Privacy Policy

Last updated 9 July 2026.

Sector AI, of 10 Edgehill, NE20 9RN (accounts@sectorai.co.uk) ("SectorAI", "we", "us") is the data controller for the personal data described below. This policy explains what we collect, why, and what rights you have over it.

What we collect

  • Account details — name, email, and business/organisation details you provide when signing up.
  • Uploaded documents and their extracted content — invoices, quotes, contracts, plans, and other files you upload, plus the supplier names, amounts, dates, and categories our AI extracts from them.
  • Questions you ask the AI — stored so you can see your own conversation history; you can turn this off in Settings → Business Memory, and past conversations remain deletable at any time.
  • Usage data — how many documents, invoices, and AI questions your workspace uses each month, for the purpose of enforcing your plan's limits.
  • Payment information — handled entirely by Stripe; we never see or store your card details ourselves, only the resulting subscription status.

Why we process it

To provide the Service you've signed up for (performance of a contract), to keep the Service secure and prevent abuse (legitimate interest), and to meet legal obligations such as tax and accounting record-keeping where applicable.

How the AI processing works

When you upload a document, its content is sent to OpenAI's API to extract structured data (supplier, amount, date, category) and to answer questions you ask about your business. OpenAI processes this under its API data usage terms, which — for API usage like this — exclude your data from being used to train their models. We never feed one customer's data into another customer's answers; every workspace's data is isolated.

Who we share data with

  • Supabase — hosts our database, file storage, and login system. Row-level security enforced in Postgres means every workspace's data is isolated from every other, in the database itself, not just in application code.
  • OpenAI — processes document content and chat questions as described above.
  • Stripe — processes payments and stores your payment method; we only receive subscription status back, never full card details.
  • Xero, Sage, or QuickBooks Online — only if you choose to connect one in Settings → Integrations. If connected, your invoice data is sent to your own account with that provider as a draft bill. Disconnecting stops this immediately.
  • Companies House — only when you use the business-name lookup at signup or in Settings → Organisation. Your search text is sent to the UK's public company register (a government service, not a marketing or advertising company) to help you find your registered company details.
  • Any webhook destination you set up (for example, Zapier) — only if you add one in Settings → Integrations. We send the event data you select to the URL you provide; you control what's sent and where.

We don't sell your data, and we don't share it with any advertising or marketing third parties.

Where your data is processed

Some of our service providers, including OpenAI, may process data outside the UK — including in the United States — as part of their global infrastructure. Where that happens, it's done under recognised safeguards such as Standard Contractual Clauses or an equivalent adequacy framework, designed to keep your data protected to a UK-equivalent standard regardless of where it's processed.

How long we keep it

We keep your data for as long as your workspace is active. If you cancel your subscription, your data remains accessible on a lapsed workspace so you can export it or resubscribe; it doesn't get silently deleted. You can permanently delete your entire workspace and everything in it at any time from Settings → Data & Privacy — this is irreversible.

Your rights

Under UK GDPR, you have the right to:

  • Access and exportyour data — available any time from Settings → Data & Privacy → Export.
  • Correct inaccurate account or organisation details — Settings → Account / Organisation.
  • Deleteyour data — Settings → Data & Privacy → Delete workspace, or contact us to request deletion of specific data.
  • Object to or restrict certain processing, and request data portability.

To exercise a right not covered by the in-app tools above, contact us. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you think we've mishandled your data.

Cookies and local storage

We use only essential cookies: one to keep you signed in, and — only if you connect Xero, Sage, or QuickBooks — a short-lived one to secure that connection process, which expires within minutes. We don't use advertising or tracking cookies, and there's no third-party analytics on the signed-in product. Some preferences (like dark mode, sidebar state, and dismissed prompts) are stored locally in your browser only and never sent to us.

Security

Every workspace's data is isolated at the database level via row-level security in Postgres, not just in application logic. Two-factor authentication is available for every account in Settings → Security. All traffic is encrypted in transit.

Children

The Service is intended for business use by adults and isn't directed at children.

Changes to this policy

We may update this policy from time to time; material changes will be communicated by email or in the app.

Contact

Questions about this policy or your data: contact us.