Privacy Policy

How we handle your money data.

Plain English on what we collect, where it lives, who can see it, and what we never touch. Written to be read, not buried.

Last updated: July 2026

01

Introduction

Lightswap ("we," "our," or "us") is a financial management application that helps users manage their bank accounts, track spending, and access brokerage services — all from a single app. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website, mobile application, and related services (collectively, the "Service").

By using the Service, you consent to the collection and use of your information as described in this policy. If you do not agree with this policy, please do not use the Service.

02

Information we collect

Account & registration information

When you create an account or join our waitlist, we may collect:

Device & technical information

When you use our mobile app, we collect:

Financial data

When you connect a bank account through our Service, we use third-party financial data providers (currently Plaid and Stripe Financial Connections) to access the following information from your linked financial accounts:

Important: we never store your full bank account numbers, IBANs, sort codes, routing numbers, or bank login credentials on our servers. Your banking credentials are handled entirely by our financial data providers (Plaid and Stripe) and are never transmitted to or accessible by Lightswap.

Accounting & invoicing data (Lightswap for Business)

If you connect an accounting or invoicing tool (currently Xero; QuickBooks and Square are planned), we read the following, on a read-only basis:

We request the narrowest permissions the provider offers — for Xero, read-only access to invoices and contacts only. We do not request, and cannot see, your payroll, your employees, your bank feeds inside the accounting tool, or your wider ledger. We never write to your accounting records.

Business financial records

Lightswap for Business works differently from the consumer app, and deliberately so. To forecast a company's cash position, spot bills that changed, and tell you when an expected payment hasn't arrived, the service has to remember your financial history rather than process it and forget it. So for business accounts we store, on our servers:

Each business's records are isolated from every other business's at the database level. Where the consumer app is described below as processing financial data transiently, that description applies to the consumer app only.

Assistant conversations

When you ask the in-app assistant a question, we collect the text of your question and the AI's response, along with the topic the app classified it as and how long the answer took. We collect the actual wording — not just a category — because seeing how people really phrase questions is how we make the assistant better at answering them.

Usage analytics

The app sends us anonymous usage analytics. This is on by default, and you can turn it off at any time with a single switch in Settings — turning it off stops everything in this section, including conversation collection above. While it is on, your device sends:

These aggregates never include individual transactions, merchant names, account numbers, or anything that identifies you — only counts, sums, and dates tied to your anonymous device identifier.

Diagnostics

Feedback & support

When you submit feedback, we collect:

03

How we use your information

We use the information we collect for the following purposes:

Financial management & insights

Payment processing

Service operation & improvement

Security & fraud prevention

04

Legal basis for processing

We process your information on the following legal grounds:

05

Data storage & regional processing

We maintain strict regional data separation:

Data belonging to US customers will never be transferred to or stored on EU servers, and data belonging to EU/UK customers will never be transferred to or stored on US servers. These datasets are kept strictly separate.

Lightswap for Business records — including invoices and bills imported from accounting tools — are processed and stored on servers located in the European Union, regardless of where your business is registered. Lightswap, Inc. is incorporated in Delaware, United States; where your data is transferred to us as a US entity, that transfer relies on the safeguards described in "Legal basis for processing" above.

06

Data sharing & third parties

We never sell your personal data. We share information only with the third parties below, solely to operate the Service. Most act as our processors, handling data on our instructions. Where a party instead acts as an independent data controller — deciding for itself how it uses your data, under its own privacy policy — that is stated explicitly.

Financial data providers

AI processing

Infrastructure providers

We do not share your financial data with any third parties beyond the service providers listed above, and only to the extent necessary to operate the Service. We contractually require our service providers to protect your data and use it only for the purposes we specify.

07

Data security

We maintain a comprehensive information security programme designed to protect your data. Our security measures include:

Zero-knowledge architecture (consumer app)

In the Lightswap consumer app:

Encryption & access controls

Security review

Monitoring & incident response

08

Data retention

We retain your data only for as long as necessary for the purposes described in this policy:

Lightswap for Business

Business records are kept for as long as your organisation has an account with us, because the service's value comes from history — a forecast built on three months of data is worse than one built on two years. Specifically:

When data is no longer required, we delete or anonymise it. Where deletion is not immediately possible (e.g., data in backup systems), we isolate and protect the data until deletion is feasible.

09

Your rights

All users

Regardless of where you are located, you have the right to:

EU/UK users (GDPR)

If you are located in the European Union or United Kingdom, you additionally have the right to:

California users (CCPA)

If you are a California resident, you have the right to:

We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.

Exercising your rights

To exercise any of these rights, contact us at support@lightswap.com. We will respond to your request within 30 days.

10

Cookies & tracking

Our website uses only essential cookies required for the site to function. We do not use advertising cookies, tracking pixels, or third-party analytics services that track you across other websites.

11

Children's privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.

12

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

13

Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at:

support@lightswap.com

Back to Lightswap