Skip to main content

Privacy Policy

Last updated: September 13, 2026

1. Introduction

This Privacy Policy explains how Richard Moore trading as Experi ("we," "us," or "our") collects, uses, stores, and protects your personal data when you use the Experi service (experi.co.uk).

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller

Name: Richard Moore (sole trader)

Trading as: Experi

Address: 6 Farm Lane, Send, Surrey, GU23 7AT, United Kingdom

ICO registration: ZC239393 (view public register)

Contact: hello@experi.co.uk

2. What Data We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Password hash (we do not store your password in readable form)
  • Account creation date

2.2 Business Profile Data

When you set up your business profile, we collect:

  • Business name
  • Contact name
  • Business address
  • Business email and phone number
  • Tax information (VAT number, company number)
  • Bank details (for display on invoices)
  • Payment preferences

2.3 Client Data

When you add clients, we collect:

  • Client name and company
  • Client email address
  • Client postal address
  • Notes about the client

2.4 Invoice Data

When you create invoices, we collect:

  • Invoice details (items, amounts, dates)
  • Payment information
  • Invoice status
  • Email send history

2.5 Payment Information

Web subscription payments are handled by Stripe. Where in-app subscriptions are available, Apple processes App Store purchases and Google processes Google Play purchases. Availability depends on the platform and app configuration; this policy does not mean purchases are enabled in every version of the app. We do not store your full credit card details. We only store:

  • Stripe customer ID
  • Subscription status
  • Subscription plan
  • Payment dates

The mobile subscription service uses RevenueCat to verify purchases, restore access and keep subscription status consistent with the web app. RevenueCat receives your Experi account identifier, purchase history and subscription transaction information, and processes these for subscription functionality and subscription analytics. We do not send your invoices, client records, password or bank details to RevenueCat. The applicable store provider (Apple or Google) and RevenueCat process this information under their respective privacy notices.

2.6 Usage Data

We automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent
  • Referring website
  • Session data
  • Performance and error data (via New Relic Browser, when you have accepted analytics cookies)

2.7 Cookies and Analytics

We use cookies for authentication and session management. With your consent we also use Google Analytics and New Relic Browser for usage and performance monitoring. See our Cookie Policy for details.

2.8 HMRC-Connected Services

If you choose to connect Experi to HMRC, we process the information needed to provide the HMRC features you authorise, which may include:

  • Encrypted OAuth access and refresh tokens and the permissions you grant
  • Taxpayer and business identifiers, such as your NINO, MTD identifier, VAT registration number, and HMRC business identifiers
  • Income sources, obligations, accounting periods, return data, calculations, declarations, submission status, and HMRC receipt or correlation references
  • Technical audit records for HMRC API calls
  • Fraud-prevention information required by HMRC, including available IP address, port, browser, device, screen, time-zone, window-size, user-identifier, and multi-factor authentication information

You sign in and grant authority on HMRC's service. Experi does not collect or store your HMRC username, password, or HMRC two-step verification code.

2.9 MCP Agent Access

If you enable MCP and connect a compatible AI agent, we process:

  • The connected client name, selected permissions, expiry, keyed token or credential hash, and revocation status
  • Connection security data such as IP address, user agent, time, requested tool, outcome, and affected record type or identifier
  • The business, client, invoice, and payment information needed to answer or carry out the tool request you authorised
  • Idempotency receipts used to prevent an agent retry from duplicating an action

Experi does not store plaintext manual credentials or OAuth tokens. OAuth access tokens are short-lived and refresh tokens rotate after use. We do not store MCP request bodies in the activity log. MCP is off by default and disabling it revokes all active OAuth connections and manual credentials.

2.10 Experi Assistant

When you choose to use Experi Assistant, your question and the current conversation are sent through Vercel AI Gateway to our configured AI model provider, such as Anthropic or OpenAI, to generate a reply. This is separate from MCP agent access. The assistant does not automatically access your business records or perform business actions. Information you type is included: do not enter customer records, tax identifiers, passwords or bank/card details.

The mobile app keeps the conversation in memory. Experi's application database retains usage and security metadata, not the chat transcript. This metadata includes account and session identifiers, subscription tier, token counts, request timing, a hashed IP address and request outcomes. The gateway and model provider have their own processing and retention arrangements; clearing the conversation on your screen does not recall information already processed by them. We do not promise zero retention by those providers. You can use ordinary business features without using the assistant.

2.11 Mobile Drafts and Local Files

Guest invoices are stored on your device and are not backed up to Experi. Signing in does not automatically save or send them: you choose a business and review the invoice before saving it to your account. The original guest draft can remain on the device after import. Anonymous guest drafts are accessible without signing in on that device, so protect access to your phone.

Signed-in offline invoice drafts are removed when you sign out. Guest drafts and recoverable timer data can remain on the device; account-linked timer recovery requires the same account to sign in again. Save or export unfinished work before signing out or clearing app data. PDF previews and exports use temporary local files, which Experi attempts to remove after use. Files you save or share elsewhere remain under your control or the recipient's; account deletion does not recall them.

After account deletion is confirmed in the mobile app, it attempts to remove that account's local invoice drafts, imported guest copies, timers and navigation cache on that device. It shows the cleanup result and a local retry if needed. This does not remotely erase another device or remove anonymous guest drafts, another person's work or files saved outside the app. If local cleanup cannot finish, follow the device-cleanup guidance and preserve any other unfinished work first.

3. Why We Collect Your Data (Legal Basis)

3.1 Contract Performance

We process your account, business, client, and invoice data to provide the Service you signed up for. If you connect HMRC, this includes retrieving authorised HMRC information, preparing returns, and transmitting a return only when you instruct us to submit it. This processing is necessary for the performance of our contract with you.

3.2 Legitimate Interests

We process usage data to:

  • Improve the Service
  • Detect and prevent fraud
  • Ensure security
  • Analyze usage patterns
  • Provide customer support
  • Review business identity and authority when you request email sending access

3.3 Legal Obligation

We may process data to comply with legal requirements, such as responding to lawful requests from authorities and collecting and sending the fraud-prevention information required for relevant HMRC API requests.

3.4 Consent

For marketing communications, we will only contact you if you have given explicit consent.

4. How We Use Your Data

We use your data to:

  • Create and manage your account
  • Provide invoice creation and management services
  • Send invoices via email to your clients
  • Process subscription payments
  • Send automated invoice reminders
  • Provide customer support
  • Send service-related notifications (e.g., password resets, subscription changes)
  • Improve and develop the Service
  • Detect fraud and ensure security
  • Comply with legal obligations
  • Connect to HMRC using OAuth 2.0 when you ask us to do so
  • Retrieve HMRC information within the permissions you grant
  • Prepare, review, and submit HMRC returns when the connected filing feature is available and you explicitly confirm submission
  • Maintain submission evidence and reconcile responses received from HMRC

✓ We Do NOT :

  • Sell your data to third parties
  • Use your data for unrelated marketing
  • Share your client data with competitors
  • Use your invoice data for our own business purposes

5. Where We Store Your Data

Your data is stored with the following trusted service providers:

  • Supabase (PostgreSQL database): Account, business, client, and invoice data, email access review messages and any supporting documents you choose to submit, together with encrypted HMRC connection credentials, tax identifiers, return records, and submission evidence. The primary database is hosted on AWS in London, United Kingdom (eu-west-2).
  • Vercel: Application processing in London, United Kingdom and Dublin, Ireland. Uploaded files are stored in Vercel Blob in Dublin, Ireland (dub1).
  • Resend: Email delivery service for sending invoices to your clients.
  • Stripe: Payment processing (USA-based, GDPR-compliant).
  • Apple, Google and RevenueCat: Where enabled, Apple App Store or Google Play processes mobile subscription payments. RevenueCat provides purchase verification, restoration, subscription status coordination and subscription analytics.
  • Vercel AI Gateway and AI model providers: Process the question and conversation you submit to Experi Assistant to generate a reply. This processing may take place outside the UK. It is distinct from our main application and database hosting locations above.
  • New Relic: Browser performance and error monitoring (only when you have accepted analytics cookies). Data is sent via our domain and processed by New Relic (USA-based, GDPR-compliant).

When data is transferred outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions.

6. Who We Share Your Data With

We may share your data with:

6.1 Service Providers

  • Hosting providers (Vercel, Supabase)
  • Email service (Resend) - to send invoices on your behalf
  • Payment processor (Stripe) - to process subscriptions
  • Apple App Store or Google Play, where enabled, and RevenueCat - to process and verify mobile subscriptions, restore access and coordinate subscription status
  • Vercel AI Gateway and the configured AI model provider - to answer questions you choose to send to Experi Assistant
  • Analytics and performance monitoring (Google Analytics, New Relic Browser) - only when you have accepted analytics cookies

6.2 Your Clients

When you send an invoice, we share the invoice data (business details, amounts, items) with your client via email. This is at your instruction.

6.3 HM Revenue & Customs

When you connect HMRC, we exchange OAuth credentials and authorised information with HMRC. When you confirm a submission, we send the relevant return data, declaration, identifiers, and HMRC-required fraud-prevention information to HMRC. HMRC processes that information under its own privacy arrangements.

6.4 Legal Requirements

We may disclose data if required by law, court order, or to protect our legal rights.

6.5 Business Transfers

If Experi is sold or merged, your data may be transferred to the new owner (you will be notified).

6.6 AI Agents You Choose

When you approve an MCP OAuth connection or give a manual MCP credential to an AI agent, information returned under the permissions you selected is sent to that service at your instruction. That third party controls its own processing, storage, and model-training practices. Review its privacy terms before connecting it, grant the smallest permissions needed, and revoke the connection or credential when it is no longer required.

7. How Long We Keep Your Data

  • Active accounts: Data is retained for as long as your account is active. This includes email access review conversations and any business evidence you submit; those files are available only to you and authorised Experi administrators.
  • After account deletion: The confirmed deletion removes your sign-in account and owned business records from our active account database. This does not automatically recall exported files, emails already delivered to recipients or copies held by service providers. Audit records may be retained in anonymized form for security and compliance. Contact us about associated files or provider-held data you want erased; applicable legal retention obligations may still apply.
  • Database backups: Deleted data may persist in encrypted backups for up to 30 days before being permanently purged.
  • Legal holds: If your account is subject to a legal investigation or court order, we may be required to retain data longer than stated above.
  • HMRC connection: Disconnecting HMRC removes the stored access and refresh tokens. Tax records, submission evidence, and audit records remain subject to the account-retention rules above and any applicable legal obligations.
  • MCP agent access: Disabling MCP revokes OAuth connections and manual credentials. Deleting your account deletes OAuth grants and tokens, manual credentials, idempotency receipts, and MCP activity records from the active database. Encrypted backup retention follows the rule above.
  • Assistant and local data: Clearing the mobile assistant conversation removes it from that screen, not usage/security records or provider-held information. Guest drafts and recoverable timer data can remain locally as described in section 2.11. Removing a business logo from your profile stops using it on new documents but does not by itself erase the previously uploaded file. Contact us for help with deletion of associated uploaded files.

Self-Service Deletion: You can review and confirm deletion through the account deletion page. Identity verification is required. Contact support if you cannot sign in or need help with associated provider-held data or uploaded files.

8. Your Rights Under GDPR

You have the following rights:

8.1 Right to Access

You can request a copy of all personal data we hold about you.

8.2 Right to Rectification

You can update incorrect or incomplete data via your account settings or by contacting us.

8.3 Right to Erasure ("Right to be Forgotten")

You can review and confirm deletion of your account and its owned business records through your account deletion page. This removes the following records from our active account database, subject to the retention and associated-data boundaries in section 7:

  • Your user profile and authentication data
  • All invoices and line items
  • All client records
  • All recurring invoice configurations
  • All email history and logs
  • Your business profile information

⚠️ Important: Account deletion is permanent and cannot be undone. We recommend exporting your data before deletion. Audit logs may be retained in anonymized form for security and compliance purposes.

8.4 Right to Data Portability

You can export supported account and business data in JSON format through your Account Settings. The export includes:

  • Your profile and account information
  • Complete invoice history with line items
  • All client data
  • Business profile settings
  • Recurring invoice configurations
  • Email sending logs
  • Recent audit logs (last 1,000 entries)

This data is provided in machine-readable JSON format, making it easy to transfer to another service or keep as a backup. The automated export is not a complete copy of every business module or uploaded file. The export screen explains its current coverage; contact us to request personal data not included in that export.

8.5 Right to Restrict Processing

You can request that we stop processing your data in certain circumstances.

8.6 Right to Object

You can object to processing based on legitimate interests or for marketing purposes.

8.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time.

How to Exercise Your Rights

To exercise any of these rights, please email us at hello@experi.co.uk. We will respond within 30 days.

9. Security

We implement appropriate technical and organizational measures to protect your data:

  • Passwords are salted and hashed using bcrypt and are not stored in readable form
  • HMRC OAuth tokens and taxpayer identifiers are encrypted at rest
  • Data is transmitted over HTTPS (SSL/TLS encryption)
  • Access to data is restricted to authorized personnel only
  • Regular security updates and monitoring
  • Database backups and disaster recovery procedures

However, no system is 100% secure. We cannot guarantee absolute security, but we take all reasonable steps to protect your data.

10. Children's Privacy

Experi is not intended for use by anyone under the age of 18. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top indicates the most recent revision.

12. Complaints

If you believe we have not handled your data properly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

Information Commissioner's Office (ICO)

Website: ico.org.uk

Phone: 0303 123 1113

Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

13. Contact Us

If you have questions about this Privacy Policy or how we handle your data:

Data Controller: Richard Moore (sole trader)

Trading as: Experi

Email: hello@experi.co.uk

Registered business address: 6 Farm Lane, Send, Surrey, GU23 7AT, United Kingdom

© 2026 Experi. All rights reserved.