30 days for abuse and security monitoring before deleting it; OpenAI does not retain the voice audio we send for transcription.
Exactly who sees your data
Sterling runs on our own servers wherever possible. These are the third-party providers that process customer data, what each one sees, and where it runs:
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Hetzner | Hosting, database and document storage | All customer data at rest | Germany (Falkenstein) |
| xAI | Reading and judging evidence: relevance scoring, document extraction, account classification | Message content and attachments, images of receipts and invoices | United States |
| OpenAI | Chat replies, search embeddings, voice transcription | Extracted document text, your questions and searches, voice audio | United States |
| Sign-in, and mailbox access if you connect Gmail | Your account identity; mailbox content (read-only) | United States / global | |
| Telegram | Chat with Sterling, if you connect it | Your messages, photos, documents and voice notes | Outside the UK |
| GoCardless / Planky | Open-banking bank connections | Account, balance and transaction data | UK / EEA |
| Companies House | Public company filings you link | Company numbers you look up | United Kingdom |
| HMRC | VAT obligations and returns, if you connect it | See the fraud-prevention note below | United Kingdom |
Error reporting, workflow orchestration and logging run self-hosted on our own infrastructure — no third party sees that data.
What HMRC requires us to send about you
If you connect HMRC, the law requires every call to HMRC’s Making Tax Digital API to carry fraud-prevention headers. On every VAT call these transmit to HMRC: your public IP address and port, a persistent device identifier, your browser’s user-agent, screen and window characteristics, your timezone, information about how you signed in (including multi-factor authentication), our internal identifier for your account, and your email address. This is HMRC’s requirement, not our choice, and it applies to every software product that talks to Making Tax Digital.
When our staff can see your data
Day to day, no human of ours reads your books — Sterling does. When an operator needs to see specific documents (for example, to investigate a fault you reported), the controls are built in, not policy on paper:
- The operator requests access to named items, with a written reason, and you approve or deny it from your own dashboard.
- An approval expires automatically after 72 hours, and you can revoke it early.
- Every reveal is recorded in the same transaction as the read — an access that fails to record itself cannot happen — and the record is permanent.
- You can see every access, and every request, in your account’s activity pages.
Your rights: export, deletion, and the rest
Export is built in. Your account pages can download everything we hold for you as a single archive: original documents byte-for-byte, extracted text, and your ledger, invoices, bank transactions and billing history as CSV files that open in a spreadsheet.
Deletion is built in. You can delete your account and its data from your account pages. We ask you to type a confirmation, and we will not delete until you have a recent export or explicitly tell us to proceed without one. Deletion removes your documents, ledger, connections and identities. What survives: billing records the law requires us to keep for tax purposes, and a minimal proof-of-deletion record with the personal data removed.
You also have the rights UK GDPR gives you — access, rectification, erasure, restriction, portability and objection. Most are answered by the export and deletion tools above; for anything else, message us. If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office (ICO).
How long we keep it
We keep your data while your account is open, so Sterling can do its job. After cancellation your data stays available to export, and we will not delete it without telling you first. We are finalising a published retention schedule with specific periods per kind of record; until then, deletion happens when you ask for it, less the tax records the law requires us to keep. One decided rule already runs: when Sterling detects a credential (a password or key) in a message, the detected text itself is erased after 14 days.