Skip to content

Privacy Policy

ThaiWealth AI · Effective 25 September 2026

1. Introduction

ThaiWealth AI exists to read your bank statements, so protecting what is in them is the whole job. This policy explains what personal data we collect, what we use it for, who receives it, how long we keep it, and the rights you have under Thailand's Personal Data Protection Act B.E. 2562 (2019), the PDPA. It is organised by type of data rather than by screen. If we later want to use your data for a purpose this policy does not cover, we will tell you first and ask for consent where the law requires it.

2. Data controller

ThaiWealth AI is a trade name. The service is operated by บริษัท เทคมาร์ค จำกัด (Techmark Co., Ltd.), which is the data controller under the PDPA for the personal data described in this policy.

Registered name
บริษัท เทคมาร์ค จำกัด (Techmark Co., Ltd.)
Company registration no.
0105561066781
Registered office
212/2-3 อาคารสุขุมวิทพลาซ่า ชั้นที่ 5 ซอยสุขุมวิท 12 ถนนสุขุมวิท แขวงคลองเตย เขตคลองเตย กรุงเทพมหานคร 10110
Data protection contact
privacy@thaiwealth.app

We have not appointed a Data Protection Officer. On our current assessment the business does not meet the conditions in section 41 of the PDPA. We will appoint one if that changes. Requests about your personal data go to the contact above and reach us directly.

3. What we collect

  • Account data. Your email address and the records needed to create, sign in to and maintain your account.
  • Financial documents you upload. Bank statements, payment slips and similar files you give us to read, and income documents (payslips, invoices, withholding-tax certificates) that you file against a tax year as your own record.
  • Extracted financial records. The transactions, balances, payee names, dates, amounts and categories we read out of those files, plus any corrections you make.
  • Records you enter. Settings and figures you type in yourself, such as budgets and holdings.
  • Feedback you give on insights. When you mark an insight as expected or as looking wrong, we keep your answer, the month, and a reference to the insight, so it stays hidden on every device you use. That reference can name the merchant or the transaction the insight was about, and it stays with your answer even if you later delete that transaction. We also count these answers across all accounts to learn which kinds of insight are useful. We keep each answer for 12 months, then delete it.
  • Messages you send us. If you connect a messaging account such as LINE, we collect the identifier for that account and the messages, images and payment slips you send through it. The messaging platform processes those messages under its own terms as well.
  • Billing records. If you subscribe, we keep the date, the amount and the payment processor's reference for each payment, and the state of your renewal: whether it is on, its next date, and when it was turned off or ended. Card numbers are held by the payment processor and never reach our systems. If you turn renewal off on the payment processor's page, it may ask why; your answer is held by the processor, and we can read it there.
  • Technical and security records. Server logs, IP addresses, device and session data, and similar records needed to run, secure and debug the service.
  • Optional product analytics. Only if you consent, we collect limited product-usage data through an analytics provider: which screens and features you use, your IP address (used for your approximate location), and the campaign or website you first arrived from, which we attach to your account when you sign up. This can include recordings of how you move through the app, with every piece of text, every typed value and every image hidden before anything leaves your browser. It does not include your transactions, statement files or the contents of documents you upload.

What you have to give us. An email address and at least one financial document. Without an email we cannot create an account, and without a document there is nothing to read. Messaging connections, product analytics and anything you type in yourself are optional. You can refuse or stop any of them later without losing the rest of the account.

4. Cookies and similar storage

We store a small number of cookies in your browser. Most are ones the service cannot work without: signing you in, keeping that session secure, remembering your language, and recording your cookie choice. Product analytics cookies are optional and run only if you allow them. Nothing optional is stored before you answer. There are no advertising cookies on this site and no cross-site profile of you.

Every cookie we use, what it does, how long it lasts and the controls to change your mind are in the Cookie Policy

5. Bank statements and other files you upload

The files you give us to read, meaning statement PDFs, payment-slip images and similar uploads, are stored only for as long as it takes to read them and are then deleted automatically under the retention rules below. Income documents you file against a tax year are different: nothing reads them and nothing deletes them on a timer, so they stay until you remove them.

We never store bank passwords or any other banking credentials. The only way a statement or slip reaches us is you uploading the file or sending the image yourself. We have no connection to your bank.

The file is temporary. The history we read from it is not. Deleting the file does not delete the transactions, categories and related records taken from it. Those stay in your account until you delete them or close the account.

We do not ask you for sensitive personal data as defined in section 26 of the PDPA, such as health, religion, trade-union membership or criminal records. A statement or slip can still contain a line that points to such a matter, for example a hospital, a pharmacy or a religious donation. If that happens, we use the line only to extract and categorise the transaction. We do not use it to build a profile of your health, religion, politics or any other section 26 category, and we do not disclose it for those purposes.

The full schedule is in our data retention policy

6. How we use your data, and why we are allowed to

  • Reading the documents you upload and extracting a transaction history from them.
  • Suggesting categories for those transactions.
  • Showing you summaries, budgets, holdings and other views of your own finances.
  • Sending you alerts and notifications about the account you asked us to run, including optional reminder and budget-alert emails when you leave those on.
  • Creating and securing your account, taking payment for a subscription, debugging failures, and keeping the records the PDPA and other applicable law require.

Lawful bases. Running your account, reading the documents you upload, extracting and categorising your transactions, showing you your own reports, sending the alerts that are part of the service, and taking subscription payments are all necessary to perform our contract with you, or to take the steps you ask for before that contract. Optional messaging connections, optional product analytics, marketing messages and personalised offers run on your consent, which you can withdraw at any time without losing the rest of the service. Technical and security logs, error monitoring, and the names of other people that appear on your statements are processed on the basis of legitimate interests: we need them to operate and protect the service and to produce a usable transaction history, and we do not use them to contact or market to those other people. Consent records and certain billing and tax records are kept because the law requires us to be able to show them.

Automatic categorisation. Categories are suggested automatically. You can change any of them. Your correction is stored in your account and applied to similar transactions of yours afterwards. We do not use those corrections to train a model that serves other customers, and we do not make decisions about you by automated means alone that have legal or similarly significant effects.

Aggregated statistics. We may combine usage data and transaction data across many accounts into statistics from which nobody can be identified, for example average spending by category and by month. We use these statistics to understand and improve the service, and we may share or sell them to third parties, including advertising and market-research partners. They never include your name, your email, your account identifiers, any individual transaction, the contents of any document, or any figure that describes one person. Each figure is drawn from a group large enough that no one in it can be singled out, and we do not give anyone the means to reverse the process. Data that cannot identify a person is not personal data under the PDPA, so this is not a sale of your personal data. Sharing data that could identify you would be a material change to this policy, and we would ask for your consent before doing it. You can exclude your account from these statistics in Settings, under Privacy. Doing so changes nothing else about the service.

Personalised offers. Off unless you turn it on. If you switch on personalised offers in Settings, we compare your own spending with criteria a partner has set, for example people who spend more than a stated amount on dining in a month, and show you a matching offer inside the app. The comparison runs on our systems. The partner learns how many people saw or clicked its offer, never who they are and never anything from your transactions. Switching it off in Settings stops the comparison immediately and changes nothing else. You also have the right under section 32 of the PDPA to object to direct marketing at any time.

We do not give any other party personal data about you for its own marketing. If we want to use your personal data for a purpose this policy does not cover, we will notify you and, where required, obtain a new consent before that use starts.

7. Other people's data on your documents

A bank statement or payment slip is not only about you. It can name the people and businesses you paid, a joint account holder, an employer, or the recipient on a slip. When we read a file we extract those names as part of each transaction, store them with your records, and send the relevant line, names and amounts included, to our AI processor with the rest of the text.

Those other people are not party to your contract with us. We process their names on the basis of legitimate interests: a transaction history that left out who the money went to would be useless, the data is limited to what already appears on a document you chose to upload, and we do not use it to contact, profile or market to those people. Please upload only documents for accounts you hold or are entitled to use. Those names are deleted when you delete the transaction or close your account, on the same schedule as the rest of your history.

8. Service providers and transfers outside Thailand

Some processing is carried out by service providers acting on our instructions. They fall into these categories: AI processors that read document text and transaction descriptions; payment processors; messaging platforms you choose to connect; cloud hosting for the account database and files, and statement processing on servers we operate ourselves in Thailand; transactional email delivery for sign-in, confirmation and password emails, and for optional reminder and budget-alert emails when you leave those on, where the provider sees your email address and the message (reminder content can include category names and amounts); bot protection on the sign-in and sign-up pages, which processes your IP address and browser signals to tell a person from a script; product analytics, only with your consent and never including your transactions; and error monitoring, limited to technical data and configured not to receive your IP address, cookies or request headers. Each provider is contractually limited to the task we engage it for. We may replace a provider within a category without notice if the new one is limited to the same task. Sending statement or slip text to a new class of recipient, to a new kind of country, or to a provider that may use it to train general models is a material change, and we will notify you before it happens.

Transfers outside Thailand. Reading a document means sending its text, payee names and amounts included, to the AI processor in the United States. Payment, hosting, messaging, email delivery, bot protection, analytics and error-monitoring data also leave Thailand when those providers process them. For each transfer we put in place appropriate safeguards under section 29 of the PDPA: a contract that limits the provider to processing the data for the service we engaged, together with standard contractual clauses or an equivalent measure accepted under the PDPA. For the core task of reading the documents you upload so that we can perform our contract with you, we also rely on section 28(3), because the transfer is necessary to perform that contract. Optional messaging and optional analytics are not necessary for the contract, so those transfers happen only if you turn the feature on, and they still go under the section 29 safeguards. We do not sell personal data about you. Aggregated statistics from which nobody can be identified are a different thing and are covered in section 6. Beyond these providers we disclose personal data only where the law requires it or a court or authority lawfully orders it.

Where your data goes. Your account database and file storage are in Singapore. Product analytics, if you consent, run in the United States. Statement processing runs on servers we operate in Thailand, so that step does not leave the country. The AI processor that reads your documents operates from the United States. Payment, messaging, email delivery, bot protection and error-monitoring providers also operate outside Thailand.

What we can and cannot promise about providers. We instruct each provider to use the personal data we send only to return the service we asked for. For the AI processor that means reading and categorising the text. We do not authorise any provider to sell that data or to use it to market to you, and we do not authorise the AI processor to use your document text or transactions to train a general model. We cannot promise that a provider keeps no operational logs of what it receives, or that it deletes those logs on our schedule rather than its own. What a provider retains for its own security and operations is governed by its terms and by our contract with it.

9. Security

All data is encrypted in transit with TLS and encrypted at rest. Access controls stop one account reading another account's records. Access to production systems is limited to the people who need it to operate the service.

No system is immune. Encryption and access controls do not defend against every failure. A bug, a misconfiguration, a compromised account, or a mistake by one of the providers above could still expose data. If a breach affects your personal data we will notify you and the Personal Data Protection Committee as the PDPA requires.

10. How long we keep things

  • Statement PDFs and similar files you give us to read: 7 to 30 days after processing, then deleted automatically.
  • Income documents you file against a tax year (payslips, invoices, withholding-tax certificates): kept until you delete them or delete your account. There is no timer. They are a record you keep, not a file we process, so deleting one is something you do.
  • Payment-slip images and chatbot attachments we store: 7 to 30 days after processing, the same as other uploaded files. LINE or another messaging platform may keep the message or image under its own terms, which we do not control.
  • Transactions, categories, budgets, holdings and your profile: for as long as your account is open, or until you delete the particular record.
  • Technical and security logs: up to 90 days, or longer only when we need a specific record to investigate a security incident or a fault.
  • Billing records we hold (date, amount, processor reference and renewal state, not the card number): for as long as the account is open, then for the period Thai accounting and tax law requires, which we treat as up to 5 years from the transaction.
  • PDPA consent and withdrawal records: the life of your account plus 3 years, because we have to be able to show that consent was given or withdrawn.
  • After you delete your account: we remove the personal data we hold within 30 days, except the records named above that the law requires us to keep, currently consent records and required billing or tax records, which run to the end of their own period.

The same schedule, item by item, is in our data retention policy

11. Children

The service is for adults. It is not offered to anyone under 20, the age of majority in Thailand, and we do not knowingly collect personal data from anyone under that age. If you believe we have, contact us and we will delete the account.

12. Your rights under the PDPA

  • Right of access: request a copy of your personal data.
  • Right to rectification: correct data that is wrong.
  • Right to erasure: ask us to delete your account and the personal data we hold, subject to the limited records the law requires us to keep.
  • Right to portability: export your data in a machine-readable format.
  • Right to object: object, in the circumstances the PDPA allows, to processing we carry out on the basis of legitimate interests, and to direct marketing at any time. Personalised offers run on your consent and can be switched off in Settings whenever you like.
  • Right to restrict processing: ask us to suspend the use of your data without deleting it.
  • Right to withdraw consent: withdraw consent at any time, without affecting processing already carried out lawfully before the withdrawal. Withdrawing consent for an optional feature turns that feature off. It does not close the account.

You can exercise any of these from your account settings, or by emailing privacy@thaiwealth.app and we will respond within 30 days of receiving your request. If you believe we are not complying with the law, you can complain to Thailand's Personal Data Protection Committee (PDPC).

13. Changes to this policy

We update this page when the policy changes and change the effective date above. Rewording that does not change what we collect, why we use it, who receives it or where it goes does not need a separate notice. A material change does: a new purpose this policy does not cover, a new category of personal data, sending statement or slip text to a new class of recipient or country, or allowing a provider to use that text to train a general model. We will notify you of a material change in the product, and where the law requires a new consent we will ask for it before the change applies to you.

14. Contact us

For any question about this policy, or to exercise any of the rights above, reach us from your account settings or by email at privacy@thaiwealth.app

บริษัท เทคมาร์ค จำกัด · 212/2-3 อาคารสุขุมวิทพลาซ่า ชั้นที่ 5 ซอยสุขุมวิท 12 ถนนสุขุมวิท แขวงคลองเตย เขตคลองเตย กรุงเทพมหานคร 10110 · Company registration no. 0105561066781