Privacy Policy
Effective date: 27 March 2026 · Last updated: 27 March 2026
This Privacy Policy explains how Truecast Ltd. ("Truecast", "we", "us", or "our") collects, uses, stores, and shares information about you when you use our website at truecast.org and our financial modelling platform (collectively, the "Service"). It also explains your rights under the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable privacy laws.
Please read this policy carefully. By using the Service you confirm you have read and understood it. If you do not agree, please discontinue use of the Service.
1. Who we are and how to contact us
The data controller for your personal data is Truecast Ltd.. You can contact us at any time regarding this policy or your data:
- Email: privacy@truecast.org
For any request relating to your personal data (access, correction, deletion, portability, or objection), the above email address is the fastest route to a response.
2. Data we collect
We collect data in the following categories:
- Account data
- Your name and email address when you register, and your password in hashed form. If you sign in via a third-party identity provider we receive only the information that provider shares with us (typically name and email).
- Financial data you upload
- Excel, CSV, and PDF files you upload to the Service. These may contain financial statements, line items, and the assumptions and figures you enter or approve within the platform.
- Usage data
- Information about how you interact with the Service: pages visited, features used, actions taken (e.g., model generated, scenario created, export downloaded), timestamps, and error logs. This data is collected in aggregate and associated with your account.
- Technical data
- Your IP address, browser type and version, device type and operating system, and session identifiers. This is collected automatically when you access the Service.
- Communications
- If you contact us by email or through any support channel, we retain the content of that communication and your contact details.
- Payment data
- For paid plans, payment is processed by our third-party payment processor. We do not store full payment card numbers. We retain a reference to the transaction, plan type, and billing email.
We do not collect sensitive personal data (such as health data, biometric data, or data revealing racial or ethnic origin) and we ask that you do not upload any such data to the Service.
3. How and why we use your data (lawful basis)
Under UK/EU GDPR, we must have a lawful basis for each processing activity. The table below sets out what we do with your data and the legal basis we rely on.
| Purpose | Lawful basis |
|---|---|
| Create and manage your account | Contract — necessary to provide the Service you signed up for |
| Generate financial models from your uploaded data | Contract |
| Process payments for paid plans | Contract; Legal obligation (invoicing/tax) |
| Send transactional emails (account confirmation, password reset) | Contract |
| Respond to support or enquiry emails | Legitimate interests — to support our users |
| Monitor for security threats, fraud, and abuse | Legitimate interests — to protect users and the Service |
| Analyse aggregated usage to improve the Service | Legitimate interests — product improvement; data is aggregated and cannot identify you |
| Comply with legal or regulatory obligations | Legal obligation |
| Send product update or marketing emails | Consent — you may opt out at any time |
We do not use your financial data to train AI or machine learning models. Your uploaded financial statements and the models derived from them are used solely to provide the Service to you. They are never shared with other users or used to improve model outputs for third parties.
4. How long we keep your data
- Account data
- Retained for as long as your account is active. If you close your account, account data is deleted within 30 days, subject to legal hold obligations.
- Financial data you upload
- Retained for as long as you maintain an active account and the relevant model exists. You may delete individual models at any time, which removes the associated uploaded files and derived data. If you close your account, all uploaded financial data and derived models are deleted within 30 days.
- Complete deletion on request
- If you submit a verified deletion request, we will delete your personal data — including all backups — within 30 days. This is not a soft delete. We will confirm completion in writing.
- Usage and technical data
- Retained in aggregate for up to 24 months for product analytics purposes. Individual session logs are retained for 90 days.
- Communications
- Support emails and other correspondence are retained for 2 years unless you request earlier deletion.
- Financial records (invoices, payment records)
- Retained for 7 years in compliance with applicable accounting and tax obligations. We cannot delete these on request as they are subject to legal hold.
6. Your rights
Under UK GDPR and EU GDPR, you have the following rights. To exercise any of them, contact us at privacy@truecast.org. We will respond within one calendar month. We may ask you to verify your identity before processing certain requests.
- Right of access (Article 15)
- You may request a copy of the personal data we hold about you and information about how it is processed.
- Right to rectification (Article 16)
- If any data we hold about you is inaccurate or incomplete, you may ask us to correct it.
- Right to erasure (Article 17)
- You may ask us to delete your personal data. We will comply unless we are required to retain it by law. See Section 4 for retention periods.
- Right to restriction of processing (Article 18)
- You may ask us to pause processing of your data in certain circumstances — for example, while you contest its accuracy.
- Right to data portability (Article 20)
- You may request a copy of your personal data in a structured, machine-readable format and ask us to transmit it to another controller where technically feasible.
- Right to object (Article 21)
- You may object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent
- Where processing is based on your consent (e.g., marketing emails), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
- Right not to be subject to automated decision-making
- We do not make decisions with legal or similarly significant effects about you using solely automated processing.
7. International data transfers
Some of our sub-processors (including OpenAI and Vercel) may process data in the United States. Where personal data is transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission or the UK ICO
- Data processing agreements that bind sub-processors to equivalent data protection obligations
You may request details of the specific safeguards in place by contacting privacy@truecast.org.
9. Security
We apply the following technical and organisational measures to protect your data:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest
- Access controls limiting staff access to personal data on a need-to-know basis
- Audit logging of access to sensitive data
- Hashed and salted password storage — we cannot recover your password
- Enforced HTTPS across all endpoints
No system is perfectly secure. If you believe your account has been compromised, please contact privacy@truecast.org immediately.
10. Children
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) and by posting a notice on the Service at least 14 days before the change takes effect.
Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy. If you do not agree to a change, you may close your account before the effective date.
12. Contact and supervisory authority
For any question about this policy or your personal data, contact us at: privacy@truecast.org.
If you are located in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. If you are located in the EU, you may contact your local Data Protection Authority.
We would, however, appreciate the opportunity to address your concern before you approach a supervisory authority.