Privacy Notice

Last updated: 18 September 2026

Who I am

This notice is published by Joseph Kirk, a private individual. I am the data controller for the processing described here. You can contact me at j2tmax@gmail.com.

This is a personal project. It is not a business, not a product, and is unrelated to any company I work for.

What this notice covers

I use Enable Banking's PSD2 account information service to read my own UK current account data (Barclays and Lloyds) into a small piece of software (an MCP server) that runs on my own computer. That software lets Claude, an AI assistant made by Anthropic, help me analyse my own spending.

The set-up is:

Because the only person whose data is involved is me, this notice mainly exists to explain, transparently, how that data moves.

What data is involved

No data about anyone else's accounts is accessed.

Where the data comes from

The data comes from my banks. It is retrieved through Enable Banking, which acts as the account information service provider (AISP) under PSD2. Access only happens after I have given explicit consent by authenticating with my bank.

Lawful basis

My lawful basis under UK GDPR is consent (Article 6(1)(a)). I give that consent when I authorise access through my bank, and I can withdraw it at any time (see below).

Why I process the data

Personal budgeting and analysis of my own spending. Nothing else.

Processing by an AI assistant

To carry out the analysis, transaction data is sent to Anthropic's Claude. Anthropic therefore acts as a data processor in this flow: it processes the data on my behalf in order to return the analysis I ask for. Anthropic's own privacy policy is available at anthropic.com/privacy.

Who the data is shared with

The data moves between my banks, Enable Banking, the software on my own computer, and Anthropic (as described above). It is not shared with anyone else, and it is not sold.

How long the data is kept

Data held on my own computer is kept for 12 months from the date of the transaction, after which it is deleted.

Withdrawing consent

I can withdraw the consent that allows access to my accounts at any time, either through my bank's app or through Enable Banking. Separately, PSD2 access sessions expire automatically after 90 days, after which no further data can be read unless I authenticate again.

Rights under UK GDPR

UK GDPR gives individuals the right to access their personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time without affecting processing that took place before withdrawal.

Anyone who believes their data has been handled improperly has the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk.

Changes to this notice

If the way I process data changes, I will update this page and the date at the top.