Effective Date: September 9, 2026
FIDGARD, Inc. ("FIDGARD," "we," "us," or "our") is committed to protecting the privacy of our users and the confidentiality of client trust accounting data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
This policy applies to all users of the FIDGARD platform, including law firm administrators, attorneys, and staff members. Given the sensitive nature of legal trust accounting data, we hold ourselves to the highest standards of data protection.
When you create an account, we collect:
In the course of using the Service, you may enter or upload:
This data belongs to you. We process it solely to provide the Service and do not use it for any other purpose.
If you connect a bank account through Plaid, we receive:
We store Plaid access tokens in encrypted form. We do not store your bank login credentials. Plaid's handling of your data is governed by Plaid's End User Privacy Policy.
If you connect QuickBooks Online, we access:
QBO OAuth tokens are stored encrypted. We post accounting records created in FIDGARD when you initiate a sync or as configured in your settings. Supporting reads enable account mapping and posting verification.
Two kinds of AI processing occur. Both send data to OpenAI's API, and we want you to know exactly what leaves our infrastructure.
Document extraction. When you upload a document — or one arrives at your firm's intake inbox — we first read any embedded text layer on our own infrastructure. No third party receives the file at that step. We then send rendered images of the document pages to OpenAI, together with the extracted text, so the model can read amounts, dates, payees and account details in their original layout. Scanned and image-only pages are transcribed the same way. This means the page image itself — the bank statement, the closing statement, the check — is transmitted to OpenAI.
AI assistance over your trust records. Ask the Books, Trust Review explanations and Smart Inbox send trust accounting records to OpenAI. Ask the Books runs your question against your books and sends the results — including ledger entry descriptions and memos, client and matter names, payee names, dates and amounts. Reconciliation matching is not in this list: it is rule-based and deterministic by design, so it reaches no third party.
Applying to both:
store=false parameter, which keeps the prompt and response out of the stored history OpenAI would otherwise make retrievable, and OpenAI's API data usage policy states that API inputs are not used to train their models. That is not the same as OpenAI holding nothing: OpenAI ordinarily retains API inputs and outputs for up to 30 days for abuse and misuse monitoring, then deletes them. Thirty days is the usual limit rather than a guaranteed one. OpenAI may hold data beyond it where the law requires, where retention is needed to protect OpenAI's services or third parties, or where its systems flag content — images and uploaded files included — for manual human review. Treat 30 days as the normal case and longer as possible in those situations.AWS Textract is supported in our software as an alternative OCR provider but is not enabled on our production service; OCR is performed by OpenAI. If we change providers we will update this policy.
If your firm's obligations do not permit client documents or matter data to be sent to OpenAI, contact us before uploading documents or enabling AI features.
We automatically collect:
Subscription payments are processed by Stripe. We do not store credit card numbers or bank account details for payments. Stripe collects and processes payment information under Stripe's Privacy Policy. We receive only a Stripe customer ID and subscription status.
We use your information to:
We do not:
We share your data only with the following categories of recipients, and only as necessary to provide the Service:
| Subprocessor | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting, file storage (S3), transactional email (SES) | All platform data (encrypted at rest) |
| Plaid Inc. | Bank account connection and transaction feeds | Bank credentials (via Plaid Link), account/transaction data |
| Intuit (QuickBooks Online) | Accounting sync | Trust account transactions, chart of accounts |
| OpenAI | Document extraction (OCR and structured extraction) and AI assistance (Ask the Books, Trust Review explanations, Smart Inbox) | Rendered document page images and document text; client and matter names, ledger descriptions and memos, payees, dates and amounts (sent with store=false; not used for model training; retained by OpenAI up to 30 days for abuse monitoring, and longer where law requires or flagged content is held for manual review — see §2.5) |
| Stripe | Subscription billing | Email, organization name, payment method (handled by Stripe) |
| SendGrid / Amazon SES | Transactional email delivery | Email address, email content |
| Datadog | Application monitoring and error tracking | System logs (PII redacted), performance metrics |
We may also share information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of FIDGARD, our users, or the public.
We implement multiple layers of security to protect your data:
Trust accounting records are subject to professional responsibility rules that typically require retention for 5 or more years after the end of representation. Our retention practices reflect this:
We do not automatically purge trust accounting records. If you need records deleted, contact us and we will work with you to balance your request against applicable retention obligations.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@fidgard.com. We will respond within 30 days.
Note: Certain trust accounting data may not be deletable if retention is required by professional responsibility rules or applicable law. We will explain any such limitations in our response to your request.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
The Service is intended for use by legal professionals and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us immediately.
We use the following cookies and similar technologies:
csrf_token, a random value your browser sends back on state-changing requests so we can reject forged ones. It is readable by JavaScript on our own pages, because the application must echo it as a request header, and it lasts up to seven days. Strictly necessary for the Service to operate securely.Both cookies above are strictly necessary. We use no advertising, analytics or attribution cookies, and no third-party advertising or analytics tags. Because we set no optional storage, there is nothing to consent to and the Service presents no cookie choice banner.
We do not sell personal information, and we do not track you across other websites.
The Service is hosted in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
For users in the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms where required by GDPR.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before the changes take effect. Corrections that make an existing practice described more accurately — without changing what we do with your data — take effect when published, since delaying them would only leave a less accurate description in place. The "Effective Date" at the top of this page indicates when the policy was last revised.
If you have questions about this Privacy Policy or our data practices, contact us at:
FIDGARD, Inc.
Privacy inquiries: privacy@fidgard.com
General support: staff@fidgard.com
© 2026 FIDGARD, Inc.. All rights reserved.