Terms of use

Who runs this

Your hub is provided to you by your adviser firm. The software behind it is built and run by Independent Check Ltd, who hold your information on that firm’s instructions and on nobody else’s. Your firm decides what goes into your hub and who may see it. We do not, and we do not sell or share it with anyone.

In the language of UK data protection law, your adviser firm is the controller and Independent Check Ltd is their processor. What your firm does with your information is their privacy policy’s business. What this software does with it is below.

What this is for, and what it is not

A hub is a place to keep a household’s financial picture in one legible form and share it with the people who need it. Nothing on it is financial, legal or tax advice. A figure on a page is a record of something a document said, or arithmetic over those records — never a valuation and never a recommendation.

What happens to a document you upload

It is read by Anthropic’s Claude API, which finds the facts in it and the exact sentence each one came from. The names already in your hub go with it, and so does the list of things your hub keeps track of, so that a document naming Grace can be matched to the right person and a second statement can be recognised as the same pension. The document and that much context are all that is sent. Under Anthropic’s commercial terms that content is not used to train their models. Anthropic is a sub-processor; the data processing agreement between us and your firm names them.

What comes back is a proposal, and it stays marked as one until your adviser has looked at it. A reading appears in your hub straight away, labelled as awaiting your adviser’s approval, and every total it is part of carries that same label — so a figure is never quietly half-checked, and you can see which parts of it nobody has confirmed yet. Approving a reading is what takes the label off. A reading your adviser rejects counts towards nothing at all.

No figure on a page is written by a model. A model reads a value out of a document — the valuation beside a pension is its reading of one sentence, and that sentence is quoted underneath it — and every total, count and comparison over those readings is arithmetic done by this software. Nothing a model writes for a page is allowed to contain a number.

Every fact says where it came from, and there are three answers. Most were read out of a document and carry the sentence, which you can open. Some came from an answer somebody gave, and carry the answer, who gave it and when. Some were typed in by your adviser, and carry their name. A fact with none of the three cannot be stored: the database refuses it. A reading your adviser corrects is superseded rather than overwritten — the original stays, with its own citation, for as long as the record does.

Where it is kept

Each firm’s records live in a database of their own, with the sensitive fields and the uploaded files encrypted using a key belonging to that firm alone. Independent Check Ltd hold the master key that unwraps those keys, so we are technically able to read a firm’s records. That is a deliberate choice rather than an oversight: a firm that lost its own key would otherwise lock a family out of their records for good. We use that access to run and repair the service, and for nothing else.

How long your records are kept is your firm’s decision rather than ours. Ask them, or read their privacy policy.

Your firm’s privacy policy

Using it

Do not upload anything you have no right to share, and do not try to reach a hub that is not yours. Access is granted by your firm and by the hub’s owner, and either of them can withdraw it. If you think somebody else has your sign-in, tell your adviser and sign in again — signing in ends every other session on your account.

We keep the service running as well as we reasonably can, and it can still be unavailable. Nothing here is a promise that it will be up at any particular moment, and a hub is not the only place a household’s important papers should exist.

Back to the hub