Support
Data Disclosure
This disclosure describes what data Finale Composer accesses, stores, and process when connected to your HubSpot portal.
Last Updated: June 9, 2026
Shared Data Disclosure
Data accessed from HubSpot
| Data | Scope | Purpose |
|---|---|---|
| Portal ID and hub domain | oauth |
Identifies your portal; used as the key for all stored settings |
| OAuth access and refresh tokens | oauth |
Required to make authenticated API calls on your behalf; rotated automatically |
| HubSpot theme colors and fonts | content |
Read at module render time to generate on-brand content; never stored |
| Design Manager source files | content |
The module's own template files are written here during install; no other Design Manager content is read |
| File Manager files and folders | files |
A finale-composer folder is created; files you attach in the chat panel are uploaded there; existing files can be browsed for selection |
Data Finale Composer does NOT access: contacts, companies, deals, tickets, forms, email, marketing campaigns, pipelines, workflows, lists, or any CRM data.
Data we store on our servers
All data is stored in Vercel KV (Redis), scoped per portal ID.
| What | Details |
|---|---|
| Portal ID and hub domain | Stored at install; used to identify your portal in the admin dashboard |
| OAuth tokens | Stored encrypted; rotated on each refresh; deleted on uninstall |
| Portal API token | A UUID generated at install; baked into your module so it can authenticate API calls; deleted on uninstall |
| Subscription status | Stripe customer ID, subscription ID, plan, trial/renewal dates, and payment timestamps synced from Stripe webhooks |
| AI provider settings | Your chosen provider (Anthropic, OpenAI, or Gemini) and API key, stored AES-256 encrypted; never logged or transmitted to any party other than the chosen provider |
| File Manager folder ID | The ID of the finale-composer folder, cached to avoid a lookup on every upload |
| Cancellation feedback | Reason text submitted when canceling a subscription; used for product improvement only |
Data processed but not stored
| What | Details |
|---|---|
| Chat messages and prompts | Sent to your configured AI provider in real time; not stored on our servers at any point |
| Attached files | Uploaded directly to your HubSpot File Manager; the file contents pass through our server in transit only and are never written to our storage |
| Generated HTML | Returned to the browser and stored in HubSpot's module field by you; not retained by us |
| HubSpot theme data | Read from the module's render context at display time; never stored |
Third-party services
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Subscription billing | Portal ID (as metadata), email address collected by Stripe during checkout |
| Anthropic / OpenAI / Google | AI content generation | Your chat prompts and any attached file URLs; governed by the respective provider's terms |
| Vercel | Hosting and KV storage | All server-side data listed above; hosted in US regions |
Data retention and deletion
- Uninstalling the app revokes OAuth tokens and deletes the portal API token from our system. Subscription records and install history are retained for internal analytics and so a returning subscriber's history is not lost.
- You may request full deletion of all portal data by contacting us directly.
- Files uploaded to your HubSpot File Manager remain there under your control after uninstall; we do not delete them.
What we do not do
- We do not sell, share, or transmit your portal data to any third party except as described above.
- We do not access, read, or store any HubSpot CRM data (contacts, companies, deals, etc.).
- We do not store chat prompts, generated content, or file contents on our infrastructure.
- We do not use your data to train AI models.
Support
Need Additional Help?
If you need further assistance, submit your question using this form and we'll get back to you ASAP!

