Forecraft

Your Data

Four questions every finance professional should ask before trusting a tool with client data. Plain English answers — no legalese.

Where is the data stored?

Your financial data lives in a PostgreSQL database hosted by Neon in the United States. When you upload a P&L or balance sheet, the file is parsed in memory, structured into rows, and written to that database. The raw file is never saved to disk or forwarded to a third party — it is processed and discarded after import.

Billing is handled entirely by Stripe. We store only your Stripe subscription ID — never your card number, bank details, or any payment credentials.

Account passwords are hashed with bcrypt before storage. We never store or log your password in plain text. If you connect QuickBooks or Xero, the OAuth tokens that allow us to pull your data are encrypted at rest.

Who can access it?

You, and any workspace members you explicitly invite. Workspace data is scoped — members of one workspace cannot see data in another.

Forecraft staff can access anonymised server logs (IP addresses, error traces, event IDs) for debugging and support. We do not have a back-office view that shows us your clients’ financial figures. Neon operates the database infrastructure but has no application-level access to your data.

No advertiser, data broker, or analytics platform sees your financial data. We do not sell it, rent it, or share it with third parties beyond the infrastructure providers listed above.

Is it used to train AI models?

No. When you use an AI feature — such as the executive narrative or variance explanation — your financial data is sent to Anthropic (maker of Claude) as context for that single request. Once the response is returned, Anthropic discards it. Anthropic’s API terms prohibit using API inputs to train or improve their models without customer consent — which we have not given.

Forecraft does not build, fine-tune, or train any model from your data. Your client’s numbers are used to produce your deliverable and nothing else.

What happens when you cancel?

Your account stays active and fully functional until the end of the current billing period. Nothing is deleted or locked when you cancel — you continue to have access to your workspaces, saved packs, and exports until the period ends.

After the period ends, your account moves to a read-only state. Your data is not automatically deleted. It stays in our database until you ask us to remove it.

To delete everything, go to Account Settings and use the “Delete account” option — this removes your account and all associated workspace data immediately. Or email privacy@forecraft.tech and we will delete it within 30 days and confirm when it is done.

For users in the European Union

ForeCraft complies with the General Data Protection Regulation (GDPR). Your financial data is processed under Standard Contractual Clauses for international data transfers to the United States.

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Lodge a complaint with your local data protection authority

To exercise any right, contact: privacy@forecraft.tech

UK users (post-Brexit)

ForeCraft complies with the UK GDPR as incorporated into UK law by the Data Protection Act 2018. Your rights are identical to those listed above.

Controller and processor roles

For the purposes of GDPR, ForeCraft acts as a data processorfor your clients’ financial data. You, as the fractional CFO or advisory firm, act as the data controller. This means you are responsible for ensuring you have the appropriate legal basis and consents to share your clients’ financial data with ForeCraft as your processor.

Last updated: June 9, 2026


If you have a question not covered here, email privacy@forecraft.tech. For the full legal detail, see our Privacy Policy and Terms of Service.

HomePricingSecurityPrivacy