01
Introduction
Lightswap ("we," "our," or "us") is a financial management application that helps users manage their bank accounts, track spending, and access brokerage services — all from a single app. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website, mobile application, and related services (collectively, the "Service").
By using the Service, you consent to the collection and use of your information as described in this policy. If you do not agree with this policy, please do not use the Service.
02
Information we collect
Account & registration information
When you create an account or join our waitlist, we may collect:
- Email address (stored in hashed form)
- Password (stored in hashed form; we never store your plaintext password)
- IP address (for security, fraud prevention, and rate limiting)
- Browser information and referral source
Device & technical information
When you use our mobile app, we collect:
- An anonymous device identifier (randomly generated UUID, not linked to your identity)
- Device platform (iOS/Android), OS version, and app version
- Locale and timezone
Financial data
When you connect a bank account through our Service, we use third-party financial data providers (currently Plaid and Stripe Financial Connections) to access the following information from your linked financial accounts:
- Account balances: current and available balances for your linked accounts
- Transaction history: recent transactions including dates, amounts, merchant names, and categories
- Account details: account type, currency, and masked account number (e.g., ****1234)
- Account ownership information: account holder name and mailing address, where required for verification
Important: we never store your full bank account numbers, IBANs, sort codes, routing numbers, or bank login credentials on our servers. Your banking credentials are handled entirely by our financial data providers (Plaid and Stripe) and are never transmitted to or accessible by Lightswap.
Accounting & invoicing data (Lightswap for Business)
If you connect an accounting or invoicing tool (currently Xero; QuickBooks and Square are planned), we read the following, on a read-only basis:
- Invoices and bills: reference number, the outstanding amount, currency, issue and due dates, and status (draft, awaiting payment, paid, voided)
- Contact names: the customer or supplier named on each invoice or bill, so we can show you who owes you money and who you owe
We request the narrowest permissions the provider offers — for Xero, read-only access to invoices and contacts only. We do not request, and cannot see, your payroll, your employees, your bank feeds inside the accounting tool, or your wider ledger. We never write to your accounting records.
Business financial records
Lightswap for Business works differently from the consumer app, and deliberately so. To forecast a company's cash position, spot bills that changed, and tell you when an expected payment hasn't arrived, the service has to remember your financial history rather than process it and forget it. So for business accounts we store, on our servers:
- transactions from your connected accounts, along with the counterparties, recurring payments and expected items derived from them
- the access tokens for your connected providers, encrypted at rest — see "Encryption & access controls" below
Each business's records are isolated from every other business's at the database level. Where the consumer app is described below as processing financial data transiently, that description applies to the consumer app only.
Assistant conversations
When you ask the in-app assistant a question, we collect the text of your question and the AI's response, along with the topic the app classified it as and how long the answer took. We collect the actual wording — not just a category — because seeing how people really phrase questions is how we make the assistant better at answering them.
- Before anything is stored, we automatically scrub emails, card numbers, IBANs, sort codes, and account numbers from the text and replace them with redaction markers.
- Conversation text is linked only to your anonymous device identifier, never your name or email.
- It is visible only to authorised staff, and deleted after 180 days (see Data retention below).
Usage analytics
The app sends us anonymous usage analytics. This is on by default, and you can turn it off at any time with a single switch in Settings — turning it off stops everything in this section, including conversation collection above. While it is on, your device sends:
- A daily "this device was active today" signal (a date and timezone, nothing else)
- Monthly aggregate numbers computed on your device: session and query counts, which features were used, counts and totals of payments made and spending analysed (bucketed into ranges), and how many accounts are connected
These aggregates never include individual transactions, merchant names, account numbers, or anything that identifies you — only counts, sums, and dates tied to your anonymous device identifier.
Diagnostics
- Error logs for debugging and service improvement
Feedback & support
When you submit feedback, we collect:
- Your feedback message
- Your email address (optional, if you choose to provide it)
- App version and device information (for debugging)
03
How we use your information
We use the information we collect for the following purposes:
Financial management & insights
- Display your bank account balances and provide a unified view of your finances
- Generate your daily financial briefing ("Rundown"), which analyses your recent transactions, spending patterns, income, and upcoming bills
- Provide AI-powered financial insights and summaries
Payment processing
- Facilitate bank payments and transfers on your behalf
- Track payment status and provide confirmation
- Maintain regulatory audit records for completed payments
Service operation & improvement
- Operate and maintain the Service
- Improve our product based on usage patterns and feedback
- Communicate updates and respond to support requests
Security & fraud prevention
- Detect and prevent unauthorised access, fraud, and abuse
- Rate-limit API requests to protect the Service
- Verify payment consent and maintain audit trails
04
Legal basis for processing
We process your information on the following legal grounds:
- Consent: when you connect a bank account, you explicitly authorise us to access your financial data through our data providers. You can revoke this consent at any time by disconnecting your account.
- Contract performance: processing necessary to provide the Service you have requested.
- Legitimate interests: service improvement, security, and fraud prevention, where these interests do not override your rights. This includes the anonymous usage analytics and assistant conversation collection described above — both of which you can switch off at any time in Settings.
- Legal obligation: where we are required to retain data to comply with financial regulations.
05
Data storage & regional processing
We maintain strict regional data separation:
- United States users: your data is processed and stored on servers located in the United States. Financial data accessed via Stripe Financial Connections is stored exclusively within the United States.
- European Union and United Kingdom users: your data is processed and stored on servers located within the European Union.
Data belonging to US customers will never be transferred to or stored on EU servers, and data belonging to EU/UK customers will never be transferred to or stored on US servers. These datasets are kept strictly separate.
Lightswap for Business records — including invoices and bills imported from accounting tools — are processed and stored on servers located in the European Union, regardless of where your business is registered. Lightswap, Inc. is incorporated in Delaware, United States; where your data is transferred to us as a US entity, that transfer relies on the safeguards described in "Legal basis for processing" above.
06
Data sharing & third parties
We never sell your personal data. We share information only with the third parties below, solely to operate the Service. Most act as our processors, handling data on our instructions. Where a party instead acts as an independent data controller — deciding for itself how it uses your data, under its own privacy policy — that is stated explicitly.
Financial data providers
- Plaid Financial Ltd — facilitates bank account connections for EU and UK users. Plaid receives your bank account data (balances, transactions) as an independent data controller, not as our processor. Plaid's use of your data is governed by the Plaid End User Privacy Policy.
- Stripe, Inc. (Financial Connections) — facilitates bank account connections for US users. Stripe accesses your bank account data (balances, transactions, account ownership) on our behalf. Stripe's use of your data is governed by the Stripe Privacy Policy.
AI processing
- Anthropic PBC — we use Anthropic's Claude AI to process your natural language queries and generate financial insights (such as your daily Rundown). Transaction data and account balances may be sent to Anthropic's API for analysis. Anthropic does not use data sent via their API to train their models. Anthropic's use of data is governed by the Anthropic Privacy Policy.
Infrastructure providers
- Cloudflare, Inc. — content delivery and security services.
- Render Services, Inc. — application hosting.
We do not share your financial data with any third parties beyond the service providers listed above, and only to the extent necessary to operate the Service. We contractually require our service providers to protect your data and use it only for the purposes we specify.
07
Data security
We maintain a comprehensive information security programme designed to protect your data. Our security measures include:
Zero-knowledge architecture (consumer app)
In the Lightswap consumer app:
- Your API keys, private keys, and bank login credentials are never stored on our servers
- Sensitive credentials are encrypted and stored locally on your device using the iOS Keychain
- Brokerage and exchange operations are executed directly from your device — our server never has access to your third-party accounts
Encryption & access controls
- All data in transit is encrypted using TLS/HTTPS with HSTS enforcement
- Sensitive data at rest (email addresses, passwords) is cryptographically hashed
- Sign-in links are stored only as a hash, are single-use, and expire 15 minutes after being issued
- Consumer app: bank account access tokens from financial data providers are used ephemerally and are not retained on our servers
- Lightswap for Business: provider access tokens are retained so we can keep your money picture up to date, and are encrypted at rest using AES-based authenticated encryption with keys held in the server environment and never in our source code. Encryption keys are rotatable without customers reconnecting
- Business records are isolated per company at the database layer: a query that does not name a company is refused rather than returning another company's data
- Access to data is restricted to authorised personnel with a demonstrated business need
Security review
- We review our dependencies and code for security issues on a quarterly cadence, and additionally whenever we change code that handles credentials, authentication, or money movement
- We have never experienced a data breach affecting personal information
Monitoring & incident response
- We monitor our systems for unauthorised access and suspicious activity
- Payment consent records are maintained in append-only audit logs that cannot be altered or deleted
- In the event of a data breach affecting your personal information, we will notify you and the relevant supervisory authorities in accordance with applicable law
08
Data retention
We retain your data only for as long as necessary for the purposes described in this policy:
- Financial data (balances, transactions): processed in real time to generate insights and not stored long-term on our servers. Cached temporarily for the duration of your session only.
- Payment records & consent audit logs: retained for a minimum of 5 years to comply with financial services regulations.
- Feedback data: retained for 2 years from submission, then automatically deleted.
- Assistant conversation text: deleted after 180 days, automatically. The scrubbed text (see "Assistant conversations" above) is never retained beyond this window.
- Device data and usage analytics: retained for as long as your account is active, then deleted within 180 days of account closure. You can also request deletion of your analytics data at any time.
- Waitlist data: retained until the waitlist programme ends or you request removal.
Lightswap for Business
Business records are kept for as long as your organisation has an account with us, because the service's value comes from history — a forecast built on three months of data is worse than one built on two years. Specifically:
- Financial records (transactions, counterparties, recurring payments, invoices, bills, expected items): retained while your account is open. Disconnecting a provider stops new data arriving but does not delete what we already hold — deleting your history is a separate, deliberate action you ask us for, so that disconnecting a bank never silently destroys your records.
- Provider access tokens: deleted immediately when you disconnect that provider, and when your account is closed.
- Decision records (the append-only log of confirmations and dismissals you have made): retained while your account is open. These are append-only by design and cannot be edited, including by us.
- On account closure: financial records are deleted within 30 days, except where we are required to retain specific records to comply with financial services or tax law.
- On request: you can ask us to delete your organisation's financial records at any time without closing your account. You can also export your raw records (accounts, transactions, invoices and bills, decisions) at any time from your settings.
When data is no longer required, we delete or anonymise it. Where deletion is not immediately possible (e.g., data in backup systems), we isolate and protect the data until deletion is feasible.
09
Your rights
All users
Regardless of where you are located, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your personal data (subject to legal retention requirements)
- Disconnect your linked bank accounts at any time
- Opt out of usage analytics and conversation collection at any time with the single analytics switch in the app's Settings
- Opt out of marketing communications
EU/UK users (GDPR)
If you are located in the European Union or United Kingdom, you additionally have the right to:
- Data portability: receive your data in a structured, machine-readable format
- Restrict processing: request that we limit how we use your data
- Object to processing: object to processing based on legitimate interests
- Withdraw consent: withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal
- Lodge a complaint: file a complaint with your local data protection supervisory authority
California users (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose
- Delete your personal information
- Non-discrimination: we will not discriminate against you for exercising your rights
We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
Exercising your rights
To exercise any of these rights, contact us at support@lightswap.com. We will respond to your request within 30 days.
10
Cookies & tracking
Our website uses only essential cookies required for the site to function. We do not use advertising cookies, tracking pixels, or third-party analytics services that track you across other websites.
11
Children's privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.
12
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13
Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at: