Support

Data Disclosure

This disclosure describes what data Finale Composer accesses, stores, and process when connected to your HubSpot portal.

Last Updated: June 9, 2026

Shared Data Disclosure

Data accessed from HubSpot

Data Scope Purpose
Portal ID and hub domain oauth Identifies your portal; used as the key for all stored settings
OAuth access and refresh tokens oauth Required to make authenticated API calls on your behalf; rotated automatically
HubSpot theme colors and fonts content Read at module render time to generate on-brand content; never stored
Design Manager source files content The module's own template files are written here during install; no other Design Manager content is read
File Manager files and folders files A finale-composer folder is created; files you attach in the chat panel are uploaded there; existing files can be browsed for selection


Data Finale Composer does NOT access: contacts, companies, deals, tickets, forms, email, marketing campaigns, pipelines, workflows, lists, or any CRM data.

Data we store on our servers

All data is stored in Vercel KV (Redis), scoped per portal ID.

What Details
Portal ID and hub domain Stored at install; used to identify your portal in the admin dashboard
OAuth tokens Stored encrypted; rotated on each refresh; deleted on uninstall
Portal API token A UUID generated at install; baked into your module so it can authenticate API calls; deleted on uninstall
Subscription status Stripe customer ID, subscription ID, plan, trial/renewal dates, and payment timestamps synced from Stripe webhooks
AI provider settings Your chosen provider (Anthropic, OpenAI, or Gemini) and API key, stored AES-256 encrypted; never logged or transmitted to any party other than the chosen provider
File Manager folder ID The ID of the finale-composer folder, cached to avoid a lookup on every upload
Cancellation feedback Reason text submitted when canceling a subscription; used for product improvement only

 

Data processed but not stored

What Details
Chat messages and prompts Sent to your configured AI provider in real time; not stored on our servers at any point
Attached files Uploaded directly to your HubSpot File Manager; the file contents pass through our server in transit only and are never written to our storage
Generated HTML Returned to the browser and stored in HubSpot's module field by you; not retained by us
HubSpot theme data Read from the module's render context at display time; never stored

 

Third-party services

Service Purpose Data shared
Stripe Subscription billing Portal ID (as metadata), email address collected by Stripe during checkout
Anthropic / OpenAI / Google AI content generation Your chat prompts and any attached file URLs; governed by the respective provider's terms
Vercel Hosting and KV storage All server-side data listed above; hosted in US regions

 

Data retention and deletion

  • Uninstalling the app revokes OAuth tokens and deletes the portal API token from our system. Subscription records and install history are retained for internal analytics and so a returning subscriber's history is not lost.
  • You may request full deletion of all portal data by contacting us directly.
  • Files uploaded to your HubSpot File Manager remain there under your control after uninstall; we do not delete them.

What we do not do

  • We do not sell, share, or transmit your portal data to any third party except as described above.
  • We do not access, read, or store any HubSpot CRM data (contacts, companies, deals, etc.).
  • We do not store chat prompts, generated content, or file contents on our infrastructure.
  • We do not use your data to train AI models.

Support

Need Additional Help?

If you need further assistance, submit your question using this form and we'll get back to you ASAP!