Legal
Privacy policy
Last updated 3 October 2026. Operated by AI Analytics LLC, a New Jersey limited liability company (“we,” “us,” or “our”).
1. Scope
This Privacy Policy describes how we collect, use, disclose, and retain information when you use the FindThings hosted service (the “Service”). It applies to each filing space you create or are invited to. By using the Service, you acknowledge this Policy and our Terms of use.
2. Who this Service is for
FindThings is a hosted filing map for one organization of any size (Office plan, including Office Premium) or a single user on the Free plan. Enterprise arrangements are made separately in writing. You own the content you enter; we provide the software that indexes and stores it. The Service is software for an organization of any size, for equipment and for paper and digital files — such as industrial machinery and its warranties, calibration certificates, safety documents, and repair manuals; title and escrow packets, insurance policies, tax and client binders, property-management leases, real-estate closing folders, law-office binders, mortgage loan files, clinic admin intake (referrals and billing paper outside an EHR), and office equipment, furniture, and vehicles tracked for value, condition, maintenance, and renewal dates. It helps you find those records and see upcoming dates. It does not certify regulatory compliance. Depreciation schedules, book-value estimates, and renewal reminders the Service calculates or sends are organizational tools to help you keep track of your own records — they are not an appraisal, a certified valuation, tax or accounting advice, or an insurance-coverage determination, and you remain responsible for verifying any figure or date before relying on it. It is not a hospital or clinic EHR, not a court e-filing or legal-records platform, not a loan origination system (LOS), not a licensed appraisal or asset-valuation service, not an insurance broker, agent, or carrier, and not a bank, pharmacy, or government records office.
3. Information we collect
Depending on how you use the Service, we may collect and store the following categories of information in connection with your space:
- Account credentials. Your email address and a hashed password. We do not store your password in plain text. You may correct inaccurate account information in Account settings or by emailing contact@aianalyticsllc.io.
- Filing map data. Locations, drawers, file names and numbers, diary entries, reminders, and activity logs within your space.
- Asset and inventory data. For items you choose to track as physical assets or inventory: quantity, unit and total value, purchase price, depreciation method and schedule, current book value, insurer and insurance-policy information, checkout, check-in, and reservation history, and condition photos captured at checkout or check-in.
- Directory and tree data. Contact information and optional organization tree data that you enter or import, and any family-tree data you entered before that page was retired (it is kept, and included in your backup export) (including contact photos you upload).
- Attachments. Optional files you upload (such as photos, PDFs, common office documents, and compressed archives), including condition photos captured at checkout or check-in, subject to size limits.
- Owner notes and vault items. Owner-only notes, and vault entries (titles in readable form; usernames, passwords, and notes in encrypted form).
- Space membership. The identity of people you invite and their role (Owner, Editor, Manager, Field Worker, or Viewer). Some roles have narrower visibility into financial and insurance-coverage fields than others; see Section 6.
- Subscription and billing metadata. Plan, subscription status, billing channel (website or installed app), and Stripe customer and subscription identifiers. We do not receive or store full payment card numbers.
- Optional contact for notifications. A mobile telephone number if you choose to save one for SMS reminders.
4. Information we do not collect or store
- Full payment card, debit card, or bank account numbers. Payment methods are collected by Stripe at checkout.
- Contents of your email inbox, telephone call logs, or third-party cloud drives. Directory import is limited to a file you choose to upload (for example, vCard or CSV).
- A master password known only to you. Although vault and file data are encrypted, we control the encryption keys required to operate the Service. The Service is not a zero-knowledge password manager.
You should not use the Service to store electronic health records, payment card data, or a general password list. Medicine reminders are scheduling aids only — they are not medical advice and are not intended as a clinical dose record.
5. How we use information
We use the information described above to provide, secure, and improve the Service; authenticate users; enforce role-based access within a space; process subscriptions; send transactional email (such as password reset) and optional reminders you configure; and comply with law. We do not sell your filing map or personal information to advertisers.
6. How information is shared
Within your space. Information you enter is visible to users you invite, according to their role. A Viewer may search and export permitted data, including financial and insurance-coverage fields. An Editor may modify the map, perform checkout, check-in, and other inventory actions, and may access vault items the Owner has marked as visible to Editors. A Manager may modify the map and perform checkout, check-in, and other inventory actions, but — unlike an Editor or Viewer — does not see financial fields (such as purchase price, depreciation, or book value) or insurance-coverage fields (such as insurer, policy number, or coverage status). A Field Worker may perform checkout, check-in, and related inventory actions on existing items, but may not otherwise modify the map, and — like a Manager — does not see financial or insurance-coverage fields. Owner-only notes and vault items not shared with Editors remain accessible to the Owner. You are responsible for invitations you issue and for the role you assign each person.
Operator access. Our personnel may create accounts and reset passwords as part of hosting the Service. Personnel are not to review file contents, vault secrets, or owner-only notes in ordinary support work unless you authorize access for a specific issue.
Service providers. We disclose information to vendors that process data on our behalf, as described in Section 12. We may also disclose information if required by law, regulation, legal process, or to protect rights, safety, and security.
7. Data isolation and location
Each space is logically isolated. Other customers cannot access your map. Your map, directory, and vault data are stored on encrypted servers in the United States. Photos and PDFs are encrypted by the application before they are stored.
8. Security and encryption
The production Service is served over HTTPS. Uploaded files and vault secrets are encrypted before storage. Encryption limits unauthorized access from third parties; it does not prevent access by someone who possesses your login credentials, an invited Editor with appropriate permissions, or an operator with access to the running application and its keys.
9. Cookies and similar technologies
We use cookies and similar technologies that are necessary to operate the Service, including signed-in session cookies, a space-switch cookie, and a FindThings.Client cookie (app or web) so website and installed-app subscriptions are handled separately. We do not use advertising or cross-site tracking cookies, and because we do not perform cross-site tracking, we do not respond differently to browser “Do Not Track” signals. The Cookie policy lists each cookie.
10. Email, SMS, and devices
Password-reset and reminder email are sent only when outbound email is configured for the host. Due reminders may be emailed to Editors you designate. SMS is optional and sent only to a number you provide. Sessions expire after a period of inactivity. You may sign out other devices from Account settings.
11. Retention, export, and deletion
The Owner may export files, diary entries, reminders, and contacts. Exported backup files do not include the password vault. The Owner may delete the space, which removes that space’s map data from our systems, including vault records and uploaded files under our control. Any member may delete their own FindThings login from Account settings (unless they are the only Owner of a space — then delete the space first).
We retain information for these periods:
- Account login and membership — for the life of your account, plus 30 days after you delete your login from Account settings (to allow recovery from accidental deletion).
- Space and filing data — for the life of the space; removed when the Owner deletes the space (map data, attachments, vault, and related records under our control).
- Subscription and checkout consent logs — up to 3 years for billing disputes, chargebacks, and tax records.
- Login security audit — 30 days.
- Database backups — encrypted backups managed by our hosting provider may persist for a limited period after deletion, consistent with the provider’s retention settings.
Unused unpaid spaces may be removed.
If we reasonably believe a breach of personal information has occurred, we will provide notice as required by applicable United States state law and inform affected Owners of what we know.
12. Service providers
We use the following categories of service providers (“subprocessors”). Each processes information only on our instructions, only as needed to provide the Service, and subject to its own terms and privacy practices:
- Cloud hosting and storage provider(s). Host the application and store filing map, directory, and attachment data in the United States, with encryption at rest. Currently Microsoft Azure.
- Malware scanning provider. Before a photo or document you upload is encrypted and stored, it is held briefly in an isolated staging area and scanned for malware. Currently Microsoft Defender for Storage, part of Microsoft Azure. A file that fails this scan is deleted and never stored.
- Payment processor. Processes recurring card, debit, PayPal, and bank payments for subscriptions. Currently Stripe, Inc. We do not receive or store full payment card numbers ourselves.
- Transactional email provider. Delivers account, password-reset, and reminder email you configure. Currently Microsoft Azure Communication Services.
- SMS provider. Delivers optional text-message reminders to a phone number you provide. Currently Twilio, Inc. We use this provider only if you turn SMS reminders on.
We may add, remove, or change subprocessors as the Service evolves; this Policy will be updated to reflect current providers, and any subprocessor that would materially change how your information is handled will not receive it without an update to this Section.
13. Eligibility and geographic scope
The Service is offered only to individuals who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. The Service is operated from the United States, and your data is stored and processed in the United States using reputable third-party cloud infrastructure providers.
14. Payments
If you subscribe, Stripe retains your payment method and, after any applicable trial period, charges recurring fees as described in our Terms of use. We retain plan, channel, and subscription status to apply cancellation, upgrade, and billing rules. See the Terms for pricing, trial terms, cancellation, and refund policy.
15. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page indicates when it was last revised. Material changes will be posted on this page. Continued use of the Service after an update constitutes acceptance of the revised Policy, to the extent permitted by law.
16. Contact
For general privacy questions, contact us at contact@aianalyticsllc.io. California residents may also use the rights described in Section 17. Disputes are governed by our Terms of use.
17. California residents
This section applies to California residents and supplements the rest of this Privacy Policy. Terms used here have the meanings given in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”).
No sale or sharing for cross-context behavioral advertising. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use advertising or cross-site tracking cookies (see Section 9).
Your rights. Subject to applicable law and certain exceptions, California residents have the right to:
- Know what personal information we collect, use, disclose, and retain about you, and to access that information;
- Delete personal information we hold about you, subject to exceptions permitted by law;
- Correct inaccurate personal information we maintain about you; and
- Non-discrimination — we will not discriminate against you for exercising these rights.
Many rights can be exercised in the Service: you may review and edit filing data in your space, update account settings, export a backup (Section 11), delete your login from Account settings, or delete your space as Owner. For requests we cannot fulfill through self-service, contact us using the process below.
Sensitive personal information. We collect categories that may qualify as sensitive personal information under California law, including account log-in credentials (email and password) and, if you provide it, a mobile telephone number for SMS reminders. We use that information only as necessary to provide the Service, authenticate you, send reminders you configure, and secure your account — not to infer characteristics about you for unrelated purposes.
How to submit a request. Email contact@aianalyticsllc.io with the subject line “California privacy request,” your account email, and whether you are requesting to know, delete, or correct personal information. We will verify your identity before fulfilling a request (for example, by confirming control of the account email or asking for information that matches our records). We will respond within 45 days of receiving a verifiable request. If we need more time, we may extend our response period by up to an additional 45 days and will notify you of the reason and extension period within the initial 45-day window.
Authorized agents. You may designate an authorized agent to submit a request on your behalf. The agent must provide written permission signed by you and we may require you to verify your identity directly with us or confirm directly with us that you authorized the agent.
Appeals and complaints. If we deny a request, we will explain why. You may contact us at the email above with questions. California residents may also contact the California Attorney General’s office regarding their privacy rights.
Terms of use · Sales agreement · Plans · California privacy rights
© 2026 AI Analytics LLC. FindThings IQ™ is a brand of AI Analytics LLC. All rights reserved.
This page describes the Service as implemented. Have qualified counsel review it before public sale. It is not legal advice.