Privacy Policy
Last Updated: August 24, 2026
Futureproof Ops, Inc. (“Futureproof,” “we,” “us,” or “our”) operates the Futureproof platform. This Privacy Policy explains how we collect, use, share, and protect your information when you use our services.
Contact: privacy@runfutureproof.com | 644 Holly Springs Rd, STE 80, Holly Springs, NC 27540, USA
1. Information We Collect
Information You Provide
Account Information:
- Name, email address, company name
- Password and authentication credentials
- Billing information (credit card details, billing address)
Financial Data:
- Transaction data from connected bank accounts and credit cards
- Manually entered transactions and adjustments
- Transaction categorizations and notes
- Financial forecasts and projections
- Cap table information and equity data
- Documents uploaded to the data room
- Budget data and departmental allocations
Tax Information:
If you upload vendor tax documents (such as Forms W-9), store or generate information returns (such as Forms 1099), place documents containing tax identification numbers in a data room or AI Knowledge Base, or import accounting data containing tax details, we receive taxpayer identification numbers (which may be Social Security numbers or EINs) and related tax attributes (such as 1099 payment totals). Where a contractor is an individual or a sole proprietor, the taxpayer identification number on these documents is that person’s Social Security number. We treat taxpayer identification numbers as sensitive information. They are encrypted in transit and at rest. Access is restricted to authorized users of your own organization and to the Futureproof personnel who need it to operate the Services, and we display only the last four digits on most screens and reports. When you upload a tax document, it is sent to our AI service providers solely to extract the fields on the form, and we do not use taxpayer identification numbers to improve the Services across customers. We retain them only as long as needed for your records and to meet legal requirements. We continue to strengthen these protections, and we will update this section as we do.
Payroll Imports:
You may import payroll data into the Services by uploading a report exported from your payroll provider, including Rippling and Gusto. These files describe your own workforce and typically contain employee and contractor names, pay period detail, gross and net pay, earnings and deduction categories, employer taxes, and benefit contributions. We use them to post payroll to your books and to report and forecast personnel costs. Uploading a payroll report does not connect your payroll account to the Services and gives us no access to your payroll provider.
Free Tools:
If you use our free Pitch Deck Review, your uploaded deck is processed by our review provider solely to generate your review. We retain decks and reviews so you can revisit your results, and we delete them on request. Calculator inputs on our website are processed to show you results; we record tool usage events, not your financial inputs, in our product analytics.
Communications:
- Messages sent to our support team
- Feedback and survey responses
- Information provided when participating in beta programs
Information We Collect Automatically
Usage Information:
- Pages visited, features used, and time spent on the Services
- Device information (type, operating system, browser)
- IP address and general location (city/state level)
- Login times and access patterns
Cookies and Similar Technologies: We use cookies, pixels, and similar technologies to collect usage data and improve the Services. See Section 9 for details.
Information from Third Parties
Bank Connection Services: When you connect financial accounts through Plaid, we receive transaction data, account balances, account identifiers (which may include account and routing numbers), statements, and investment holdings from your financial institutions, depending on the accounts and features you enable. We treat financial account identifiers as sensitive information.
CRM and HRIS Integrations: If you connect CRM or HRIS systems through the Services, we may receive:
- Contact and customer data from CRM systems (e.g., Salesforce, HubSpot)
- Employee and payroll data from HRIS systems (e.g., BambooHR, Gusto)
- Sales pipeline and revenue data
- Headcount and compensation data
- Related metadata and usage information
The data we access depends on the permissions you grant and the integrations you enable.
Ecommerce and Marketplace Integrations: If you connect a sales channel such as Amazon, Shopify, eBay, or TikTok Shop, we may receive order and transaction records, settlement and payout reports, fees and refunds, product and inventory data, and related metadata. We use this data to build your books and reporting inside the Services. We do not send your data back to these platforms.
Accounting Systems and Historical Books: If you connect an accounting platform such as QuickBooks, or upload an export or backup of your prior books, we receive your historical accounting records. These may include your chart of accounts, general ledger and journal entries, trial balances, accounts receivable and payable, customer and vendor lists, invoices and bills, payroll summaries, contractor and 1099 vendor records, and attached source documents. Because these records are your own books, they may contain personal information about your employees, contractors, customers, and vendors. We use them to migrate your history into the Services and to produce your financial statements and reports. We do not write data back to your accounting platform.
Advertising Platforms: If you connect an ad account such as Meta, Google Ads, Amazon Ads, or TikTok Ads, we receive campaign spend and performance data on a read-only basis so we can report marketing costs and channel profitability. We do not upload customer lists, audiences, or conversion data to these platforms.
Google Integrations: If you connect Google Ads or Google Drive to the Services, we receive the data described in Section 6 (Google User Data).
Other Sources: We may receive information from service providers who help us operate the Services (e.g., payment processors, analytics providers).
2. How We Use Your Information
Provide the Services:
- Process and categorize transactions
- Generate financial forecasts and reports
- Manage cap table and equity information
- Facilitate data room document sharing
- Sync data from connected bank accounts, CRM, and HRIS systems
- Enhance forecasting with sales pipeline and hiring plan data
- Provide customer support
Improve the Services:
- Train and improve AI models (see Section 3)
- Develop new features and enhance existing ones
- Analyze usage patterns to improve user experience
- Conduct internal research and analytics
Communicate with You:
- Send account-related notifications and updates
- Respond to your inquiries and requests
- Send service announcements and feature updates
- Request feedback or participation in research
Business Operations:
- Process payments and prevent fraud
- Comply with legal obligations
- Enforce our Terms of Service
- Protect our rights and the security of our Services
Marketing (with your consent):
- Send promotional emails about new features
- Share relevant content and resources
You can opt-out of marketing communications by clicking “unsubscribe” in any email or contacting privacy@runfutureproof.com.
3. AI Training and Product Improvement
How AI Processing Works
Serving you: To categorize transactions and generate outputs, the Services send relevant data to the AI service providers listed in Section 4, under agreements that prohibit those providers from using your data to train their own models. Your corrections, rules, and agent instructions are used to make the Services more accurate for your account — this is part of providing the Services.
Improving the platform: We use de-identified data — stripped of identifiers so it can no longer reasonably be linked to you or your business, maintained subject to technical safeguards, and which we publicly commit never to attempt to re-identify — to improve categorization, forecasting, and agent features for all customers.
Human review: New or uncertain entries are held for your review and approval before they post to your books. Recurring entries apply automatically on rules and vendor categorizations you have previously approved, and every entry is recorded in an audit log you can review.
Example: When you categorize a “Stripe” transaction as “Payment Processing,” that pattern (with your identifying details removed) helps our categorization improve for other SaaS companies. We never share your actual amounts, company name, or other identifying details.
After You Cancel Your Subscription
When you cancel, you have 30 days to export your data. After that:
What We Retain:
- De-identified transaction patterns to continue improving the Services
- Aggregated usage data combined with other customers
What We Delete Immediately:
- Data room documents
- Cap table details
- Access credentials
What “De-identified” Means:
- All personally identifiable information removed (company name, specific vendor names you added, account numbers)
- Data aggregated with data from other customers
- Cannot reasonably be used to re-identify you or your company
- We maintain technical safeguards against re-identification and publicly commit never to attempt to re-identify de-identified data
Your Options:
- Request Complete Deletion: Email privacy@runfutureproof.com with subject “Data Deletion Request” to have your data deleted (typically within 90 days, except data required by law)
Deletion Timeline:
- Within 30 days: your export window closes and you lose access
- Within 90 days of cancellation at the latest: identifiable data is deleted, whether or not you ask us to
We do not keep your books on file after you leave. Only de-identified patterns remain, and data required by law or held under legal process is retained for as long as that requirement lasts. Copies in disaster-recovery backups are removed on our backup rotation schedule.
Export before you go. Because we delete on this schedule, you should export anything you may need later. Your accounting records may be needed for tax filing or an audit, and those obligations rest with you.
For complete details, see Section 11.
4. How We Share Information
We never sell your personal information.
We share information only in the following circumstances:
Service Providers
We share data with third-party companies that help us operate the Services:
- Anthropic — AI transaction categorization and document understanding
- OpenAI — Document embeddings for search and retrieval
- Plaid — Bank and financial account connections
- Unified.to — Accounting, CRM, HRIS, commerce, and advertising data sync
- Stripe — Subscription billing (we don't store your full credit card number)
- Supabase — Database and file storage
- Vercel — Application hosting
- Clerk — Authentication and user management
- Bunny — Subscription management
- PostHog — Product analytics
- HubSpot — CRM and marketing communications
- Resend — Email delivery
- Trigger.dev — Background job processing
- Redis Cloud — Caching and rate limiting
- Google — Gemini AI models, website analytics, tag management, and spreadsheet imports
- hCaptcha — Abuse prevention on web forms
- Lovable — Pitch Deck Review processing, and the AcceleratorHub and EventsHub applications
- Airtable — Partner directory applications and listings
These providers are contractually required to protect your data and use it only for the purposes we specify. We update this list when providers change.
Your Direction
Data Room: When you share documents through the data room, they're accessible to the investors, advisors, or other recipients you designate. We don't monitor or review shared content.
Third-Party Users: When you grant access to accountants, bookkeepers, or other professionals, they can view and use your data according to the permissions you set.
Connected Systems: When you connect an outside system — a CRM, an HRIS, a sales channel, an ad account, or an accounting platform — we access data from that system according to the permissions you grant. Data flows into the Services; we do not disclose your data back to those platforms. Your use of those systems is governed by their respective privacy policies.
Google Drive Backup: If you connect Google Drive, we copy receipt files you upload to the Services into folders our application creates in your own Google Drive. See Section 6 for details.
Business Transfers
If Futureproof is involved in a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Legal Requirements
We may disclose information to:
- Comply with legal obligations (subpoenas, court orders)
- Protect our rights, property, and safety
- Prevent fraud or security threats
- Enforce our Terms of Service
With Your Consent
We may share information in other contexts with your explicit consent.
5. Bank Connections and Financial Data
How Bank Connections Work
The Services allow you to connect bank accounts and credit cards through third-party financial data aggregation services (primarily Plaid Technologies, Inc.).
When you connect an account:
- You authorize us and our service providers to access your transaction data
- We receive transaction details, account balances, and account information
- We do not store your banking login credentials—these are handled securely by third-party providers
- The connection is governed by both our Privacy Policy and the third-party provider's privacy policy
Third-Party Privacy Policies:
Please review Plaid's privacy policy to understand how your credentials and data are handled.
When You Disconnect a Bank Account
What Stops:
- Automatic import of new transactions from that account
- Access to the account through the third-party service
What Remains:
- Historical transaction data previously imported
- Your categorizations and modifications
- Financial records and reports that include data from that account
Why We Retain Historical Data:
- Accurate bookkeeping requires complete historical records
- Tax reporting may require prior period transaction data
- Financial statements need historical comparisons
- Legal and regulatory requirements may mandate retention
Deleting Historical Bank Data
To delete historical transaction data from a disconnected account, email privacy@runfutureproof.com with a deletion request. We will inform you of the implications—including gaps in financial records and potential tax compliance issues—before processing.
Important: Deletion is permanent and cannot be undone.
6. Google User Data
The Services offer optional integrations with Google Ads and Google Drive. This section describes how we handle data received from Google APIs when you connect these integrations. Futureproof's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What Google Data We Access
- Google Ads: If you connect Google Ads, we access your campaign spend and performance metrics (such as cost, impressions, clicks, and conversions) on a read-only basis. We do not modify your Ads account.
- Google Drive: If you connect Google Drive, we use the
drive.filescope, which limits our access to files and folders created through Futureproof. We access file metadata only for the folders our application creates. We cannot see, open, or modify any other files in your Google Drive. - Account identity: We receive the email address of the Google account you connect, so we can identify and manage the connection.
How We Use Google Data
- Google Ads data is used solely to display advertising spend in your financial reports, cash forecasts, and budget-vs-actual analysis.
- Google Drive is used solely to back up receipt files uploaded through the Services to folders our application creates in your Drive.
We do not use Google user data for advertising, and we do not use it for any purpose other than providing and improving these user-facing features.
Who We Share Google Data With
We do not transfer or sell Google user data to any third party, including data brokers or advertisers. Google user data is processed only on our secured infrastructure by service providers acting on our behalf to operate the Services (see Section 4), as necessary for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
How We Protect Google Data
- Google user data is encrypted in transit and at rest.
- Access is restricted to authenticated users within your organization.
- OAuth refresh tokens are stored encrypted at rest and are never exposed to other users or third parties.
Retention and Deletion of Google Data
You can disconnect a Google integration at any time in Settings → Integrations, or revoke Futureproof's access from your Google Account security settings. When you disconnect, we stop accessing your Google account and delete the stored OAuth tokens for that connection. Data previously synced into your Futureproof account (such as Ads spend already reflected in your financial reports) is retained as part of your financial records, consistent with Section 11, unless you request deletion by emailing privacy@runfutureproof.com. Upon deletion of your account, all of your data, including Google-sourced data, is permanently deleted except where retention is required by law.
7. Data Room and Document Sharing
How the Data Room Works
The data room feature allows you to securely share pitch decks, financial statements, and other documents with investors, advisors, and stakeholders.
You Control Access:
- You decide what to share and with whom
- You set permissions for each recipient
- You can revoke access at any time
Our Role:
- We provide the technical infrastructure and security
- We don't monitor, review, or access documents you share with recipients
- We may provide analytics on document views and engagement
AI Knowledge Base: If you create an AI Knowledge Base room and place documents in it, you direct our Services (including the AI service providers listed in Section 4) to process those documents so your agents can reference them. Knowledge Base rooms are internal-only and cannot be shared externally.
When You Delete or Revoke Access:
- Documents are removed from our platform
- Recipients who previously downloaded documents may still have copies
- We are not responsible for how recipients use or retain documents they've accessed
8. Third-Party Access
You may grant access to your Account to accountants, bookkeepers, tax preparers, or other financial professionals.
When you grant access:
- Third-Party Users can view and use data according to the permissions you set
- They must comply with our Terms of Service
- You are responsible for managing their access and permissions
We don't:
- Have direct relationships with Third-Party Users
- Verify their credentials or qualifications
- Monitor their use of your data
You should:
- Only grant access to trusted professionals
- Revoke access when no longer needed
- Review permissions regularly
9. Cookies and Tracking Technologies
We use cookies, pixels, web beacons, and similar technologies to:
- Remember your preferences and settings
- Understand how you use our Services
- Improve performance and user experience
- Provide security features
- Analyze usage patterns
Types of Cookies We Use:
- Essential Cookies: Required for the Services to function (e.g., authentication, security).
- Analytics Cookies: Help us understand how you interact with our Services (e.g., Google Analytics).
- Preference Cookies: Remember your settings and choices.
Your Choices:
Browser Settings: Most browsers allow you to control cookies through settings. Note that blocking essential cookies may prevent use of some features.
Opt-Out Tools:
- Google Analytics Opt-out
- Industry opt-out tools at aboutads.info and networkadvertising.org
Your Privacy Choices:
Cookie Preferences: You can review and change your cookie choices for our website at any time through our cookie preferences panel. Visitors in regions that require opt-in consent are asked before any non-essential cookies are set.
Global Privacy Control: We recognize and honor the Global Privacy Control (GPC) browser signal. If your browser or a browser extension sends a GPC signal, we automatically treat it as a valid request to opt out of the sale or sharing of your personal information for that browser — no further action is required from you, and advertising cookies remain off even if you otherwise accept cookies. Learn how to enable GPC at globalprivacycontrol.org.
10. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest.
- Access Controls: Limited employee access based on role and need.
- Authentication: Secure login with optional two-factor authentication.
- Monitoring: Regular security audits and vulnerability assessments.
- Secure Infrastructure: Data hosted in SOC 2 compliant data centers.
However, no system is completely secure. We cannot guarantee absolute security and are not liable for unauthorized access or security incidents beyond our reasonable control.
Your Responsibility:
- Use strong, unique passwords
- Enable two-factor authentication when available
- Keep login credentials confidential
- Notify us immediately of suspected security incidents
Security Incidents
If we determine that a security incident has affected your personal information, we will notify you without unreasonable delay consistent with applicable law, describe what happened and what data was involved, and tell you what we are doing and what you can do. We will also notify regulators and partners where required by law or contract.
11. Data Retention and Deletion
During Active Use
We retain your data for as long as your Account is active and as necessary to provide the Services.
After Disconnecting Bank Accounts
When you disconnect a bank account, we retain historical transaction data as part of your bookkeeping records unless you request deletion.
After Disconnecting Other Integrations
When you disconnect a CRM, HRIS, sales channel, ad account, or accounting integration, we stop importing new data but retain historical data previously imported for bookkeeping, forecasting, and reporting purposes unless you request deletion.
After Account Cancellation
First 30 Days:
- You can log in and export your data (CSV, Excel, PDF)
- Full access to all features for data retrieval
Immediately Upon Cancellation:
- Data room documents deleted
- Cap table details deleted
- Access credentials deleted
After 30 Days:
- You lose access to your data through our platform
- De-identified transaction patterns retained to improve the Services
- Specific financial details and identifying information not retained
Within 90 Days:
- Identifiable transaction data deleted
- Only de-identified, aggregated patterns remain
Note on Timing: 90 days is an outer limit, not a target; in practice we delete sooner. Copies in disaster-recovery backups are removed on our backup rotation schedule and may persist somewhat longer.
Legal and Regulatory Retention
We may retain limited data beyond the schedule above where required by:
- Legal process (subpoenas, court orders, pending or reasonably anticipated litigation)
- Anti-money laundering and fraud prevention laws
- Records we are separately required to keep, such as the consent records our bank connection provider requires us to retain
- Our own business and tax records, such as the invoices we issued to you and the payments we received
To be clear about whose records are whose: the bookkeeping records you build in Futureproof are yours, and any obligation to retain them for tax or audit purposes rests with you, not with us. We do not keep them on your behalf after you leave. Our own tax records are a separate and much smaller set.
Beta Features
Data created using Beta Features may be lost, corrupted, or deleted if features are modified or discontinued. You are responsible for backing up important data from Beta Features.
Our Commitment
While we strive to meet the timelines outlined above, actual deletion may vary based on technical and operational constraints, backup procedures, and system architecture. We will always comply with applicable legal retention requirements and data protection regulations.
12. Your Privacy Rights
Depending on your location, you may have the following rights:
Access and Portability:
- Request a copy of your personal data
- Export financial data in common formats (available directly in the Services)
Correction:
- Request correction of inaccurate data
- Update account information directly in settings
Deletion:
- Request deletion of your data (subject to legal retention requirements)
- See Section 11 for deletion timelines and processes
Restriction and Objection:
- Object to certain data processing activities
- Restrict how we process your data in certain circumstances
Withdraw Consent:
- Withdraw consent for marketing communications or other optional data uses
How to Exercise Your Rights
Email privacy@runfutureproof.com with your request. Include:
- Your name and Account email
- The specific right you're exercising
- Any relevant details
We will typically respond within 30 days (or as required by applicable law). We may need to verify your identity before processing certain requests. Response times may vary based on the complexity of the request and volume of requests received.
California Residents (CCPA)
Under the California Consumer Privacy Act, you have additional rights:
- Right to Know: What personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out of Sale or Sharing: We do not sell personal information for money. To the extent our use of advertising and analytics cookies is considered “sharing” under the CCPA, you can opt out at any time through our cookie preferences panel, or automatically via the Global Privacy Control browser signal, which we honor (see Section 9)
- Right to Limit Use of Sensitive Personal Information: Some information we handle — financial account numbers together with access credentials, and taxpayer identification numbers that are Social Security numbers — is “sensitive personal information” under California law. We use it only to perform the Services you asked for, to keep the Services secure, and to meet legal obligations. We do not use or disclose it to infer characteristics about you, so the right to limit does not restrict any additional use. If our practices change, we will say so here and offer the choice
- Right to Non-Discrimination: We won't discriminate against you for exercising your privacy rights
Availability of the Services
The Services are offered to businesses located in the United States. We do not currently offer the Services in the European Economic Area, the United Kingdom, or Switzerland.
13. International Data Transfers
Futureproof is based in the United States, the Services are offered to businesses located in the United States, and your information is processed in the United States. If you access the Services from outside the U.S., you consent to the transfer of your information to the United States.
14. Children's Privacy
Our Services are not intended for individuals under 18 years old. We do not knowingly collect personal information from minors under 18.
If we become aware that we have collected data from a person under 18, we will take steps to delete it promptly. If you believe we have collected information from a minor, please contact privacy@runfutureproof.com.
15. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors.
When We Make Changes:
- We will update the “Last Updated” date at the top
- For material changes, we will make reasonable efforts to notify you by email or prominent notice on the Services
- Changes become effective when posted unless otherwise specified
Your Continued Use: Your continued use of the Services after changes become effective means you accept the updated Privacy Policy.
Review Regularly: We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
16. Contact Us
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us:
Futureproof Ops, Inc.
644 Holly Springs Rd, STE 80
Holly Springs, NC 27540, USA
Email: privacy@runfutureproof.com