Privacy Policy
Phirise, Inc. Privacy Policy - How we collect, use, protect, and govern information
Last updated: May 29, 2026
Introduction
Phirise, Inc. ("Company") is committed to protecting your privacy, your business records, and your agency over how your data is used. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website and applications (collectively, the "Service"), including AI-powered features, operating reviews, proof profiles, documents and businesses, connected-data features, usage-based credits, and paid subscriptions. By accessing or using the Service, you acknowledge the practices described in this Privacy Policy. Where applicable law requires consent for a specific practice, we will request that consent separately. Legal Basis for Processing (GDPR): Where GDPR applies, we process your personal data on the following legal bases: - Contract Performance: Processing necessary to provide the Service you requested (e.g., account management, AI outputs, payments, connected-data analysis, proof generation, and business collaboration). - Consent: Where you have given explicit consent (e.g., connecting financial accounts via Plaid, enabling optional data contribution features, receiving marketing communications, or participating in a Proof Rewards program). - Legitimate Interests: Processing necessary for our legitimate business interests (e.g., security, fraud prevention, service reliability, product diagnostics, customer support, and analytics using aggregated or de-identified information), where those interests are not overridden by your rights. - Legal Obligation: Processing necessary to comply with applicable laws and regulations (e.g., tax reporting, responding to lawful government requests, retention obligations, and breach notification duties).
I. Information We Collect
We collect information you provide directly and information collected automatically when you use the Service. This may include: - Account and Profile Information: name, email address, password (stored via our authentication provider), profile photo (if provided), business/business details, roles, and settings. - Payment and Billing Information: subscription status, invoices, credit purchases, and limited billing metadata. Payment card information is processed by our payment processor (e.g., Stripe) and is not stored by Company. - Connected Financial Data: If you choose to connect a bank account or financial institution through Plaid or another integration, we collect account balances, transaction history, masked account numbers, institution names, account holder information where provided, and related financial data. This data is collected with your explicit authorization through the connection flow and is used for the permissible purposes disclosed at the time of connection, such as operating reviews, cash-flow context, revenue verification, proof generation, and connected-account features. - User Content: content you upload or submit to the Service, including documents, prompts, messages, proof records, files, field observations, stakeholder updates, and related metadata. - Audio and Voice Data (if you use voice features): transcripts and, where enabled, audio snippets or recordings needed to provide voice features. - Usage and Device Data: log data, device identifiers, IP address, browser type, pages viewed, feature usage, credit usage, token usage estimates, diagnostics, security events, and audit records. - Optional Contribution Data: if you opt into a Proof Rewards, consent-to-intelligence, research, or contribution program, we may process the specific redacted proof pattern, observation, evaluation example, or feedback described in that consent flow. Please do not submit sensitive personal information (e.g., Social Security numbers, driver's license numbers, payment card numbers, health information, or protected community-sensitive knowledge) into prompts or documents unless explicitly required for your intended use and you have the right to do so.
Financial Data Collection and Intelligence
When you connect your bank account, payment processor, accounting system, or other financial institution through Plaid or another integration: Consent and Authorization: You explicitly authorize us to access your financial data for the specific purposes disclosed during the connection process, including operating review, cash-flow context, revenue verification, proof generation, connected metrics, and account-management features. Data Collected: We may collect bank account information, transaction history (including dates, amounts, merchant names, and categories), account balances, account holder information, institution details, and related integration metadata. Purpose and Usage (Not a Lender or CRA): Phirise provides operating review, proof, financial context, and business-intelligence features. We are not a lender, broker, bank, financial institution, credit repair organization, or Consumer Reporting Agency under the Fair Credit Reporting Act. We use financial data to provide the Service to you, not to issue credit, make lending decisions, or provide consumer reports. Data Security: Financial data is transmitted through our partners' encrypted connections and stored using industry-standard encryption and strict access controls. Sensitive integration tokens are stored using protected secret-management infrastructure. Model Training: We do not use identifiable financial data for shared model training, external datasets, resale, or licensing unless you explicitly opt in through a separate consent flow. Data Retention: Financial data is retained for as long as reasonably necessary to provide the connected feature, comply with legal obligations, resolve disputes, maintain audit records, and enforce our agreements. See our Data Retention and Disposal Policy for more detail. Your Rights: You may revoke access to connected financial accounts at any time by disconnecting accounts in your settings or through the relevant integration provider. Revoking access may affect our ability to provide connected financial analysis, proof, or operating-review features. Third-Party Services: Financial integration partners such as Plaid and Stripe are third-party service providers. Their processing of your data is governed by their respective privacy policies and agreements.
Information Collected via Technology
We (and our service providers) may automatically collect certain information when you use the Service, including through cookies and similar technologies. This may include device and browser information, IP address, referring URLs, and usage data. We use cookies and similar technologies to (a) keep you signed in, (b) remember preferences, (c) enable core functionality, and (d) understand usage to improve the Service. We do not use cookies for third-party advertising or remarketing. You can control cookies through your browser settings, but disabling cookies may affect Service functionality. Cookie Consent: Where required by applicable law (including GDPR for EU/EEA users), we obtain your consent before placing non-essential cookies on your device. You may manage your cookie preferences at any time through our cookie settings or your browser settings. For more information about our use of cookies, you may contact us at support@phirise.com.
Information from Account Registration
When you create an account, we collect the information you provide (such as your email address and profile details). If you subscribe to a paid plan, we also associate your account with billing and subscription information from our payment processor.
Children's Privacy
The Site and Service are not directed to anyone under age 13. We do not knowingly collect information from anyone under 13, or allow anyone under 13 to sign up. If we learn we have gathered personal information from anyone under 13 without parental consent, we will delete that information immediately. If you believe we have collected such information, contact us at support@phirise.com.
II. How We Use and Share Information
How we use information: We use information to provide, maintain, secure, personalize, and improve the Service, including to authenticate users, process payments, allocate and track credits, respond to support requests, generate AI Outputs, maintain proof and operating records, prevent abuse and fraud, enforce our Terms, comply with legal obligations, and evaluate service reliability and quality. AI Processing: When you use AI features, we may send the minimum reasonably relevant prompts, context, files, outputs, and metadata to contracted AI providers to generate Outputs or provide requested features. We do not provide your identifiable User Content to third-party AI model providers for those providers to train their own models. No Shared Model Training by Default: We do not use identifiable User Content, financial data, private conversations, source documents, proof records, field observations, or business records to train or fine-tune general-purpose models shared across customers unless you explicitly opt in through a separate consent flow. Optional Contributions: If you choose to participate in a Proof Rewards, consent-to-intelligence, research, or contribution program, the relevant consent flow will describe what data is contributed, whether it is redacted or de-identified, how it may be used, what benefit you receive, retention and revocation limits, and any forbidden uses. How we share information: We may disclose information to: - Service Providers and Processors that help us operate the Service (e.g., hosting, storage, analytics, monitoring, customer support, payment processors, financial-data providers, email providers, and AI model providers acting on our behalf). - Legal and Safety recipients if required by law, legal process, or to protect the rights, safety, and security of Company, users, or others. - Business Transfer recipients in connection with a merger, acquisition, financing, corporate reorganization, or sale of assets, subject to applicable law and this Privacy Policy. No ads or sale: We do not show third-party ads, run remarketing, sell personal information for money, or share personal information for cross-context behavioral advertising. If we engage in data practices that constitute a "sale" or "sharing" under applicable law in the future, we will provide required disclosures and opt-out mechanisms. Sub-Processors: A current list of our sub-processors is available at /sub-processors. We evaluate sub-processors for appropriate security and data protection measures and require them to process data only as instructed by us.
Non-Personal Information Use
We may use aggregated or de-identified information to operate, secure, debug, understand, and improve the Service, develop new features, measure product quality, create internal benchmarks, and analyze usage trends. Where required by law, we will maintain and use de-identified information in de-identified form and will not attempt to re-identify it. This use is not a blanket permission to repurpose private customer records. Aggregated or de-identified operational analytics may support product improvement, but identifiable User Content, financial data, conversations, source documents, proof records, field observations, and business records are not used for shared model training, external datasets, resale, or licensing without explicit opt-in. Examples of permitted operational use include: - Measuring whether a proof workflow completed successfully - Detecting stale or unsupported proof claims at an aggregate level - Tracking latency, error rates, and feature usage - Improving redaction, caveat detection, and overclaim-prevention workflows - Building internal evaluation cases where the required consent and redaction controls are present Optional partner datasets or public/common-good contribution programs require a separate consent and governance process.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your Personal Information may be among transferred assets. You acknowledge and consent that such transfers may occur and any acquirer may continue to process your Personal Information as set forth in this Privacy Policy. If our information practices change, we will post policy changes on the Site so you may opt out of new practices.
III. How We Protect Information
We implement administrative, technical, and organizational safeguards designed to protect information. However, no security measures are perfect, and we cannot guarantee absolute security. Data Retention and Disposal: We retain information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, maintain security and audit records, and enforce our agreements. Retention periods vary depending on the type of data, the purpose for which it was collected, legal requirements, and user deletion choices. Illustrative retention periods include: - Account Information: retained for the duration of your account relationship, then retained only as reasonably necessary for legal, security, fraud-prevention, tax, accounting, dispute, and audit purposes. - Connected Financial Data: retained while the connected feature is active or as needed for the purpose disclosed at collection, then retained only as required or reasonably necessary for legal, audit, dispute, security, and compliance purposes. - Transaction and Billing Records: retained for tax, accounting, audit, and dispute purposes, generally up to 7 years where applicable. - User Content: retained until you delete it or close your account, subject to recovery windows, backups, legal holds, and lawful retention obligations. - Security and Audit Logs: retained according to log category and compliance need; security, authentication, and audit logs may be retained longer where needed for security investigations, abuse prevention, and compliance. Data Disposal: When retention periods expire or deletion is required, we delete, de-identify, anonymize, or otherwise dispose of data using methods appropriate for the system involved. In cloud-managed environments, this may include logical deletion, database purging, lifecycle-based backup expiration, cryptographic erasure where supported, and deletion instructions to processors where applicable. Security Incident Response: In the event of a confirmed data breach affecting your personal information, we will notify affected users and applicable regulatory authorities as required by law. Notification will be provided without unreasonable delay and will include legally required information about the incident, the types of data involved, steps we are taking, and recommended protective actions where appropriate. Third-Party Security: We evaluate and contractually require third-party service providers to maintain appropriate security measures. No provider can guarantee perfect security, and their independent services are governed by their own terms, privacy policies, and security commitments. Your Security Responsibilities: You play an important role in protecting your data. We strongly recommend that you use a strong, unique password; enable multi-factor authentication when available; keep devices and software updated; promptly report suspicious activity to support@phirise.com; and revoke access to connected integrations you no longer use. International Data Transfers: The Service is operated from the United States. If you are located outside the United States, your personal data may be transferred to and processed in the United States and other countries where our service providers operate. Where required, we rely on Standard Contractual Clauses, UK transfer mechanisms, data processing agreements, and other lawful transfer safeguards.
IV. Your Rights Regarding Personal Information
Marketing communications: You can opt out of marketing emails by using the unsubscribe link in those emails. We may still send transactional or administrative messages (e.g., account, security, billing, service, or policy updates). California privacy rights: California residents may have rights under the CCPA/CPRA, including the right to know, delete, correct, limit certain uses of sensitive personal information, opt out of sale or sharing, and non-discrimination for exercising privacy rights. We do not sell personal information for money or share personal information for cross-context behavioral advertising. How to exercise rights: Contact support@phirise.com. We may need to verify your identity before responding. If you use an authorized agent, we may request proof of authorization as required by law. Model Training and Contribution Controls: We do not use identifiable User Content, financial data, private conversations, source documents, proof records, field observations, or business records for shared model training, external datasets, resale, or licensing unless you explicitly opt in through a separate consent flow. If you participate in an optional contribution program, you may review the applicable consent terms, available revocation choices, and reward terms in that flow or by contacting us. European Economic Area (EEA) and UK Residents — GDPR Rights: If you are located in the EEA or UK, you may have the following rights under data protection law: - Right of Access: You may request a copy of the personal data we hold about you. - Right to Rectification: You may request correction of inaccurate or incomplete personal data. - Right to Erasure: You may request deletion of your personal data, subject to legal retention requirements and exceptions. - Right to Restriction of Processing: You may request that we limit how we process your data in certain circumstances. - Right to Data Portability: You may request your personal data in a structured, commonly used, machine-readable format. - Right to Object: You may object to processing based on legitimate interests, including certain profiling. You may also object to direct marketing at any time. - Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. - Right to Lodge a Complaint: You may lodge a complaint with your local data protection supervisory authority if you believe our processing violates applicable law. To exercise any of these rights, contact us at support@phirise.com. We will respond within the timeframe required by applicable law.
V. Links to Other Websites
We may provide links to or compatibility with other websites or applications, but we are not responsible for their privacy practices or content. This Privacy Policy applies solely to information collected through our Site and Service. When you access third-party sites via our Service, their privacy policies apply. We encourage users to read privacy statements of other websites before using them.
VI. Changes to Our Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email, in-app notice, or prominent posting). Where applicable law requires consent for a new processing purpose, we will request that consent separately.
VII. Contact Us
If you have questions about this Privacy Policy, want to exercise privacy rights, or need to contact our Data Protection Officer, you may reach us at: Data Protection Officer / Privacy Lead Phirise, Inc. 2261 Market Street STE 86584 San Francisco, California 94114 Email: support@phirise.com Telephone: (618) 591-2361 For information about how long we retain your data, see our Data Retention and Disposal Policy, available at /data-retention or upon request at support@phirise.com. For EEA/UK residents: If you are not satisfied with our response to a privacy request, you have the right to lodge a complaint with your local data protection supervisory authority.
Questions about our privacy practices?
Contact our privacy team