Skip to content

Privacy policy

Effective 9 June 2026 · Last updated 4 October 2026

Philofounder (the service) is operated by GRANDPOINT LTD. This policy explains what the service collects, why, and how we look after it. We keep only the data the service needs, and we never sell it.

Who we are (data controller)

Company: GRANDPOINT LTD
Companies House number: 16498233 (incorporated 5 June 2025, England and Wales)
Registered office: 50 Princes Street, Ipswich, IP1 1RJ, United Kingdom
ICO Data Protection registration: ZC084167
Data Protection Officer: privacy@grandpoint.uk
Product support: hello@philofounder.co.uk

GRANDPOINT LTD is the data controller for personal information processed through Philofounder, registered with the UK Information Commissioner’s Office under reference ZC084167.

For the records inside a company’s workspace (its mail, bank feed, ledger, documents and the people who appear in them) that company is the controller and we act as its processor under the data processing addendum, which is part of our terms.

What we collect

  • Your email address. Used to sign you in with a single-use link and to send account and compliance notifications.
  • Company information you add. Company name, registration number, officers, deadlines, products, and documents you choose to store; the statutory records you keep in the service (board minutes and the meeting transcripts you add to prepare them, which record what each person at the meeting said; the letters register, the purchase register, and the register of members, which holds the names and, if you enter them, the contact details of the company’s shareholders); and the people you invite to your workspace (their email address and role).
  • Public register data. Information drawn from Companies House about the companies you track.
  • Data from accounts you choose to connect. When you connect an account, the service reads, on your instruction and read-only:
    • your email inbox (Gmail or Microsoft 365), to find and file finance mail such as invoices, receipts, and registry or HMRC notices, and, when you ask, to read the mail exchanged with someone you are meeting so Philo can draft the agenda;
    • your bank transactions (via Open Banking), to reconcile spending and track the director’s loan account;
    • your VAT position (via HMRC Making Tax Digital): obligations, liabilities, and payments;
    • your bookkeeping software (FreeAgent): company facts, bank balances, bills, invoices and VAT returns, so the assistant can answer from the books and check them against your records;
    • your connected website, to keep your company profile current.
    Google Drive is the one connection that also writes: with the drive.file permission the service sees only the folders and files you choose in Google’s picker and the files it creates itself, files copies of your cabinet documents into the folders you map, and brings in files you pick. It never sees the rest of your Drive and never deletes or moves anything there.
  • Documents and a CV you upload. Files you add to your cabinet, and the structured background extracted from a CV you choose to upload.
  • Your conversations with Philo. The questions you ask the assistant and its replies, so threads persist for you.
  • Usage, device, and security logs. Including IP address and browser information, needed to run the service and protect your account.

How we use it

We use your data to provide the service: to sign you in, track your deadlines and filings, file documents into your cabinet, reconcile money, answer your questions through Philo, and send you reminders. We do not sell your data, and we do not use it for advertising.

Connected accounts and external sources

Connections are made through each provider’s official authorisation flow. Most are read-only. Two also write: Google Drive saves copies into folders you choose, when you send them or automatically if you turn that on, and creates a standard folder set if you have none; the Microsoft 365 calendar creates, moves and cancels the Teams meetings you schedule and sets their recording and transcript options, and Microsoft sends the invitations and cancellations from your calendar. We request the narrowest access needed, store the resulting tokens on our servers only (never in your browser), and never use them to file, pay, or change anything without asking you first. Access tokens are encrypted at rest. The providers are: Google (Gmail, and separately Google Drive), Microsoft (Microsoft 365), your bank via an Open Banking provider (TrueLayer), HMRC (Making Tax Digital), FreeAgent, and Companies House. Gmail and Google Drive are two separate connections with two separate consents; each token carries its own permission only.

The workspace owner can disconnect any account at any time on the Connections page. What that does depends on the provider: for Google and for Open Banking (TrueLayer) we also withdraw our access at the provider straight away; for Microsoft, HMRC and FreeAgent, which offer no way for an app to withdraw its own access, we delete every token we hold (so we can no longer read anything) and the Connections page explains how to remove Philofounder from your Microsoft account, your HMRC online account or your FreeAgent account as well. Withdrawing Open Banking consent at your bank itself is done in your banking app.

Public register data (Companies House)

When you set up a company we read its public record from Companies House through the Companies House API: the company’s name, number, status, registered office, accounting dates, SIC codes, filing history, and the names, months and years of birth, nationalities, occupations and service addresses of its officers and people with significant control, exactly as the register publishes them. We read the record again on every check so that your copy stays in step with the register, and we show you where each fact came from. This is public information that the registrar is required by the Companies Act 2006 to make available; Companies House places no conditions on its use, and we use it only to keep your company’s own record and deadlines. Contains public sector information licensed under the Open Government Licence v3.0.

People who are not our customers

A company’s records name people who never sign in to Philofounder: its directors and people with significant control (from the public register), members on the register of members, the people who send and receive the emails and letters filed in its cabinet, and the suppliers and contacts in its purchase register and address book. Our customer, the workspace owner, decides what goes into their company’s records; we process these details on their instructions to keep the statutory records and correspondence of that company, which is a legitimate interest of the company and of ours in providing the service. We do not use these details for anything else, we do not contact these people, and we do not share their details with anyone except the providers listed below that run the service. If you are one of these people and want to know what a company holds about you, or want it corrected or erased, contact the company, or write to us at the address at the end of this policy and we will help.

If you are asked to sign a document with Philofounder Sign, the company that sent it is the controller of your details and we process them for it. We keep your name, email address and any role you sign in, the one-time code we email you (only as a fingerprint, and only for ten minutes), the signature you type or draw, and when and from which internet address you opened, confirmed and signed. These appear on the certificate page of the signed document, because they are the evidence that you signed it. We email you the signed copy and nothing else. The records stay with the company’s documents for as long as it keeps them. When everyone has signed, we seal the file with Philofounder’s own digital seal and ask a public timestamp service (DigiCert or Sectigo) to date it. The timestamp service receives only a short fingerprint of the seal, never the document or anyone’s details.

If a company schedules its meetings through Philofounder on Microsoft Teams, it connects one organiser account it chooses, and Philofounder creates the meeting in that account’s calendar. We keep the meeting’s title, time, join link and the names and email addresses of the people invited, so the meeting can be moved or cancelled and appear in the company’s minute book. Invitations are sent by Microsoft from the organiser’s account, and the company is the controller of that list. An invitation says plainly when a meeting will be transcribed, and video is recorded only when someone chooses it for that one meeting. If the company also turns on fetching meeting records (its Microsoft 365 administrator approves this), Philofounder reads, after each meeting, Teams’ attendance report and keeps, for each person in it with an email address (guests and people from outside the company included), that address and when they first joined; and, only for meetings where a transcript was asked for, the transcript Teams made, stored encrypted with the company’s minutes and handled like an uploaded transcript. Philofounder only reads these; it never changes or deletes anything in Teams, and the company can turn this off at any time in Connections.

If you ask a company to change your name in Philofounder, the company keeps your request, the reason you give and, if you choose to attach one, a supporting document. Only you and the company’s owners can open the document; it is stored encrypted and deleted 30 days after an owner decides. The decision and your reason are kept as the record of the change. You never have to attach a document.

If you save your signature in your account, we keep it encrypted, linked to you rather than to any company, and place it on a document only when you choose to sign while signed in. You can replace or remove it at any time, and it is deleted with your account.

Time and tasks. When a company uses Philofounder to record time, we record only what each person chooses to log: the time, the day, a heading, a task and a note. We take no screenshots and record no activity, keystrokes or location. Each person edits only their own time. Whether colleagues can see each other’s hours is set by the company and shown on the Time page.

Google user data

When you connect Gmail, Philofounder requests read-only access (gmail.readonly) plus your email address. We use it only to find finance mail (invoices, receipts, statements, and Companies House or HMRC notices), file those messages and their attachments into your workspace’s document cabinet, and let Philo answer your questions about them. When you ask Philo to draft a meeting agenda from your correspondence with someone, it also searches the mailbox for the mail exchanged with that address and does not keep it (see Service providers). When a filed message from an outside sender arranges a meeting, the Heartbeat can suggest adding it to your minute book; that check runs inside Philofounder and sends nothing to an AI provider. We never send, delete, or change your email.

When you connect Google Drive, Philofounder requests the per-file permission (drive.file) plus your email address. That permission covers only the folders and files you select in Google’s picker and the files Philofounder creates; we use it to file copies of your cabinet documents into the folders you map, to create folders where you ask, and to bring in files you pick. We never read the rest of your Drive and never delete or move anything there. Disconnecting withdraws the permission at Google straight away and leaves every file on your Drive.

Philofounder’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Gmail data only to provide and improve the user-facing features described above; we do not transfer it to others except as needed to provide those features (for example, to our AI provider to answer a question you ask, or to our hosting and storage providers), to comply with law, or as part of a merger or sale with notice to you; we do not use it for advertising; we do not use it to develop, improve, or train generalised AI or machine-learning models; and no person reads it unless you ask us to (for support), it is needed for security or to investigate abuse, or the law requires it.

Filed messages and attachments are kept, encrypted, until you delete them, disconnect is followed by deleting them, or the workspace is deleted. Disconnecting Gmail withdraws our access at Google immediately.

Service providers we rely on

We use the providers below (our processors) to run the service. Each processes data only to deliver its part of the service:

  • Vercel, for hosting the application and storing uploaded and filed documents (encrypted before storage).
  • Supabase, for storing your account and company data.
  • Resend, for sending sign-in links and notification emails.
  • Anthropic, for the Philo assistant and for reading documents on your instruction (a CV you upload, a receipt or invoice from which a purchase is captured, a filed letter or email Philo drafts a reply to, and, only where a workspace owner has turned meeting help on, a meeting transcript Philo drafts minutes from and the description or correspondence Philo drafts an agenda from; text is sent pseudonymised as described below); the text is processed to produce the reply or the extraction, is not used to train models, and is deleted by Anthropic within 30 days unless the law or its usage policy requires longer.

Minutes and agendas drafted by Philo. Before a transcript, a meeting description or a set of emails is sent to Anthropic, the people the company has on record go as codes, which Philofounder turns back into names when the draft comes back. Always coded are its current directors and its shareholders (from the company record and its own share register). Then, for a transcript, the people speaking in it; for a meeting description, the chair, the people listed as present or sending apologies, the owners of the company’s open meeting actions, and who the meeting is with (the name it records and the contact linked to it); for correspondence, the person it is with, the owners of open meeting actions, and everyone named in the From and To lines of the emails. Email addresses and phone numbers are removed. Dates, times, company numbers and amounts are kept, because minutes and agendas need them. This is pseudonymisation, not anonymisation: a name that appears only in the body of a message or in a description someone types, and is not one of the people above, is sent as written, and a phone number dictated with punctuation between its groups (for example commas) may not be recognised. To draft an agenda from correspondence, Philofounder searches the connected mailbox, at the moment you ask, for the last year’s mail with the address you choose, or uses a thread you paste. That mail is read to draft the items and is not kept. What is saved with the meeting is what you then see and review: the agenda items, the plan Philo worked to, beside an item any sentence quoted from the mail word for word as its evidence, and, when Philo opens the meeting record from a meeting arranged in the mail, that record’s title, date and time.

Briefings prepared by Philo. When you ask Philo to prepare a briefing for a meeting, Philofounder gathers records your workspace already holds: the meeting’s agenda, earlier meetings of the same kind or with the same party, the address book entry, letters, purchases and deadlines involving them, questions anyone in the workspace has asked Philo that name them, the company’s own record, products, website, open meeting actions and deadlines in the next 60 days, the name and role of the person preparing, and, for mail filed in your cabinet, its title, its date and the one sentence already saved from it that names a date. It does not read the mail itself. With them go the meeting’s own title, date, time and format, the goal you type, and, from Meetings settings, the name of your board and the names your meetings use. Before any of this is sent to Anthropic, the people the company has on record, the people named on those records and the party you are meeting go as codes, and email addresses and phone numbers are removed; a name that is not one of these people, for example one written only inside a resolution or a note, is sent as written. Company figures, dates and amounts are kept, because a briefing needs them. The briefing is stored with the meeting, shown to members of your workspace only, and is not filed, emailed or shared outside it. Notes you write yourself on the same page are stored with the meeting and are not used to build the briefing; Philo reads them only if you ask it about the briefing in Ask Philo. This is pseudonymisation, not anonymisation.

Presentations drafted by Philo. When you ask Philo to draft a presentation for a meeting, Philofounder sends Anthropic the briefing for that meeting (without its questions to ask, its notes on conduct and what to capture after), the goal typed for the briefing, your team’s own notes, its agenda, the meeting’s own title, date and who it is with, the company’s own record, products, tagline and website, and, from Meetings settings, the names your meetings use. The records behind the briefing are not sent again: no mail, letters, purchases or questions asked of Philo. People and the party you are meeting go as codes, and email addresses and phone numbers are removed, as for briefings. The slides are stored with the meeting and shown to members of your workspace only. When you make a presentation final, its PDF and PowerPoint files are kept with the meeting, encrypted; you decide whether to file the PDF in your cabinet and on your Google Drive. Philofounder never sends a presentation to anyone. Deleting it removes the slides and the kept files; a copy you filed stays in your cabinet until you remove it there.

Your company’s pictures (Assets). Pictures you upload to Assets, or import from your website, are stored encrypted and shown only to members of your workspace; location and camera details are removed from photos when they are added. When you import, Philofounder reads only your own website (its pages and the files they name), follows the rules your site sets for robots, and copies only the pictures you choose. Pictures are never sent to an AI model. Removing a picture deletes it; a presentation already made final keeps its own copy.

Letters, email replies and invoices read by Philo. When Philo drafts a letter or an email reply, the text it is given goes in the same coded form: your instruction, a letter you paste, the text of the email being answered, the current draft when you ask for a revision, and the company facts. Coded are the company’s directors and shareholders, the person the letter is addressed to, the person signing it, and everyone named in the From, To and Cc lines of the email being answered; as above, any other name in the text is sent as written. Email addresses and phone numbers are removed, and the addressee’s postal address is not sent at all: Philofounder adds it, and the real names, from your records when the draft comes back. When an invoice or receipt arrives as the text of an email, that text is coded the same way before it is read: the company’s people and everyone named in the From, To and Cc lines, or only the company’s people when the mail’s text cannot be fetched from your mailbox and the stored subject and preview are read instead. Email addresses and phone numbers in that text are removed, including one written after an invoice or order number label; supplier and company names, invoice numbers, most VAT numbers, amounts and dates are kept, because the purchase needs them (a number after such a label is kept only when it does not look like a phone number, and a VAT number of ten or more digits, such as a 12-digit UK branch number or some EU numbers, looks like one and is removed). Two things are still sent as written, because a file cannot be coded: a filed PDF letter that Philo is replying to, which is attached whole, and an invoice or receipt filed as a PDF or an image. Questions you ask Philo in chat, and a CV you upload about yourself, are also sent as written.

Some providers may process data outside the UK. Where they do, the transfer is covered by appropriate safeguards (such as UK adequacy or the International Data Transfer Agreement).

Data retention

We keep your personal data only for as long as needed to provide the service or as required by law. When you delete a document, we delete the stored file as well as the record. When you disconnect an account, we delete its tokens (see above). When a company is deleted, its documents, files, drafts, products and profiles are deleted; its activity log is kept for the life of the workspace. When the workspace owner deletes a workspace, we withdraw connected accounts, delete every file, logo and record in it, including its activity log, and, if you belong to no other workspace, your account too. We do not retain the raw CV file after extracting your profile.

To protect the service, we keep an activity and security log for each workspace (who did what, when, and from which IP address and browser). It cannot be edited, and it is deleted only when the workspace is deleted. Counters used to limit sign-in and invitation emails hold a one-way hash of the email or IP address, not the address itself.

For each device you sign in on we keep the browser type, IP address and sign-in times, so you can see and sign out your devices in Settings; these records are deleted 30 days after the session ends. If you use two-step sign-in we store your passkeys’ public keys (never anything that would let us sign in as you), your authenticator-app secret encrypted, and one-way hashes of your recovery codes.

Each time a Philofounder feature uses an AI model, we record a usage entry: the workspace, the feature, the model, the number of tokens, the cost, whether it worked and how long it took. We use these entries to keep each company within its monthly AI allowance, to cost and run the service, and to spot misuse (our legitimate interests). They never contain your documents, questions or answers. They say which person made the call only in a workspace GRANDPOINT runs as internal, whose members are told so in Settings; a customer’s entries never name a person. They are kept for thirteen months and then deleted. When a workspace is deleted, its entries are kept only as anonymous totals, with the workspace and any person removed, so the month’s figures stay right.

When your company invites you to an online meeting through Philofounder, we may email you a reminder the day before and an hour before (you can turn these off in Settings), and when you join through Philofounder we record that you joined and when, so the company can take attendance for its minutes. These records are kept with the company’s other meeting records and deleted with the workspace.

Your rights under UK GDPR

You have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase your data;
  • restrict processing;
  • data portability;
  • object to processing;
  • withdraw consent at any time.

The owner of a workspace can export or permanently delete all of its data at any time from the Settings page. Anyone else can ask us to act on their own data using the contacts below.

To exercise any of these, email our Data Protection Officer at privacy@grandpoint.uk or product support at hello@philofounder.co.uk. You also have the right to complain to the UK Information Commissioner’s Office at any time: ico.org.uk/make-a-complaint (telephone 0303 123 1113).

Security

Sign-in is passwordless and uses single-use links that expire; the number of links that can be requested is limited. Two-step sign-in (a passkey or an authenticator app) is available to everyone and required for owners of workspaces holding company records; sensitive actions ask for it again. If Philofounder is left open and unused for an hour, it locks and asks you to confirm it is you. Sessions last up to 7 days, and you can sign out of any device, or every device, from Settings. Uploaded documents and connected-account tokens are encrypted at rest (AES-256-GCM). We will never ask for a password, card details, or banking credentials by email. Sign-in links come only fromlogin@philofounder.co.uk. We apply appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. To report a security concern, email security@grandpoint.uk.

Cookies

We use strictly necessary cookies for sign-in, security, and connecting accounts. See our cookie policy for details. We do not use advertising cookies.

Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new effective date and, where appropriate, let you know.

Contact

Questions about this policy or your data? Email our Data Protection Officer at privacy@grandpoint.uk, or product support at hello@philofounder.co.uk. Postal: GRANDPOINT LTD, 50 Princes Street, Ipswich, IP1 1RJ, United Kingdom.

Philofounder

Your limited company, kept in order. Philofounder keeps a limited company’s deadlines, records and money in order, and explains what to do next in plain English.

hello@philofounder.co.uk

Trust

  • Sign-in links come only from login@philofounder.co.uk.
  • We never ask for a password, card details or bank credentials by email.
  • Security reports: security@grandpoint.uk

Philofounder is a service of GRANDPOINT LTD, a private limited company registered in England and Wales, company number 16498233. Registered office: 50 Princes Street, Ipswich, IP1 1RJ, United Kingdom. ICO registration ZC084167.

Copyright 2026 GRANDPOINT LTD. Companies House, HMRC and the names of connected services belong to their owners; Philofounder is not affiliated with them.