Scrinio
Privacy Policy
Last updated: 7 July 2026
This policy explains what personal data Scrinio (“we”, “us”) collects when you use the app, why we hold it, who processes it on our behalf, and the rights you have over it. Scrinio is a private, invitation-only tool for recording and understanding your own UK payslips, tax and student-loan position.
Who we are
The data controller — the person who decides why and how your data is handled — is P Dobrev, contactable at privacy@scrinio.app. For any question about this policy or your data, use that address.
What data we collect
- Account data— the email address you sign in with (magic-link authentication; we don’t store a password).
- Profile data you provide — such as your name, employer, role, tax code, National Insurance number, pension contribution rates, salary and student-loan details.
- Payslip and loan data — the figures from each payslip and student-loan statement you add (gross pay, tax, NI, pension, deductions, balances and similar).
- Uploaded documents — the payslip and loan-statement files (PDFs and images) you upload, kept so you have the source alongside the parsed figures.
- Preferences — settings such as your chosen views and projection assumptions.
This data includes information about your finances. It does notinclude special-category data, and we don’t ask for more than the app needs to do its job.
How we use it, and our lawful basis
We use your data solely to provide the service to you: to store your records, compute your tax, NI, pension and student-loan figures, and show you summaries and projections. Because Scrinio is a tool you choose to use for your own records, our lawful basis under UK GDPR is performance of a contract with you (Article 6(1)(b)), and where relevant our legitimate interests in operating and securing the service (Article 6(1)(f)). We do not use your data for advertising, and we do not sell it.
Automated document processing
When you upload a payslip or statement, its contents are sent to our document-processing provider, Anthropic(the Claude API), which extracts the figures so you don’t have to type them in. Every extracted value is shown to you for review before it is saved, and all tax / NI / student-loan calculations are performed by our own deterministic engine — not by an AI model. We do not use your data to train any AI model. This processing does not make any decision that produces a legal or similarly significant effect on you.
Where your data is stored and who processes it
We rely on a small number of processors, each handling data only to run the service:
- Supabase — database, authentication and file storage. Your data is stored in the United Kingdom (London region).
- Railway — application hosting (serves the app; does not store your records).
- Anthropic — document figure-extraction, as described above.
Your records and files are stored at rest in the UK. The one transfer outside the UK is document parsing: when you upload a payslip or statement, its contents are sent to Anthropic in the United Statesto extract the figures. That transfer is covered by Anthropic’s data-processing terms and standard contractual safeguards. No other personal data leaves the UK.
How long we keep it
We keep your data for as long as your account exists. When you delete your account, your profile, all payslips, loan statements, preferences and every uploaded file are erased immediately (see below). We do not retain deleted-account data beyond our hosting provider’s standard backup rotation, after which it is gone permanently.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- receive your data in a portable format;
- restrict or object to certain processing;
- complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.ukif you think we’ve mishandled your data.
You can exercise most of these directly in the app: your profile is editable at any time, and Delete account (on your Profile page) permanently erases everything — your records and every uploaded file together, with no recovery. For access or portability requests, contact us at privacy@scrinio.app.
Security
Access is protected by magic-link sign-in and row-level security, so each account can only ever reach its own data. Files are stored in per-user locations under the same access rules. We use encrypted connections throughout.
Changes to this policy
If we change how we handle your data we’ll update this page and its “last updated” date. Material changes will be brought to your attention.
Contact
Questions about this policy or your data? Email privacy@scrinio.app.