Skip to main content

Headlight is in a closed beta. Access is by invitation only. Request early access

FeaturesPricingSecurityFAQ
Sign in

Privacy Policy

Last updated: July 22, 2026

1. Who We Are and What This Covers

Headlight ("Headlight," "we," "us," or "our") provides software that serves as the operating system for how professional firms serve clients. One workspace for households, documents, tasks, and meetings. Search everything. Track what's due. Ask Headlight AI, grounded in your documents and data (the "Service"). The Service is designed for advisory firms, family offices, trust companies, and wealth management firms, and other professional services firms that run on client documents. This Privacy Policy describes how we collect, use, and share personal information when you visit our public marketing website at withheadlight.com (the "Marketing Site"), use the authenticated Service at app.withheadlight.com and related applications (the "Service"), or otherwise interact with us. Advertising and remarketing technologies in this policy apply to the Marketing Site only, not to the authenticated Service. Product analytics in the Service and on the Marketing Site are described in Section 2.

Headlight plays two distinct roles with respect to personal information, and it is important to understand the difference:

  • Headlight as a data controller. We decide how and why to process certain information, such as the account information of the professionals who use the Service, billing records, website visitor data, and communications with us. This Privacy Policy applies fully to that information.
  • Headlight as a data processor (service provider). The documents, client records, and related information that our customers upload to or create in the Service ("Customer Content") are controlled by the customer firm, not by Headlight. We process Customer Content only on the customer's behalf and under the customer's instructions, as set out in our agreement with the customer. If your personal information appears in Customer Content (for example, because you are a client of an advisory firm that uses Headlight), the firm's own privacy practices govern that information, and you should direct privacy requests to that firm. Section 4 describes how we handle Customer Content.

2. Information We Collect

When we act as a data controller, we collect the following categories of information:

  • Account information. Name, work email address, role, and organization details for the users our customers authorize to access the Service. Authentication is handled by our identity provider, WorkOS; we do not store passwords.
  • Billing information. Organization name, subscription status, plan details, and usage metering. Payments are processed by Stripe; Headlight does not receive or store full payment card numbers.
  • Communications. Messages you send us, including support requests, sales inquiries, and emails to our published addresses.
  • Usage and device data. Log data generated when you use the Service or visit the Marketing Site, such as IP address, browser type, pages viewed, timestamps, feature interactions, and error and performance diagnostics. In the Service, we use this data for security, debugging, and operating the Service, and we use a third-party product analytics service to understand how authorized users navigate features so we can improve the product. We do not use advertising or remarketing technologies in the authenticated Service, and we do not use Customer Content for advertising. On the Marketing Site, we use a third-party product analytics service to understand how visitors use the site. We may also use advertising and measurement technologies (such as conversion tags and remarketing pixels) to measure our marketing campaigns and show relevant ads on other sites. Those advertising technologies apply to Marketing Site visits only, not to your use of the authenticated Service. Analytics and advertising providers are identified in our Trust Center. We do not sell personal information.
  • Portal and link recipients. If a Headlight customer sends you a secure portal link (for example, to upload requested documents or to view records as an outside trustee), we collect the information needed to deliver and secure that experience, such as your email address, access events, and the content you submit. The content you submit becomes Customer Content controlled by the firm that requested it.

3. How We Use Information

We use the information described in Section 2 to:

  • Provide, maintain, secure, and improve the Service;
  • Understand product usage through analytics in the Service and on the Marketing Site (Section 2);
  • Measure and improve our marketing on the Marketing Site, including through advertising and measurement partners where we use them (Section 2);
  • Authenticate users and enforce role-based access controls;
  • Process subscriptions, billing, and usage metering;
  • Send transactional communications such as invitations, notifications, document request emails, and account digests;
  • Respond to support requests and other inquiries;
  • Monitor for, investigate, and prevent security incidents, fraud, and abuse;
  • Maintain audit logs of sensitive actions taken in the Service; and
  • Comply with legal obligations.

We do not sell personal information. We do not use the authenticated Service for cross-context behavioral advertising. On the Marketing Site, we may share limited visitor information with advertising and measurement partners as described in Section 2; where required by law, you may opt out as described in Section 10.

4. Customer Content We Process on Behalf of Customers

The core of the Service is helping firms organize and understand their client records. Customer Content may include documents (such as wills, trusts, tax returns, account statements, and operating agreements) and structured records about the people, households, trusts, entities, and transactions described in those documents. Customer Content may contain sensitive personal information, including names, contact details, dates of birth, family relationships, government identifiers, financial account details, and tax information.

With respect to Customer Content:

  • We process it only to provide the Service to the customer and as instructed by the customer under our agreement with them;
  • It is logically isolated per customer using database row-level security, encrypted at rest, and protected with additional field-level encryption for the most sensitive values (see Section 8);
  • We do not use it to train, fine-tune, or improve AI models (see Section 5);
  • We do not sell it or share it for advertising purposes; and
  • We delete or return it in accordance with our agreement with the customer and Section 9 of this policy.

For customers that are financial institutions subject to the Gramm-Leach-Bliley Act, SEC Regulation S-P, or similar rules, we act as a service provider with respect to nonpublic personal information contained in Customer Content and handle it in accordance with our agreement with the customer.

5. AI Processing

The Service uses artificial intelligence to read documents, extract structured information, and answer questions grounded in a customer's own records. We designed this processing to keep Customer Content within our controlled infrastructure:

  • Model inference runs in AWS. Document text and prompts are processed using foundation models through Amazon Bedrock within our AWS environment. We configure inference to provide the Service. Subprocessors such as AWS and underlying model providers operate under their own agreements with us, which may change over time.
  • No training on Customer Content. We do not use Customer Content to train, fine-tune, or improve any AI models, whether ours or a third party's. Subprocessors used for AI inference operate under their own agreements with us, which may change over time, as described in Section 6 and our DPA.
  • AI observability. When enabled, we monitor AI quality and performance using self-hosted Langfuse within our AWS environment in the United States. Trace metadata may include organization and user identifiers and bounded excerpts from prompts or responses for debugging. Trace data is stored in our infrastructure, not sent to Langfuse's cloud service. We do not send full Customer Content to observability tools for unrelated purposes.
  • Human review. AI-extracted information is presented to the customer's authorized users for review before it is committed to the client record. Authorized Headlight personnel may access Customer Content only when necessary to provide support, investigate security incidents, or as required by law, and such access is logged.
  • Public reference search. If a user asks our assistant a question that requires public sources (for example, IRS guidance), documents and client records are not sent to the search provider. Query text is scrubbed using pattern redaction, name and address detection, and removal of known organization record names from the customer's workspace. If residual identifying information is detected after scrubbing, the search is blocked and nothing is sent. Only scrubbed, approved query text is sent to Brave Search to retrieve public results. We do not claim perfect prevention of every possible identifying term.

6. How We Share Information

We share personal information only as described below. We do not sell it or rent it to anyone.

  • Service providers (subprocessors). We use third-party vendors to host, secure, analyze, bill, and operate the Service and Marketing Site. The current subprocessor list, including each provider's role and the categories of personal information each processes, is maintained in our Trust Center. For Customer Personal Data we process on our customers' behalf, subprocessors are governed by our Data Processing Addendum, which incorporates the Trust Center list by reference. We post subprocessor changes to the Trust Center and notify customers as required under the DPA; updating the Trust Center does not by itself require a change to this Privacy Policy.
  • Integrations you direct. If a customer connects a third-party service, including but not limited to Box, Dropbox, Google Drive, or Google Calendar, we exchange data with that service as directed by the customer (for example, importing documents the customer selects or syncing calendar events from a Google Calendar the customer connects). Access tokens for connected services are stored encrypted. The third party's own privacy policy governs its handling of data on its platform, and customers can disconnect integrations at any time. Additional details for Google Calendar are in Section 6.1 below.
  • Within your organization. Information in the Service is visible to other authorized users of your organization according to the roles and permissions your organization configures, and to recipients of links your organization chooses to share.
  • Legal and safety. We may disclose information if we believe in good faith that disclosure is required by law or legal process, or is necessary to protect the rights, safety, or property of Headlight, our customers, or others. Where legally permitted, we will notify the affected customer before disclosing Customer Content in response to a legal demand.
  • Business transfers. If Headlight is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy and to confidentiality protections.

6.1 Google Calendar Integration

This section supplements the Integrations you direct description above. Synced meeting data stored in the Service is Customer Content controlled by the customer firm and is processed by Headlight on the customer's behalf as described in Section 4.

If you choose to connect Google Calendar to Headlight, we access Google user data through the Google Calendar API under the scopes you approve during OAuth consent.

Data we access from Google. When you connect Google Calendar, we may access your Google account email address (to identify which account is connected) and events from your primary Google Calendar within a rolling sync window (events from the past seven days through the next ninety days), including event title, description, start and end time, location, video-conference or join link, event status, a link to the event in Google Calendar, and the number of event attendees. We do not request write access to your Google Calendar. We do not create, modify, or delete events in Google Calendar. We do not read or store individual attendee email addresses from calendar events.

How we use Google Calendar data. We use this data only to provide calendar-related features in the Service, including displaying synced meetings on the dashboard and Meetings pages, linking meetings to client households within your organization, supporting meeting notes and related workflows initiated by authorized users, and (when enabled for your organization) matching forwarded meeting notes to synced calendar events. Synced meetings are visible within your organization according to the roles and permissions your organization configures (see Within your organization above): the user who connected their calendar sees their synced events; other authorized users may see meetings that have been linked to a household or otherwise made available within the organization. We do not use Google Calendar data for advertising, interest-based profiling, or credit eligibility. We do not sell Google Calendar data.

How we store and protect Google Calendar data. OAuth access and refresh tokens are stored encrypted with our other integration credentials. Synced calendar event data is stored in Headlight's secure cloud infrastructure (AWS, United States) as Customer Content, with encryption in transit and at rest, multi-tenant isolation, and role-based access controls, as described in Sections 4 and 8 of this policy.

Retention and deletion. Synced calendar data is retained while your Google Calendar connection is active and your organization's account is active, subject to Section 9. You may disconnect Google Calendar at any time from the dashboard calendar widget or the Meetings page in the Service. When you disconnect, we remove the connection and stop syncing new data from Google. Previously synced events may remain in the Service as Customer Content until deleted in accordance with your organization's use of the Service and Section 9 of this policy. To request deletion of personal information Headlight controls, contact privacy@withheadlight.com. If your request concerns synced meeting data held as Customer Content, we may refer you to the controlling customer firm, as described in Section 10.

Sharing. Google is a third-party service you connect at your direction; it is not a Headlight subprocessor (see our Data Processing Addendum). We receive calendar data from Google only to provide the integration you authorized. We store and process that data using service providers (subprocessors) that help us host and operate the Service, as listed in our Trust Center. We require these providers to protect the data and use it only to provide services to us.

AI and machine learning. Google Calendar data is not sent to AI models for inference and is not used to train, fine-tune, or improve artificial intelligence or machine learning models, whether Headlight's or a third party's, consistent with Section 5 of this policy.

Google API Services User Data Policy. The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Cookies

In the Service, we use essential cookies: a session cookie that keeps you signed in and related cookies necessary for security (such as preventing cross-site request forgery). Our third-party product analytics service may set cookies or use similar technologies to recognize your browser or device during authenticated sessions.

On the Marketing Site, our product analytics service and any advertising and measurement partners we use may set cookies or use similar technologies to recognize your browser or device across visits, measure campaigns, and deliver or measure relevant ads on other sites. Those technologies are not used in the authenticated Service.

We do not respond differently to browser "Do Not Track" signals because industry practice for those signals is inconsistent.

8. Security

We build the Service for firms that handle highly sensitive financial and estate information, and our security program reflects that:

  • Encryption in transit (TLS) and at rest (AWS KMS) for all customer data;
  • Additional application-layer field encryption (AES-256-GCM with KMS-backed keys) for the most sensitive values, such as contact details, extracted document text, and sensitive financial fields;
  • Multi-tenant isolation enforced at the database layer with PostgreSQL row-level security;
  • Role-based access control and audit logging of sensitive actions;
  • API keys stored hashed, never in plaintext;
  • Secrets and encryption keys managed in AWS Secrets Manager and KMS with least-privilege access; and
  • A SOC 2-aligned control environment, including vendor and risk management.

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify affected customers and individuals as required by law. Security researchers and others can reach our security team at security@withheadlight.com.

9. Data Retention and Deletion

  • Active accounts. Customer data is retained while the customer's account is in good standing.
  • After termination. Customer Content remains available for export or reactivation for 30 days after termination, unless we are required by law to retain it longer or a separate agreement with the customer provides a different period. After that window, we delete Customer Content from production systems.
  • Deletion requests. Verified deletion requests are processed within 30 days for data we have no legal or contractual obligation to retain. Deletion covers production systems, including database records, stored documents, and derived data such as extracted text, document chunks, and vector embeddings.
  • Backups. Deleted data may persist in encrypted, access-controlled database backups until those backups expire. Our current automated backup retention period is seven days for production database clusters. Backups are not used to restore individually deleted records.
  • Audit and security logs. Audit logs and security records are generally retained for one year, unless a longer period is required by law or for an active security investigation.

To request deletion, contact privacy@withheadlight.com. If your information is part of Customer Content, we may refer your request to the controlling firm, since deleting it is their decision under our agreement with them.

10. Your Rights and Choices

Depending on where you live, you may have rights under state privacy laws (such as the California Consumer Privacy Act) or other applicable laws to access, correct, delete, or obtain a copy of your personal information, and to not be discriminated against for exercising those rights.

We do not sell personal information. We do not use cross-context behavioral advertising in the authenticated Service. If our use of advertising and measurement technologies on the Marketing Site constitutes "sharing" under applicable state privacy laws, you may opt out by enabling Global Privacy Control (GPC) in your browser when you visit the Marketing Site. We treat an enabled GPC signal as a request to opt out of sharing for that browser and display confirmation when that request is honored. You may also email privacy@withheadlight.com with the subject line "Opt out of sharing." We will not discriminate against you for exercising either choice.

If you are a resident of a U.S. state with a comprehensive privacy law, the rights above apply to personal information Headlight controls about you. The Service is offered to U.S.-established organizations only (Section 11). Headlight does not market the Service in the European Economic Area, the United Kingdom, or Switzerland, and does not offer the Service to individuals there except through a customer firm's portal or shared link at that firm's direction.

Customer Content is controlled by the customer firm; we process it as a processor under our Data Processing Addendum.

To exercise these rights for information that Headlight controls, email privacy@withheadlight.com. We will verify your request and respond within the time required by applicable law. If your request concerns information contained in Customer Content, please contact the firm you work with; we will support that firm in fulfilling your request.

You may also unsubscribe from non-essential emails using the link in those emails. Transactional messages (such as document requests and security notices) are part of the Service and cannot be opted out of while you use it.

11. Data Location and International Use

Headlight is based in the United States, and the Service is hosted in AWS data centers in the United States.

Who we serve. We market to and contract with organizations established in the United States only. We do not market the Service in the European Economic Area, the United Kingdom, or Switzerland, and we are not open to new customers established in those jurisdictions unless we have agreed in writing (including any required data processing terms). The Service is intended for use from the United States; we may restrict access from other jurisdictions.

Individuals in Customer Content. Our U.S. customers may store personal information about their clients and related parties who live or are located outside the United States, including in the EEA, UK, or Switzerland (for example, beneficiaries, trustees, or family members named in estate documents). That does not mean Headlight offers the Service to those individuals or markets to them. Those individuals should contact the customer firm that controls their information. The customer firm, not Headlight, decides whether it may lawfully collect that information and transfer it to Headlight in the United States. Headlight processes Customer Content as a processor under our Data Processing Addendum.

GDPR and transfer tools. Our standard Privacy Policy and DPA are designed for our U.S. go-to-market. They do not include EU Standard Contractual Clauses, a UK Addendum, or other GDPR-specific processor terms by default. If a customer requires those tools because of the nature of its Customer Content or its own obligations, the customer must contact us before processing so we can agree in writing on appropriate terms. A geoblock or U.S.-only customer eligibility alone may not satisfy that customer's obligations if it systematically processes personal data of individuals in the EEA, UK, or Switzerland.

If you access the Marketing Site or Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

12. Children

The Service is for business use and is not directed to children, and we do not knowingly collect personal information directly from children. Customer Content may include information about minors (for example, as beneficiaries in estate documents); that information is controlled by the customer firm and processed only on its behalf.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify customers through the Service or by email at least 30 days before the changes take effect, and we will update the "Last updated" date above. The current version always lives at this page. Updates to our subprocessor list on the Trust Center are handled as described in Section 6 and our DPA and are not material changes to this Privacy Policy by themselves.

14. Contact Us

Privacy questions and requests: privacy@withheadlight.com

Security: security@withheadlight.com

General: hello@withheadlight.com

  • Security
  • FAQ
  • Privacy
  • Terms of Service
  • Trust Center
© 2026 Headlight