Legal
Privacy Policy
Effective 2026-08-25. The short version: your client's financial data never reaches us, and this page lists — exhaustively — the small amount that does.
1. Summary
- Statements, transactions, balances, account numbers and conservatee names never leave your device. They are processed in your browser and stored on your computer. We could not produce them if compelled, because we never receive them.
- We hold your account email, minimal case metadata, and purchase records.
- The app sends no telemetry. No analytics, no usage events, no crash reports, no opt-in ping.
- This marketing site sets no cookies at all.
- We do not sell or share personal information, under any definition, including the CCPA/CPRA definitions.
2. Who we are
FiduKit operates fidukit.com and app.fidukit.com and is the controller of the personal information described here. Contact: [email protected].
3. What we collect
| Category | What exactly | Why | Legal basis |
|---|---|---|---|
| Account | Email address; sign-in timestamps | Authentication; restoring your purchase on another computer | Contract |
| Case metadata | A case label you choose and an accounting due date | Deadline reminder emails you asked for | Contract |
| Purchases | Purchase and refund records, entitlement status | Unlocking downloads; accounting and tax records | Contract; legal obligation |
| Support | Emails you send us and our replies | Answering you; improving statement-format coverage | Legitimate interests |
| Server logs | IP address, user agent, request path, timestamp | Security, abuse prevention, debugging | Legitimate interests |
| Site analytics | Aggregate page-view counts (Cloudflare Web Analytics — cookieless, no cross-site tracking, no device fingerprint used for advertising) | Knowing which pages are read | Legitimate interests |
A case label is a label. If you name a case "Alvarez, second accounting", we hold that string and a date. We do not hold the statements, the transactions, the amounts, or anything else about the conservatee.
4. What we never collect
Bank and brokerage statements. Transactions. Amounts. Balances. Account numbers. Conservatee names and personal details. Generated packets. Working papers. Project files. These are processed entirely on your device and are never transmitted to us — not in encrypted form, not in aggregate, not for "improving the product". This is enforced by the application's architecture and by a Content-Security-Policy that gives client-side code nowhere to send data, and it is verified by an automated test that fails our build if any network request occurs while an accounting is being processed. See Privacy & security for how to confirm it yourself.
5. No telemetry in the application
The application ships with zero analytics and zero error reporting. There is no opt-in usage ping, no counter, no measurement endpoint. Errors are surfaced to you in the interface and logged only to your own browser console. Parse failures reach us only if you choose to email support about one.
6. Cookies
This marketing site sets no cookies. The application sets a single strictly-necessary session cookie once you sign in, so you stay signed in. It is not used for analytics, advertising, or tracking, and it never travels to a third party.
7. Service providers
| Provider | Role | What they see |
|---|---|---|
| Cloudflare | Hosting, CDN, cookieless site analytics | Request metadata; aggregate page views |
| Polar | Merchant of record for payments | Your email and payment details. Never any case or statement data. |
| Resend | Transactional email (sign-in links, deadline reminders, receipts) | Your email address and the message content — which contains a case label and a date, nothing more. |
We do not use advertising networks, data brokers, or third-party session-recording tools.
8. How long we keep things
| Data | Retention |
|---|---|
| Account and case metadata | While your account is open. Deleted within 30 days of account deletion. |
| Purchase and refund records | 7 years, as tax and accounting records require. Reduced to the minimum needed for that purpose after account deletion. |
| Support email attachments | Deleted when the ticket is resolved. |
| Support email threads | 12 months. |
| Server logs | 30 days. |
| Site analytics | Aggregate counts only; no per-visitor record exists to retain. |
| Your accounting data | Not applicable — we never have it. It lives on your device until you delete it. |
9. Your rights
California residents have the right under the CCPA/CPRA to know what personal information we collect, to access and delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined, and we have never done so. Residents of other jurisdictions with comparable laws (including the GDPR's rights of access, rectification, erasure, restriction, portability and objection) may exercise the same rights.
Exercise any of them by emailing [email protected] from your account address. We respond within 30 days. Account deletion is also available in the product without contacting anyone.
Note the useful consequence of the architecture: a request to delete "everything you have about my client" is already satisfied, permanently, because we never had it.
10. Children
FiduKit is a professional tool and is not directed to anyone under 18. We do not knowingly collect information from children.
11. International transfers
Our infrastructure is operated by providers with global networks; account and purchase data may be processed in the United States. Because the sensitive data never leaves your device, the cross-border exposure is limited to the small categories listed in section 3.
12. Security and incident response
We apply a strict Content-Security-Policy, transport encryption, least-privilege access, and automated checks that would fail our build if the zero-egress property regressed. If a security incident affects the data we hold, we notify affected users promptly and describe exactly what was involved. Report a vulnerability to [email protected].
13. Changes
Changes are posted here with a new effective date; material changes are also emailed to account holders. We will never quietly relax the "your data never leaves your device" commitment — a change to that would be an announced, deliberate change of product, and we do not intend to make one.