Quiggy · proof of concept
Privacy notice
Last updated 14 September 2026
This is a private proof of concept run by Geckoandlime (Malta). It is not a public product. Access is limited to people invited by us. This notice explains what it holds about you and why.
Who is responsible
Geckoandlime, Malta, is the data controller. For anything in this notice — including access, correction or erasure requests — write to finance@quiggy.app.
What we hold
- Your email address — to sign you in. There is no password.
- The receipts and invoices you upload, and whatever you type alongside them (the note and the total). A receipt often names a merchant, a date, an amount and sometimes a person — so it is personal data, and we treat it that way.
- What the system read and decided — the extracted fields, the account chosen, a confidence score, and a SHA-256 hash of the image used to detect duplicates.
- An append-only activity log of what was posted and answered, and by whom.
Why we hold it
To do the thing you asked for: read a receipt and record it in a double-entry ledger. The lawful basis is performance of our agreement with you, and our legitimate interest in keeping an accurate and auditable set of books. Bookkeeping records are also subject to statutory retention periods.
Where it goes
These are the only processors in the path. Each is bound by a data processing agreement.
- Supabase — database, sign-in and file storage, hosted in the EU (Frankfurt).
- Vercel — application hosting.
- Anthropic — reads the receipt image and proposes where it belongs. The image and your note are sent for that purpose.
- Resend — sends the sign-in email.
- Cloudflare — DNS.
We do not sell your data, and we do not use it for advertising.
How long we keep it
For the life of this proof of concept. Accounting evidence is normally retained for several years under Maltese and EU tax law, and a posted ledger entry is immutable by design — corrections are made by posting a reversing entry, never by editing or deleting. Ask us and we will delete your account and the documents you uploaded; where a record must be retained for tax purposes we will say so rather than quietly keep it.
Your rights
Under the GDPR you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form. Write to finance@quiggy.app and we will respond within one month. If you are not satisfied you can complain to the Information and Data Protection Commissioner in Malta.
Security
Data is encrypted in transit and at rest. Each business's records are isolated at the database level. The activity log cannot be altered. Sign-in links are single-use and short-lived.