Privacy Policy
Last updated: January 28, 2026
Finault ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI cost governance platform.
1. Information We Collect
Information You Provide
- Account Information: Email address, name, company name when you create an account
- Invoice Data: AI provider invoices you upload for analysis (CSV files)
- Payment Information: Processed securely by Stripe; we don't store full card numbers
- Communications: Emails, support requests, and feedback you send us
Information Collected Automatically
- Usage Data: Features used, pages visited, actions taken
- Device Information: Browser type, operating system, IP address
- Cookies: Session cookies for authentication; analytics cookies (optional)
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process your invoices and generate Close Packs
- Send you service-related communications
- Respond to your requests and support inquiries
- Monitor and analyze usage patterns to improve the product
- Detect, prevent, and address technical issues or fraud
3. Data Processing & Security
Invoice Data Processing
When you upload an invoice:
- Free tier: Data is processed in your browser and not stored on our servers
- Pro/Business tier: Data is encrypted (AES-256) and stored according to your plan's retention period
- We do not use your invoice data to train AI models
- We do not share your invoice data with third parties
Security Measures
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- SOC 2 Type II certification (in progress)
- Regular security audits and penetration testing
4. Data Retention
| Tier | Retention |
|---|---|
| Free | No data stored (browser only) |
| Pro | 90 days |
| Business | 2 years |
| Enterprise | Custom (up to 7 years) |
5. Information Sharing
We do not sell your personal information. We may share information with:
- Service Providers: Stripe (payments), Supabase (database), Cloudflare (hosting)
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
6. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information
- Export your data in a portable format
- Opt out of marketing communications
To exercise these rights, email us at privacy@finault.ai.
7. International Data Transfers
Your information may be transferred to and processed in the United States and other countries. We use Standard Contractual Clauses and other safeguards to ensure adequate protection.
8. Children's Privacy
Finault is not intended for use by children under 16. We do not knowingly collect information from children under 16.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website.
10. Contact Us
If you have questions about this Privacy Policy, contact us at:
- Email: privacy@finault.ai
- Address: Finault, Inc., 123 Finance Street, San Francisco, CA 94105