FOLIO — PRIVACY NO LEDGER COPY · DATA RIGHTS · TRANSFERS

Privacy is architectural.

We hold no copy of your ledger.

FinHelm holds no copy of your ledger. Every ERP read is fetched live from your accounting system, used to compute the analysis in front of you, and discarded. What FinHelm stores is what you author inside FinHelm, your forecast history, and your account, billing, and audit records. Section V details retention.

Last updated XV May MMXXVI · Replaces March MMXXVI · v2.0
Product analytics disclosure updated XI September MMXXVI

SECTION IScope of this Policy

This Privacy Policy applies to all FinHelm products and services, including FinHelm Clarity (our QuickBooks Online–connected SMB FP&A product), FinHelm Platform (our mid-market and enterprise FP&A product), the FinHelm MCP connector for AI clients, and marketing pages and demo tools at finhelm.ai. Where MCP connector–specific terms apply, they are noted in the relevant section.

SECTION IIWho we are

FinHelm Corp is a Tennessee C-Corporation, founded MMXXVI. Our principal place of business is in Tennessee, U.S.A. For data protection purposes, FinHelm Corp is the data controller for marketing and authentication data, and a data processor for ERP analysis data on behalf of our customers.

Contact: privacy@finhelm.ai.

SECTION IIIData we collect

FinHelm collects only what is necessary to operate the product and meet legal obligations.

FIG. III.a · The ledger boundary is structural. The ledger we never store, we cannot lose.

SECTION IVHow we use data

The following table lists the purposes and legal bases for our account and service processing. Product analytics is described separately below.

Data category Purpose Legal basis
Email & password hashAccount creation, authentication, password resetContract
OAuth tokensRead-only access to connected ERP on user’s instructionContract
ERP transaction data (transient)Compute UES™, Monte Carlo, variance, runway, narrativesContract
Analysis outputsDisplay in AI client; Reflection Engine™ fidelity scoringContract
Audit metadataOperational integrity, security incident response, billingLegitimate interest
Sign-in metadataAccount security, fraud preventionLegitimate interest
Marketing email (opt-in only)Product updates and educational contentConsent

Product analytics and session replay

FinHelm uses PostHog for product analytics and session replay to understand which parts of FinHelm are useful and improve the service. Analytics is on by default on selected website and product pages unless you have declined it in this browser or enabled Do Not Track or Global Privacy Control. PostHog creates visitor profiles with page visits and product actions, a browser identifier, browser and device details, the browser’s user-agent string, language, timezone, IP address and approximate location. Profiles also contain initial and recent visit details, referring domains and limited acquisition categories. PostHog processes this information in our U.S. project.

While analytics is on, we automatically record clicks and form change or submit actions, including repeated clicks and clicks with no visible response. We measure scrolling, time on a page and page exits, and use heatmaps to understand interaction patterns. These events can include public button or link labels, the location of an element on the page, and link destinations with queries and fragments removed. Automatic interaction events do not include the values you enter into forms.

We select all eligible sessions for session replay, recording page layout, public text, pointer movements, clicks, scrolling and viewport changes. All form values are masked in recordings. We also mask text in signed-in product pages and financial or user-content areas of the assessment. Embedded frames, canvases and designated private visualizations are blocked. Replay excludes console logs and network request or response contents. Sign-in and other excluded pages are not recorded. These recordings use the same analytics choice described below.

After you successfully submit a contact form or save an assessment while analytics is allowed, we link your browser activity to the email address you submitted. Your PostHog profile may include that email, your name, company, role, company-size category, selected ERP product and tier of interest, where provided. Submitting the same email on another device can link those visits. For signed-in accounts with analytics allowed, we also use a stable account identifier, account email, plan and subscription status. We record confirmed lead saves, account visits, checkout and subscription outcomes, billing amounts and currency, and email delivery outcomes when they can be linked to an existing account or lead with analytics allowed. We do not send message bodies, financial inputs or assessment results, ledger data, payment credentials, passwords, parameters from visited URLs or sign-in tokens to PostHog.

We also use Google Analytics on selected public marketing pages, enabled by default with the same opt-out. We send selected page visits and confirmed contact-form submissions, using predefined page names and limited categories such as product tier. Google may also process browser and device information, session activity, approximate location and a random browser identifier. This integration excludes assessment, account and sign-in pages. We do not send form contents, financial inputs or results, account identifiers, raw URL query strings or referring URLs to Google Analytics. Advertising features and automatic measurement of forms, searches and clicks are disabled. Learn how Google uses information from sites that use its services.

While analytics is enabled, we also record limited acquisition categories, such as a search engine, LinkedIn, an email campaign, or a direct visit, together with a predefined landing page. We keep these categories in session storage for the current browser tab, expiring after 30 minutes without measurement activity, and include them with confirmed lead submissions. PostHog also receives the referring origin and domain; referring paths, queries and fragments are removed. We discard advertising click identifiers and unrecognized campaign text. Declining analytics clears the locally stored acquisition categories.

PostHog also receives page-performance measurements, sanitized application error categories and server tool-call timings and outcomes. Performance events contain timings and layout-stability measurements, without page contents or form values. Error events use fixed categories and may include application JavaScript file locations and line numbers; we remove raw error messages, variables and data values. Tool diagnostics exclude prompts, tool arguments, results and model responses. These diagnostics use the same analytics choice.

We also measure delivery of selected public website requests using limited hosting logs in PostHog. These operational records contain approved public paths, response status and delivery metadata. They exclude private account and API routes, URL queries, referring URLs, request and response bodies, and runtime log messages. Client identifiers are hashed before transmission and these records do not create visitor profiles or link to account and lead identities. This operational measurement is separate from browser analytics and its opt-out.

You can turn analytics off and continue using FinHelm. While analytics is on, PostHog stores a browser, submitted-lead or account identifier in browser local storage. FinHelm uses first-party cookies lasting up to one year to pass the analytics choice and browser session context to our server and to recognize a confirmed lead when saving a choice. Google Analytics uses first-party cookies configured to expire after 180 days without refreshing that period on a visit. Use Privacy choices below at any time to select Allow analytics or Decline for both providers. A saved browser choice remains until you change it or clear browser storage; it does not expire automatically. We also save the choice against a recognized lead or signed-in account so later server events respect it. Clearing browser storage removes the local choice; a saved account decline can apply again when you sign in. Declining stops new browser events and session recording, discards replay and heatmap data waiting in the browser, and removes these integrations’ stored browser identifiers. Requests already sent may finish or retry, and changing this choice does not delete events already delivered. Allowing analytics again starts a new browser identifier and recording session; a later confirmed submission or sign-in can link activity to the corresponding lead or account. We honor Do Not Track and Global Privacy Control even when analytics was previously allowed.

We do not sell, rent, or trade personal information. We do not use ERP data or analysis outputs to train third-party AI models. AI models accessed via our MCP connector are invoked ephemerally per request; outputs are returned and not pooled into a training set.

SECTION VData retention

Data category Retention period
Raw ERP transaction dataNot retained — transient memory only
OAuth tokens (active)Until you revoke access or close your account
OAuth tokens (revoked)Deleted within 24 hours of revocation
Content you author (budgets, drivers, scenarios)Until you delete it or close your account
Analysis outputs and forecast history13 months from generation, then deleted
Audit metadata13 months from event, then deleted
Account data (active)Until you close your account
Account data (closed)30 days, then deleted (legal-hold exceptions noted)
Marketing consent recordsUntil you withdraw consent, plus 24 months evidence

SECTION VIThird-party services & sub-processors

FinHelm contracts the sub-processors below to operate the product. The canonical list is mirrored on finhelm.ai/security/.

Sub-processor Purpose Region
Amazon Web ServicesCompute, storage, KMS, Cognito, networkingU.S. — us-east-1
Anthropic, PBCAI model invocation (ephemeral, per-request)U.S.
Stripe, Inc.Payments processing (when paid tiers enforced)U.S.
SentryApplication error monitoring (no ERP data sent)U.S.
VercelFrontend hostingStandard web logs
PostHogProduct and journey analytics, visitor profiles, heatmaps, masked session replay and diagnostics with an opt-out; separate limited public-request delivery records; no ledger dataU.S.
Google AnalyticsPublic marketing analytics, on by default with the same opt-out; no ERP data or form contentsGoogle infrastructure; see Google’s processing information

PostHog and Google Analytics: See Section IV for the events collected and your shared analytics choice.

FinHelm provides 30 days’ notice before adding a new sub-processor that processes customer ERP data. Subscribe to sub-processor change notifications at privacy@finhelm.ai.

SECTION VIIYour data rights

Depending on your jurisdiction, you have the following rights:

To exercise any of these rights, email privacy@finhelm.ai. We respond within 30 days.

SECTION VIIISecurity

FinHelm implements industry-standard technical and organizational measures:

Detailed security architecture is documented at finhelm.ai/security/.

SECTION IXChildren’s privacy

FinHelm is a B2B finance product and is not directed to individuals under 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it.

SECTION XInternational data transfers

FinHelm’s primary infrastructure is hosted in the U.S. (AWS us-east-1). For customers outside the U.S., this constitutes a cross-border transfer. Where required (for example, EEA and UK customers), we rely on Standard Contractual Clauses and equivalent transfer mechanisms. Contact privacy@finhelm.ai for the applicable transfer mechanism documentation.

SECTION XIChanges to this policy

We will notify customers of material changes by email and by updating the “Last updated” date at the top of this page at least 14 days before changes take effect. Non-material edits (typo fixes, link updates) take effect on publication. The previous version (March MMXXVI) is available on request.

FOLIO — INVITATION · DATA SUBJECT REQUESTS

Exercise your data rights.

Access, rectification, erasure, portability, objection, and consent withdrawal. We respond within 30 days.