Privacy Policy

Last updated: 10 September 2026

This policy explains what personal data Summarly processes, why, and the rights you have over it. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and the Cyprus data protection law.

Who we are

Summarly is operated by Summarly (“Summarly”, “we”, “us”), a company registered in Cyprus. For any privacy question or to exercise your rights, contact founders@summarly.com.

Which of us is responsible for what

We hold two different kinds of personal data and our role is not the same for both. The distinction decides who answers when someone exercises a right, so it is worth stating before anything else.

DataControllerOur role
Your workspace contents — transactions, receipts, invoices, customers, suppliers, employees and payslipsYouProcessor.We hold and process it to run the service for you, on your instructions and nobody else’s.
Your account — sign-in identity, name, email, billing record, and the technical logs that keep the service upSummarlyController. We decide what is needed in order to give you an account and run it safely.

So the people named inside your books — your customers, your suppliers, your employees — are your data subjects, not ours. If one of them exercises a right against you, you act on it, and the export and deletion tools described below are how.

What we collect

  • Account data — your email address, and your name and avatar if your sign-in provides them.
  • Workspace & financial data — the company details, bank accounts, transactions, categories, VAT data, and the receipt and payslip files you upload. This is the core of the service and may include personal data about you and third parties named in your records.
  • Assistant conversations — the messages you send to the in-app AI assistant and its responses, stored so your history persists.
  • Technical data — basic logs needed to operate and secure the service (e.g. timestamps and error logs). We do not use third-party advertising or analytics trackers.

How we use it & our legal basis

  • To provide the service — importing statements, categorizing transactions, matching receipts, producing reports and exports. Legal basis: performance of our contract with you.
  • To secure and maintain the service — authentication, backups, fraud and abuse prevention. Legal basis: our legitimate interests in running a safe service.
  • To communicate with you — service emails such as sign-in links and important notices. Legal basis: performance of our contract and our legitimate interests.

Those legal bases are ours, for the account data we control. For the contents of your workspace we act on your instructions as processor, and the legal basis for processing the people named in your books is yours to establish — normally your own contract with them, or the accounting and tax law you are keeping the records under.

We do not sell your data, and we do not use your financial data or assistant conversations to train AI models. Our AI Terms set out exactly which features send data to a model and what reaches it.

Sub-processors

We rely on a small number of vetted service providers to run Summarly. Each processes data only on our instructions and under a data processing agreement.

ProviderPurpose
SupabaseDatabase, file storage, authentication.
Anthropic (Claude)AI categorization, receipt extraction, and the assistant. Inputs are not used to train models — see our AI Terms.
VercelApplication hosting.
MXrouteSign-in and notification emails we send you.
ResendReceipts and invoices you forward to your workspace email address, and the waiting list.
CloudflareBot protection on sign-up and the waiting list, which sees the IP address of the device making the request.

Some of these providers are established outside the EEA. Where personal data is transferred to them, the transfer is protected by appropriate safeguards such as the EU Standard Contractual Clauses.

Payments are handled by Polar, who act as merchant of record. They are the seller for your subscription rather than a provider acting on our instructions, which makes them a separate data controller for the payment — their own privacy policy governs what they hold. We never see or store your card details.

How your data is protected

  • Each workspace’s data is isolated at the database level, so one customer can never access another’s records.
  • Data is encrypted in transit (TLS) and at rest. Receipt and payslip files are kept in a private store, reachable only through short-lived signed links.
  • Access by Summarly staff is restricted to what is needed to operate and support the service.

How long we keep it

We keep your data for as long as your account is active. When you delete your workspace, its records and uploaded files are permanently removed, except where we must retain limited information to meet a legal obligation.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • export your data — you can download a full copy at any time from Settings → Privacy & data;
  • delete your data — you can erase your workspace and account from Settings → Privacy & data;
  • correct inaccurate data, or restrict or object to processing;
  • lodge a complaint with the Cyprus Office of the Commissioner for Personal Data Protection.

Those are the rights you hold against us, over the account data we control. For the personal data inside your workspace we are the processor and you are the controller, so a request from someone named in your books is answered by you — we will help, and we will not act on their data ourselves except on your instructions or where the law requires it.

Changes

We may update this policy from time to time. Material changes will be communicated through the app or by email before they take effect.

Questions? Email founders@summarly.com.