Autonomo Pilot Autonomo Pilot
Legal notice Terms of Service Privacy Policy Cookie Notice
EN · ES

Privacy Policy

Last updated: 27 July 2026. This is an English courtesy translation; in case of any discrepancy, the Spanish version prevails.

This policy explains how personal data is processed when you use Autonomo Pilot (autonomo-pilot.com, app.autonomo-pilot.com, demo.autonomo-pilot.com), in accordance with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

Liam Cordrey, self-employed professional, NIF Y7966498W, Andasol Business Center, Avenida Andasol, 29604 Marbella, Málaga, Spain — [email protected].

2. What data is processed

  • Account data: the email address you sign in with (it identifies your account).
  • Financial data you upload: bank-statement exports (CSV/XLS) and the transactions derived from them — dates, amounts, descriptions, the categories you assign, income details (gross amounts, withholdings), and settings you configure. This is treated as highly sensitive data and protected accordingly.
  • Uploaded files: the original statement files, kept as an encrypted archive so imports can be audited.
  • Feedback: if you use the in-app Feedback button, the message you write and your email address.
  • Technical data: minimal server logs necessary to operate and secure the service. The app and demo have no analytics at all; the marketing site (autonomo-pilot.com) uses Cloudflare Web Analytics, a cookieless aggregate measurement service that stores no personal identifiers and does no cross-site tracking (see the Cookie Notice). No advertising trackers anywhere.

The public demo processes no real personal data: visitors get a temporary sandbox with fictional data, deleted automatically after 48 hours.

3. Purposes and legal bases

Purpose Legal basis
Providing the service: storing and processing the data you upload, producing estimates and exports Performance of contract (GDPR art. 6.1.b)
Security, abuse prevention, technical logs Legitimate interest (art. 6.1.f)
Answering feedback and support requests Legitimate interest / pre-contractual steps (art. 6.1.b/f)
Legal obligations (e.g. responding to competent authorities) Legal obligation (art. 6.1.c)

Your data is never sold, never shared with third parties for their own purposes, and never used to train AI models. No automated decisions with legal effect are made about you; the service's categorisation suggestions are always subject to your review.

4. Where data is stored and who processes it

  • Data is stored on a private server located in the European Union, operated by the controller.
  • Encryption in transit: TLS on every connection. Encryption at rest: the database is encrypted in full (SQLCipher, AES-256) and uploaded statement archives are encrypted with AES-256-GCM before touching disk.
  • Every account's data is isolated: all storage and queries are scoped to your account identity; exports contain your own data only.
  • Sub-processors / recipients — the complete list:
Who What they receive Why
Clerk, Inc. (USA) Your email address and sign-in identity — never your financial data Authentication (sign-in, sign-up, account security)
Cloudflare, Inc. (USA/EU) Traffic in transit; encrypted backup files CDN, TLS, network security; encrypted off-site backups (files are encrypted before they leave the server)
Google LLC / Microsoft Corp. Only your name and email, and only if you choose to sign in with that provider Optional single sign-on
Resend (email delivery) The contents of an accountant pack — only when you choose to email one Sending your quarterly pack to the address you specify
Telegram Operator alerts and feedback messages only — never financial data Notifying the operator of errors and feedback

Transfers outside the EEA are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses. No other third party receives your data. In particular: your transaction data is never sent to any AI or machine-learning service, and is never sold or shared for anyone else's purposes.

(Exchange rates are fetched from a public ECB-rate service using only a date and a currency code — no personal or transaction data is sent.)

5. Retention

Data Kept for
Account + financial data (transactions, categories, settings) While your account is active. Deleting your account removes it immediately and irreversibly from the live database — including your sign-in identity at Clerk.
Uploaded statement files (encrypted archive) While your account is active; deleted with the account.
Encrypted off-site backups Rolling 31 days, then automatically destroyed. A deleted account therefore disappears from backups within 31 days at the latest.
A closed or lapsed account you don't delete yourself No more than 12 months after it lapses, then deleted. You can always export first.
Demo sandboxes Automatically purged after 48 hours.
Feedback messages / operator alerts As long as needed to act on them, then deleted.

You are your own system of record. Spanish tax rules generally require you to keep supporting records for several years; Autonomo Pilot is a working tool, not your statutory archive. Export your data (Settings → Backup) and keep your own copies — and confirm retention requirements with your gestor.

6. Your rights

You may exercise the rights of access, rectification, erasure, restriction, portability and objection at any time:

  • In the app (immediate): Settings → Backup gives a full JSON export (portability/access); Settings → Backup → Danger zone deletes all your data irreversibly (erasure). Transactions and settings can be edited directly (rectification).
  • By email: [email protected] — answered within one month at most.
  • Complaint: you may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es).

7. Security and breaches

Beyond the encryption and isolation measures above, the service port is never exposed publicly, access requires authenticated identity on every request, and nothing sensitive is written to logs. In the event of a personal-data breach likely to result in a risk to your rights, the controller will notify the AEPD within 72 hours and affected users without undue delay, as GDPR requires.

8. Cookies

Only technical cookies strictly necessary for the service to function are used — see the Cookie Notice. No analytics or advertising cookies are set.

9. Changes to this policy

Material changes will be announced in the app or by email before they take effect. The "last updated" date at the top reflects the current version.

Back to the app Autonomo Pilot — Liam Cordrey