Privacy Policy
How we protect your data and respect your privacy
Last updated: August 6, 2026
At Finch, we understand that privacy is fundamental to trust. This privacy policy explains how we collect, use, protect, and disclose information about you when you use our AI-powered reflection platform for coaches.
We take your privacy seriously. Our approach is built on transparency, minimal data collection, and strong encryption — especially for sensitive coaching data.
1. What Information We Collect
Account Information
When you sign up for Finch, we collect your name, email address, phone number (optional), and authentication credentials through Supabase Auth. We may also collect your organizational information if you're part of a coaching group or firm.
Coaching Data
The core of Finch is your coaching practice. We store:
- Client profiles (names, roles, coaching history, behavioral patterns)
- Session transcripts or notes (verbatim or summarized coaching conversations)
- AI analysis and reflections generated from those sessions
- Case notes, action items, and follow-up reminders
- Tags and organizational metadata for your practice management
Integration Data
To integrate with your existing tools, we collect and store:
- Google Calendar credentials (read-only access to your calendar for session scheduling)
- Granola API tokens (if you use Granola for transcript sync)
- Your Anthropic API key — only if you choose to connect your own key (encrypted, stored securely)
Usage Information
We automatically collect analytics about how you use Finch — pages visited, features used, interaction patterns — to improve the platform. We do not track individual session contents or client names in analytics.
Device Information
We collect standard web analytics: IP address, browser type, operating system, pages visited, and time spent on pages. This information helps us diagnose technical issues and understand platform usage.
2. How We Use Your Information
Core Service Delivery
We use your coaching data (transcripts, notes, client profiles) to generate AI-powered reflections and analysis. This is the core value of Finch — pre-session briefings, post-session analysis, and ongoing case synthesis.
Platform Improvement
We analyze usage patterns to improve the platform, identify bugs, optimize performance, and develop new features. We do this without looking at the actual content of your coaching sessions — we focus only on how the platform is used.
Communication
We use your email address to send you service notifications (password resets, billing updates, platform announcements), and optionally, product updates and educational content about coaching. You can opt out of non-essential emails at any time.
Account Management
We use your account information to authenticate you, manage your subscription, process billing, and support your account.
Legal & Safety
If required by law, we may use your information to comply with legal obligations, enforce our terms of service, or protect the rights and safety of Finch, our users, or the public.
3. How AI Processing Works
Finch generates its analysis through Anthropic's Claude API. By default, Finch handles this for you — you don't need to provide anything. Advanced users and agencies can optionally connect their own Anthropic API key.
Managed by default
Out of the box, Finch processes your requests using its own managed Anthropic API access. There's nothing for you to set up, and AI usage is included in your Finch plan.
Optional: bring your own key
In Settings, you can switch to your own Anthropic API key. When you do, your requests use your key and Anthropic bills you directly. We encrypt your key using AES-256-GCM before storing it, and never log or expose it in plaintext.
Your data goes to Anthropic
When you request AI analysis, your coaching data — tokenized by default to remove client identities (see Section 4) — is sent to Anthropic's Claude API. The specific data sent depends on your request (pre-session briefing, post-session analysis, etc.).
Review Anthropic's privacy policy
Data sent to Anthropic is subject to Anthropic's terms of service and privacy policy. See Anthropic's privacy policy for details.
4. Data Anonymization & PII Handling
Finch includes an anonymization system to protect personally identifiable information (PII) before data is sent to the AI. You can choose to anonymize client names, company names, and other sensitive details before requesting analysis.
When anonymization is enabled:
- Client names are replaced with placeholders (e.g., "Client A")
- Company names and specific locations are redacted
- Other identifiable details are masked or removed
- The anonymized data is sent to the AI for analysis
Anonymization is on by default for every account: identities are tokenized before analysis is requested, and Finch re-personalizes the results only on your screen. You can review or disable this in Settings → Privacy — you remain responsible for reviewing what data you share.
5. Data Encryption & Security
In-Transit Encryption
All data sent to and from Finch is encrypted using TLS 1.2 or higher. Your browser establishes a secure connection before any data is transmitted.
At-Rest Encryption
Sensitive data — API keys, session transcripts, client profiles — is encrypted at rest in our Supabase PostgreSQL database. We use AES-256-GCM encryption for API keys and other highly sensitive credentials.
Access Controls
Only you and your team members (if you've invited them) can access your data. Finch staff do not have access to your coaching data without explicit permission for support purposes.
Regular Security Updates
We keep dependencies up to date, perform regular security patches, and conduct periodic security reviews. We use industry-standard tools for vulnerability scanning.
Infrastructure Security
Finch is hosted on Vercel, which provides DDoS protection, firewalls, and infrastructure security. Our database is hosted on Supabase, which includes automated backups, encryption, and compliance certifications.
6. Data Retention
Active Accounts
We retain all your data (account information, coaching data, analysis) for as long as your account is active. You can review, export, or delete data at any time through your account settings.
After Account Deletion
When you delete your account, we permanently delete your coaching data, client profiles, and personal account information. Some anonymized usage analytics may be retained for up to 90 days to help us understand platform usage, but these cannot be linked to you.
Backups & Legal Holds
We maintain automated backups for disaster recovery. In rare cases, backup data may take up to 90 days to fully expire after deletion. If we receive a legal request to preserve data, we will retain information as required by law.
Email Communications
We retain transactional emails (password resets, billing confirmations) for account management purposes. You can request deletion of these records by contacting us.
7. Third-Party Services & Data Sharing
Finch uses several third-party services. Here's how your data flows through them:
Anthropic (Claude API)
When you request AI analysis, your coaching data (or anonymized version) is sent to Anthropic using your API key. Anthropic processes your data according to their privacy policy and terms of service. They do not use your data to train their models unless you explicitly opt in. See Anthropic's privacy policy.
OpenAI (Search Embeddings)
To let you search across a client's full history by meaning (not just keywords), we generate “embeddings” — numeric representations — of your session content using OpenAI's embeddings API. This content is tokenized first (client and other personal identities are removed and replaced with placeholders) before it is sent, so OpenAI does not receive real names. OpenAI does not use API data to train its models. See OpenAI's privacy policy.
Supabase (Database)
We use Supabase for authentication and data storage. Your account information and coaching data are stored in Supabase's PostgreSQL database. Supabase is SOC 2 certified and complies with GDPR and CCPA. See Supabase's privacy policy.
Vercel (Hosting)
Finch is deployed on Vercel. Vercel provides infrastructure, CDN, and hosting services. They collect standard hosting analytics (IP addresses, page views, uptime metrics). See Vercel's privacy policy.
Resend (Transactional Email)
We use Resend to send password resets, billing notifications, and platform announcements. Your email address is shared with Resend for these communications. Resend does not store your coaching data. See Resend's privacy policy.
Google Calendar (Integration)
If you enable Google Calendar integration, we request read-only access to your calendar to help you schedule sessions. We do not modify your calendar or store your calendar events. Google handles this data according to their privacy policy. See Google's privacy policy.
Granola (Transcript Sync)
If you use Granola for transcript sync, you provide Granola's API token to Finch. We store this token encrypted and use it only to import transcripts from Granola. We do not share your transcript data with Granola beyond what's needed for the sync. See Granola's privacy policy.
Important: We do not sell or rent your data to any third party. We do not use your coaching data for marketing or to train our own models. Data is shared only as necessary to deliver the Finch service.
8. Your Privacy Rights
If you're in the EU, California, or another jurisdiction with privacy laws, you have certain rights:
Right to Access
You have the right to access all personal data we hold about you. You can download your data through your account settings or request a data export by contacting us.
Right to Correction
You can correct, update, or modify your account information at any time through your settings.
Right to Deletion
You can delete your account and all associated data. We will permanently delete your information within 30 days of your request, except where we're required to retain it by law.
Right to Data Portability
You can request a copy of your data in a portable format (JSON, CSV). Contact us to request a data export.
Right to Opt Out
You can opt out of marketing emails, analytics, and non-essential communication at any time. Opting out will not affect your core service access.
Right to Object (GDPR)
If you're in the EU, you have the right to object to processing of your data for certain purposes. Contact us with your objection.
Exercising Your Rights
To exercise any of these rights, contact us at [email protected] with your request. We'll respond within 30 days.
9. Cookies & Tracking
Session Cookies
We use session cookies to keep you logged in and maintain your preferences. These cookies expire when you close your browser.
Persistent Cookies
We may use persistent cookies to remember your login preference and improve your experience. You can disable persistent cookies in your browser settings.
Analytics
We use minimal analytics (page views, feature usage) to understand how the platform is used and identify bugs. We do not track your individual coaching sessions or client data.
Third-Party Cookies
Our third-party integrations (Google, Granola) may set their own cookies. We recommend reviewing their privacy policies.
Opting Out
You can opt out of analytics by disabling cookies in your browser or requesting not to be tracked. This will not affect your ability to use Finch.
10. Children's Privacy
Finch is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will delete it immediately. If you believe we have collected information from a child under 13, please contact us at [email protected].
11. International Data Transfers
Finch is hosted in the United States (Vercel & Supabase). If you're accessing Finch from outside the US, your data will be transferred to and stored in the US. By using Finch, you consent to this transfer.
For EU users, we comply with GDPR requirements for international data transfers, including the use of Standard Contractual Clauses where applicable. Supabase, our data processor, is GDPR certified.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we'll notify you by email and update the "Last updated" date at the top of this page.
Your continued use of Finch after changes indicates your acceptance of the updated privacy policy. We encourage you to review this policy periodically.
13. Questions & Feedback
If you have questions about this privacy policy or our privacy practices, please contact us:
Website
finch.coach
Mailing Address
AADP LLC (operating Finch)
1401 Lavaca St PMB 40682
Austin, TX 78701
Data Protection Issues (EU)
If you believe your privacy rights have been violated, you have the right to lodge a complaint with your local data protection authority.
14. HIPAA Disclaimer
Important: Finch is not HIPAA-compliant and should not be used to store protected health information (PHI). If you are a covered entity or business associate under HIPAA, do not upload PHI to Finch. You are responsible for ensuring your use of the Service complies with all applicable healthcare privacy regulations.
Disclaimer: This privacy policy is provided for informational purposes. It is not legal advice. Privacy laws vary by jurisdiction, and your specific obligations may differ. If you have concerns about compliance with applicable privacy laws (GDPR, CCPA, HIPAA, etc.), please consult with your own legal counsel. Finch makes no representation about the completeness or accuracy of this policy for your specific situation.
Ready to use Finch safely?
We've built privacy into every layer of Finch. Request a walkthrough and see how we protect your coaching practice.
Request a walkthrough
