Last updated: July 2026
See Security & trust for a plain-language summary, including how encryption actually works here.
Account information (name, email), the client, engagement, document, and billing data your firm enters, and connection tokens for integrations you explicitly enable (QuickBooks Online, Xero, SmartVault, Stripe, firm email). SMS follow-ups and AI drafting need no connection token from you — they run through FirmLync's own Twilio and Anthropic accounts once you turn them on.
Every firm's data is scoped by row-level security policies enforced in the database itself — not just application code — so one firm can never query another firm's records, and a client portal login can only ever see that one client's own record, never another client's or the firm's other clients.
Used for every firm, by default:
Used only if your firm turns the feature on:
We don't sell data or share it for advertising, and don't use your data to train AI models.
Data is retained for as long as your firm's account is active. On cancellation, data remains available for 30 days for export or reactivation, after which it's deleted. You can request earlier deletion at any time by contacting us.
You can export your client list at any time, disconnect any integration or cancel your subscription from Settings, and request full account deletion by contacting us. If your firm needs a signed Data Processing Agreement, email us before signing up.