1. Introduction
The official FIDGARD application privacy policy, including optional ChatGPT and Claude connection disclosures, is available at app.fidgard.com/privacy. This page also describes the public marketing website’s practices.
FIDGARD Inc. (“FIDGARD,” “we,” “us,” or “our”) is committed to protecting the privacy of our users and the confidentiality of client trust-accounting data. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and the choices and rights available regarding personal information.
This Policy applies to the FIDGARD website, application, and related services used by law-firm administrators, attorneys, staff members, and other authorized users.
2. Information We Collect
2.1 Account Information
We may collect your name, work email address, organization name, role, timezone, authentication information, and other details needed to create and administer your account.
2.2 Trust-Accounting Data
To provide the Service, we may process trust-account identifiers, client and matter names, client-ledger records, deposits, checks, electronic-payment records when enabled, payee information, reconciliation data, reports, audit records, and uploaded source documents. This data belongs to your organization and is processed to provide the Service.
2.3 Bank Data Through Plaid
If you connect a bank account through Plaid, we may receive linked-account identifiers, balances, and posted or pending transaction data. We do not receive or store your bank login credentials. Plaid access tokens are stored in encrypted form.
2.4 QuickBooks Online Data
If you connect QuickBooks Online, FIDGARD posts accounting records created in FIDGARD to your connected QuickBooks company. To support account mapping and reliable posting, we access company information, the chart of accounts, linked-account balances, and previously posted records used to verify exports and prevent duplicates. QuickBooks OAuth tokens are stored in encrypted form.
2.5 Documents and Records Processed With AI
FIDGARD uses OpenAI’s API for document extraction and AI assistance over trust records. For uploaded documents and documents received through a firm’s intake inbox, FIDGARD can send rendered page images and extracted text to OpenAI. This includes visible names, signatures, bank details, dates and amounts. Reading a PDF’s embedded text happens on FIDGARD’s infrastructure; OCR and AI extraction can send content to the provider. Users must review the resulting draft against the source document before approval.
Structured document extraction applies best-effort masking of Social Security numbers, dates of birth, driver’s licence numbers and passport numbers in its text input. This is not a guarantee that all sensitive data is removed. Page images are not redacted, and the workflow does not provide general redaction of bank account and routing details. Smart Inbox and Ask the Books can send stored text without this masking, including client and matter names, descriptions, memos, payees, dates and amounts. Trust Review explanations also send supporting trust-record information.
These API calls set store=false. That setting does not mean OpenAI retains nothing. OpenAI’s published API policy says data is not used for model training unless the customer opts in, and describes abuse-monitoring retention and applicable exceptions. See OpenAI’s API data controls. This is separate from the optional ChatGPT and Claude connections described below.
The configured production OCR path uses OpenAI. The software also supports AWS Textract as an alternative or fallback for text recognition; when that path is used, AWS receives document images for OCR. FIDGARD stores uploaded source documents in its own Amazon S3 storage. Contact us before enabling AI workflows if your firm’s obligations restrict sending client information to these providers.
2.5A Optional ChatGPT and Claude Connections
Where the FIDGARD connection is available in your ChatGPT or Claude account, you may choose to connect it. You sign in to FIDGARD and select the firms the connection may read. FIDGARD checks your current role, firm access and connection grant on read requests. The public connection can find selected firms, list their trust accounts, return account setup and balance information, and look up recorded checks and historical withdrawals with their clearing evidence. It cannot create or change accounting records, import a workbook, connect a bank or initiate a payment.
Depending on the request and account setup state, information returned to the service you choose can include firm, trust-account, client and matter names and identifiers; bank names; book and client-ledger balances; opening and cutover status, amounts and related dates; deposit and outstanding-check details, descriptions, memos and references; bank-statement filenames and document identifiers; setup completion information; and bank connection status, balances and timestamps already held by FIDGARD. This may include confidential client information. Bank information is labeled cached, stale or unavailable. The account setup read makes no live bank request, and a FIDGARD book balance is not necessarily a current bank balance.
Check lookup may also return payee and client names, check and reference numbers, dates, amounts allocated to client ledgers, recorded check and clearing status, clearing dates or other stored evidence, and identifiers linking allocations of a combined check. Historical withdrawals whose payment method is unknown are labeled separately. Check-clearing results reflect records held by FIDGARD; the lookup does not contact a bank and is not a live bank confirmation.
The receiving service handles information under its own account settings and terms. FIDGARD does not control whether information already returned remains in a conversation or how that service retains or uses it. The store=false setting used for FIDGARD’s separate OpenAI API processing does not establish your ChatGPT account’s data-handling settings and does not apply to Claude.
Without optional renewable access, a FIDGARD connection lasts no more than ten minutes and also ends if the originating browser session expires or is revoked. Where renewable access is offered and you explicitly choose it during authorization, the read-only connection can last up to seven days from that authorization, including after your browser sign-in expires. It does not disconnect merely because it is unused. Use and background credential renewal do not extend the original seven-day deadline. Access tokens still last no more than ten minutes; the connected service can renew them only while the connection remains valid. Renewal does not add firms or permissions, and existing connections do not gain renewable access automatically.
When you open FIDGARD during the final 24 hours of a valid renewable connection, the dashboard and Settings can show an expiry reminder. Keep connected opens instructions; it does not extend access. Complete a new authorization in the connected service and review the selected firms to start a new connection. The reminder is shown in FIDGARD, not promised as a notification from ChatGPT or Claude. Without new authorization, access ends at the original deadline.
Use FIDGARD Settings → Connected apps to review or revoke a connection. Revocation or expiry stops subsequent reads through that grant. Password changes, explicit revocation of the originating browser session, account security invalidation, loss of required firm access or archival of a selected firm can also stop access earlier. Passive browser-session expiry alone does not end an explicitly renewable connection. Disconnecting in ChatGPT or Claude is a separate action and may not immediately revoke a still-active FIDGARD grant. Expiry or revocation does not delete information already returned to the other service or change accounting records.
2.6 Usage, Attribution, and Billing Information
We may collect login events, IP address, browser and device information, feature usage, support interactions, referral source, UTM parameters, and advertising click identifiers where consent is required. Stripe processes subscription payment information. FIDGARD receives subscription, invoice, and limited billing details needed to administer your account; we do not store full payment-card numbers.
3. How We Use Information
- Provide trust-accounting, reconciliation, reporting, document, and connected-account features.
- Authenticate users, manage permissions, and protect the Service.
- Process subscriptions and communicate about accounts, support, security, and service changes.
- Diagnose problems, improve reliability, and understand feature usage.
- Measure advertising and referrals where permitted by your consent choices.
- Comply with law, protect rights, and enforce our agreements.
We do not sell client trust-accounting data, use uploaded trust documents for advertising, share one customer’s data with another customer, or use customer documents to train general-purpose AI models.
4. Service Providers and Subprocessors
We share data with the service providers listed below as necessary to provide FIDGARD. If you separately choose to connect ChatGPT or Claude, the information returned to that service is described in section 2.5A. That user-directed connection is distinct from FIDGARD’s OpenAI API processing listed in the table.
| Provider | Purpose | Information involved |
|---|---|---|
| Amazon Web Services | Infrastructure and file storage; OCR when the alternative Textract path is used | Platform data stored or processed to provide the Service, including uploaded documents |
| Plaid Inc. | Bank-account connection, balances, and transaction feeds | Connection data entered through Plaid Link, account identifiers, balances, and transaction data |
| Intuit, Inc. | Posting FIDGARD records to QuickBooks Online | Company and account-mapping information, linked-account balances, and records involved in posting and verification |
| OpenAI | Document extraction and AI assistance over trust records | Rendered document page images and extracted text; client and matter names, ledger descriptions and memos, payees, dates and amounts. API calls set store=false; see section 2.5 for limitations. |
| Stripe | Subscription billing | Email, organization information, subscription details, and payment information handled directly by Stripe |
| Email and monitoring providers | Transactional email, service monitoring, and error investigation | Email addresses, message content, operational logs, and performance data as needed |
| OpenAI Ads | Advertising conversion measurement, subject to your privacy choices | Browser and referral identifiers, successful demo-request signals, and securely hashed contact information where detected |
| Google Ads | Advertising conversion measurement through Google Consent Mode | Basic website and conversion signals; advertising identifiers only if separately enabled |
We may also disclose information if required by law, legal process, or a valid governmental request, or when reasonably necessary to protect the Service, our users, or others.
5. Security
FIDGARD uses administrative, technical, and organizational safeguards designed to protect information. These include encryption in transit and at rest, encrypted storage of integration tokens, role-based access, organization-level isolation, audit and activity logging, and protected transaction-history controls. No system is completely secure, and users remain responsible for safeguarding their credentials and devices.
6. Retention and Data Export
We retain customer data while an account is active and for a limited period after cancellation to support export, legal obligations, dispute resolution, and applicable professional recordkeeping requirements. Exact retention periods may vary by data type. Organizations may request an export or contact us about deletion, subject to contractual, legal, security, and recordkeeping obligations.
7. Your Choices and Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing of, or obtain a portable copy of personal information. Authorized organization administrators may also manage user access and request exports. Contact privacy@fidgard.com to submit a request.
8. Cookies and Advertising Measurement
The public marketing website loads a Google Ads tag with advertising and analytics storage denied. It sends basic cookieless measurement signals and records a conversion only after a demo request is successfully submitted. Our conversion event does not include the name, firm, email address, practice area, or other demo-form fields. Enhanced conversions are not enabled.
In the current configuration, the Google Ads tag does not set optional advertising or analytics cookies. Google may receive the page URL, referring page, browser and device information, IP address, and advertising click parameters that remain in the page URL. These signals are used to measure and model advertising performance.
The public marketing website automatically initializes the OpenAI Measurement Pixel on pages with a demo form, unless you have turned it off below or your browser sends Global Privacy Control or Do Not Track. No advertising checkbox is required to submit the form. The Pixel uses browser cookies and advertising referral identifiers to measure successful demo requests. Automatic advanced matching, when enabled, may detect supported contact information and hash it in your browser before sending it to OpenAI. Our event payload contains only the fact that a demo request succeeded and a randomly generated event identifier; it does not include trust-account records, financial documents, or demo-form text. Events are marked to opt out of future user-level personalization. Turning measurement off stops future events and asks the Pixel to remove its measurement cookies. We store your choice in this browser. You can still request a demo with measurement turned off.
Advertising measurement choices apply to this browser.
The FIDGARD application uses authentication and security cookies:
- Authentication cookies: HttpOnly cookies maintain signed-in sessions, including a separate partner session where applicable.
- Security cookie: the JavaScript-readable
csrf_tokencookie helps verify requests that change data. It has a maximum age of seven days and may be refreshed during use.
The application also uses browser storage for product functions, including your display preference and cached account information. Its current interface does not provide an advertising or analytics cookie-choice control, and it does not capture a first-touch advertising attribution cookie or load advertising or analytics tags. These application practices are separate from any public marketing-site measurement described in this policy.
9. Children and International Processing
The Service is intended for legal professionals and is not directed to children. FIDGARD operates in the United States. Information accessed from another country may be transferred to and processed in the United States using appropriate safeguards where required.
10. Changes and Contact
We may update this Policy to reflect changes in the Service, law, or our practices. We will provide notice of material changes as required.
FIDGARD Inc.
2333 56th Drive
Brooklyn, NY 11234
Privacy: privacy@fidgard.com
Support: staff@fidgard.com
© 2026 FIDGARD Inc. All rights reserved.