Privacy Policy
Pilot-ready privacy summary for FinFile's current mortgage workflow. Legal review remains outstanding before broad commercial launch.
What we collect
FinFile collects account information for brokerage users, application workflow data, applicant and mortgage-file details entered by brokers, uploaded documents, generated documents, Compliance Check outputs, Red Flags, compliance notes, audit events, and support requests.
Applicant information is file data managed by the brokerage. Applicants do not need a FinFile platform account for the current mortgage pilot workflow.
How we use the data
We use the data to operate the broker workflow: document upload, OCR/extraction, broker review, form generation, e-signature routing, compliance review, audit history, support, and product reliability monitoring.
AI-assisted outputs are advisory workflow aids. Brokers and compliance users remain responsible for reviewing extracted fields, generated summaries, Red Flags, and documents before relying on them.
Where data is processed
Production deployments must use operator-approved storage, database, and AI/OCR services before real client financial data is accepted.
The deployment region is configurable and must be selected, documented, and pinned to satisfy the brokerage's applicable contractual and legal requirements.
Service providers
FinFile may use Supabase for authentication and database services, Azure Blob Storage for files, Azure AI Foundry for OCR and AI-assisted reasoning, Dropbox Sign for e-signature, Resend for transactional email, Upstash Redis for rate limiting, Vercel for hosting, and PostHog for product analytics and session replay.
PostHog must be configured with PII masking for production pilot use, and demo traffic should not be mixed into production analytics.
Retention and deletion
Raw upload retention is configurable by operators. Generated documents, audit logs, Compliance Checks, compliance notes, and current legacy audit binders may need to be retained for brokerage compliance and examination obligations. FinFile Examination Records are Planned and are not available in this pilot.
Deletion, export, and correction requests should be sent through the support channel so the brokerage and FinFile operator can determine the appropriate compliance-safe action.
Security and access
FinFile uses role-based access controls. Brokers see their own files, Compliance Officers see files for their brokerage, and administrative access is restricted to operational support.
Do not upload files unless you are authorized by the brokerage to process them in FinFile.
Questions or access requests? Use the support form or email hello@mortgagemate.ai, FinFile's transitional MortgageMate inbox.