Privacy Policy
Effective date: September 21, 2026
This Privacy Policy explains how Amolfi, Inc. collects, uses, shares, retains, and protects information when you use the website, public pages, app, integrations, AI features, and support channels.
1. Information we collect
Amolfi collects information directly from you, automatically through your use of the platform, and from third parties when you or your workspace authorize an integration.
1.1 Account, authentication, and profile information
When you create or use an Amolfi account, we collect information such as name, email address, authentication identifiers, sign-in provider details, organization membership, role, profile settings, and workspace preferences. Authentication currently uses Firebase Authentication and may support Google Sign-In or other sign-in methods.
1.2 Workspace and operations data
We collect the information you and your users create, import, sync, upload, or receive in a workspace. This can include clients, contacts, leads, projects, tasks, forms, intake responses, finance records, quotes, invoices, budgets, retainers, receipts, connected-account metadata, knowledge documents, files, approvals, contracts, calendar records, email records, social planning data, automations, AI conversations, audit logs, and public client-surface submissions.
1.3 AI prompts, outputs, and tool context
When you use AI-assisted features, Amolfi may process prompts, outputs, workspace context, selected records, tool results, citations, review decisions, and related metadata. AI features may use providers such as Anthropic, OpenAI, or AWS AI services depending on the feature. We process this information to provide AI assistance, maintain safety controls, create work receipts, debug errors, and improve product quality.
1.4 Financial and bank data through Plaid
When you connect a bank or financial account through Plaid, Amolfi receives the information you authorize Plaid to share for the enabled financial workflows. Depending on the connection and feature, this may include institution metadata, account names, masked account numbers, account type, balances, transactions, transaction metadata, connection status, and consent or revocation records. Amolfi does not receive or store your bank login credentials.
1.5 Payment, billing, and metered-usage data
We use Stripe for Amolfi's own subscription billing, for members and add-ons, and for Crown purchases. You enter card details on Stripe's own pages, not Amolfi's, and Amolfi never receives or stores a full card number or CVV code. Amolfi may receive billing contact details, customer identifiers, subscription status, invoice metadata, payment status, plan information, tax information, card brand, and last four digits. Amolfi does not currently provide Stripe Connect or process payments on invoices issued from customer workspaces.
Stripe also gives Amolfi a fingerprint of the card — an identifier that stands for the card without being the card number. Amolfi uses it for one purpose only: stopping the same card from taking repeated trials or from working around purchase limits. For the same purpose, and no other, Amolfi derives a normalized form of your email address so that one trial and one pre-purchase workspace can be counted per person. Neither is used for marketing, profiling, or advertising.
Amolfi records the metered usage a workspace is billed on: the work it runs, how much storage it holds, and the size of the files you download or share, which is counted against your plan's monthly download amount. Plan usage itself is measured in a weekly window, and Amolfi records when that window started for your workspace. Metering records the size, time, and workspace of a transfer, not the contents of the file.
Where Amolfi gives a workspace a promotional usage reset, it keeps a record of it as part of the billing history: which workspace it was for, who gave it and who used it, the reason written with it, when it expires, and whether it was used, revoked or left to expire. A reset addressed to a workspace is addressed by the owner's email address or by the workspace's identifier, and the reason is written by Amolfi rather than collected from you.
1.6 Optional integrations
If your workspace uses an available third-party connection, we process the information required for that workflow. Currently available workflows use Plaid for bank connections, BoldSign for document signing, and Ayrshare with supported social platforms for social publishing. QuickBooks and Xero are supported through manual CSV exports rather than live connected accounts. Other services process workspace data only when a specific connection is enabled for your workspace, and availability may change as integrations are added or retired.
1.7 Website, device, and usage information
We collect technical and usage information such as IP address, browser type, device type, operating system, approximate region, referring page, pages and features used, timestamps, event logs, error reports, performance information, and security signals. We use this information to operate, secure, debug, measure, and improve Amolfi.
1.8 Communications and support
If you contact Amolfi, submit a form, request support, join a waitlist, schedule a call, respond to an email, or otherwise communicate with us, we collect your contact details and the content of that communication. If you opt into product or marketing updates, we retain the information needed to send and manage those communications until you unsubscribe or request deletion.
1.9 Text messaging
When you opt in to the Amolfi text messaging program, we use your mobile number to send phone verification codes, customer-care replies, and workspace messages you request. Message frequency varies. Message and data rates may apply. Consent to text messaging is optional and is not a condition of purchase. Reply HELP for help or STOP to opt out. You can also contact support@amolfi.com for help.
Mobile information and opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes. Service providers may process this information only to deliver and support the messaging service.
2. How we use information
Amolfi uses information for the purposes below.
- Provide the service. Create and manage accounts, operate workspaces, display and sync records, run workflows, deliver AI assistance, process files, support public links, send transactional messages, and connect authorized third-party services.
- Secure Amolfi. Authenticate users, enforce permissions, maintain audit logs, detect suspicious activity, prevent abuse, protect tenant boundaries, and investigate security incidents.
- Support customers. Respond to questions, debug problems, manage onboarding, troubleshoot integrations, and communicate about service, billing, security, or product changes.
- Process Amolfi billing and subscriptions. Manage Amolfi plan charges, subscription invoices, renewals, tax, account status, failed payments, refunds, and billing communications.
- Improve the platform. Measure feature use, diagnose errors, evaluate performance, develop new features, and improve reliability. We may use aggregated or de-identified information for product and business analysis.
- Comply with law and enforce agreements. Meet tax, accounting, security, privacy, payment, abuse-prevention, and legal obligations, respond to lawful requests, and enforce Amolfi agreements.
What we do not do
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising.
- We do not use third-party advertising trackers on Amolfi's product surfaces.
- We do not use workspace data to advertise to your clients or end customers.
3. Plaid and financial connections
Amolfi integrates with Plaid Inc. to support customer-authorized financial connections.
3.1 How the connection works
When you choose to connect a financial account, Amolfi presents Plaid Link, which is operated by Plaid. You enter credentials into Plaid's interface, not Amolfi. Plaid returns a scoped token to Amolfi after a successful authorization, and Amolfi stores sensitive Plaid tokens server-side.
3.2 What Amolfi receives
Amolfi receives only the data authorized through the Plaid consent flow and required for the enabled financial features. This may include institution details, account metadata, masked account identifiers, balances, transactions, transaction descriptions, dates, categories, and connection status. We do not receive full bank account credentials or bank login passwords.
3.3 Consent, revocation, and audit records
Amolfi records consent and revocation events for security, audit, and support purposes. Workspace members with finance management permission can revoke a Plaid connection under Finance › Accounts & import. When a connection is revoked, Amolfi calls Plaid's removal endpoint where applicable, deletes the stored access token, and marks the connection and its linked accounts revoked so no further data is retrieved through that connection. Financial records already imported into your workspace ledger remain workspace business records; you can request their deletion using the contact route in this policy.
3.4 Plaid's privacy practices
Plaid separately processes information you provide directly to Plaid. Plaid's privacy practices are described in Plaid's End User Privacy Policy at plaid.com/legal/end-user-privacy-policy.
5. Data retention and deletion
We keep information only as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law, security, audit, billing, backup, tax, dispute, or abuse-prevention needs.
- Workspace and account data is generally retained while the workspace or account is active. Closing a workspace does not itself schedule automatic deletion from primary systems. To request deletion of a closed workspace, contact security@amolfi.com. We verify identity and workspace authority, determine the scope of the request, and process it subject to applicable legal, security, audit, billing, tax, dispute, backup, and contractual retention requirements.
- Stored files in a workspace with no plan are deleted automatically. A workspace that has had no active paid plan for 90 consecutive days has its stored files deleted, and a workspace that never bought a plan becomes read-only 30 days after it is created and has its stored files deleted 90 days after it is created. Billing records, receipts, and audit records are retained on the separate schedules in this section. The Terms of Service state the same two clocks.
- Plaid-sourced consumer financial data stops being retrieved after authorization is revoked and the stored access token is deleted. Financial records already imported into your workspace ledger remain workspace business records and are handled through the same verified deletion-request process described above.
- Plaid consent, revocation, and security audit records may be retained for up to 7 years where needed for legal, audit, security, or compliance purposes.
- Application audit logs may be retained for up to 7 years where needed for security, abuse prevention, compliance, or internal review.
- Operational logs in Amolfi's production AWS application data spine are configured for six months. Logs held by other providers may follow their applicable operational schedules, and logs may be retained longer when required for incident response, investigation, security, or law.
- Backups rotate on operational schedules. Deletion from backups may lag primary-system deletion until the relevant backup expires.
- Marketing communications data is retained until you unsubscribe or request deletion, except for suppression records needed to honor opt-outs.
To request deletion, export, correction, or access, contact security@amolfi.com. We may need to verify your identity or workspace authority before acting on a request.
6. Your privacy rights
Depending on where you live and how you use Amolfi, you may have rights to request access to your information, correction, deletion, portability, restriction, objection, withdrawal of consent, or more information about how personal information is collected, used, retained, disclosed, or shared.
California residents may have rights under the CCPA/CPRA, including the rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and non-discrimination for exercising privacy rights. Amolfi does not sell personal information or share it for cross-context behavioral advertising.
Individuals in the European Economic Area, United Kingdom, or similar jurisdictions may have rights under applicable data-protection laws, including access, correction, deletion, portability, restriction, objection, and complaint rights with a supervisory authority. Where Amolfi relies on consent, you may withdraw that consent at any time.
To make a request, email security@amolfi.com. We will verify and respond within the timeline required by applicable law. If your information is controlled by a customer workspace, we may direct the request to that customer or assist the customer in responding.
7. Security
Amolfi uses administrative, technical, and organizational safeguards designed to protect customer data. Controls include workspace membership checks, role-based access, server-side action handlers, signed bridge requests, encrypted storage where supported by infrastructure providers, secret management, audit logs, least-privilege access patterns, rate limits, and review gates for higher-risk AI and automation workflows.
No online service can guarantee perfect security. You are responsible for protecting credentials, using appropriate access controls, reviewing workspace membership, managing connected services, and notifying us promptly about suspected compromise.
Report security or privacy concerns to security@amolfi.com.
9. Children
Amolfi is a business operations platform and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to Amolfi, contact security@amolfi.com.
10. International data transfers
Amolfi is based in the United States, and information may be processed in the United States and other countries where Amolfi or its service providers operate. Those countries may have data-protection laws that differ from the laws where you live. Where required, Amolfi uses appropriate transfer safeguards.
11. Changes to this policy
We may update this Privacy Policy as Amolfi, our vendors, or legal requirements change. When we make material changes, we will update the effective date and provide notice where required or appropriate. The version and date above identify the current public policy.
12. Contact us
For privacy, deletion, export, access, correction, or security requests, contact:
If your request relates to a workspace controlled by an Amolfi customer, include enough information for us to identify the relevant workspace and account.