Privacy Policy
Effective July 9, 2026
Fin is a document-intelligence service operated by Windfall Inc ("Fin", "we", "us"). It reviews Google Slides presentations for accessibility and quality issues, and — when you ask it to — applies fixes. This policy explains what information Fin handles and why. Questions any time: web@windfallstudio.com.
Information we collect
- Account information. Your name, email address, and a hashed password when you create a Fin account.
- Connected Google accounts. When you connect Google, we store your Google profile name, email, and OAuth tokens. Tokens are encrypted at rest and used only to make the API calls described below.
- Scan results. When you run a report, we store the outcome: scores, and the list of findings (which can include short excerpts from your presentation, such as a link's text or an image's alt text, needed to explain each issue). We fetch your presentation's contents to analyze them; we do not keep a copy of the presentation itself.
- Fix history. When you apply a fix, we record what changed and how to undo it, so every automatic change is auditable and reversible.
- Usage data. Standard server logs (IP address, request times) kept for security and debugging.
How we use Google user data
Fin requests these Google permissions, and uses them only for the purposes listed:
- Drive file metadata (read-only) — to show you a list of your presentations so you can pick one to analyze.
- Google Slides (read and write) — to read a presentation's contents when you run a report, and to modify it only when you explicitly apply a fix.
Fin's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we only use Google user data to provide and improve Fin's user-facing features; we never sell it; we never use it for advertising; and no human reads it except with your permission, for security or debugging purposes, or where required by law.
AI processing
Some features use an AI model to generate suggestions — for example, writing alt text for an image. When you request such a suggestion, the relevant content (the image and a short description of its context) is sent to our AI provider, currently OpenAI, to generate the suggestion, and is not stored by Fin beyond the resulting suggestion itself. We do not use your content — including any Google user data — to train AI models, and our AI provider processes API data without using it for training under its API terms. AI features only run when you invoke them.
Storage, security, and sharing
Data is transmitted over TLS and stored on servers we manage with a commercial cloud provider, currently DigitalOcean. OAuth tokens are encrypted at rest. We share data only with the service providers needed to run Fin — Google (APIs), OpenAI (AI suggestions you request), and Digital Ocean (hosting) — and never sell personal information to anyone.
Retention and deletion
- Disconnecting a Google account in Fin deletes its stored tokens immediately.
- You can also revoke Fin's access at any time from your Google account permissions.
- Deleting your Fin account (Settings) removes your account data, connected accounts, scans, findings, and fix history.
- You can email us to request deletion of any of your data.
Changes to this policy
If we make material changes, we'll update the effective date above and, where appropriate, notify you in the product or by email.