Privacy notice

VERSION 2026-08-12

This explains what Phjord collects about you, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.

01

Who is responsible for your data

Phjord is a trading name of Jeffrey Afianmagbon, a sole trader established in England and Wales, Ellison Pl, Newcastle upon Tyne NE1 8ST. That is the data controller: a person, not a company, so the responsibility is personal.

Contact us about anything in this notice at support@phjord.com.

02

What we collect, why, and how long we keep it

Your account

Name, email address, password (stored hashed, never in readable form), phone number and business address. The name and business address appear on the invoices you issue. The phone number is there so a client or we can reach you.

BASIS: Performance of your contract with us · KEPT: While your account is open, then 6 years

The records you create

Clients, invoices, line items, payments, expenses, categories and the receipt images and PDFs you upload. This is the product.

BASIS: Performance of your contract with us · KEPT: 6 years after the end of the tax year they relate to, because tax records must be

Your bank details, if you add them

Sort code and account number, shown on your own invoices so your clients can pay you. We never take money using them.

BASIS: Performance of your contract with us · KEPT: Until you remove them, then 6 years with the invoices that showed them

Payments to us

Stripe handles your card. We never see or store the card number. We keep a customer reference, the subscription status and what you paid.

BASIS: Performance of your contract, and our legal duty to keep accounting records · KEPT: 6 years

Sign-in records

Your session, and the IP address and browser your device reports when you sign in, so we can keep the account secure and spot misuse.

BASIS: Our legitimate interest in keeping accounts secure · KEPT: Until the session expires or you sign out, then 12 months

What you write to us

Support emails and their contents, and any feedback you send as a founding member, including anything you choose to put in it.

BASIS: Our legitimate interest in answering you and improving the product · KEPT: 3 years

Your HMRC connection, if you choose to connect

Your National Insurance number, which HMRC needs in order to find your business records, and the access HMRC gives us to send your quarterly updates. That access is stored encrypted and can only be used for the tax data you have granted. You can disconnect at any time, and we delete it when you do.

BASIS: Performance of your contract with us · KEPT: Until you disconnect or close your account

What we tell HMRC about your device

HMRC requires by law that anything sending them tax data also sends details of the device it came from: your IP address, the size of your screen and window, your time zone, which browser you use, and an identifier for the device. It is there so HMRC can spot fraudulent submissions. We send it only when you are connected to HMRC, and only on requests to them.

BASIS: Our legal obligation under the Delivery of Tax Information through Software (Ancillary Metadata) Regulations 2019 · KEPT: We do not keep it. It is sent with the request and not stored.

How you word your invoice emails

When you edit and approve an invoice email, we save your wording as your template, with the amounts and names replaced by placeholders, so your next email sounds like you rather than like us.

BASIS: Performance of your contract with us · KEPT: Until you change it or close your account

The retention periods above are what we aim to hold ourselves to. Where a period has passed and the data is still here, ask and we will remove it.

03

Who else sees it

We do not sell your data, and we do not share it for anyone's marketing unless you have said yes to exactly that (the Meta entry below is the only one, and it is off by default). We use these services to run Phjord, and each sees only what its job needs:

  • Google Cloud, which hosts the application, the database and your uploaded receipts. The database and file storage are in Google's London region.
  • Google's Gemini API, which reads what you submit to draft invoices, read receipts and suggest categories. That means the text you type and the receipt images you upload are sent to Google to be processed. We use the paid tier, under which Google does not use what we send to train its models. We do not send it your password, your card details or your bank details.
  • Stripe, which takes your payment and holds your card details. We never see the card number.
  • Postmark, which sends the email we send on your behalf and to you, so it handles the addresses and the message contents.
  • Companies House, when you look up a client company. We send the search term, never your details.
  • HMRC, if you connect your HMRC account. We send the quarterly figures you have approved, and the device details described above that they require by law. We only ever act with the access you granted us, using your own HMRC sign in. Phjord is not your tax agent and does not file your annual tax return.
  • Meta (Facebook and Instagram), only if you said yes to the cookie banner. Meta's pixel tells it which of our pages you visit, and if you start a trial we send Meta a scrambled (hashed) version of your email address so our adverts can be measured against real signups. Meta also uses this data for its own purposes as a separate controller, under its own data policy. Section 07 has the details, and saying no to the banner keeps Meta out entirely.

We will also disclose your data if the law requires it, and we would tell you unless we were forbidden from doing so.

04

Where your data goes

Phjord's own database and file storage are in the United Kingdom, in Google's London region. We would rather say your data never leaves the UK, but that would not be true: Stripe, Postmark and Google's Gemini API are international services, so some of your data is processed outside the UK by them, under the transfer safeguards those providers offer.

If you said yes to advertising measurement, Meta also processes that measurement data in the United States, under Meta's standard contractual clauses with the UK addendum, or the UK Extension to the EU-US Data Privacy Framework where Meta's certification covers it. The ICO explains both safeguards at ico.org.uk under international transfers.

05

A competition we have entered

Phjord is entered in the Build with Gemini XPRIZE, a business competition run by the XPRIZE Foundation with Google. The organisers ask entrants to show they have real customers.

What we give them at submission is numbers only: how many customers we have, and roughly what kinds of business they run. No names, no email addresses, no phone numbers, nothing about your invoices or your clients.

The organisers can ask us to prove a customer is real. If they ask, we come to you first and ask whether you are happy to be named. You will never be put forward without being asked, and saying no changes nothing about your account or your price. If you do say yes, you can change your mind in Settings at any time, though we cannot pull back something already sent.

If you say yes, your name and email go to the organisers in the United States. There is no UK adequacy decision covering them and we have no contract with them that protects you, so you may have fewer rights over that information there, it may be harder to get it deleted, and it may be harder to complain if something goes wrong. That is set out again, in full, at the point we ask.

06

Decisions made about you

Phjord drafts. You approve. An AI model proposes invoice wording, reads figures off your receipts and suggests an expense category, and none of it takes effect until you have looked at it and said yes. Nothing about you is decided by a machine on its own, and no total anywhere in Phjord is produced by an AI model. The arithmetic is done in code.

07

Cookies and advertising measurement

Phjord sets one cookie by default, which keeps you signed in. It is strictly necessary for a service you asked for, so we do not ask permission for it and you cannot turn it off while using the product. We do not run third-party analytics.

If you say yes to the cookie banner, we also load Meta's (Facebook's) advertising pixel, which sets Meta cookies (_fbp, _fbc, which last about three months) so we can tell whether our adverts on Facebook and Instagram bring people to Phjord. A small cookie of ours remembers your banner answer either way, for 180 days, after which we ask again. If you consented and then start a subscription, we also tell Meta that a trial started, identified only by a one-way hash of your email address, so the advertising can be measured against real signups. Meta acts on this data as described in its own data policy; where it goes is covered in section 04.

Our basis for all of this is your consent, and none of it happens unless you agreed. Saying no changes nothing about how Phjord works, and you can change your answer at any time, right here: , from the Cookie choices link in the site footer, or from Settings if you are signed in. Withdrawing stops the pixel and expires Meta's cookies.

08

Your rights, and how to use them

You can ask us to:

  • give you a copy of what we hold about you, and in a portable form
  • correct anything that is wrong
  • delete your data, or restrict what we do with it
  • stop relying on legitimate interests where you object
  • withdraw any consent you have given, which is as easy as giving it was

Getting a copy of your data is a button: Settings, under Your data, downloads everything we hold about you and your records in one file, immediately and without asking anyone.

Being straight with you about the rest: there is no button for the other rights yet. Email support@phjord.com and a person, currently the person named at the top of this notice, will do it by hand. We will confirm within a month, and sooner where we can.

Two honest limits. Records the law requires us to keep, such as invoices and payments for tax, we cannot delete on request until that period is up. And Phjord keeps an unalterable log of what its automated agents decided and did, which exists so that neither we nor an AI can quietly rewrite history. If you ask us to erase your data we will tell you exactly what has to stay, and why.

09

Complaints

If you are unhappy with how we have handled your data, tell us at support@phjord.com. We will acknowledge it within 30 days, look into it, and tell you what we have decided.

You can also complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113, and you do not have to come to us first.

10

Changes to this notice

When the substance of this notice changes we change the version at the top, and you will be asked to confirm you have seen the new one next time you sign in. Our terms of service cover the rest of the relationship.