Magpie

Legal · Privacy policy · Last updated 2026-09-07

Privacy policy

Draft — not yet lawyer-reviewed

Written honestly by the engineers who built Magpie. A solicitor should review this document before Magpie takes real customers.

Who runs Magpie

Magpie is operated by J M DIMONACO LTD, a company registered in England and Wales (company number 14260548). For anything in this policy, email hello@magpie.tax. J M DIMONACO LTD is the data controller for the personal data described below.

What Magpie stores

Magpie stores what it needs to match receipts to payments and to track filing deadlines — nothing else. Concretely:

  • Your account — email address, name, and a password hash if you sign up with a password (never the password itself). If you sign in with Google or Microsoft, we store the identifier that provider gives us. While you are signed in we also keep routine session records — IP address and browser details — which are deleted with your account.
  • Company details — your company number and the public Companies House data derived from it (accounts and confirmation statement due dates, filing history dates).
  • Bank transactions — date, amount, merchant, category, account identifiers, and the bank's free-text description line (which can itself contain names or payment references) for accounts you connect. Bank accounts are connected through a regulated open-banking provider — TrueLayer, or GoCardless for older connections (see below) — which is how every bank reaches Magpie. There is no bank-specific integration.
  • Receipts — receipt emails and attachments fetched from inboxes you connect (Gmail or Outlook), receipts forwarded to your Magpie ingest address, and files you upload by hand. Confirmed receipts are stored in Magpie's file vault.
  • OAuth tokens — the access and refresh tokens for services you connect (Google, Microsoft, TrueLayer). These live server-side only and are never sent to your browser.
  • Organisation membership — who belongs to which organisation, their role, and the email addresses of people who have been invited.
  • Service records — basic first-party usage facts, like counts of what the service has done for you (receipts filed, reminders sent, AI actions used this month). These exist so the operator can see Magpie is working and understand how it is used. They stay in Magpie's own database, carry no transaction amounts or receipt contents, and never go to any analytics company.
  • Export packs — if you build an accountant export pack, the ZIP is held for 24 hours so you can download it, then deleted automatically.

Who processes it

Magpie runs on a small set of infrastructure and service providers. Each only receives what its job requires:

  • Convex — the database and file storage. Everything listed above lives here.
  • Vercel — hosts the web application.
  • Google — sign-in; and Gmail (read-only) and Google Drive (files Magpie creates only), when you connect them. Magpie's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide Magpie's receipt features to you — finding and filing your receipts, and answering the questions you ask Ask Magpie about them. It is never used for advertising, never sold, never read by a human except where you ask for support or the law requires it, and never used to train AI models.
  • Microsoft — sign-in; and Outlook inbox reading, when you connect it.
  • TrueLayer — the FCA-authorised open-banking provider that connects to your bank and passes your transactions to Magpie, when you connect an account. Your bank credentials are entered at your bank, never at Magpie or TrueLayer.
  • GoCardless — an alternative open-banking provider. It is dormant: it handles bank connections made before 2026-07-18, and is only ever used for a new one on a deployment where TrueLayer is unavailable.
  • Resend — sends Magpie's emails (deadline reminders, invites, verification and password resets) and receives email you choose to forward to your Magpie ingest address.
  • Companies House — Magpie queries the public Companies House API with your company number.
  • Anthropic — the AI features, and only when you ask for them. Nothing is sent automatically. “Scan with AI” sends the text of that one receipt or forwarded email. “Draft with AI” sends your instruction, the text of the document you are editing, and your company name and number. Ask Magpie (the chat) sends your question plus whatever it needs to answer it from the organisation you are working in — that can include transaction rows (date, merchant, the bank's description line, amount, category) and details of receipts waiting to be filed (sender, subject, filename, and what Magpie read from them). Magpie never sends anything from another organisation, and Anthropic does not train models on it.
  • PostHog — product analytics may be enabled; it is currently not. If it is enabled, this policy will say so and describe what is collected. Magpie uses no other third-party analytics or tracking service; the first-party service records described above are the whole story.

Where it lives

Plainly: Convex and Vercel host in the United States, and Anthropic processes AI requests there, so your data is stored and processed there. Under UK GDPR that is an international transfer. It relies on each provider's data-processing terms, which incorporate the UK's approved transfer safeguards — the ICO's addendum to the standard contractual clauses, or the UK–US Data Bridge where the provider is certified. If US hosting is a dealbreaker for you, Magpie is currently not the right tool.

Why we're allowed to (lawful basis)

Under UK GDPR, Magpie processes your data on two bases: contract — storing transactions, receipts and tokens is the service you signed up for and cannot be done without them — and legitimate interest for deadline reminder emails and the service records above, which exist so your company doesn't file late and so the operator can keep the service working. Magpie does not sell data or use it for advertising.

Some data Magpie holds is about people other than you: the email address of someone you invite to your organisation, or a name that appears in a bank transaction's description line. Magpie processes that under legitimate interest too, solely to run your organisation and match your receipts.

Who else can see your data

If you join or create an organisation with other people, the organisation's data — transactions, receipts, deadlines — is visible to its members. That is the point: you invite your accountant so they can see it. Roles limit what members can do (only owners and admins manage members and connections), but assume anyone in your organisation can read its data.

The accountant role reads everything and builds export packs. It is a working role: it can triage and file receipts, categorise, and write notes, documents and templates, and it can run AI actions, which draw on that organisation's monthly allowance rather than the accountant's own. It cannot change org settings or connections, and it cannot delete your organisation's shared records — a deletion it asks for goes to an owner or admin to approve. It can remove notes and templates it wrote itself.

The boundary runs the other way too: each organisation's data is visible only to its own members. An accountant who works with several companies on Magpie sees each client separately — one organisation's members never see another's data. And if a member you invited exports your data into their own systems (an accountant pulling records into their practice software), those copies are theirs to look after, under their own professional and legal obligations.

We can see some of it. Magpie's operator has an internal dashboard showing account and organisation metadata — organisation names, owner email addresses, member counts, plan, and how many AI actions each organisation has used this month — so we can answer support questions and manage billing. It does not show your transactions, receipts, documents, notes or templates. The operator can also reach data where genuinely needed to run, debug and support the service, and does so only for that. Aside from that, nobody outside your organisations sees your data.

How long we keep it

Your data is kept while your account exists. A few things expire on their own timers: export pack ZIPs are deleted 24 hours after they are built, and the short-lived state used during OAuth connection flows expires after one hour. Everything else stays until you delete it — or delete your account.

Deleting your account

You can delete your account and all associated data at any time from Settings → Danger zone. Deletion is immediate and total in Magpie's live systems: every transaction, receipt, vaulted file, connection and stored token of yours is erased, and third-party access is revoked where the provider supports it: the Google grant is revoked outright; a GoCardless bank consent is deleted; TrueLayer is told to delete the data held against your connection, though the bank consent itself simply lapses on its own 90-day timer. Microsoft offers no remote revoke endpoint, so those tokens are destroyed on our side — you can additionally withdraw Magpie's access in your Microsoft account settings, and your bank or its app can withdraw an open-banking consent at any time.

One guard: if you own an organisation that still has other members or pending invites, deletion is refused until you remove them or transfer ownership — so an accountant's access is never silently orphaned.

What deletion cannot reach

Honestly, a few copies are beyond the delete button:

  • Platform backups. Convex keeps operational backups and point-in-time recovery snapshots of the whole deployment. Your rows vanish from the live database instantly but persist inside those backups until they age out on Convex's schedule; we cannot surgically erase one user from a platform backup.
  • The providers' own copies. Revoking our access deletes nothing at Google, Microsoft, TrueLayer or your bank — your bank still has your transactions and Gmail still has the receipt emails, under each provider's own terms. Magpie only ever held read copies.
  • Email already sent. Deadline reminders and invites already delivered can't be recalled, and Resend retains delivery metadata per its own policy.
  • Copies in your own storage. Receipts exported to your Google Drive or Nextcloud, export packs you already downloaded, and data a member of your organisation exported while they had access, are outside Magpie and stay where they were put.
  • A just-deleted session, briefly. A signed-in session's token stays technically valid for up to ~15 minutes after deletion (it cannot renew). Only your own already-open tab could use it.
  • Operational logs. Convex and Vercel request logs may retain non-identifying operational metadata for their standard windows.

Cookies

Magpie sets the cookies needed to keep you signed in — nothing else. No analytics, advertising or cross-site tracking cookies, which is also why there is no cookie banner: there is nothing to ask consent for.

Your rights

UK GDPR gives you the right to access, correct, export, restrict and erase your personal data, and to object to processing. Most of these you can exercise yourself: export packs give you your data; the danger zone erases it. For anything else, email hello@magpie.tax. If you think Magpie has mishandled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk.

Changes to this policy

When this policy changes materially, the date at the top changes and signed-in users will be told in the app. The current version always lives at this address. See also the Terms of Service.