Privacy Policy
Last updated: 9/14/2026
At FileFree, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application.
Information We Collect
Personal Information
When you create an account, we collect:
- Full name and email address
- Payment information (processed securely through third-party providers)
- Business information you choose to provide
Financial Data
You provide financial data including:
- Transaction records (income and expenses)
- Bank account connection information (encrypted)
- Financial calculations and saved reports
- Business documents and receipts you upload
Usage Information
We automatically collect:
- Device information (browser type, operating system)
- IP address and location data
- Usage patterns and feature interactions
- Log data and performance metrics
How We Use Your Information
- Provide and maintain our service
- Process your transactions and calculations
- Send you important updates and notifications
- Improve our application and develop new features
- Provide customer support
- Detect and prevent fraud or security issues
- Comply with legal obligations
Regulatory Compliance
FileFree is committed to full compliance with federal and state regulations governing financial data:
- Gramm-Leach-Bliley Act (GLBA): Full compliance with federal requirements for protecting consumer financial information, including administrative, technical, and physical safeguards
- SEC Regulations: Compliance with Securities and Exchange Commission requirements for financial record-keeping and data protection (if applicable to your business activities)
- SOX Compliance: Adherence to Sarbanes-Oxley Act requirements for financial data integrity and audit trails
- IRS Publication 1075: Compliance with federal tax information security guidelines and 7-year retention requirements
- FINRA Rules: Compliance with Financial Industry Regulatory Authority data protection standards (where applicable)
- Federal Trade Commission (FTC) Standards: Full adherence to FTC Safeguards Rule for customer information protection
- State-Level Compliance: Compliance with state data breach notification laws and financial privacy regulations
Critical Security Guarantees
What We NEVER Store:
- Credit Card Numbers: We never store, process, or have access to your credit card information. All payment processing is handled directly by Stripe, a PCI DSS Level 1 certified payment processor.
- Bank Login Credentials: Your bank usernames and passwords are NEVER transmitted to or stored on our servers. Bank connections use OAuth tokens managed by Plaid.
- CVV/CVC Codes: Card security codes are never stored or accessible to us.
- Full Account Numbers: We only store the last 4 digits of bank accounts for display purposes.
- Social Security Numbers: We do not collect or store SSNs or Tax ID numbers.
Data Security & Access Controls
We implement enterprise-grade security measures that meet or exceed federal standards:
- 256-bit SSL/TLS Encryption: All data transmission uses bank-level encryption (same standard as financial institutions)
- AES-256 Data Encryption: All stored data is encrypted using military-grade encryption at rest
- Row-Level Security (RLS): Database-level enforcement ensures users can ONLY access their own financial data - no other user's data is visible or accessible
- Zero-Knowledge Architecture: Financial data is encrypted with user-specific keys
- Multi-Factor Authentication: Available for enhanced account protection
- Regular Security Audits: Annual third-party penetration testing and vulnerability assessments
- Secure Cloud Infrastructure: Hosted on SOC 2 Type II certified infrastructure with 24/7 monitoring
- Access Logging: All data access is logged and monitored for regulatory compliance and security
- Automatic Session Timeout: Sessions expire after inactivity to prevent unauthorized access
Account Access Restrictions
Your data is ONLY accessible to you:
- Only the authenticated account holder can view or modify their financial data
- No other users, even within the same organization, can access your data without explicit permission
- Our staff has extremely limited access to user data, only for technical support when explicitly requested
- All staff access is logged, monitored, and subject to strict confidentiality agreements
- Administrative access requires multi-factor authentication and is audited quarterly
Bank Account Connections & Payment Security
Bank Account Integration
We use Plaid, a SOC 2 Type II certified and GLBA-compliant service, for secure bank connections:
- No Credential Storage: Your bank login credentials are NEVER transmitted to or stored on our servers - authentication happens directly between you and Plaid
- Read-Only Access: We can only view your transactions - we CANNOT move money, initiate transfers, or modify your accounts
- OAuth 2.0 Security: Bank connections use industry-standard OAuth tokens that can be revoked at any time
- Encryption: All bank data is encrypted both in transit (TLS 1.2+) and at rest (AES-256)
- Minimal Data Storage: We only store transaction descriptions, amounts, and dates - never full account numbers
- Instant Disconnection: You can disconnect any bank account instantly from your settings
- Federal Compliance: All bank integrations comply with federal Electronic Fund Transfer Act (EFTA) regulations
Payment Processing Security
We use Stripe, a PCI DSS Level 1 certified payment processor (the highest security standard):
- Zero Card Data Storage: Credit card numbers, CVV codes, and expiration dates NEVER touch our servers
- Direct Processing: Payment information goes directly from your browser to Stripe's secure servers
- PCI DSS Compliant: We maintain PCI compliance by never handling card data directly
- Tokenization: We only receive secure tokens from Stripe, never actual payment details
- 3D Secure: Additional authentication for enhanced fraud protection
- Fraud Detection: Stripe's machine learning monitors for suspicious transactions
Third-Party Services & Vendor Compliance
We carefully vet all third-party services to ensure they meet federal security and privacy standards:
- Stripe (Payment Processing): PCI DSS Level 1 certified, SOC 1 & SOC 2 certified. Your card details never touch our servers - Stripe processes all payment information directly with bank-level security.
- Plaid (Bank Connections): SOC 2 Type II certified, GLBA compliant, used by major financial institutions. Your bank credentials are NEVER stored by us or transmitted to our servers - Plaid uses OAuth for secure, read-only access.
- Base44 (Infrastructure & Hosting): SOC 2 Type II certified cloud platform with multi-region redundancy, 24/7 security monitoring, and automated backups. All data stored in secure, US-based data centers.
- Tawk.to (Support Chat): GDPR compliant chat service. Chat transcripts stored securely for quality assurance and regulatory compliance.
Vendor Security Requirements:
- All vendors must sign Data Processing Agreements (DPAs) ensuring GDPR and CCPA compliance
- Vendors undergo annual security reviews and compliance verification
- We monitor vendor security incidents and respond immediately to any concerns
- All vendors must maintain SOC 2 or equivalent security certifications
- Vendors are contractually prohibited from selling or sharing your data
Information Sharing
We do NOT sell your personal information. We may share your information with:
- Service Providers: The third-party services listed above to provide functionality
- Legal Requirements: When required by law, court order, or to protect our rights
- Business Transfers: In case of merger, acquisition, or asset sale (with notification)
- With Your Consent: When you explicitly authorize us to share
We require all third-party service providers to respect the security of your data and treat it in accordance with the law.
Your Privacy Rights
Depending on your location, you have the following rights:
- Right to Access: View and download all your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Deletion: Request permanent deletion of your account and data (via Settings page)
- Right to Data Portability: Export your data in machine-readable format (JSON)
- Right to Opt-Out: Unsubscribe from marketing emails (not transactional emails)
- Right to Withdraw Consent: Revoke cookie consent or other permissions at any time
- Right to Object: Object to data processing for marketing purposes
- Right to Restrict Processing: Request limited use of your data in certain circumstances
How to Exercise Your Rights:
- Export data: Go to Settings → Export Your Data
- Delete account: Go to Settings → Delete Account (danger zone)
- Update information: Go to Business Profile page
- Other requests: Email support@filefree.com
We will respond to all valid requests within 30 days. For security, we may ask you to verify your identity before processing certain requests.
Data Retention and Deletion Policy
We maintain a defined and enforced data retention policy in compliance with applicable data privacy laws. We retain your data for as long as your account is active or as needed to provide services. This policy is reviewed annually and updated as needed to ensure compliance with evolving regulations.
Retention Periods
- Account Information: Retained while your account is active, deleted within 30 days of account deletion
- Financial Records: Retained for 7 years after account deletion for legal and tax compliance (IRS requirements)
- Transaction Data: Retained for 7 years to comply with financial record-keeping regulations
- Support Communications: Retained for 3 years for quality assurance and dispute resolution
- Usage Analytics: Aggregated data may be retained indefinitely (anonymized, non-identifiable)
- Backup Data: May persist in backups for up to 90 days after deletion from production systems
Data Deletion Process
You have the right to request deletion of your personal data at any time:
- Automated Deletion: Use the "Delete Account" feature in Settings to permanently delete your account and all associated data
- Confirmation Required: For security, you must type "DELETE" to confirm permanent deletion
- 30-Day Processing: Non-financial data is deleted within 30 days of your request
- Legal Retention: Financial records are retained for 7 years as required by tax law, then automatically purged
- Manual Requests: Contact support@filefree.com for special deletion requests or questions
Policy Review and Updates
This data retention and deletion policy is reviewed annually (each January) to ensure compliance with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- IRS record-keeping requirements
- Other applicable federal and state regulations
Policy enforcement is automated through our application and monitored by our compliance team. You can request early deletion of your data by contacting support@filefree.com, though we may retain certain information where legally required.
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience:
- Essential Cookies: Required for authentication, security, and core functionality. Cannot be disabled.
- Functional Cookies: Remember your preferences and settings (e.g., cookie consent choice)
- Analytics Cookies: Help us understand how you use the app to improve features (anonymized data)
- Third-Party Cookies: Set by Stripe (payments), Plaid (banking), and Tawk.to (support chat)
Managing Cookies: You can control cookie preferences through:
- Our cookie consent banner (appears on first visit)
- Your browser settings (may affect functionality)
- Account Settings page to reset cookie preferences
Note: Disabling essential cookies will prevent you from using core features like login and transactions.
Children's Privacy (COPPA Compliance)
Our service is not intended for users under 18 years of age. We do not knowingly collect information from children under 18. If we become aware that a user is under 18, we will promptly delete their account and all associated data. If you believe a child has provided us with personal information, please contact us immediately at support@filefree.com.
International Data Transfers
Your data may be transferred to and processed in countries other than your own. These countries may have different data protection laws. When we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by regulatory authorities.
Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will notify you within 72 hours via email and through the application. The notification will include the nature of the breach, the data affected, and steps we're taking to address it.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated via email and a notice in the application at least 30 days before taking effect. The "Last Updated" date at the top indicates when changes were made. Your continued use after changes constitutes acceptance.
Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: support@filefree.com
Website: Contact Form
