Privacy policy
How we handle your information, and how to reach us.
Effective and last updated: September 29, 20261. Who we are and what this policy covers
FORFI, Inc., a Delaware corporation in the United States ("FORFI", "we", "us"), operates FORFI Analytics. This policy covers the application at intelligence.forfi.ai and analytics.forfi.ai. We are responsible for the personal information described here. This policy covers this analytics application and related account and support communications. Other websites and services have their own policies.
FORFI Analytics provides research based on public bank and credit-union reports. You do not need to connect a bank account or provide customer financial records to use it.
2. Information we collect
- Account information: your email address, full name, organization, optional phone number, account identifier, and account creation, last successful sign-in, and email-verification records. We store a password hash, not your readable password.
- Workspace information: institutions you save, dashboard widgets, saved comparisons, research, scenarios, screening criteria, alert rules, and related preferences you choose to save.
- Support and feedback: your messages, contact details, the application page associated with feedback, browser information, and records needed to respond to your request.
- Usage analytics: the pages you view and the page that referred you, the links and buttons you click, a few named actions (such as opening a signal, starting or completing signup, and sending feedback), your browser and device type, screen size, and approximate location (country, region and city) derived from your IP address. Analytics does not record what you type into forms, and it is not linked to your account.
- Technical and security information: information needed to serve requests and protect the service, including IP addresses processed by our infrastructure, hashed rate-limit identifiers, session records, account-access status, administrative action records, browser information, errors, and email-delivery, bounce, and complaint records.
We receive information directly from you, through your use of the service, and from our hosting and email providers. Public regulatory datasets used for institution analytics are separate from your private account and workspace information. Please do not send passwords, verification links, bank customer records, account numbers, or other confidential financial information in support messages or saved research.
3. How we use information
We use information to create and authenticate accounts, verify email ownership, recover access, save and display your workspace, provide requested alerts and support, investigate problems, improve the service, prevent abuse, maintain backups, and meet applicable legal obligations. Our use of feedback and technical information helps us understand and resolve service problems.
Signup and password-reset messages are transactional. Creating an account does not subscribe you to a marketing mailing list. We do not use your account information to make automated credit, lending, employment, or eligibility decisions about you.
4. Cookies and browser storage
We use an essential sign-in cookie to maintain your session. It expires after seven days unless replaced by a new session, and signing out invalidates that session. Your browser stores preferences such as theme and chart settings. Local development previews may also store a preview workspace in browser storage.
We use PostHog for product analytics, to learn which pages and features are useful, and session replay to understand navigation, clicks, scrolling, and problems using the site. Analytics uses a temporary anonymous identifier held only in page memory, without analytics cookies, local storage, or session storage. A full page reload starts a new anonymous session; we do not link it to your account. Form values are masked, and dialogs, saved workspaces, account administration, and feedback inbox content are excluded from replay. We do not capture console logs or network request and response contents for replay. Analytics and replay are switched off when your browser sends a Do Not Track or Global Privacy Control signal.
We do not use advertising cookies or email open-tracking pixels. We do not sell personal information or share it for cross-context behavioral advertising, and we do not track you across unrelated websites. Do Not Track and Global Privacy Control signals do not change the application's essential session and preference storage. You can clear cookies and browser storage in your browser; this may sign you out or reset preferences.
5. When information is shared
We use Amazon Web Services for hosting, database and backup infrastructure, operational notifications, and transactional email through Amazon SES. Support correspondence sent to our FORFI mailbox is handled through Microsoft 365. PostHog provides the usage analytics described above. These providers process information needed to deliver those services. Authorized FORFI personnel may access information when needed for support, security, and operations.
We may disclose information when required by law or a valid legal process, to protect rights and security, with your direction, or in connection with a merger, acquisition, financing, or transfer of our business, subject to applicable safeguards. Your workspace is not published to other users merely because you create an account or list your employer.
6. Where information is processed
The application's primary hosting and backups are in AWS's US East (Northern Virginia) region, and usage analytics are processed in PostHog's United States cloud. Our service providers and authorized personnel may process information in other countries where they operate. Privacy protections can differ between countries. Where applicable law requires safeguards for international transfers, those requirements apply to our handling of your information.
7. Retention and deletion
We keep account and saved workspace information while your account is active, unless you request deletion or it is no longer needed. We retain support and security records as needed to resolve requests, protect the service, comply with legal requirements, and address disputes. Retention depends on the record's purpose, sensitivity, and applicable obligations.
Verification and password-reset links expire after 30 minutes. Expired authentication records are removed during subsequent authentication activity. Rotating backups and snapshots may temporarily retain deleted information until they are replaced or expire. Backup copies are used for recovery, not routine access. If a backup is restored, completed deletion requests must be reapplied before restored accounts are made available.
Deleting an account removes its active profile, credentials, sessions, saved workspace, saved research, and associated alerts. We also review associated support records and copies held in support systems; information subject to a legal retention requirement may be kept for that purpose. Public regulatory reports are not removed when a user account is deleted.
8. Your choices and privacy requests
You can request access to, a copy of, correction of, or deletion of your personal information by emailing shai@forfi.ai. To delete your account, send a request from your account email with the subject "Delete my FORFI Analytics account". We may ask you to verify ownership before acting. Do not send your password or an identity document unless we explain why additional verification is necessary and provide an appropriate method.
Depending on where you live and which laws apply, you may have additional rights to portability, restriction, objection, withdrawal of consent where processing relies on it, or an appeal of a denied request. We respond within applicable legal time limits, explain any permitted exceptions, and do not discriminate against you for exercising applicable privacy rights. You may appeal a decision by emailing the same address with the subject "Privacy request appeal", and may contact the relevant privacy regulator or attorney general.
Account deletion is handled by our team after verification. It ends access to that account and its saved work. See Support & account requests for the process.
9. Security
We use safeguards including encrypted web connections, password hashing, access controls, and restricted backups. No system or transmission method is completely secure. Please use a unique password and keep verification and password-reset links private. Report suspected unauthorized access to shai@forfi.ai.
10. Children
This service is intended for adults conducting professional or institutional research and is not directed to children under 18. We do not knowingly collect personal information from children under 18. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
11. Changes and contact
We will update the date above when this policy changes and provide additional notice of material changes where required. If we introduce new uses of personal information, we will provide notice and obtain consent where required before using information that way.
For privacy, support, or account-deletion requests, contact FORFI, Inc. at shai@forfi.ai. Our current contact address is always shown on this page.