01
Introduction
Lightswap ("we," "our," or "us") makes financial software for small businesses. It connects to the bank accounts, accounting software and payment tools a business already uses, works out where the business stands, and tells the owner what needs their attention. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website, our applications, and related services (collectively, the "Service").
Lightswap previously offered a personal finance application for individuals. That application is no longer under active development and is not offered to new users, but some people still use it, so this policy covers it too. Where a section applies to only one of the two, it says so.
By using the Service, you consent to the collection and use of your information as described in this policy. If you do not agree with this policy, please do not use the Service.
02
Information we collect
Account & registration information
When you create an account or join our waitlist, we may collect:
- Email address (stored in hashed form)
- Password (stored in hashed form; we never store your plaintext password)
- IP address (for security, fraud prevention, and rate limiting)
- Browser information and referral source
Device & technical information
When you use our mobile app, we collect:
- An anonymous device identifier (randomly generated UUID, not linked to your identity)
- Device platform (iOS/Android), OS version, and app version
- Locale and timezone
Financial data
When you connect a bank account through our Service, we use third-party financial data providers (currently Plaid and Stripe Financial Connections) to access the following information from your linked financial accounts:
- Account balances: current and available balances for your linked accounts
- Transaction history: recent transactions including dates, amounts, merchant names, and categories
- Account details: account type, currency, and masked account number (e.g., ****1234)
- Account ownership information: account holder name and mailing address, where required for verification
Important: we never store your bank login. Where you connect through Plaid or Stripe, we never store your full account numbers, IBANs, sort codes or routing numbers either. Those providers handle your login, and Lightswap never sees it. Mercury is the one exception. When you connect a Mercury account directly (below), Mercury gives us the account number and routing number, and we keep them encrypted so you can look them up in Lightswap. Only the account's owner can see them, and only when they ask. They are deleted when you disconnect.
Accounting & invoicing data (Lightswap for Business)
If you connect an accounting or invoicing tool (currently Xero; QuickBooks and Square are planned), we read the following, on a read-only basis:
- Invoices and bills: reference number, the outstanding amount, currency, issue and due dates, and status (draft, awaiting payment, paid, voided)
- Contact names: the customer or supplier named on each invoice or bill, so we can show you who owes you money and who you owe
We request the narrowest permissions the provider offers — for Xero, read-only access to invoices and contacts only. We do not request, and cannot see, your payroll, your employees, your bank feeds inside the accounting tool, or your wider ledger. We never write to your accounting records.
Business financial records
Lightswap for Business works differently from the consumer app, and deliberately so. To forecast a company's cash position, spot bills that changed, and tell you when an expected payment hasn't arrived, the service has to remember your financial history rather than process it and forget it. So for business accounts we store, on our servers:
- transactions from your connected accounts, along with the counterparties, recurring payments and expected items derived from them
- the access tokens for your connected providers, encrypted at rest — see "Encryption & access controls" below
Each business's records are isolated from every other business's at the database level. Where the consumer app is described below as processing financial data transiently, that description applies to the consumer app only.
Assistant conversations
When you ask the in-app assistant a question, we collect the text of your question and the AI's response, along with the topic the app classified it as and how long the answer took. We collect the actual wording — not just a category — because seeing how people really phrase questions is how we make the assistant better at answering them.
- Before anything is stored, we automatically scrub emails, card numbers, IBANs, sort codes, and account numbers from the text and replace them with redaction markers.
- Conversation text is linked only to your anonymous device identifier, never your name or email.
- It is visible only to authorised staff, and deleted after 180 days (see Data retention below).
Usage analytics
The app sends us anonymous usage analytics. This is on by default, and you can turn it off at any time with a single switch in Settings — turning it off stops everything in this section, including conversation collection above. While it is on, your device sends:
- A daily "this device was active today" signal (a date and timezone, nothing else)
- Monthly aggregate numbers computed on your device: session and query counts, which features were used, counts and totals of payments made and spending analysed (bucketed into ranges), and how many accounts are connected
These aggregates never include individual transactions, merchant names, account numbers, or anything that identifies you — only counts, sums, and dates tied to your anonymous device identifier.
Diagnostics
- Error logs for debugging and service improvement
Feedback & support
When you submit feedback, we collect:
- Your feedback message
- Your email address (optional, if you choose to provide it)
- App version and device information (for debugging)
03
How we use your information
We use the information we collect for the following purposes:
Financial management & insights
- Display your bank account balances and provide a unified view of your finances
- Generate your daily financial briefing ("Rundown"), which analyses your recent transactions, spending patterns, income, and upcoming bills
- Provide AI-powered financial insights and summaries
Payment processing
- Facilitate bank payments and transfers on your behalf
- Track payment status and provide confirmation
- Maintain regulatory audit records for completed payments
Service operation & improvement
- Operate and maintain the Service
- Improve our product based on usage patterns and feedback
- Communicate updates and respond to support requests
Security & fraud prevention
- Detect and prevent unauthorised access, fraud, and abuse
- Rate-limit API requests to protect the Service
- Verify payment consent and maintain audit trails
04
Legal basis for processing
We process your information on the following legal grounds:
- Consent: when you connect a bank account, you explicitly authorise us to access your financial data through our data providers. You can revoke this consent at any time by disconnecting your account.
- Contract performance: processing necessary to provide the Service you have requested.
- Legitimate interests: service improvement, security, and fraud prevention, where these interests do not override your rights. This includes the anonymous usage analytics and assistant conversation collection described above — both of which you can switch off at any time in Settings.
- Legal obligation: where we are required to retain data to comply with financial regulations.
05
Data storage & regional processing
We maintain strict regional data separation:
- United States users: your data is processed and stored on servers located in the United States. Financial data accessed via Stripe Financial Connections is stored exclusively within the United States.
- European Union and United Kingdom users: your data is processed and stored on servers located within the European Union.
Data belonging to US customers will never be transferred to or stored on EU servers, and data belonging to EU/UK customers will never be transferred to or stored on US servers. These datasets are kept strictly separate.
Lightswap for Business records — including invoices and bills imported from accounting tools — are processed and stored on servers located in the European Union, regardless of where your business is registered. Lightswap, Inc. is incorporated in Delaware, United States; where your data is transferred to us as a US entity, that transfer relies on the safeguards described in "Legal basis for processing" above.
06
Data sharing & third parties
We never sell your personal data. We share information only with the third parties below, solely to operate the Service. Most act as our processors, handling data on our instructions. Where a party instead acts as an independent data controller — deciding for itself how it uses your data, under its own privacy policy — that is stated explicitly.
Financial data providers
- Plaid Financial Ltd — facilitates bank account connections for EU and UK users. Plaid receives your bank account data (balances, transactions) as an independent data controller, not as our processor. Plaid's use of your data is governed by the Plaid End User Privacy Policy.
- Stripe, Inc. (Financial Connections) — facilitates bank account connections for US users. Stripe accesses your bank account data (balances, transactions, account ownership) on our behalf. Stripe's use of your data is governed by the Stripe Privacy Policy.
- Monzo Bank Ltd — where you connect a Monzo account directly, Monzo provides your account balances and transactions to us with your authorisation. Monzo acts as an independent data controller under its own privacy policy.
- Stripe, Inc. (payments data) — where you connect a Stripe account, we read your payouts, charges and fees so that money you have taken appears in your picture. We do not process payments on your behalf.
- Mercury Technologies, Inc. — where you connect a Mercury account directly using a read-only API token you create in Mercury, we read your account names, account and routing numbers, balances and transactions. Nothing is sent to Mercury beyond the requests that read them, and the token cannot move money. Mercury's use of your data is governed by the Mercury Privacy Policy.
AI processing
- Anthropic PBC — we use Anthropic's Claude AI to process your natural language queries and generate financial insights (such as your daily Rundown). Transaction data and account balances may be sent to Anthropic's API for analysis. Anthropic does not use data sent via their API to train their models. Anthropic's use of data is governed by the Anthropic Privacy Policy.
Accounting, documents and company data
- Xero Limited — where you connect Xero, we read invoices, bills and contacts, so that they appear in your cash picture and so a late invoice can be identified.
- Dropbox, Inc. and Google LLC — where you choose to connect a document store, we read only the files you point us at, so that bills and invoices can be recognised.
- Companies House (UK) — we look up publicly filed company information to confirm details of a business. This is a public register, and none of your personal data is sent to it.
- Postmark (ActiveCampaign, LLC) — sends transactional email on our behalf: sign-in links, and the notifications you have asked for. Where your business forwards invoices to a Lightswap email address, Postmark receives those messages so that we can read the attachment.
Infrastructure providers
- Cloudflare, Inc. — content delivery and security services.
- Render Services, Inc. — application hosting.
We do not share your financial data with any third parties beyond the service providers listed above, and only to the extent necessary to operate the Service. We contractually require our service providers to protect your data and use it only for the purposes we specify.
07
Data security
We maintain a comprehensive information security programme designed to protect your data. Our security measures include:
The legacy consumer app
These apply to the personal finance application described in section 1, and not to Lightswap for Business:
- Exchange API keys and wallet private keys are never stored on our servers. They are held on your own device in the iOS Keychain, and operations using them are carried out from the device
- Transactions read to write the daily briefing are processed in memory and are not retained on our servers
- Where a connection has to stay live between sessions — a directly connected Monzo account, for example — the access and refresh tokens for that connection are retained on our servers, because the connection has to outlive the app being open
Encryption & access controls
- All data in transit is encrypted using TLS/HTTPS with HSTS enforcement
- We do not use passwords. Signing in is by emailed link, so there is no password to store, to leak, or for you to lose
- Your email address is stored so that we can send you those links and reach you about your account. A one-way hash of it is stored alongside, and that is what our systems match on internally
- Sign-in links are stored only as a hash, are single-use, and expire 15 minutes after being issued
- Consumer app: access tokens from Plaid are supplied by your device for each sync and are not retained on our servers. Tokens for a directly connected bank are retained, as described above, because that connection has to outlive the session
- Lightswap for Business: provider access tokens are retained so we can keep your money picture up to date, and are encrypted at rest using AES-based authenticated encryption with keys held in the server environment and never in our source code. Encryption keys are rotatable without customers reconnecting
- Business records are isolated per company at the database layer: a query that does not name a company is refused rather than returning another company's data
- Access to data is restricted to authorised personnel with a demonstrated business need
Security review
- We review our dependencies and code for security issues on a quarterly cadence, and additionally whenever we change code that handles credentials, authentication, or money movement
- We have never experienced a data breach affecting personal information
Monitoring & incident response
- We monitor our systems for unauthorised access and suspicious activity
- Payment consent records are maintained in append-only audit logs that cannot be altered or deleted
- In the event of a data breach affecting your personal information, we will notify you and the relevant supervisory authorities in accordance with applicable law
08
Data retention
We retain your data only for as long as necessary for the purposes described in this policy:
- Financial data (balances, transactions): processed in real time to generate insights and not stored long-term on our servers. Cached temporarily for the duration of your session only.
- Payment records & consent audit logs: retained for a minimum of 5 years to comply with financial services regulations.
- Feedback data: retained for 2 years from submission, then automatically deleted.
- Assistant conversation text: deleted after 180 days, automatically. The scrubbed text (see "Assistant conversations" above) is never retained beyond this window.
- Device data and usage analytics: retained for as long as your account is active, then deleted within 180 days of account closure. You can also request deletion of your analytics data at any time.
- Waitlist data: retained until the waitlist programme ends or you request removal.
Lightswap for Business
Business records are kept for as long as your organisation has an account with us, because the service's value comes from history — a forecast built on three months of data is worse than one built on two years. Specifically:
- Financial records (transactions, counterparties, recurring payments, invoices, bills, expected items): retained while your account is open. Disconnecting a provider stops new data arriving but does not delete what we already hold — deleting your history is a separate, deliberate action you ask us for, so that disconnecting a bank never silently destroys your records.
- Provider access tokens: deleted immediately when you disconnect that provider, and when your account is closed.
- Decision records (the append-only log of confirmations and dismissals you have made): retained while your account is open. These are append-only by design and cannot be edited, including by us.
- On account closure: financial records are deleted within 30 days, except where we are required to retain specific records to comply with financial services or tax law.
- On request: you can ask us to delete your organisation's financial records at any time without closing your account. You can also export your raw records (accounts, transactions, invoices and bills, decisions) at any time from your settings.
When data is no longer required, we delete or anonymise it. Where deletion is not immediately possible (e.g., data in backup systems), we isolate and protect the data until deletion is feasible.
09
Your rights
All users
Regardless of where you are located, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your personal data (subject to legal retention requirements)
- Disconnect your linked bank accounts at any time
- Opt out of usage analytics and conversation collection at any time with the single analytics switch in the app's Settings
- Opt out of marketing communications
EU/UK users (GDPR)
If you are located in the European Union or United Kingdom, you additionally have the right to:
- Data portability: receive your data in a structured, machine-readable format
- Restrict processing: request that we limit how we use your data
- Object to processing: object to processing based on legitimate interests
- Withdraw consent: withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal
- Lodge a complaint: file a complaint with your local data protection supervisory authority
California users (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose
- Delete your personal information
- Non-discrimination: we will not discriminate against you for exercising your rights
We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
Exercising your rights
To exercise any of these rights, contact us at support@lightswap.com. We will respond to your request within 30 days.
10
Cookies & tracking
Our website uses only essential cookies required for the site to function. We do not use advertising cookies, tracking pixels, or third-party analytics services that track you across other websites.
11
Children's privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.
12
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13
Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at: