Privacy Policy
This policy explains what Amwali collects, how statements are processed, and the controls you have over your data. Last updated 16 August 2026.
1. What we collect
Amwali collects only what is needed to analyse your finances and operate your account:
- Account data — email address, authentication tokens, plan and billing status.
- Statements you upload — files in PDF, CSV, XLSX or image form, and the transactions parsed from them.
- Open banking data — only if you explicitly connect an account, and only for the scopes you approve.
- Product usage — aggregate, non-identifying events such as feature usage counts and error rates.
We do not collect contact lists, location history, device identifiers for advertising, or browsing activity outside Amwali.
2. How statements are processed
Uploaded files are encrypted on receipt and processed inside an isolated environment. Parsing, de-duplication, categorisation and insight generation run automatically against pseudonymised records: the analysis pipeline works with an internal identifier, not with your name or email.
Model inference is performed on data stripped of direct identifiers. Your transactions are not used to train third-party foundation models, and are not pooled into any shared training corpus.
3. Who can see your data
No Amwali employee has a route to your raw transactions. Support tooling exposes account state — plan, upload counts, error logs — and never line items. Access to production systems is limited, logged and reviewed.
Where a support request genuinely requires inspection, it can only proceed with explicit, per-case consent from you, scoped to a single file and revoked automatically afterwards.
4. Retention and deletion
Statements and derived analysis are retained while your account is active, so that year-over-year comparisons remain possible. You can delete individual statements, a full account history, or the entire account at any time from settings.
Deletion removes source files, parsed transactions and every insight derived from them. Backups holding residual copies are rotated out within 30 days. Records we are legally required to keep — for example invoices for tax purposes — are retained separately and contain no transaction detail.
5. Sharing and third parties
We do not sell data, and we do not share it with advertisers or data brokers. A small number of processors are used strictly to run the service:
- Cloud infrastructure for hosting and encrypted storage.
- A payment provider, which receives billing details only — never financial statements.
- Error monitoring, configured to scrub payload contents.
Each processor is bound by contract to process data only on our instructions.
6. Your rights
Regardless of where you live, you can:
- Access a copy of the data held about you, in a portable format.
- Correct inaccurate account information.
- Delete your data, permanently and without justification.
- Object to processing, or withdraw an open banking connection at any time.
Requests are handled from within the product and take effect immediately; nothing requires an email exchange.
7. Security measures
Data is encrypted in transit with TLS and at rest with per-user keys. Environments are segmented, secrets are rotated, and dependencies are monitored continuously. Authentication supports multi-factor verification, and sessions can be revoked device by device.
8. Contact
Questions about this policy can be sent to privacy@amwali.ai. We aim to answer substantive privacy requests within five working days.