GLASS is built on a simple promise: we help you understand your money without ever touching it. This page explains, in plain language, exactly what happens to your data when you use GLASS, and the rights you have under the Nigeria Data Protection Act (NDPA) 2023.
The short version
We read, we never touch. GLASS does not move money, hold money, connect to your bank, or ask for your bank password.
Your statement is processed in your browser. Your transactions, amounts and balances are read on your own device. We do not upload or store your statement on our servers.
The optional AI story sends only a summary. To write your money story, GLASS sends a limited summary (a few uncategorised descriptions and rounded totals) to our secure function, never your account number, balances, or full statement.
The AI reader is opt-in. If your bank's PDF layout cannot be read on your device, GLASS asks first before sending the statement page images to our secure function to read them. It only happens if you tap "Read it with AI", and the images are not stored.
Analytics never sees your money. We measure anonymous usage to improve the app. No cookies, no financial data, and you can opt out below.
Delete anytime. Close the tab and your statement data is gone. We keep no copy.
Who we are
GLASS is a product of TATAFO, operated from Nigeria. For the purposes of the NDPA, TATAFO is the data controller for GLASS. You can reach us about anything in this policy at [email protected].
What GLASS does, and does not do
GLASS reads a bank statement you choose to upload and turns it into insights: where your money went, a plain-English money story, your biggest leaks, and a suggested budget. That is the whole job.
GLASS is read-only. It does not move or hold funds, it does not connect to your bank account, and it never asks for your bank login or password.
What data we handle, and where it is processed
Your bank statement in your browserWhen you upload a PDF, CSV or Excel file, it is read and analysed entirely on your own device. Your transactions, amounts and balances are used to build your dashboard and never leave your browser for this part. We do not receive, upload, or store your statement.
The AI Money Story limited summaryGLASS currently uses an AI feature to write a sharper money story and to label the few transactions our rules could not categorise. For this, and only this, GLASS sends a limited summary to our own secure server function, which calls Anthropic's Claude API. That summary is the descriptions of the uncategorised transactions plus rounded category totals. It does not include your account number, your balances, or your full statement. The API key stays on our server and never reaches your browser.
The AI reader only if you askSome banks export PDF statements in a layout the on-device reader cannot decode. In that case GLASS offers an AI reader, and asks for your permission first. If you accept, GLASS turns each statement page into an image and sends those images to the same secure server function, which calls Anthropic's Claude API to read the table into transactions. Because it is the full page, this can include your account number and balances, which is why it is your explicit choice and never automatic. The images are processed in real time to read your statement and are not stored by us.
Anonymous usage analytics no financial dataWe use PostHog (hosted in the EU) to count anonymous actions such as opening the app, starting the demo, and reaching the dashboard, so we can see what is working. This never includes any financial figure, transaction, or statement. We do not use cookies, your IP address is not stored (our analytics provider is set to discard it), and we respect your browser's Do Not Track setting. You can opt out lower on this page.
Settings on your device local onlyA few small, non-sensitive items are kept in your browser's local storage: your light or dark theme choice, an anonymous analytics identifier, your first-touch referral source, your A/B test group, and your consent and analytics opt-out choices. No financial data is ever stored there, and none of it is shared with us.
Hosting CloudflareGLASS is served over an encrypted (HTTPS) connection through Cloudflare's global network.
Who else processes your data
We keep the list of third parties short and necessary:
Anthropic (USA) processes the limited AI summary to generate your money story, and, only if you opt in to the AI reader, the statement page images used to read a hard-to-decode layout. Under Anthropic's commercial API terms, they do not use this data to train their models.
PostHog (European Union) processes anonymous usage analytics on our behalf.
Cloudflare provides hosting and security.
Because some of these providers operate outside Nigeria, using GLASS may involve a cross-border transfer of the limited data described above. We only use providers that commit to protecting your data and not repurposing it.
Our legal basis
We rely on your consent, which you give before you upload a statement, as the basis for processing the statement and generating your AI money story. We rely on our legitimate interest in improving the product as the basis for anonymous, non-financial analytics, which you can opt out of at any time.
How long we keep your data
Your statement data lives only in your browser while you use GLASS. When you close or refresh the page, or start a new statement, that data is cleared from memory. We keep no copy of your statement. The limited AI summary, and any statement page images you choose to send to the AI reader, are processed in real time and are not stored by us. Anonymous analytics events are retained by our analytics provider for a limited period and contain no financial data.
Your rights under the NDPA
You have the right to access, correct, delete, and port your personal data, to object to processing, and to withdraw consent at any time. We ask for your consent fresh each time you choose to upload a statement, and because we keep no copy of your statement, withdrawing it is automatic the moment you close the tab. You can turn analytics off at any time using the control below, and you can clear every choice GLASS has saved by clearing this site's data in your browser. For anything else, or to make a request, email [email protected] and we will respond within 30 days, as the NDPA requires. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
Opt out of analytics
Anonymous analytics help us improve GLASS, but they are entirely your choice. Use the button below to turn them off on this device. Your decision is saved in your browser and takes effect immediately.
Anonymous usage analytics
Currently on. No financial data is ever included.
Security
Your statement is processed in your browser, not on our servers. Every connection to GLASS is encrypted (the .app domain forces HTTPS). The key that powers the AI story lives only on our server and is never exposed to your browser.
Children
GLASS is not directed at anyone under 18, and we do not knowingly process the data of children. Because statements are processed only in your browser and never stored by us, no child's data is retained on our systems.
Changes to this policy
If we change how GLASS handles data, we will update this page and the date at the top. For significant changes, we will make the update clear in the app.
Contact
Questions, requests, or concerns: [email protected]. We read every message.
GLASS, a product of TATAFO. Read-only insights. We never hold or move your money. Back to GLASS