PRIVACY NOTICE

Your business data stays tied to the work you asked us to do.

A plain-language account of the information Firmkind needs, the boundaries we apply, and the choices available to you.

Account and organization data

We process business contact details, authentication identifiers, organization membership, roles, and settings so we can secure and administer each workspace.

Accounting data

When accounting connections become available, Firmkind will process the customers, contacts, invoices, balances, payments, credits, and sync metadata needed to show accurate receivables and stop follow-up when authoritative accounting state changes.

Mailbox and message data

When mailbox connections become available, Firmkind will use bounded message and thread data needed to find invoice conversations, prepare approved follow-up, preserve threading, and pause on relevant replies. We do not use mailbox data for advertising.

Billing and operations data

We may process subscription status, provider identifiers, support correspondence, audit events, IP address, device and browser details, and security logs. Payment-card details are handled by Stripe rather than stored by Firmkind.

HOW WE USE DATA

Purpose-limited processing

Firmkind uses information to authenticate users, isolate workspaces, connect services at an administrator's direction, synchronize authoritative accounting state, prepare and deliver approved follow-up, detect replies and payments, provide support, secure the service, comply with law, and improve reliability. We do not sell personal information or use connected accounting or mailbox data for cross-context behavioral advertising.

CONNECTED SERVICES

Providers process only what the workflow needs

Firmkind uses service providers for identity, hosting, accounting connectivity, mailbox connectivity, billing, model-assisted drafting, notifications, and operations. Those providers currently or when enabled may include Clerk, DigitalOcean, QuickBooks, Xero, Nylas, Google, Microsoft, Stripe, OpenAI, Resend, Sentry, and PostHog. Connected Google Workspace data is used only to provide or improve the user-facing features you authorize and is handled under the Google API Services User Data Policy, including its Limited Use requirements. Model calls are server-controlled, tool-free for drafting, and configured with store:false when the production drafting feature is enabled.

RETENTION AND CONTROL

Keep what is useful. Remove what is not.

The public tour contains sample data and resets when you leave. For connected pilot workspaces, the opening retention defaults are seven days for an abandoned preview and ninety days for message bodies after a case closes, unless you delete sooner or a longer period is required for security, legal, or dispute handling. You can disconnect a provider or request access, correction, export, or deletion at any time through our disconnect and deletion page or by emailing privacy@firmkind.com.

SECURITY AND REGION

Built for a U.S.-only controlled pilot

Firmkind's opening pilot is limited to U.S. organizations and U.S. processing. We use access controls, tenant isolation, encrypted transport, restricted provider access, managed secrets, audit records, and fail-closed safety checks. No online service can promise absolute security; report concerns to security@firmkind.com. Firmkind is a business service and is not directed to children.

YOUR RIGHTS

Questions and privacy requests

Depending on where you live, you may have rights to know, access, correct, delete, or receive a copy of personal information, limit certain uses, or appeal a decision. We will verify requests before acting and will not discriminate against you for exercising an applicable privacy right. Contact privacy@firmkind.com. Firmkind, Inc. is responsible for this notice. Effective and last updated July 15, 2026.