Features Pricing Your data About Contact
Sign in Start free

Your data

How we look after your charity's records

Trustees are answerable for the charity's information as well as its money. This page says what we actually do, without jargon, so a committee can tick it off and move on.

Last updated: 21 September 2026

One charity never sees another

Every record belongs to exactly one charity, and every screen is limited to the charity you are signed in to.

The sensitive fields are encrypted

DBS numbers, safeguarding records, breach details and subject access notes are encrypted in the database, not merely hidden on screen.

Looking is not changing

Six roles, each with a different set of keys. A trustee can see all the money and change none of it.

Keeping charities apart

The separation is not a filter we remember to apply. It is applied to every record and every query for the charity you are signed in to, at the point the page is built, so a screen cannot show another charity's data even if somebody guesses a web address. It is the most important thing on this page, and it is enforced in one place rather than repeated in a hundred.

A trustee who serves at two charities switches between them deliberately and sees one at a time.

What is encrypted

Some of what a charity keeps is ordinary administration. Some of it would do real harm if it leaked. The second kind is encrypted at rest:

  • DBS certificate numbers
  • Safeguarding incidents: the account of what happened, who was involved, what was done and the outcome
  • Data breach records and the remedial action taken
  • Subject access requests and the notes on how they were answered
  • Notes held against a consent record

A name on a consent record is deliberately not encrypted, because the whole use of that list is searching it before an email goes out, and a list you cannot search is a list nobody keeps up to date.

Who can see what

Roles belong to the charity, not to the person, because the same volunteer is routinely a treasurer at one charity and an ordinary trustee at another. Signing in gives you the keys that charity gave you and nothing else.

The load-bearing rule is that a trustee can see all the money and change none of it. Trustees are personally answerable for a charity's finances and must be able to look. Six people all able to edit the ledger is how a set of accounts stops reconciling.

Signing in

  • Everything is served over an encrypted connection.
  • Passwords are stored as one-way hashes. We cannot read yours, and neither can anybody who reaches the database.
  • Sessions are tied to the browser they started in, and signing out ends them.
  • Two-factor authentication and passkeys are available for the accounts that want them.

Backups and where it lives

Your charity's data is held on servers in the United Kingdom and backed up regularly. The servers are provided by DigitalOcean, in its London data centre, and the whole server is backed up automatically by them, with the backups kept in the same place. Nothing is stored outside the United Kingdom.

Leaving

Your records are yours. You can export them while you are with us, and if you close the account we delete the charity's data after a short grace period rather than keeping it indefinitely. The grace period is 90 days. The only things kept longer are our own invoices and payment records, for six years, because tax law requires it.

Telling us about a problem

If you think you have found a security problem, please tell us before you tell anybody else and we will work with you on it. Write to hello@thecharityoffice.co.uk.

What we do not do. We do not sell charity data, we do not share it with advertisers, and we do not use it to train anything. Subscriptions are how the product is paid for, and that is the whole arrangement.

Questions your committee wants answered?

Send them over. We would rather answer a difficult one before you sign up than after.