Privacy policy
Effective 2026-09-27 · firmary.app
Scope
This policy explains how Firmary, LLC (“Firmary”, “we”) handles information collected through this website, early-access requests, the Firmary practice platform (including its client portal), integrations you connect to it, AI assistants you connect to it, and Firmary transactional text messaging. Firmary is a pre-launch practice platform for accounting firms.
Accounting firms use Firmary to work with their own clients. For client information a firm stores in Firmary, the firm decides what is collected and why, and Firmary processes that information on the firm’s behalf and under its instructions. If you are a client of a firm, please contact that firm first about your information; we will help the firm respond.
Information we collect
Early access. If you request early access, we collect the email address you submit, the form and page you used, how you reached our site (for example a search engine, a link, or a campaign tag), how many times you visited before joining, the kind of device you used, and your approximate location (country, region, and city) and network provider, derived from your connection. We don’t store your IP address with your request. If you choose to answer our optional questions, we also collect details about your firm and your role.
Accounts. For firm staff and firm clients who use the platform, we collect name, email address, phone number where provided, firm membership and role, and sign-in and multi-factor authentication records.
Firm content. Information a firm or its clients put into Firmary, such as client records, documents and uploads, messages, requests, tasks, workflows, engagement and signature records, and invoices and payment status. Payment card details are handled by our payment processor and never reach Firmary.
Connected services. If you connect another service (for example Google, a calendar, cloud storage, or accounting software), we receive the account identifier and the data that service shares for the features you turn on. Google user data is described in its own section below.
Text messaging. If you enroll in Firmary text messaging, we collect your mobile phone number, your consent and opt-out records, and information associated with message delivery, such as delivery status and opt-out status.
Security and service logs. When you use the website or platform, we and our hosting providers process request information such as IP address, browser details, timestamps, and error reports to deliver, secure, and troubleshoot the service.
Website analytics. On firmary.app we use PostHog and Google Analytics to understand how visitors use the site: the pages you view, clicks and scrolling, page speed, and (in PostHog) recordings of page interactions in which every form field is hidden. Analytics are linked to random identifiers stored in first-party cookies on firmary.app, and to your early-access record if you join. PostHog discards IP addresses after estimating location. If your browser sends Global Privacy Control or Do Not Track, or is set to a European time zone, we measure visits without storing anything on your device and don’t record sessions.
Advertising. For visitors in the United States, firmary.app uses advertising tags from Google, LinkedIn, Meta, Reddit, and X to measure our ads and to show them to people who have visited our site. These companies may receive your browser and device details, the pages you visit on firmary.app, and whether you joined the waitlist. They don’t receive your email address from these tags. Under some state laws this counts as “sharing” personal information for advertising. You can turn it off with “Your privacy choices” at the bottom of every page, and we treat a Global Privacy Control signal as that choice. Advertising tags run only on firmary.app, never inside the Firmary platform or a client portal.
Bot protection. Our signup form uses Cloudflare Turnstile to tell people from automated abuse. See Cloudflare’s Turnstile privacy addendum.
How we use information
We use information to provide, secure, and support Firmary: to run the features a firm and its users choose, authenticate users, enforce each firm’s access rules, send notifications and messages users request, keep audit records, prevent abuse, troubleshoot problems, and meet legal obligations.
We use an early-access email address to manage the request and send an invitation when access is ready. We do not add it to an advertising list.
We use website analytics to understand and improve firmary.app, and advertising tags to measure our own ads and show them to people in the United States who have visited the site.
We use mobile information to send account and workflow notifications, customer-support messages, security alerts, and one-time verification codes that you have requested or authorized. Message frequency varies based on account activity.
We do not sell personal information, use firm or client content for advertising, or use it to train generalized AI or machine-learning models.
Google user data
If you choose to connect a Google account, Firmary requests only the access needed for the features you turn on: Gmail (reading message details and content, and sending messages you ask Firmary to send), Google Calendar (reading and managing events), Google Drive (storing and retrieving firm documents in the Drive you connect), and your Google email address to identify the connected account.
We use Google user data only to provide and improve those user-facing features: showing and filing client correspondence in Firmary, sending messages you request, scheduling, and storing documents. We do not sell Google user data, use it for advertising, or transfer it to others except as needed to provide these features, for security, or to comply with law. People at Firmary do not read Google user data unless you give us permission for a specific message, it is needed for security or abuse investigation, or the law requires it.
Firmary’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Firmary does not use Google Workspace user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
You can disconnect Google at any time in Firmary’s integration settings. Disconnecting revokes Firmary’s access with Google and deletes the stored access credentials. You can also remove access from your Google account permissions.
AI features and AI assistant connections
Connecting an assistant. A firm user can connect an AI assistant, such as Claude or ChatGPT, to Firmary. Before anything is shared, the user signs in to Firmary and approves the exact access on a consent screen. The assistant can then reach only the data and actions that user approved, within the limits their firm sets. Firm administrators can see, limit, suspend, and revoke every connected assistant, and actions taken through one are recorded in the firm’s audit log.
Firmary sends an assistant only the results of the requests it makes on the user’s behalf. Firmary does not receive or store your conversations with the assistant. Information you share with an assistant is handled by that provider under its own terms and privacy policy.
AI inside Firmary. Some Firmary features, such as preparing documents for signature, may send the relevant content to an AI model provider to perform that task. Providers act as our service providers under terms that do not allow them to train their models on that content, and we send only what the feature needs.
Messaging disclosure
Text Messaging and Mobile Information
Firmary may provide mobile information to service providers that help us operate the messaging service, including communications platforms such as Twilio and mobile carriers. These providers may use the information only to deliver and support Firmary’s messaging services.
We do not sell mobile information. We do not share mobile phone numbers, SMS consent records, or opt-in information with third parties or affiliates for their own marketing or promotional purposes.
You may withdraw your consent at any time by replying STOP. Reply HELP for assistance or contact support@firmary.app. Message and data rates may apply, and message frequency varies based on account activity.
How we share information
We share information only with service providers that help us run Firmary, under contracts that limit their use to providing their service to us: Amazon Web Services (platform hosting and storage in the United States), Cloudflare (website hosting, bot protection, and early-access submissions), PostHog (website analytics), Google (website analytics and advertising), LinkedIn, Meta, Reddit, and X (advertising on firmary.app for visitors in the United States), Loops (early-access email), Twilio and mobile carriers (text messaging), Resend (email delivery), Stripe (payments), Sentry (error reporting), and AI model providers for the features described above.
Within a firm, information is shared with the people and connected apps the firm authorizes. We also share information with services you or your firm choose to connect, when required by law or to protect rights and safety, or as part of a merger or acquisition subject to this policy.
How we protect information
We treat firm content, client records, financial and tax information, account credentials, and data from connected services, including Google user data, as sensitive, and protect it with these safeguards:
- Encryption in transit. All connections use TLS 1.2 or higher; plain HTTP is redirected to HTTPS.
- Encryption at rest. Databases, document storage, and backups are encrypted with keys managed in AWS Key Management Service.
- Protected credentials. Access tokens for connected services, including Google, are additionally encrypted with AES-256-GCM before storage, and are never shown to users or written to logs.
- Firm isolation and least privilege. Every request is checked on the server against the requesting firm and the person’s specific permissions before any data is read. Access by Firmary personnel is limited to what is needed to operate and support the service.
- Strong sign-in. Multi-factor authentication is required for firm owners and administrators and available to everyone; sign-in is rate-limited.
- Audit and monitoring. Sensitive actions are recorded in an append-only audit log, and systems are monitored for errors and abuse.
- Safe uploads. Uploaded files are scanned for malware before anyone can download them.
No system is perfectly secure. If we learn of a breach affecting your information, we will notify affected firms and people as required by law. See our security overview for more.
Retention and deletion
We keep firm content while the firm’s account is active and as the firm directs. Deleted items may remain recoverable for a short period before they are permanently removed. When a firm leaves Firmary, it can export its data, after which we delete it, except audit records, which we keep for up to seven years for security and compliance. Data from a connected service is deleted or stops updating when you disconnect it. We keep early-access and messaging consent records only as long as reasonably needed to provide the service, document consent and opt-out choices, comply with law, and resolve disputes. We keep website analytics for up to seven years.
Your choices and rights
You may ask to access, correct, export, or delete your information, or ask a privacy question, by writing to support@firmary.app. If your information is held by a firm you work with, we will route the request to that firm. You can disconnect integrations and AI assistants at any time, and stop Firmary text messages by replying STOP. You can turn off analytics and advertising tags on firmary.app under “Your privacy choices” at the bottom of every page, and we honor Global Privacy Control. Firmary is intended for businesses and their clients and is not directed to children under 13.
Changes and contact
Material changes to this policy will be dated on this page. Firmary, LLC is responsible for this policy; contact us at support@firmary.app.