Privacy Policy

Last updated: June 2026

This Privacy Policy explains how SMITH (“SMITH”, “we”, “us”) collects, uses, stores and protects information when accountancy firms and their team members use our web application at smithforaccountants.co.uk. SMITH is a software platform for accountancy practices that uses artificial intelligence to assist with bookkeeping, accounts review, tax workflows, email triage and related tasks.

We act as a data processor for the client information your firm uploads, and as a data controller for your firm’s own account and usage data. If you are a client of a firm that uses SMITH, please contact that firm in the first instance.

1. Information we collect

  • Account data — your name, email address, role, and firm, used to sign you in and manage access.
  • Client and document data — the client records, invoices, bank statements, accounts and other documents your firm uploads or creates in SMITH.
  • Google account data — where you choose to connect Google services (see section 3).
  • Usage data — basic logs needed to operate and secure the service (e.g. feature used, timestamps, AI token counts).

2. How we use information

  • To provide the SMITH service and its AI-assisted features.
  • To process documents and produce outputs (e.g. bookkeeping entries, reviews, summaries) at your request.
  • To send service emails on your behalf (e.g. task reminders and client approvals) from a mailbox you connect.
  • To secure, maintain and improve the service.

3. Google user data

Some SMITH features are optional integrations that you must explicitly connect via Google’s OAuth consent screen. We request access only when you enable the relevant feature, and only the scopes that feature needs. The table below sets out exactly what we access, why, and the Google OAuth scope involved.

Data we access

  • Gmail (scopes gmail.modify, gmail.send, gmail.settings.basic) — when you connect a mailbox for the Email triage and/or task & proposal sending features, we access your email messages (headers and body), labels and basic send settings. We use this to display and triage your inbox inside SMITH (categorise, label, summarise and draft replies), and to send emails you initiate — such as client approvals and task reminders — from your own mailbox. We do not delete your emails.
  • Google Calendar (scope calendar) — when you connect Calendar, we read and write your calendar events so SMITH can display them and create/update events (e.g. pushing approved holidays or deadlines) at your request.
  • Google Drive (scope drive) — when you connect Drive, we create, list and retrieve the client documents you choose to file in or load from Drive through SMITH’s Document Vault. We access files for the purpose of the actions you take in SMITH.
  • Basic profile (scope userinfo.email) — your Google account email address, used only to identify which mailbox/account you have connected.

How we use it

We use Google user data solely to provide the user-facing features you enabled (inbox triage, sending email on your behalf, calendar display/scheduling and document filing). We do not use it for advertising, we do not sell it, and we do not use it to train generalised AI/ML models.

How we share it

We do not transfer Google user data to third parties except as necessary to provide the features you use, for security, or to comply with law. Specifically, where you invoke an AI-assisted feature on Gmail content (for example, summarising a thread or drafting a reply), the relevant content is transmitted to our AI sub-processor Anthropic (Claude) to perform that task and return a result; Anthropic does not use API-submitted data to train its models. We do not otherwise share Google user data with third parties.

SMITH’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect any Google integration at any time in Settings, which revokes and deletes the access and refresh tokens SMITH holds for your account, and you can additionally revoke access from your Google Account permissions page.

4. Artificial intelligence processing

SMITH uses the Anthropic (Claude) API to process documents and generate outputs. Content you submit for an AI task is sent to Anthropic solely to perform that task and return a result. Anthropic does not use data submitted via its API to train its models. We do not use your content, or Google user data, to train any models.

5. Storage, security and sub-processors

All data, including any Google user data we process, is stored in secured, access-controlled databases and file storage. We protect it with the following measures:

  • Encryption in transit — all connections use TLS/HTTPS.
  • Encryption at rest — our database and file storage are encrypted at rest by our infrastructure providers.
  • Tenant isolation — row-level security ensures each firm can only access its own data.
  • OAuth token protection — Google access and refresh tokens are held server-side with restricted, service-role-only access and are never exposed to the browser.
  • Access controls — administrative access is limited to authorised personnel on a need-to-know basis.

We use the following sub-processors to operate SMITH:

  • Supabase — database, authentication and file storage.
  • Anthropic — AI processing (including AI features run on connected-mailbox content).
  • Google — where you connect Gmail / Calendar / Drive.
  • Vercel — application hosting.
  • Resend — sending certain system emails.

6. Data retention and deletion

We retain your data for as long as your firm uses SMITH and as needed for the audit and record history features of the service, subject to any legal retention obligations. Google user data is only retained while the relevant integration is connected.

Deleting your data. You can:

  • Disconnect a Google integration at any time in Settings — this immediately revokes and deletes the Google access and refresh tokens we hold, so SMITH can no longer access your Gmail, Calendar or Drive.
  • Request deletion of your account and associated data by emailing hello@smithforaccountants.co.uk. We will delete or anonymise your personal data, and any cached Google user data, within 30 days of a verified request, except where we are required to retain it by law.

7. Your rights

Depending on your location (including under UK GDPR), you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at hello@smithforaccountants.co.uk.

8. Cookies

We use only the cookies necessary to keep you signed in and to operate the service. We do not use advertising or third-party tracking cookies.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated “last updated” date above and, where appropriate, notified in-app.

10. Contact

Questions about this policy or your data? Email us at hello@smithforaccountants.co.uk.