Privacy Policy
Last updated 22 September 2026
Lanthea is a service for companies' bookkeeping, provided by Fly by wire AB: receipts and supplier invoices, sales invoices, a mileage log, connected mailboxes, and AI agents that read documents, sort mail and answer questions about the company's records. This page explains what personal data the service processes, why, and what your rights are.
Who is responsible
For your account (your sign-in, your sessions and the companies you belong to), Fly by wire AB (org. no. 559316-3313) is the data controller. Postal address: Flädervägen 1B, 61146 Nyköping, Sverige. Questions and requests about personal data: support@lanthea.ai.
For the records a company keeps in the service, such as its receipts, invoices, trips, mail and conversations with its agents, the company is the data controller. Fly by wire AB processes the personal data in them on the company's behalf, under the Data Processing Agreement. Requests about those records go to the company, and we help it answer them.
What we process
Your account
You sign in with a code we send to your email address, or with your Google or Apple account. We keep your email address and, from Google or Apple, your name and, from Google, your profile picture. We use them to identify you while you are signed in and to record who created, changed or verified an entry. A sign-in code works once and for ten minutes, and we keep it only in a form that cannot be turned back into the code.
Every sign-in starts a session. The browser keeps it in a cookie and the iOS app keeps an equivalent token on the device; we keep a fingerprint of it together with the name of the device, taken from the browser or the app (such as "Safari on Mac"), and when it was last used, so that you can see your signed-in devices in Settings and sign any of them out. To stop anyone guessing codes, the service counts sign-in attempts per email address and per network address, in memory only.
We keep which companies you belong to and your role in each. When someone invites you to a company, we keep your email address, the company, the role and who invited you until the invitation is accepted, declined, revoked or expires.
Company records
Everything a company's members enter: the company (including bank and VAT details), customers, invoices, trips (start and end address, distance, purpose and, when recorded with the iOS app, the GPS route), and receipts (the document, amounts, VAT, supplier, category, payment method and, for private outlays, who paid). Every change to a receipt is logged with the previous and new value and who made it. For a company in Sweden these are accounting records under the Bookkeeping Act (bokföringslagen).
The map of a trip is drawn from OpenStreetMap's map tiles, which your browser fetches from OpenStreetMap's servers; they see your network address and the part of the map shown.
Bank accounts
A company can bring its bank account's statements in as files, or link the account to its bank. To link it, a person with rights in the company's internet bank gives consent at the bank, signing in there with BankID. The account's transactions (the day, amount, text, counterparty and reference of each, and the balance after it) and its balance are then read about four times a day, and whenever a member asks, until the consent ends after 180 days at the most, is withdrawn at the bank, or the link is removed in the service. The transactions can name people the company paid or was paid by. The service never makes payments. The link goes through Enable Banking Oy in Espoo, Finland, a registered account information service provider regulated by the Finnish Financial Supervisory Authority, which reads the account at the bank and passes what it read on to the service.
Sending invoices from Gmail
A company can connect a Gmail account for sending invoices. We store the connection token Google issues and use it only to send the invoice emails you compose from that account. This connection cannot read mail.
Receipts from connected mailboxes
You can connect a Gmail mailbox for reading so that the service picks receipts out of incoming mail. For each connected mailbox the service, about once a minute:
- lists the new messages in the inbox;
- leaves out mail the mail server has tagged as spam and, in Gmail, mail in the Promotions, Social and Forums tabs; the spam folder is never read;
- sends the sender, subject and date of each remaining message, the names and sizes of its attachments and the beginning of its text to Anthropic's API, whose model says what kind of mail it is and whether it belongs in the receipts inbox. While this is switched off, the mailboxes are not read;
- for messages it files as receipts, stores the attached PDF or images, or a rendered copy of the message when there is no attachment, as a receipt document, together with the sender, subject and date;
- for every message it has looked at, keeps the message identifier, sender, subject, date and the outcome, including the model's one-line summary and reason, so that a message is examined only once. The text of messages that are not filed is not stored.
On request it can also scan a past period of up to 90 days. You can pause a mailbox or disconnect it at any time; disconnecting a Google mailbox revokes the token with Google and deletes it from our database.
A mailbox at another provider, such as a personal Gmail, iCloud, Yahoo, Fastmail or any mail host, is connected with an app password you create at the provider. The service then signs in over IMAP and reads new mail in the same way; it opens the mailbox read-only and never changes, moves or deletes anything. Revoking the app password at the provider disconnects the mailbox.
Connection tokens and app passwords are encrypted at rest with a key kept outside the database.
Lanthea's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The AI agents
When a member asks the service to read a receipt or to audit an entry, or when automatic reading is on, the receipt's documents, including those filed from mail, are sent to Anthropic's API, which returns the fields it read or the problems it found.
Members whose role allows it can ask the agent about their company. To answer, the agent looks up the company's records that the member's role reaches, and the question, what the agent looked up and its answer are sent to Anthropic's API. The conversation is kept, visible only to the member who had it, until they delete it.
For every call to an AI model we record the company, the member who asked for it, which agent made it, what it was about (a receipt, a mail or a conversation), the number of tokens and the cost.
Notifications
The iOS app registers a random identifier for the installation so it can fetch notices about newly filed receipts. No advertising identifiers are used.
Why we may do this
We process your account data to provide the service under the agreement with you or your company, and in our legitimate interest in keeping the service secure. We process a company's records on its behalf and on its instructions; the company's own obligations, such as its bookkeeping, are its legal basis. Gmail connections rest on the consent you give on Google's consent screen, which you withdraw by disconnecting. A bank link rests on the consent given at the bank, which ends by itself, and is withdrawn by removing the link or at the bank.
Who else sees the data
- Our subprocessors, listed on the Subprocessors page: Hostup hosts the service in Sweden, Anthropic (Claude API) runs the AI agents, Resend delivers the sign-in codes and invitations we email, and Enable Banking reads the bank accounts companies link to their banks. Anthropic processes the data under its commercial API terms and does not use it to train its models.
- Google and Apple provide sign-in when you choose them, and Google the Gmail connections, under your agreements with them.
- OpenStreetMap serves the map tiles your browser fetches for a trip's map.
- A company decides which of its members see its records, and what it shares with its accountant or with authorities.
We do not sell personal data, use it for advertising, or share it with anyone else.
Where the data is
The service and its data are hosted in Sweden, and Enable Banking is in Finland. Anthropic and Resend are in the United States; what is sent to them is transferred with the safeguards the GDPR requires, such as the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
How long we keep it
We keep your account until you ask us to delete it. A session ends after 30 days without use, a browser's after 90 days at most, and is deleted a day after it ends; sign-in codes are deleted a day after they expire.
A company's records are kept while the company uses the service. When its owners delete the company in the service, its records are deleted with it; the company must keep its accounting records as long as the law requires (seven years in Sweden), and can export them first. Conversations with the agent are kept until the member deletes them or the company is deleted. Mailbox connection tokens and app passwords are kept until the mailbox is disconnected, and the log of examined messages is removed with the mailbox. Records of AI calls keep only who asked, what for, the token counts and the cost, and are kept with the company.
Your rights
Under the GDPR you may ask for access to your personal data, correction, erasure (where the law does not require it to be kept), restriction and portability, and you may object to processing based on legitimate interests. Write to support@lanthea.ai; a request about a company's records we pass on to the company. You can also complain to the Swedish Authority for Privacy Protection (IMY).
Changes
We update this page when the service changes; the date at the top says when. We tell companies' owners in advance about changes that matter to them.