Footings

Privacy policy

Last updated August 17, 2026 · Footings is in active beta

Footings exists to keep a construction company's job costing and books straight. The data you put in it is yours. This page says plainly what we collect, where it lives, and who can see it.

What we collect

Where it lives

All application data is stored in Canada (our database and file storage run in a Canadian data-centre region), encrypted in transit and at rest. Payment card details are not collected — Footings has no paid plans during the beta.

Who can see it

Support access to your account

Some problems can't be answered from a description. A figure that looks wrong on a job, an invoice that won't post, a supplier bill the document reader misread — those have to be looked at in your actual records. When that happens an authorized Footings operator opens a support session against your company and works in your account.

Inside a session the operator can read your company's business records — company settings, users and roles, invitations, jobs, estimates, invoices, credit notes, payments, purchase orders, bills, expenses, contracts, uploaded documents and photographs, document-reading results, vendors, the books, reports, GST and PST worksheets, receivables and payables, your plan and billing status, and support and diagnostic information. They can also change those records, because some fixes are a correction rather than an explanation.

The limits on that access are enforced by the database, not by good intentions:

What a support session does not reach: passwords and password hashes, multi-factor authentication secrets, password-reset and confirmation tokens, and your live sign-in sessions — an operator cannot sign in as you or take over your session. Payment credentials are not reachable either: full card numbers and card security codes are never stored in Footings at all, and our payment processor's keys and our database's administrative keys are not in the data an operator works with. A session also cannot hand an operator standing membership of your company: it cannot read or rotate your invite code, change who owns the company, change your plan, or add itself to your team.

[TO CONFIRM: whether the company owner is emailed each time a support session is opened against their company, or whether this policy and the in-app record are the only notice given.]

Support Mode is built but not yet enabled in production — this section is here so the policy is ahead of the feature, not behind it.

Automatic document reading (when enabled)

Footings can read a photographed receipt or invoice and pre-fill the entry for you. When this feature is enabled and you request a read, that one document is transmitted securely to our document-processing provider (Anthropic) for extraction and is not used to train their models under our configuration. The provider may hold the submitted copy briefly under its API data-handling terms before it is deleted from their systems; the lasting record is only ever the one in our Canadian storage, and deleting a document in Footings deletes that stored copy. Documents are never sent for processing unless a user asks for that document to be read; skipping the feature and typing the entry yourself keeps the document entirely in Canada. This feature is currently not enabled in production — this section is here so the policy is ahead of the feature, not behind it.

Support messages and the in-app assistant

The support form is processed by Netlify (our hosting provider) and lands in our support inbox. Send only what the problem needs — support messages are kept while the issue is worked and for a reasonable record afterwards, and are readable only by the people running Footings.

The Help assistant inside the app generates its answers using the same AI provider as document reading (Anthropic). When you use it, your conversation and basic diagnostics (which screen you were on, app version, plan, role, browser, and the last error the app raised) are transmitted securely to that provider to produce the reply, and are not used to train their models under our configuration. On the Business plan and up, the assistant can also look up records from your own company's books to answer questions — those lookups are read-only, limited to what your own signed-in account can already see, and the retrieved records are sent to the provider only as context for that one answer. The assistant cannot change any record. If a conversation files a problem report, the report and its diagnostics are stored with us and emailed to our support inbox. If you prefer that nothing be processed this way, use the support form instead — the assistant only processes what you choose to send it.

Sensitive identifiers

Subcontractor tax identifiers (business numbers, SINs entered for T5018 slips) get extra protection: they are stored separately, shown masked, readable in full only by your owner, admin and accounting roles, and every reveal is written to an audit trail. A Footings operator inside a support session can reveal them too; that reveal is audited the same way, in your trail, marked as a support action.

Your controls

Changes and contact

If this policy changes materially we'll note it here with a new date.

Footings is operated from Canada, and all application data is stored in Canada. [TO CONFIRM: whether every person who can start a support session works from Canada, and what this policy should say if that ever stops being true.] Privacy questions, access requests and deletion requests all go through the support page, which reaches the people who run Footings directly.

Beta honesty: Footings is under active development. This policy is written to be accurate today and will be reviewed by counsel before general availability.