SECTION IScope of this Policy
This Privacy Policy applies to all FinHelm products and services, including FinHelm Clarity (our QuickBooks Online–connected SMB FP&A product), FinHelm Platform (our mid-market and enterprise FP&A product), the FinHelm MCP connector for AI clients, and marketing pages and demo tools at finhelm.ai. Where MCP connector–specific terms apply, they are noted in the relevant section.
SECTION IIWho we are
FinHelm Corp is a Tennessee C-Corporation, founded MMXXVI. Our principal place of business is in Tennessee, U.S.A. For data protection purposes, FinHelm Corp is the data controller for marketing and authentication data, and a data processor for ERP analysis data on behalf of our customers.
Contact: privacy@finhelm.ai.
SECTION IIIData we collect
FinHelm collects only what is necessary to operate the product and meet legal obligations.
- Account & authentication data: Email address (required for account creation); your password, which you enter in a FinHelm form and which FinHelm passes to AWS Cognito over TLS to verify; FinHelm never stores it, and only the Cognito password hash is retained; OAuth tokens for connected ERP providers (encrypted at rest with AWS KMS); sign-in metadata (timestamp, IP address, user-agent).
- ERP data — fetched live, never warehoused: When you invoke an authenticated tool, FinHelm fetches only the slice of your ledger required to compute the requested output, processes it for that request, and discards it. FinHelm does not retain your ledger: raw transactions and customer or vendor records are not written to FinHelm's data stores. Account identifiers you select while authoring drivers or budgets persist only inside the content you author.
- Analysis outputs (retained): UES™ scores and band classifications; Monte Carlo distribution summary statistics (P10/P50/P90, mean, standard deviation); AI-generated narratives describing variance drivers; Reflection Engine™ fidelity scores.
- Content you author and forecast history: budgets, driver sets, and scenario configurations you enter into FinHelm, and the record of each forecast run (inputs, distribution outputs, timestamps) used to score forecast reliability over time. Retention is described in Section V.
- Audit metadata (retained): Tool name invoked, timestamp, response status (success or failure); user identifier and connected entity identifier.
FIG. III.a · The ledger boundary is structural. The ledger we never store, we cannot lose.
SECTION IVHow we use data
The following table lists the purposes and legal bases for our account and service processing. Product analytics is described separately below.
| Data category | Purpose | Legal basis |
|---|---|---|
| Email & password hash | Account creation, authentication, password reset | Contract |
| OAuth tokens | Read-only access to connected ERP on user’s instruction | Contract |
| ERP transaction data (transient) | Compute UES™, Monte Carlo, variance, runway, narratives | Contract |
| Analysis outputs | Display in AI client; Reflection Engine™ fidelity scoring | Contract |
| Audit metadata | Operational integrity, security incident response, billing | Legitimate interest |
| Sign-in metadata | Account security, fraud prevention | Legitimate interest |
| Marketing email (opt-in only) | Product updates and educational content | Consent |
Product analytics and session replay
FinHelm uses PostHog for product analytics and session replay to understand which parts of FinHelm are useful and improve the service. Analytics is on by default on selected website and product pages unless you have declined it in this browser or enabled Do Not Track or Global Privacy Control. PostHog creates visitor profiles with page visits and product actions, a browser identifier, browser and device details, the browser’s user-agent string, language, timezone, IP address and approximate location. Profiles also contain initial and recent visit details, referring domains and limited acquisition categories. PostHog processes this information in our U.S. project.
While analytics is on, we automatically record clicks and form change or submit actions, including repeated clicks and clicks with no visible response. We measure scrolling, time on a page and page exits, and use heatmaps to understand interaction patterns. These events can include public button or link labels, the location of an element on the page, and link destinations with queries and fragments removed. Automatic interaction events do not include the values you enter into forms.
We select all eligible sessions for session replay, recording page layout, public text, pointer movements, clicks, scrolling and viewport changes. All form values are masked in recordings. We also mask text in signed-in product pages and financial or user-content areas of the assessment. Embedded frames, canvases and designated private visualizations are blocked. Replay excludes console logs and network request or response contents. Sign-in and other excluded pages are not recorded. These recordings use the same analytics choice described below.
After you successfully submit a contact form or save an assessment while analytics is allowed, we link your browser activity to the email address you submitted. Your PostHog profile may include that email, your name, company, role, company-size category, selected ERP product and tier of interest, where provided. Submitting the same email on another device can link those visits. For signed-in accounts with analytics allowed, we also use a stable account identifier, account email, plan and subscription status. We record confirmed lead saves, account visits, checkout and subscription outcomes, billing amounts and currency, and email delivery outcomes when they can be linked to an existing account or lead with analytics allowed. We do not send message bodies, financial inputs or assessment results, ledger data, payment credentials, passwords, parameters from visited URLs or sign-in tokens to PostHog.
We also use Google Analytics on selected public marketing pages, enabled by default with the same opt-out. We send selected page visits and confirmed contact-form submissions, using predefined page names and limited categories such as product tier. Google may also process browser and device information, session activity, approximate location and a random browser identifier. This integration excludes assessment, account and sign-in pages. We do not send form contents, financial inputs or results, account identifiers, raw URL query strings or referring URLs to Google Analytics. Advertising features and automatic measurement of forms, searches and clicks are disabled. Learn how Google uses information from sites that use its services.
While analytics is enabled, we also record limited acquisition categories, such as a search engine, LinkedIn, an email campaign, or a direct visit, together with a predefined landing page. We keep these categories in session storage for the current browser tab, expiring after 30 minutes without measurement activity, and include them with confirmed lead submissions. PostHog also receives the referring origin and domain; referring paths, queries and fragments are removed. We discard advertising click identifiers and unrecognized campaign text. Declining analytics clears the locally stored acquisition categories.
PostHog also receives page-performance measurements, sanitized application error categories and server tool-call timings and outcomes. Performance events contain timings and layout-stability measurements, without page contents or form values. Error events use fixed categories and may include application JavaScript file locations and line numbers; we remove raw error messages, variables and data values. Tool diagnostics exclude prompts, tool arguments, results and model responses. These diagnostics use the same analytics choice.
We also measure delivery of selected public website requests using limited hosting logs in PostHog. These operational records contain approved public paths, response status and delivery metadata. They exclude private account and API routes, URL queries, referring URLs, request and response bodies, and runtime log messages. Client identifiers are hashed before transmission and these records do not create visitor profiles or link to account and lead identities. This operational measurement is separate from browser analytics and its opt-out.
You can turn analytics off and continue using FinHelm. While analytics is on, PostHog stores a browser, submitted-lead or account identifier in browser local storage. FinHelm uses first-party cookies lasting up to one year to pass the analytics choice and browser session context to our server and to recognize a confirmed lead when saving a choice. Google Analytics uses first-party cookies configured to expire after 180 days without refreshing that period on a visit. Use Privacy choices below at any time to select Allow analytics or Decline for both providers. A saved browser choice remains until you change it or clear browser storage; it does not expire automatically. We also save the choice against a recognized lead or signed-in account so later server events respect it. Clearing browser storage removes the local choice; a saved account decline can apply again when you sign in. Declining stops new browser events and session recording, discards replay and heatmap data waiting in the browser, and removes these integrations’ stored browser identifiers. Requests already sent may finish or retry, and changing this choice does not delete events already delivered. Allowing analytics again starts a new browser identifier and recording session; a later confirmed submission or sign-in can link activity to the corresponding lead or account. We honor Do Not Track and Global Privacy Control even when analytics was previously allowed.
We do not sell, rent, or trade personal information. We do not use ERP data or analysis outputs to train third-party AI models. AI models accessed via our MCP connector are invoked ephemerally per request; outputs are returned and not pooled into a training set.
SECTION VData retention
| Data category | Retention period |
|---|---|
| Raw ERP transaction data | Not retained — transient memory only |
| OAuth tokens (active) | Until you revoke access or close your account |
| OAuth tokens (revoked) | Deleted within 24 hours of revocation |
| Content you author (budgets, drivers, scenarios) | Until you delete it or close your account |
| Analysis outputs and forecast history | 13 months from generation, then deleted |
| Audit metadata | 13 months from event, then deleted |
| Account data (active) | Until you close your account |
| Account data (closed) | 30 days, then deleted (legal-hold exceptions noted) |
| Marketing consent records | Until you withdraw consent, plus 24 months evidence |
SECTION VIThird-party services & sub-processors
FinHelm contracts the sub-processors below to operate the product. The canonical list is mirrored on finhelm.ai/security/.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Compute, storage, KMS, Cognito, networking | U.S. — us-east-1 |
| Anthropic, PBC | AI model invocation (ephemeral, per-request) | U.S. |
| Stripe, Inc. | Payments processing (when paid tiers enforced) | U.S. |
| Sentry | Application error monitoring (no ERP data sent) | U.S. |
| Vercel | Frontend hosting | Standard web logs |
| PostHog | Product and journey analytics, visitor profiles, heatmaps, masked session replay and diagnostics with an opt-out; separate limited public-request delivery records; no ledger data | U.S. |
| Google Analytics | Public marketing analytics, on by default with the same opt-out; no ERP data or form contents | Google infrastructure; see Google’s processing information |
PostHog and Google Analytics: See Section IV for the events collected and your shared analytics choice.
FinHelm provides 30 days’ notice before adding a new sub-processor that processes customer ERP data. Subscribe to sub-processor change notifications at privacy@finhelm.ai.
SECTION VIIYour data rights
Depending on your jurisdiction, you have the following rights:
- Access — receive a copy of your account data and analysis outputs.
- Rectification — correct inaccurate data we hold.
- Erasure — delete your account and associated data (subject to legal-hold exceptions).
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for any consent-based processing (such as marketing email).
To exercise any of these rights, email privacy@finhelm.ai. We respond within 30 days.
SECTION VIIISecurity
FinHelm implements industry-standard technical and organizational measures:
- TLS 1.2+ for data in transit.
- AES-256 encryption at rest, AWS KMS customer-managed keys.
- Identity managed by AWS Cognito. People sign in through a first-party FinHelm form over TLS; connecting applications authorize through OAuth 2.0 with PKCE.
- Read-only ERP scopes; no write access requested or granted.
- Principle of least privilege for internal access.
- Dependabot security updates and code review on every commit.
Detailed security architecture is documented at finhelm.ai/security/.
SECTION IXChildren’s privacy
FinHelm is a B2B finance product and is not directed to individuals under 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it.
SECTION XInternational data transfers
FinHelm’s primary infrastructure is hosted in the U.S. (AWS us-east-1). For customers outside the U.S., this constitutes a cross-border transfer. Where required (for example, EEA and UK customers), we rely on Standard Contractual Clauses and equivalent transfer mechanisms. Contact privacy@finhelm.ai for the applicable transfer mechanism documentation.
SECTION XIChanges to this policy
We will notify customers of material changes by email and by updating the “Last updated” date at the top of this page at least 14 days before changes take effect. Non-material edits (typo fixes, link updates) take effect on publication. The previous version (March MMXXVI) is available on request.