Privacy notice
Tracepaper Privacy Notice
This notice explains what happens to your information when you use Tracepaper (the “Service”).
1. Who we are
to be completed before the beta opens, of to be completed before the beta opens. We are the data controller for the personal data described in this notice. Our ICO registration number is to be completed before the beta opens. You can contact us about privacy at to be completed before the beta opens.
2. The short version
The Service is built so that your documents never leave your device as documents. Here is what actually happens when you use it:
- You upload a payslip, P60, P11D, P45 or broker statement in your browser.
- Before anything is sent anywhere, your browser removes your name, National Insurance number, address, employee number and bank/account details from the page image, and stamps it “Redacted copy — not an original document.”
- That redacted page image is sent, over an encrypted connection, through a relay we operate — a Cloudflare Worker which logs nothing and keeps nothing of your document, only a count of how many documents your beta pass has read (§7) — to Anthropic’s Claude API, which reads the figures off the page and returns them.
- The figures — pay, tax, NI, pension contributions, share vest amounts and so on — are stored in your own browser, on your own device. We do not store them, the document, the page image, or your name/NI number/address, because our systems never receive them.
- There is no account. Nothing you upload or confirm is tied to you anywhere except in your own browser, and clearing it there removes the only copy. The one piece of personal data we may hold is the email address you gave to get a beta pass (§3a). We do not join it to the relay’s document count, and the count is stored under a key that gives no way of finding out whose it is — but we are the people who hold both the secret that makes those keys and the sign-up list, so this is us keeping two things apart, not something mathematics does for you. §7 says so again, in full.
The rest of this notice sets out the legal detail UK GDPR requires.
3. What personal data we process, and where
| Data | Where it lives | Who processes it |
|---|---|---|
| Redacted page image (a payslip/P60/etc. with name, NI number, address, employee number and bank details removed in your browser before upload) | Transits a relay we operate; sent on to Anthropic’s Claude API for extraction; not stored by us | Us, only in transit; the relay (our processor, which logs nothing and keeps nothing of the document); Anthropic (processor, see §5) |
| Beta pass document count — one number, how many documents that pass has read | Our relay, under a key derived from the pass identifier with a secret salt; expires when the pass does | Us (controller) — see §7 and §8 |
| Extracted figures (pay, tax, NI, pension contributions, share vest values, dates, tax codes, employer name as printed, scheme name as printed) | Your browser’s own storage, on your device; on no server of ours | You. We never receive them |
| Optional improvement data (tier 1: layout fingerprint and which fields needed checking, no figures; tier 2: a redacted page plus your confirmed figures, only if you opt in per document) | Our servers, not linkable to you — there is no account to link to | Us (controller) — see §4 and §9 |
| Beta sign-up email address (asked for when you request a beta pass; nothing else — see §3a) | A store kept apart from every other system described in this notice, including the relay | Us (controller); Cloudflare (processor, hosting the store) |
| Support correspondence | Our mailbox, to be completed before the beta opens | Us (controller); our email hosting provider (processor) |
We do not collect your name, National Insurance number, home address, employee number or bank account details as a matter of design — your browser removes them before any upload happens. If you type any of these into a free-text field (for example a support message), we hold what you send us, as with any support correspondence.
3a. The beta sign-up list
If you asked for a beta pass by giving us your email address, that address is the one piece of personal data we hold that is not a figure you confirmed or a support message you sent us. We keep it and nothing else about you — no name, no documents, nothing about what you upload. We use it for two things: to tell you when the beta opens or when something about it changes, and to ask you a handful of questions once you have used it. Ask and we delete it. Using the Service does not require a beta pass to work once the beta ends, and the pass itself carries no trace of your email — it is a random identifier the relay checks without looking anything up.
We do not join that address to the one number the relay keeps against your pass (§7), and we have built it so that the number gives no way of finding out whose it is. We would rather be exact than reassuring about what that means: joining the two would need both the relay’s secret salt and this sign-up list, we hold both, and nobody outside holds either. Somebody who obtained the whole relay store and nothing else would learn that some pass had read twelve documents and could not say whose. That is a real protection against a breach and against anyone else; it is not a claim that we could not do it ourselves.
One further field is stored on that record, and only when the link you followed carried
one: a short tag naming the link, such as ?src=hn, so we can tell which link
brought people here. It is a word we put in our own links; it is not derived from you, and
it is the only thing about your visit that is recorded. No cookie is set, no IP address,
browser or referrer is stored, and there is no analytics on the site or in the app. The
whole record is four fields: your email address, the identifier of your pass, the date, and
that tag.
4. Why we process it, and the legal basis (UK GDPR Article 6)
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the calculation service you asked for (extraction, reconciliation, tax and pension figures) | Redacted page image (transiently); extracted figures | Contract (Article 6(1)(b)) — necessary to perform the service you signed up for |
| Keeping the reader open only to beta users, and within a spend we can bear | The beta pass (a random identifier the relay checks), the count of documents that pass has read (§7), and, at sign-up, your email address | Legitimate interests (Article 6(1)(f)) — keeping the Service running for everyone using it |
| Improving extraction accuracy — tier 1 signal (layout fingerprint, which fields failed a check, no figures) | Layout fingerprint, field names, pass/fail outcomes, rotating pseudonym | Legitimate interests (Article 6(1)(f)) — see §9; documented in our legitimate interests assessment (part of our data protection impact assessment); you can turn this off in settings |
| Improving extraction accuracy — tier 2 (a redacted document plus your confirmed figures, used as a test case) | Redacted page, confirmed field values | Consent (Article 6(1)(a)) — asked separately for each document, never bundled with these terms |
| Legal and regulatory compliance (tax, accounting, complaint handling) | Billing records once there is a paid service (there is none during the beta); complaint correspondence | Legal obligation (Article 6(1)(c)) |
We do not rely on consent for the core Service, because consent must be freely given and it is not “free” if refusing it means the Service does not work. The core processing (§3, redacted-image extraction) is necessary to perform the contract with you.
5. Anthropic — the transient processor doing the reading
The one thing that leaves your device that could, if the relay or Anthropic misbehaved, be linked back to you is the redacted page image. This section is deliberately detailed because it is the crux of the architecture.
- What Anthropic receives: a redacted page image (no name, NI number, address, employee number or bank details — removed in your browser before upload) and the extraction prompt. It does not receive your name or your email address; the relay does not forward them, and the beta pass it checks is a random identifier that carries neither.
- What Anthropic does with it: reads the figures off the page and returns structured data. Per Anthropic’s Commercial Terms (effective 17 June 2025) and Data Processing Addendum (effective 24 February 2025, both read 2026-09-09): “Anthropic may not train models on Customer Content from Services”; Anthropic is the processor, we are the controller.
-
Retention — the point that must not be glossed over. Anthropic’s stated
default (
privacy.claude.com, “How long do you store personal data”, last updated 1 July 2026, read 2026-09-09) is: “we automatically delete inputs and outputs on our backend within 30 days of receipt or generation,” except content flagged by trust-and-safety systems (kept up to 2 years, with classifier scores kept 7 years), or “when you and we have agreed otherwise (e.g. zero data retention agreement).” Zero data retention is available only “subject to Anthropic’s approval,” requested through their sales team, and even then Anthropic retains safety-classifier results. As of this notice, we have not yet signed a zero data retention agreement with Anthropic. Until we do, the honest position is: the default 30-day retention applies to the page images sent for extraction, held on Anthropic’s infrastructure, not ours. A zero-retention agreement must be in place, and this notice updated to reflect it, before this product accepts real users’ documents at scale. - International transfer. Anthropic processes in the United States. It acts as our processor under its Data Processing Addendum, which incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (the Information Commissioner’s template, version B1.0). That Addendum is the safeguard this transfer relies on. We do not rely on the UK–US data bridge, because we have not confirmed that Anthropic is certified under it.
- The relay. The relay between your browser and Anthropic is a Cloudflare Worker. Its request logging is switched off, and it keeps nothing of your document once it has passed the image on and the figures back. It has exactly one store attached and nothing else — no second database, no file store, no queue — and that one store holds a single number per beta pass and nothing more (§7). It counts requests per IP address for up to a minute, to stop one address flooding it, and keeps no record afterwards. Cloudflare, as the network the request travels through, necessarily processes connection details such as your IP address to deliver and protect the service, as our processor; we do not collect or keep them.
6. Other processors
- Hosting for the site, the relay and the beta sign-up list: Cloudflare. Nothing of yours is hosted there except, if you asked for a beta pass, your email address (§3a).
- Email: our email hosting provider, for correspondence you send us.
- Each processor operates under a data processing agreement consistent with UK GDPR Article 28. Cloudflare’s incorporates the UK Addendum to the EU Standard Contractual Clauses for any transfer outside the UK.
We do not sell your data, and we do not use your figures to train any AI model.
7. What we do not hold
Because redaction happens on your device before upload, and because we do not store page images or documents server-side at all (§3), the following are, by design, not in our systems: your name (except the email address you give to get a beta pass, or what you tell us when contacting support), your National Insurance number, your home address, your employee number, your bank account or sort code, or a copy of any document you upload. If you believe a name or NI number has reached us despite this design (redaction is a best effort with a human-reviewable step, not infallible), tell us at to be completed before the beta opens and we will delete it.
The one exception, and it is stated here in full rather than buried. A beta pass says it covers 200 documents. To make that true rather than decorative, our relay keeps one number per pass — how many documents that pass has read — stored under a key derived from the pass identifier with a secret salt, with a lifetime that expires when the pass does. There is no date in that record, no address, no document, no file name, no figure and nothing the reading returned; there is no history, because each count replaces the last. It is the only thing the relay keeps about anything.
What that does and does not protect, said plainly:
- Someone who obtained the whole relay store and nothing else would learn that some pass had read twelve documents, and would have no way of saying whose. That is a real protection, and it is the reason the record is shaped this way.
- Linking a count back to an email address needs both the relay’s secret salt and the sign-up list (§3a). We hold both. Nobody outside holds either. So this is us keeping two things apart — not a thing mathematics does on your behalf, and we would rather say so than let you assume otherwise.
- We still hold no account containing your financial data, and we still never receive your documents.
Once there is a paid licence rather than a beta pass, the same record does the same job, with one thing added that we will say here when it happens: a licence identifier is something our payment processor could link to your name.
The Service also has no way of telling us anything by itself. There is no analytics script, no error reporter that fires on its own, and no “phone home”. Two requests can leave your device, and each one waits for something you do: the page image you asked to have read (§3), and a small readiness check of the relay — carrying your beta pass and nothing else — when you add a document of your own, save a beta pass or the reader’s address, open the panel that holds them, or ask for a document already here to be sent. Opening the Service, reopening it with documents still waiting to be read, reading this page or running the example year sends nothing. A fault report is sent by you or not at all (§9a).
8. How long we keep things
- Documents and page images: not held server-side at all, beyond the transient relay described in §5. Nothing to delete on our side because nothing is stored.
- Extracted figures: kept in your own browser for as long as you keep them there. “Delete everything stored here” in the app empties that store at once, including the name and address you typed so they could be blacked out. There is nothing on our side to delete, because we never had a copy.
- Anthropic’s copy of the page image sent for extraction: governed by Anthropic’s retention terms (§5) — 30 days by default until a zero-retention agreement is signed, at which point this notice will be updated to state the agreed term.
- Tier 1 improvement signal: kept in aggregate; the rotating pseudonym changes yearly and is not linkable back to you by us.
- Tier 2 improvement data (only if you opted in): kept until you withdraw consent, or until the document is no longer needed for testing, whichever is sooner; deletion on request within 30 days, described in full in the consent wording you see at the time.
- The beta pass document counter (see §7): deletes itself when your pass expires. It is not kept afterwards, and nobody has to remember to delete it: the record is written with an expiry and the store removes it. There is no archive and no history of it. The same will be true of a paid licence’s counter when there is one.
- Correspondence you send us: deleted within 12 months of the last message in the conversation, unless we need it for longer to deal with a complaint or a legal claim.
- Billing records (none during the beta): kept as long as required by tax/accounting law — typically 6 years from the end of the relevant accounting period — after that, deleted.
9. The two ways you can help us get extraction more accurate
Summarised here because it is part of what “your data” means for this product:
- Always on, and figure-free (tier 1): we record which layout your documents matched, which fields needed you to check them, and the pass/fail outcome of our cross-checks — never an amount, a date finer than the tax month, or any name. This is enforced in code, not just policy: the emitter refuses to send a record that contains anything matching a money, date, NI-number or name pattern. Basis: legitimate interests (§4); you can turn it off in settings and the Service still works.
- Opt-in, per document (tier 2): only when a document’s figures could not be checked against anything else, we may ask whether you’re willing to let us keep the redacted page and your confirmed figures, to test our reading of that layout. This is a real copy of your payslip with your name removed, not anonymous data, and we say so at the point of asking. You decide per document; declining changes nothing about the Service.
- We never take an unredacted document, and there is no setting that would let us — the upload endpoint only accepts the redactor’s own output.
9a. When something goes wrong
The Service does not report its own faults to us. Nothing is sent automatically, and there is no error-reporting endpoint in it.
Instead, “Something went wrong — show me what I could send” writes a report on your device and shows you the whole of it. You copy it or save it, and you decide whether to send it to us. If you do, you are sending it to us the way you would send any email: we then hold whatever you sent, and you can ask us to delete it (§10).
What the report is allowed to contain: which browser and operating system, the version of the Service and of its tax engine, how many documents this browser holds, whether a relay answered, whether blacking-out was switched on, and the error messages themselves. Before an error message reaches the report it goes through the same rules that black out a document before it is sent to be read — your name and address, National Insurance number, UTR, email address, telephone number, bank details, postcode, and the names of your documents — and then one more rule: every figure is replaced, because no amount is ever useful in a fault report. “£54,320.18 is not a valid amount” becomes “£# is not a valid amount”. Your tax year is kept, because it tells us which rules were in use and identifies nobody.
Two honest limits, both stated in the report itself:
- We can only remove a name we have been told. If you have not filled in “your details, so they can be blacked out”, the report says so in its own first lines and asks you to look.
- This is why you are shown the report before anything happens to it. If you see something of yours in it, do not send it — tell us what it was, because that is a fault in its own right.
10. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you (Article 15).
- Rectify inaccurate data (Article 16) — in practice, correct an extracted figure yourself in the app, which is faster than asking us.
- Erase your data (Article 17): the email address on the beta list, and any support correspondence. Your figures and documents are in your own browser, where deleting them is yours to do at any moment and needs no request to us.
- Restrict processing in some circumstances (Article 18).
- Data portability (Article 20) — export your extracted figures.
- Object to processing based on legitimate interests (Article 21), including the tier 1 signal.
- Not be subject to a solely automated decision with legal or similarly significant effect (Article 22) — the Service calculates figures for you to review and file yourself; it does not make a decision about you, and a human (you) confirms every figure before it is used.
To exercise any of these, contact to be completed before the beta opens. We will respond within one month.
11. How to complain
If you are unhappy with how we have handled your personal data, tell us first at to be completed before the beta opens so we can try to fix it. You can also complain to the UK’s data protection regulator:
Information Commissioner’s Office
Website: ico.org.uk
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Changes to this notice
We will update this notice when what we do changes — in particular when a zero data retention agreement with Anthropic is signed (§5), when hosting or processor details are confirmed (§6), and when the ICO registration is complete (§1). The “last updated” date at the top will change with it.