Futureproof
Legal

Privacy Policy

Last Updated: August 10, 2026

Futureproof Ops, Inc. (“Futureproof,” “we,” “us,” or “our”) operates the Futureproof platform. This Privacy Policy explains how we collect, use, share, and protect your information when you use our services.

Contact: privacy@runfutureproof.com | 644 Holly Springs Rd, STE 80, Holly Springs, NC 27540, USA

1. Information We Collect

Information You Provide

Account Information:

  • Name, email address, company name
  • Password and authentication credentials
  • Billing information (credit card details, billing address)

Financial Data:

  • Transaction data from connected bank accounts and credit cards
  • Manually entered transactions and adjustments
  • Transaction categorizations and notes
  • Financial forecasts and projections
  • Cap table information and equity data
  • Documents uploaded to the data room
  • Budget data and departmental allocations

Tax Information:

If you upload vendor tax documents (such as Forms W-9), place documents containing tax identification numbers in a data room or AI Knowledge Base, or import accounting data containing tax details, we receive taxpayer identification numbers (which may be SSNs or EINs) and related tax attributes (such as 1099 payment totals). We treat taxpayer identification numbers as sensitive information: they are encrypted, access-restricted, processed by our AI service providers solely to extract document data, never used to improve the Services across customers, and retained only as long as needed for your records and legal requirements.

Free Tools:

If you use our free Pitch Deck Review, your uploaded deck is processed by our review provider solely to generate your review. We retain decks and reviews so you can revisit your results, and we delete them on request. Calculator inputs on our website are processed to show you results; we record tool usage events, not your financial inputs, in our product analytics.

Communications:

  • Messages sent to our support team
  • Feedback and survey responses
  • Information provided when participating in beta programs

Information We Collect Automatically

Usage Information:

  • Pages visited, features used, and time spent on the Services
  • Device information (type, operating system, browser)
  • IP address and general location (city/state level)
  • Login times and access patterns

Cookies and Similar Technologies: We use cookies, pixels, and similar technologies to collect usage data and improve the Services. See Section 9 for details.

Information from Third Parties

Bank Connection Services: When you connect financial accounts through Plaid, we receive transaction data, account balances, account identifiers (which may include account and routing numbers), statements, and investment holdings from your financial institutions, depending on the accounts and features you enable. We treat financial account identifiers as sensitive information.

CRM and HRIS Integrations: If you connect CRM or HRIS systems through the Services, we may receive:

  • Contact and customer data from CRM systems (e.g., Salesforce, HubSpot)
  • Employee and payroll data from HRIS systems (e.g., BambooHR, Gusto)
  • Sales pipeline and revenue data
  • Headcount and compensation data
  • Related metadata and usage information

The data we access depends on the permissions you grant and the integrations you enable.

Google Integrations: If you connect Google Ads or Google Drive to the Services, we receive the data described in Section 6 (Google User Data).

Other Sources: We may receive information from service providers who help us operate the Services (e.g., payment processors, analytics providers).

2. How We Use Your Information

Provide the Services:

  • Process and categorize transactions
  • Generate financial forecasts and reports
  • Manage cap table and equity information
  • Facilitate data room document sharing
  • Sync data from connected bank accounts, CRM, and HRIS systems
  • Enhance forecasting with sales pipeline and hiring plan data
  • Provide customer support

Improve the Services:

  • Train and improve AI models (see Section 3)
  • Develop new features and enhance existing ones
  • Analyze usage patterns to improve user experience
  • Conduct internal research and analytics

Communicate with You:

  • Send account-related notifications and updates
  • Respond to your inquiries and requests
  • Send service announcements and feature updates
  • Request feedback or participation in research

Business Operations:

  • Process payments and prevent fraud
  • Comply with legal obligations
  • Enforce our Terms of Service
  • Protect our rights and the security of our Services

Marketing (with your consent):

  • Send promotional emails about new features
  • Share relevant content and resources

You can opt-out of marketing communications by clicking “unsubscribe” in any email or contacting privacy@runfutureproof.com.

3. AI Training and Product Improvement

How AI Processing Works

Serving you: To categorize transactions and generate outputs, the Services send relevant data to the AI service providers listed in Section 4, under agreements that prohibit those providers from using your data to train their own models. Your corrections, rules, and agent instructions are used to make the Services more accurate for your account — this is part of providing the Services.

Improving the platform: We use de-identified data — stripped of identifiers so it can no longer reasonably be linked to you or your business, maintained subject to technical safeguards, and which we publicly commit never to attempt to re-identify — to improve categorization, forecasting, and agent features for all customers.

Human review: New or uncertain entries are held for your review and approval before they post to your books. Recurring entries apply automatically on rules and vendor categorizations you have previously approved, and every entry is recorded in an audit log you can review.

Example: When you categorize a “Stripe” transaction as “Payment Processing,” that pattern (with your identifying details removed) helps our categorization improve for other SaaS companies. We never share your actual amounts, company name, or other identifying details.

After You Cancel Your Subscription

When you cancel, you have 30 days to export your data. After that:

What We Retain:

  • De-identified transaction patterns to continue improving the Services
  • Aggregated usage data combined with other customers

What We Delete Immediately:

  • Data room documents
  • Cap table details
  • Access credentials

What “De-identified” Means:

  • All personally identifiable information removed (company name, specific vendor names you added, account numbers)
  • Data aggregated with data from other customers
  • Cannot reasonably be used to re-identify you or your company
  • We maintain technical safeguards against re-identification and publicly commit never to attempt to re-identify de-identified data

Your Options:

  1. Request Complete Deletion: Email privacy@runfutureproof.com with subject “Data Deletion Request” to have your data deleted (typically within 90 days, except data required by law)

Automatic Deletion Timeline:

  • After approximately 1 year: Identifiable data deleted (only de-identified patterns remain)
  • After approximately 7 years: All data deleted except as required by law

Actual deletion timing may vary based on system processes and backup retention schedules.

For complete details, see Section 11.

4. How We Share Information

We never sell your personal information.

We share information only in the following circumstances:

Service Providers

We share data with third-party companies that help us operate the Services:

  • Anthropic — AI transaction categorization and document understanding
  • OpenAI — Document embeddings for search and retrieval
  • Plaid — Bank and financial account connections
  • Stripe — Subscription billing (we don't store your full credit card number)
  • Supabase — Database and file storage
  • Vercel — Application hosting
  • Clerk — Authentication and identity
  • Bunny — Subscription management
  • PostHog — Product analytics
  • HubSpot — CRM and marketing communications
  • Resend — Email delivery
  • Google — Website analytics, tag management, and spreadsheet imports
  • hCaptcha — Abuse prevention on web forms
  • Lovable — Pitch Deck Review processing

These providers are contractually required to protect your data and use it only for the purposes we specify. We update this list when providers change.

Your Direction

Data Room: When you share documents through the data room, they're accessible to the investors, advisors, or other recipients you designate. We don't monitor or review shared content.

Third-Party Users: When you grant access to accountants, bookkeepers, or other professionals, they can view and use your data according to the permissions you set.

Connected Systems: When you connect CRM or HRIS systems, we access data from those systems according to the permissions you grant. Your use of those systems is governed by their respective privacy policies.

Google Drive Backup: If you connect Google Drive, we copy receipt files you upload to the Services into folders our application creates in your own Google Drive. See Section 6 for details.

Business Transfers

If Futureproof is involved in a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.

Legal Requirements

We may disclose information to:

  • Comply with legal obligations (subpoenas, court orders)
  • Protect our rights, property, and safety
  • Prevent fraud or security threats
  • Enforce our Terms of Service

With Your Consent

We may share information in other contexts with your explicit consent.

5. Bank Connections and Financial Data

How Bank Connections Work

The Services allow you to connect bank accounts and credit cards through third-party financial data aggregation services (primarily Plaid Technologies, Inc.).

When you connect an account:

  • You authorize us and our service providers to access your transaction data
  • We receive transaction details, account balances, and account information
  • We do not store your banking login credentials—these are handled securely by third-party providers
  • The connection is governed by both our Privacy Policy and the third-party provider's privacy policy

Third-Party Privacy Policies:

Please review Plaid's privacy policy to understand how your credentials and data are handled.

When You Disconnect a Bank Account

What Stops:

  • Automatic import of new transactions from that account
  • Access to the account through the third-party service

What Remains:

  • Historical transaction data previously imported
  • Your categorizations and modifications
  • Financial records and reports that include data from that account

Why We Retain Historical Data:

  • Accurate bookkeeping requires complete historical records
  • Tax reporting may require prior period transaction data
  • Financial statements need historical comparisons
  • Legal and regulatory requirements may mandate retention

Deleting Historical Bank Data

To delete historical transaction data from a disconnected account, email privacy@runfutureproof.com with a deletion request. We will inform you of the implications—including gaps in financial records and potential tax compliance issues—before processing.

Important: Deletion is permanent and cannot be undone.

6. Google User Data

The Services offer optional integrations with Google Ads and Google Drive. This section describes how we handle data received from Google APIs when you connect these integrations. Futureproof's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What Google Data We Access

  • Google Ads: If you connect Google Ads, we access your campaign spend and performance metrics (such as cost, impressions, clicks, and conversions) on a read-only basis. We do not modify your Ads account.
  • Google Drive: If you connect Google Drive, we use the drive.file scope, which limits our access to files and folders created through Futureproof. We access file metadata only for the folders our application creates. We cannot see, open, or modify any other files in your Google Drive.
  • Account identity: We receive the email address of the Google account you connect, so we can identify and manage the connection.

How We Use Google Data

  • Google Ads data is used solely to display advertising spend in your financial reports, cash forecasts, and budget-vs-actual analysis.
  • Google Drive is used solely to back up receipt files uploaded through the Services to folders our application creates in your Drive.

We do not use Google user data for advertising, and we do not use it for any purpose other than providing and improving these user-facing features.

Who We Share Google Data With

We do not transfer or sell Google user data to any third party, including data brokers or advertisers. Google user data is processed only on our secured infrastructure by service providers acting on our behalf to operate the Services (see Section 4), as necessary for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.

How We Protect Google Data

  • Google user data is encrypted in transit and at rest.
  • Access is restricted to authenticated users within your organization.
  • OAuth refresh tokens are stored encrypted at rest and are never exposed to other users or third parties.

Retention and Deletion of Google Data

You can disconnect a Google integration at any time in Settings → Integrations, or revoke Futureproof's access from your Google Account security settings. When you disconnect, we stop accessing your Google account and delete the stored OAuth tokens for that connection. Data previously synced into your Futureproof account (such as Ads spend already reflected in your financial reports) is retained as part of your financial records, consistent with Section 11, unless you request deletion by emailing privacy@runfutureproof.com. Upon deletion of your account, all of your data, including Google-sourced data, is permanently deleted except where retention is required by law.

7. Data Room and Document Sharing

How the Data Room Works

The data room feature allows you to securely share pitch decks, financial statements, and other documents with investors, advisors, and stakeholders.

You Control Access:

  • You decide what to share and with whom
  • You set permissions for each recipient
  • You can revoke access at any time

Our Role:

  • We provide the technical infrastructure and security
  • We don't monitor, review, or access documents you share with recipients
  • We may provide analytics on document views and engagement

AI Knowledge Base: If you create an AI Knowledge Base room and place documents in it, you direct our Services (including the AI service providers listed in Section 4) to process those documents so your agents can reference them. Knowledge Base rooms are internal-only and cannot be shared externally.

When You Delete or Revoke Access:

  • Documents are removed from our platform
  • Recipients who previously downloaded documents may still have copies
  • We are not responsible for how recipients use or retain documents they've accessed

8. Third-Party Access

You may grant access to your Account to accountants, bookkeepers, tax preparers, or other financial professionals.

When you grant access:

  • Third-Party Users can view and use data according to the permissions you set
  • They must comply with our Terms of Service
  • You are responsible for managing their access and permissions

We don't:

  • Have direct relationships with Third-Party Users
  • Verify their credentials or qualifications
  • Monitor their use of your data

You should:

  • Only grant access to trusted professionals
  • Revoke access when no longer needed
  • Review permissions regularly

9. Cookies and Tracking Technologies

We use cookies, pixels, web beacons, and similar technologies to:

  • Remember your preferences and settings
  • Understand how you use our Services
  • Improve performance and user experience
  • Provide security features
  • Analyze usage patterns

Types of Cookies We Use:

  • Essential Cookies: Required for the Services to function (e.g., authentication, security).
  • Analytics Cookies: Help us understand how you interact with our Services (e.g., Google Analytics).
  • Preference Cookies: Remember your settings and choices.

Your Choices:

Browser Settings: Most browsers allow you to control cookies through settings. Note that blocking essential cookies may prevent use of some features.

Opt-Out Tools:

Your Privacy Choices:

Cookie Preferences: You can review and change your cookie choices for our website at any time through our cookie preferences panel. Visitors in regions that require opt-in consent are asked before any non-essential cookies are set.

Global Privacy Control: We recognize and honor the Global Privacy Control (GPC) browser signal. If your browser or a browser extension sends a GPC signal, we automatically treat it as a valid request to opt out of the sale or sharing of your personal information for that browser — no further action is required from you, and advertising cookies remain off even if you otherwise accept cookies. Learn how to enable GPC at globalprivacycontrol.org.

10. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: Data encrypted in transit (TLS/SSL) and at rest.
  • Access Controls: Limited employee access based on role and need.
  • Authentication: Secure login with optional two-factor authentication.
  • Monitoring: Regular security audits and vulnerability assessments.
  • Secure Infrastructure: Data hosted in SOC 2 compliant data centers.

However, no system is completely secure. We cannot guarantee absolute security and are not liable for unauthorized access or security incidents beyond our reasonable control.

Your Responsibility:

  • Use strong, unique passwords
  • Enable two-factor authentication when available
  • Keep login credentials confidential
  • Notify us immediately of suspected security incidents

Security Incidents

If we determine that a security incident has affected your personal information, we will notify you without unreasonable delay consistent with applicable law, describe what happened and what data was involved, and tell you what we are doing and what you can do. We will also notify regulators and partners where required by law or contract.

11. Data Retention and Deletion

During Active Use

We retain your data for as long as your Account is active and as necessary to provide the Services.

After Disconnecting Bank Accounts

When you disconnect a bank account, we retain historical transaction data as part of your bookkeeping records unless you request deletion.

After Disconnecting CRM or HRIS Systems

When you disconnect CRM or HRIS integrations, we stop importing new data but retain historical data previously imported for forecasting and reporting purposes unless you request deletion.

After Account Cancellation

First 30 Days:

  • You can log in and export your data (CSV, Excel, PDF)
  • Full access to all features for data retrieval

Immediately Upon Cancellation:

  • Data room documents deleted
  • Cap table details deleted
  • Access credentials deleted

After 30 Days:

  • You lose access to your data through our platform
  • De-identified transaction patterns retained to improve the Services
  • Specific financial details and identifying information not retained

After Approximately 1 Year:

  • Identifiable transaction data deleted
  • Only de-identified, aggregated patterns remain

After Approximately 7 Years:

  • All remaining data deleted except as required by law

Note on Timing: Actual deletion timing may vary based on system processes, backup rotation schedules, and technical constraints. Data in disaster recovery backups is typically deleted within 180 days but may persist longer due to backup retention schedules.

Legal and Regulatory Retention

We may retain certain data longer as required by:

  • Tax laws and regulations (typically 3–7 years for financial records)
  • Anti-money laundering and fraud prevention laws
  • Legal process (subpoenas, court orders, pending litigation)
  • Legitimate business interests (enforcing our Terms, protecting our rights)

Beta Features

Data created using Beta Features may be lost, corrupted, or deleted if features are modified or discontinued. You are responsible for backing up important data from Beta Features.

Our Commitment

While we strive to meet the timelines outlined above, actual deletion may vary based on technical and operational constraints, backup procedures, and system architecture. We will always comply with applicable legal retention requirements and data protection regulations.

12. Your Privacy Rights

Depending on your location, you may have the following rights:

Access and Portability:

  • Request a copy of your personal data
  • Export financial data in common formats (available directly in the Services)

Correction:

  • Request correction of inaccurate data
  • Update account information directly in settings

Deletion:

  • Request deletion of your data (subject to legal retention requirements)
  • See Section 11 for deletion timelines and processes

Restriction and Objection:

  • Object to certain data processing activities
  • Restrict how we process your data in certain circumstances

Withdraw Consent:

  • Withdraw consent for marketing communications or other optional data uses

How to Exercise Your Rights

Email privacy@runfutureproof.com with your request. Include:

  • Your name and Account email
  • The specific right you're exercising
  • Any relevant details

We will typically respond within 30 days (or as required by applicable law). We may need to verify your identity before processing certain requests. Response times may vary based on the complexity of the request and volume of requests received.

California Residents (CCPA)

Under the California Consumer Privacy Act, you have additional rights:

  • Right to Know: What personal information we collect, use, and share
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out of Sale or Sharing: We do not sell personal information for money. To the extent our use of advertising and analytics cookies is considered “sharing” under the CCPA, you can opt out at any time through our cookie preferences panel, or automatically via the Global Privacy Control browser signal, which we honor (see Section 9)
  • Right to Non-Discrimination: We won't discriminate against you for exercising your privacy rights

Availability of the Services

The Services are offered to businesses located in the United States. We do not currently offer the Services in the European Economic Area, the United Kingdom, or Switzerland.

13. International Data Transfers

Futureproof is based in the United States, the Services are offered to businesses located in the United States, and your information is processed in the United States. If you access the Services from outside the U.S., you consent to the transfer of your information to the United States.

14. Children's Privacy

Our Services are not intended for individuals under 18 years old. We do not knowingly collect personal information from minors under 18.

If we become aware that we have collected data from a person under 18, we will take steps to delete it promptly. If you believe we have collected information from a minor, please contact privacy@runfutureproof.com.

15. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors.

When We Make Changes:

  • We will update the “Last Updated” date at the top
  • For material changes, we will make reasonable efforts to notify you by email or prominent notice on the Services
  • Changes become effective when posted unless otherwise specified

Your Continued Use: Your continued use of the Services after changes become effective means you accept the updated Privacy Policy.

Review Regularly: We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

16. Contact Us

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us:

Futureproof Ops, Inc.
644 Holly Springs Rd, STE 80
Holly Springs, NC 27540, USA

Email: privacy@runfutureproof.com