Privacy Policy
Last updated: August 14, 2026
Median Labs Inc. ("Median," "we," "our," or "us") provides bookkeeping, tax preparation, financial reporting, and related services through the Median platform (the "Service"). This Privacy Policy describes what personal information we collect, how we use it, who we share it with, how long we keep it, and what rights you have. It applies to the Median website at medianfi.com, the Median application, and any related services we offer.
This policy is written to be readable. If you want the full legal framework, it works alongside our Terms of Service. If you are an individual whose information is processed by Median on behalf of a Median customer, please also refer to that customer's own privacy notice for information about how they handle your data.
1. Scope and Our Role
Median is a business-to-business service. Our direct customers are businesses (sole proprietors, LLCs, corporations). Within that context, we handle two kinds of personal information in two different roles:
- As a controller, we collect and use information about the people who sign up for Median and administer customer accounts (for example, name, email, billing information). We decide why and how this information is processed.
- As a processor, we process customer financial records and transactional data on behalf of our customers, on their instructions, in order to deliver the Service. Our customers remain the controller of that data.
This distinction matters under the GDPR and similar laws. When we process data as a processor, the Median customer is responsible for obtaining appropriate consents and providing appropriate notices to individuals whose data is processed.
2. Information We Collect
Account information
When you sign up, we collect your name, email address, company name, job title, phone number (if provided), and billing details. We need this to create and administer your account, bill you, and communicate with you about the Service.
Business and financial data
This is the core of what we do. With your authorization, we connect to your financial accounts and import transactional data so we can categorize it, reconcile it, and produce financial statements. Depending on your setup, this includes:
- Bank and credit card transactions, balances, and account metadata (via Plaid)
- Stripe balance transactions, fees, payouts, refunds, and related metadata (via the Stripe App, using the balance_read scope only)
- Data from other financial tools, accounting software, or document uploads you choose to connect or provide (for example, QuickBooks Online, Xero, or CSV imports)
- Company legal information, such as entity name, EIN, state of incorporation, and fiscal year end
- Tax records and supporting documents you upload for tax preparation
Some of this information is "nonpublic personal information" under the Gramm-Leach-Bliley Act (GLBA) and "sensitive personal information" under certain state privacy laws. We treat it with the heightened care those laws require.
Communications with us
When you email, chat, or speak with us (including during onboarding or feedback sessions), we keep records of that communication so we can support you and improve the Service. By joining a video call with Median (for example, an onboarding call, a support call, or a feedback session), you agree that the call may be recorded and automatically transcribed for our internal records. If you do not want a particular call recorded, tell us at the start of the call and we will turn off recording and transcription for that call.
Usage and device data
We collect standard usage data about how you interact with the Service, including pages visited, features used, approximate location (derived from IP address), browser type, operating system, device identifiers, referrer URLs, and timestamps. We use this to improve the product, debug issues, and detect abuse, not to sell ads.
Cookies and similar technologies
See Section 15 (Cookies and Tracking) for how we use cookies and similar technologies.
3. Free Tools
Median publishes free tools that anyone can use without an account, including a public Model Context Protocol server at medianfi.com/mcp and compliance skills for AI assistants. These are designed so that your documents never reach us. The assistant reads your files, email, and accounts on your own machine or in your own connected services, and sends Median only a small set of structured facts.
What we receive and store from these tools: the type of legal entity, its state and date of formation, its fiscal year end, the two-letter codes of states where it operates, employs people, uses contractors, or has customers, a revenue band rather than any figure, the payroll and incorporation arrangement, the type of physical presence in a state, yes or no answers to threshold questions, which obligations the tool returned, how many questions remained open, and whether any item matched a service Median offers. We also store a company name when one is supplied, and a salted, truncated, non-reversible hash derived from the network request, rotated daily, used only to tell repeat use apart from separate users. We do not store IP addresses from these tools.
Supplying a company name is optional. The tool returns exactly the same answer without it. Where it is supplied, we use it to understand who is using the tool and we may contact that business about Median's services.
What we do not receive: your documents or their contents, employer identification or other government identification numbers, street addresses, names of individuals, bank or financial account details, transaction data, or dollar amounts. No field in these tools accepts them, and you should not attempt to submit them. If free text is submitted in a field where it does not belong, we may discard it rather than store it.
These tools are hosted on our website infrastructure, so our hosting and content delivery providers process the underlying network request as they do for any visit to medianfi.com. See Section 6. That provider keeps a short operational record of each request: the address requested, the HTTP method, the response status, the name of the tool that ran, how long it took, and, where a call fails, the text of the error. It does not receive the contents of your request, so the facts you send about a company are not part of that record.
Records from these tools are retained for up to twenty-four months and then deleted or aggregated. To ask what we hold for a given company name, or to have it deleted, contact us using Section 19.
4. How We Use Your Information
We use the information we collect to:
- Provide the Service: categorize transactions, reconcile accounts, close your books, prepare financial statements, calculate tax filings, and generate reports
- Create, administer, and secure your account
- Process payments for your subscription
- Communicate with you about your account, onboarding, support tickets, platform updates, and service announcements
- Train human members of the Median team (not third-party AI models) to improve service quality
- Improve the Service, including fixing bugs, building new features, and tuning our automation using anonymized or aggregated data
- Detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms
- Comply with legal obligations, respond to lawful requests, and enforce our agreements
We do not sell your personal information. We do not share your financial information with advertisers, data brokers, or marketing networks. We do not use your financial data to train artificial intelligence models that are made available to other customers in a way that would expose your specific information.
5. Legal Bases for Processing (EEA and UK Residents)
If you are in the European Economic Area ("EEA") or the United Kingdom, we rely on the following legal bases under the General Data Protection Regulation (GDPR) and the UK GDPR:
- Performance of a contract: to deliver the Service you subscribed to, including onboarding, bookkeeping, tax, reporting, and billing.
- Legitimate interests: to operate and improve the Service, prevent fraud and abuse, secure our systems, and carry out internal analytics, provided our interests are not overridden by your rights.
- Legal obligation: to comply with applicable laws, including tax, accounting, anti-money-laundering, and information-request laws.
- Consent: where we explicitly ask for it (for example, for non-essential cookies or certain marketing communications). You may withdraw consent at any time without affecting processing that happened before withdrawal.
6. Third-Party Services and Subprocessors
We rely on a small number of trusted service providers to operate the Service. These are "subprocessors" under the GDPR. Each one is bound by a written agreement with confidentiality and security obligations at least as protective as this policy. We only share the minimum personal information needed for the service to work.
| Provider | Purpose | Region |
|---|---|---|
| Plaid | Bank account connections and transaction data | United States |
| Stripe | Subscription billing and payment processing | United States |
| Stripe App | Reading balance transactions from your Stripe account using the balance_read scope only | United States |
| Cloud infrastructure provider | Application hosting, databases, and backups | United States |
| Email providers (Gmail, SendGrid) | Transactional and service email | United States |
| Analytics providers | Product analytics and error monitoring | United States |
| Video conferencing | Customer calls, onboarding, and feedback sessions (may include automated transcription) | United States |
Each subprocessor has its own privacy policy. Median does not control how these providers handle data once it passes to them under their own terms. We keep this list current; email privacy@medianfi.com if you want to be notified when we add or change a subprocessor.
7. Stripe App
When you connect your Stripe account to Median:
- We request read-only access to your balance transactions using the balance_read permission
- We import transaction amounts, fees, and payout details
- We do not access your customers' personal information
- We do not make charges, transfers, or any write operations on your Stripe account
- You can disconnect at any time from Settings in Median or directly from your Stripe dashboard
- When you disconnect, we stop pulling new data. Previously imported transactions remain in your ledger as historical records. You can request deletion separately by emailing privacy@medianfi.com.
8. Gramm-Leach-Bliley Act and Financial Privacy
Median handles nonpublic personal information ("NPI") as that term is used in the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations. We access, use, retain, and disclose NPI only as described in this policy, as permitted by law, and in compliance with the obligations we have under our agreements with data providers like Plaid. We do not sell NPI, and we do not share it with unaffiliated third parties for their own marketing purposes.
9. Data Storage and Security
- All data is encrypted in transit using TLS and at rest using industry-standard algorithms
- Financial data is stored in access-controlled databases with audit logging
- We run on infrastructure that follows SOC 2-aligned security practices
- Access to production systems is limited to personnel who need it, with multi-factor authentication and least-privilege controls
- We perform regular backups and maintain disaster recovery procedures
- We maintain an information security program designed to protect NPI in a manner consistent with the GLBA Safeguards Rule
Audit roadmap. Median is pursuing independent security attestation on an accelerated timeline. Our current targets are a SOC 1 Type I attestation in May 2026 and a SOC 2 Type I attestation in the second half of 2026. Attestation timelines are estimates, not guarantees. When these reports become available, current and prospective customers may request a copy under NDA by emailing security@medianfi.com.
No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you without undue delay and, where applicable, notify regulators and affected data subjects in accordance with applicable breach notification laws, including the 72-hour supervisory-authority notification requirement of GDPR Article 33 where the GDPR applies.
10. Data Retention
We retain personal information only as long as we need it for the purposes described in this policy and to comply with our legal and contractual obligations. Our general retention schedule:
- Customer Data (bank and credit card transactions via Plaid, Stripe balance transactions via the Stripe App, uploaded documents, general ledger entries, reconciliations, financial statements, reports, tax returns, and related workpapers): retained in full for as long as the account is active. For up to seven (7) years after account closure, retained so that we can respond to IRS or state tax audits, regulatory inquiries, or the customer's own follow-up requests.
- Account identity and billing records (name, email, company legal name, Stripe customer ID, invoice history): for the life of the active account plus seven (7) years after the final invoice, consistent with IRS recordkeeping rules.
- Support and communications records (emails, chat messages, onboarding call recordings and transcripts): up to three (3) years after the last interaction with the customer.
- Cookie consent records and marketing preferences: up to three (3) years after consent was last refreshed or withdrawn. Unsubscribe and do-not-contact flags are retained indefinitely so we do not accidentally re-contact someone who has opted out.
- Affiliate referral codes: up to sixty (60) days in your browser. Once a referral is credited, the resulting record is held by our affiliate platform for as long as the commission relationship lasts.
- System, audit, and access logs: up to one (1) year for general application logs; up to two (2) years for authentication and security-sensitive logs.
- Analytics and usage data: in GA4, up to two (2) months for event-level data and up to fourteen (14) months for user-level data; up to thirteen (13) months in Contentsquare; indefinite in aggregated, de-identified form.
- Backups: point-in-time recovery backups are retained for up to thirty-five (35) days, and snapshot archives for up to ninety (90) days. Data deleted from production typically persists in backups until the next rotation cycle ages it out.
You can request earlier deletion of personal information that is not required to be kept for tax, legal, or regulatory reasons by contacting privacy@medianfi.com. Some information may be retained longer when required by law, necessary to resolve a dispute, or needed to enforce our agreements. Retention periods may also be extended by a legal hold, a regulatory investigation, or a customer's written request.
11. International Data Transfers
Median is based in the United States and stores and processes personal data in the United States on infrastructure provided by our cloud and subprocessor partners. If you are located outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home jurisdiction.
Current scope. Median is a United States business and does not currently direct or target the Service at residents of the European Economic Area ("EEA"), the United Kingdom, or Switzerland. We do not have an EU establishment, we do not offer the Service in EU languages or currencies, and our pricing and marketing are US-focused. As a result, most data transfers under this policy do not cross into scope of the GDPR or UK GDPR in the first place.
Transfer safeguards. Where a customer or end user is located in the EEA, the UK, or Switzerland and their data is transferred to the United States through the Service, Median relies on appropriate safeguards under applicable data protection laws, including:
- The European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor) for transfers from the EEA to the United States
- The United Kingdom's International Data Transfer Addendum for transfers from the United Kingdom
- The Swiss Federal Data Protection and Information Commissioner's recognition of the Standard Contractual Clauses for transfers from Switzerland, with Swiss-specific adaptations
- Supplementary technical and organizational measures (encryption in transit and at rest, access controls, and the information security program described in Section 8)
Median is willing to execute a Data Processing Addendum that incorporates these transfer mechanisms on request from any EEA, UK, or Swiss customer. Email privacy@medianfi.com to request a copy or to initiate the process.
Our subprocessors (listed in Section 5) are themselves bound by their own transfer safeguards with Median, which they make available on request.
12. Your Rights
Regardless of where you live, you can:
- Access or export your financial data at any time through the Service
- Disconnect any integration from Settings
- Request correction of inaccurate account information
- Request deletion of your account and personal information by emailing privacy@medianfi.com
- Opt out of non-essential marketing emails by using the unsubscribe link in any email
- Contact us at privacy@medianfi.com with any privacy question or complaint
We will respond to verifiable requests within the time required by applicable law. We may need to verify your identity before fulfilling a request, and we may decline requests that we cannot verify or that are excessive or unfounded.
If you are in the EEA or the UK
You have rights under the GDPR and UK GDPR including: access, rectification, erasure, restriction of processing, data portability, objection to processing (including direct marketing), and the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. You also have the right to lodge a complaint with your local supervisory authority.
If you are a California resident
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), you have the right to:
- Know what personal information we have collected about you, the sources, the business purpose, and the categories of third parties we share it with
- Delete personal information we have collected from you, subject to certain exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information. Median does not sell personal information and does not share personal information for cross-context behavioral advertising, so there is nothing to opt out of in this respect
- Limit the use and disclosure of sensitive personal information. We only use sensitive personal information to provide the Service you requested, to prevent fraud, and for other purposes permitted by law
- Not be discriminated against for exercising any of these rights
You may authorize an agent to make a request on your behalf. To exercise any of these rights, email privacy@medianfi.com.
Other U.S. state privacy laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have rights similar to those above. We honor these rights in the same way we honor California and EEA rights. Email privacy@medianfi.com to exercise them.
13. Do Not Sell or Share
Median does not sell personal information, and Median does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA and CPRA. We do not engage in targeted advertising using personal information.
14. Automated Decision-Making and AI
The Service uses automation, machine learning, and artificial intelligence to categorize transactions, reconcile accounts, detect anomalies, and produce draft reports. Qualified human accounting professionals review, supervise, and correct automated outputs.
Median does not make decisions about you that produce legal effects or similarly significant effects based solely on automated processing without meaningful human involvement. We do not use your financial data to train artificial intelligence models that are made available to other customers in a way that would expose your specific information, and we do not sell your data to AI model providers.
15. Children's Privacy
The Service is for businesses. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@medianfi.com and we will delete it.
16. Cookies and Tracking
We use two categories of cookies and similar technologies on medianfi.com and in the Median application:
- Strictly necessary: required to run the Service, keep you signed in, remember your preferences (including your cookie consent choice), and keep the Service secure. These are loaded on every visit and cannot be turned off.
- Analytics and advertising: optional cookies from Google Tag Manager, Google Analytics (GA4), Google Ads, Meta (Facebook) Pixel, Reddit Pixel, and Contentsquare. These help us understand how the Service is used and measure advertising effectiveness. They are only loaded if you accept them via the cookie consent banner.
- Affiliate attribution: if you arrive on medianfi.com through a partner or affiliate link (a link containing a
?red=code), we store that partner's code in a first-party cookie for up to sixty (60) days so we can credit them if you later become a customer. We share the code with our affiliate platform, Reditus, only at the point you give us your email address, for example by submitting a form or booking a call. No Reditus cookies or scripts are loaded while you browse, and nothing is sent to Reditus if you never contact us. To remove the code, clear cookies for medianfi.com in your browser.
Your choice. The first time you visit medianfi.com, a consent banner asks whether you want to allow all cookies or only strictly necessary ones. Your choice is stored locally and honored on subsequent visits for up to twelve (12) months. You can change or withdraw your choice at any time by clicking "Cookie preferences" in the footer of any page on the website. If you withdraw consent, analytics and advertising scripts will not load on future page views, though cookies already set by those services may remain until they expire or you clear them from your browser.
Do Not Track. Because there is no industry-standard response to Do Not Track browser signals, we do not currently respond to them as a substitute for the consent banner. You should use the banner or your browser's cookie controls to manage your preferences.
17. Data Breach Notification
If we discover a security incident that affects your personal information, we will notify you without undue delay and, where applicable, notify relevant regulators and affected data subjects in accordance with applicable breach notification laws. For individuals and customers to whom the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a reportable personal data breach, consistent with GDPR Article 33. For U.S. state notification laws, we will meet the notification windows required by each applicable state. Our notification will include, at minimum, what happened, what categories of information were affected, what we are doing about it, and what you can do to protect yourself.
18. Changes to This Policy
If we make meaningful changes to this Privacy Policy, we will notify you by email or through the Service at least thirty (30) days before the change takes effect, unless a shorter period is required by law. Minor wording fixes may not trigger a notification, but the "last updated" date at the top will always reflect the most recent version. Continued use of the Service after a change takes effect means you accept the updated policy.
19. Contact Us
Questions, privacy requests, or complaints? Email privacy@medianfi.com or write to us at:
Median Labs Inc.
447 Broadway, Fl 2 Ste 559
New York, NY 10013
United States
For general support, email support@medianfi.com. For legal matters, email legal@medianfi.com. For security incident reports, email security@medianfi.com.