PRIVACY POLICY
Balanced — California Fiduciary Accounting Software
Last Updated: September 30, 2026
1. INTRODUCTION
This Privacy Policy describes how Balanced Legal Technology, LLC (“Balanced,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the Balanced website (balanced.law), one-time accountings ordered at balanced.law/accounting (“One-Time Accountings”), the Balanced desktop application (“Software”), and related services (collectively, the “Services”).
This Policy applies to information collected through (a) the Balanced website, (b) the installed Software, and (c) communications you send to us (e.g., support email). The Software’s data-handling practices are also addressed in detail in Section 4 of the End User License Agreement (“EULA”), which is the controlling document with respect to the Software. This Privacy Policy summarizes those practices in plain language and adds disclosures specific to the website and other Services.
If a conflict exists between this Privacy Policy and the EULA with respect to the Software, the EULA controls. For One-Time Accountings, the data-handling practices are set out in Section 8 of the Terms of Service for One-Time Accountings, which is the controlling document for those orders; Section 6A below summarizes them.
2. WHO WE ARE
Balanced is operated by:
Balanced Legal Technology, LLC
California Limited Liability Company
Contact: support@balanced.law
3. INFORMATION YOU PROVIDE TO US
We collect information you voluntarily provide when you:
- Purchase a license. During checkout (handled by our payment processor, Stripe), you provide your email address, firm name, and billing information. Payment card details are entered directly into Stripe’s checkout form and are never seen, stored, or transmitted by Balanced.
- Order a One-Time Accounting. You provide your email address (entered twice), a matter name, and, if you have one, a discount code. Payment card details are entered directly into Stripe’s payment form within the page and are never seen, stored, or transmitted by Balanced. The statements and documents you add are described in Section 6A.
- Contact support. When you email support@balanced.law, the contents of your message and any attachments are received by us.
- Activate the Software. The Software uses the email address and firm name on your license key for license validation. Your firm name is converted to an irreversible short hash (the “firm hash”) and embedded in the license key — see Section 6 below.
4. INFORMATION COLLECTED AUTOMATICALLY ON THE WEBSITE
When you visit balanced.law, the following information is collected automatically:
- Microsoft Clarity analytics. We use Microsoft Clarity to understand how visitors use the website (session replay, heatmaps, anonymized visit data). Clarity does not collect personally identifiable information without your input. Microsoft’s privacy practices for Clarity are described at privacy.microsoft.com.
- Cloudflare logs. The website is hosted on Cloudflare, which logs IP addresses, request timestamps, user-agent strings, and similar technical data for security, abuse prevention, and operational purposes. Cloudflare’s privacy practices are described at cloudflare.com/privacypolicy.
- Cookies. We do not set marketing or advertising cookies. Microsoft Clarity and Cloudflare may set technical cookies necessary for their respective functions.
5. INFORMATION THE SOFTWARE DOES NOT TRANSMIT
The Software processes your PDF financial statements entirely on your local device. The following are NEVER transmitted to Balanced under any circumstances:
- Your original PDF financial statement documents
- Your payment card details (handled directly by Stripe; we never receive them)
See EULA Sections 4.1, 4.15, and 4.18 for the full disclosure of what is and is not transmitted, and Section 6 below for what limited diagnostic information may be transmitted.
6. INFORMATION THE SOFTWARE DOES TRANSMIT
The Software transmits only two narrow categories of information to Balanced, both fully disclosed in the EULA:
6.1 Diagnostic Telemetry (EULA Sections 4.2–4.5)
When the Software’s internal quality-assurance processes detect an incomplete extraction, the Software transmits an automatically-generated diagnostic data fragment to Balanced over an encrypted (TLS) connection. The fragment does NOT contain the actual PDF document itself, but rather diagnostic structural metadata essential for understanding layout patterns, column placement, summary locations, institution-unique dollar-amount identifiers (i.e. whether dollar symbols ($) are used, the number of decimal places used, whether cash outflows use negative symbols (-) or parenthesis, etc.) and similar information necessary to improve data extraction. The fragment is not a copy of, image of, or visual reproduction of the source PDF document.
Diagnostic telemetry is retained to validate that future Software updates do not break prior extraction accuracy. See EULA Section 4.16 for full details.
6.2 Anonymous Usage-Analytics Ping (EULA Section 4.5a)
When you click the “Generate Accounting” button in the Software, and again when that run finishes, a fire-and-forget transmission containing exactly three fields is sent to Balanced over an encrypted (TLS) connection:
- An irreversible firm hash (the first 8 hexadecimal characters of a SHA-256 hash of your lowercased firm name)
- The Software version string (e.g., “1.5.57”)
- A one-word run outcome, from a fixed list:
started,balanced,imbalanced,imbalanced_dup,imbalanced_unsent, orerror
The run outcome is a category only. It tells us whether an accounting balanced and whether the diagnostic report reached us — never by how much, over what period, for which institution, or anything else drawn from your documents. We use it to confirm that the diagnostic telemetry described in Section 6.1 actually reaches us when a run produces one, so that a defect which silently prevents it can be found and fixed.
No other information is transmitted with this ping. The full disclosure is in EULA Section 4.5a.
6A. ONE-TIME ACCOUNTINGS (balanced.law/accounting)
This section summarizes how One-Time Accountings handle your information. The full and controlling disclosure is Section 8 of the Terms of Service for One-Time Accountings.
6A.1 Your Original PDF Documents Never Leave Your Computer
The privacy architecture of a One-Time Accounting begins on your own computer. Your PDF statements and documents are opened and read locally, in your web browser. Your original PDF documents are never uploaded, transmitted, copied, or provided to Balanced under any circumstances.
What is transmitted, and only after your payment is completed, is a machine-oriented text data artifact produced by that local reading process: the text and figures extracted from your documents. It is not a copy, image, scan, or visual reproduction of any document. The images, logos, letterhead, signatures, and visual appearance of your documents are discarded and never transmitted. This transformation from the original document to extracted text data is the primary privacy and confidentiality boundary of the Service.
6A.2 Local Anonymization Before Transmission
Before any extracted text data leaves your computer, the Service applies an automated anonymization step, on your own computer, that identifies and redacts Social Security numbers. The anonymization step is designed to preserve the financial and descriptive information needed to prepare your accounting, including account information, dollar amounts, dates, transaction, payee, and description details, and holdings.
The extracted text data is transmitted over an encrypted (TLS) connection, together with the file names, the accounting period you entered, and your carry-forward file (if any).
6A.3 Anonymization Limitations
A fiduciary accounting cannot be prepared without the account and transaction information in your statements, and that information may identify individuals, institutions, or accounts. While the Service employs commercially reasonable automated redaction, Balanced cannot guarantee that the anonymization step will detect and redact every Social Security number or other sensitive identifier. Please do not submit any document or information that is not needed to prepare the accounting. See Terms Section 8.2a.
6A.4 Order Information
When you place an order, the email address you enter, the matter name, any discount code, and the number of files you are submitting are sent to us so that we can process your payment and deliver your accounting. Our hosting provider also records the country your order came from. Payment card details are entered directly into Stripe’s payment form and are never seen, stored, or transmitted by Balanced.
6A.5 How It Is Used
To prepare, check, review, and deliver your accounting; to send you the two order emails (confirmation when your accounting begins, and delivery when it is complete); to provide support; to keep a record of your order; and to test, maintain, and improve the Service, including as part of the permanent regression test collection described in Section 6A.6.
6A.6 Retention Is Necessary for the Service to Function and Improve
The extracted text data and the delivered accounting are retained and incorporated into a permanent regression test collection. Before any new version of the Service is used, it is tested against the statement formats it has already processed, so that an improvement made for one customer never breaks the accuracy of another customer’s accounting. This retention is not an ancillary collection practice: the permanent regression test collection is a load-bearing component of the Service itself (Terms Section 8.5). The matter name is used to label your delivered accounting and is deleted from our order record after it is sent. Your email address and the other order details are retained as a record of your purchase.
6A.7 No Sale, No Third-Party Use, No AI Training by Balanced
Your statements, documents, and accounting are never sold, rented, traded, or disclosed to any third party for its own purposes, and are never used for marketing, advertising, or profiling. Balanced does not train artificial intelligence models, machine learning models, large language models, or neural networks on them. Access is limited to authorized personnel and to service providers processing data for us (Section 8), and they are treated with the same care we use to protect our own confidential information, and not less than reasonable care.
7. HOW WE USE INFORMATION
We use the information described above for the following purposes:
- Prepare and deliver One-Time Accountings: as described in Section 6A
- Deliver and operate the Software — including issuing license keys, validating activations, and providing support
- Process payments — through Stripe (we never see card details)
- Improve the Software — through the diagnostic telemetry described in Section 6.1
- Understand product usage — through the usage-analytics ping described in Section 6.2
- Improve the website — through Microsoft Clarity analytics
- Respond to your inquiries — when you contact us
- Comply with legal obligations — when required by law or court order
We do not use any of this information for marketing, advertising, profiling, training of artificial intelligence models, or sale to third parties.
8. THIRD-PARTY SERVICE PROVIDERS
We use a small number of service providers to operate the Services. Each is contractually bound to use information only for the purposes described below and to maintain reasonable security practices. We do not authorize any service provider to use your information for their own marketing or to sell it.
The categories of service providers we use are:
- Payment processing (Stripe)
- Email delivery
- Cloud hosting, storage, and content delivery
- Server infrastructure
- Code hosting
- Artificial intelligence tools
- Website analytics
- Business email
Our service providers process information for us to operate the Services, not for their own purposes, and never sell it. A current list of our service providers is available on request at support@balanced.law.
9. DATA SHARING
We do not sell, rent, trade, or share your personal information with third parties for their own marketing, advertising, or any other purpose, except as follows:
- Service providers — as described in Section 8, strictly to operate the Services
- Legal compliance — if required by valid legal process (subpoena, court order, etc.)
- Business transfers — in the event of a merger, acquisition, or sale of substantially all assets, your information may transfer to the successor entity, subject to the terms of this Policy
10. DATA RETENTION
- Email addresses and license records — retained for as long as you maintain an active license, plus a reasonable period thereafter for tax, accounting, and legal-record purposes
- One-Time Accountings: extracted text data and delivered accountings retained indefinitely for records, support, re-delivery, and permanent regression testing; the matter name deleted after delivery; email and order details retained as a purchase record (Section 6A.6)
- Diagnostic telemetry — retained for essential product regression testing and validation (EULA Section 4.16)
- Anonymous usage-analytics pings — retained indefinitely in aggregate form (EULA Section 4.5a)
- Website analytics (Microsoft Clarity) — retained per Microsoft Clarity’s default retention (typically 13 months for session data)
- Cloudflare logs — retained per Cloudflare’s standard log-retention practices
- Support email correspondence — retained for as long as reasonably necessary to respond to follow-up questions and to maintain a record of resolved issues
11. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively, “CCPA/CPRA”):
- Right to Know — you may request a copy of the personal information we hold about you
- Right to Delete — you may request deletion of your personal information, subject to limited exceptions
- Right to Correct — you may request correction of inaccurate personal information
- Right to Opt Out of Sale or Sharing — we do not sell or share your personal information for cross-context behavioral advertising, so there is nothing to opt out of
- Right to Limit Use of Sensitive Personal Information — we do not collect sensitive personal information as defined under CCPA/CPRA
- Right to Non-Discrimination — we will not discriminate against you for exercising any of these rights
To exercise any of these rights, email support@balanced.law with the subject line “CCPA Request” and a description of your request. We will respond within the time period required by law (generally 45 days). We may need to verify your identity before fulfilling certain requests.
One-Time Accountings. The statements and documents you submit typically describe other people, such as a decedent, conservatee, trust, or beneficiaries. For that information, you determine the purpose of its submission and Balanced processes it on your behalf to provide the Service (Terms Section 8.8). A request concerning an individual named in an accounting should be directed to the fiduciary or firm that ordered it.
Diagnostic Telemetry Data is deidentified under CCPA/CPRA. As disclosed in EULA Section 4.17, you agree that Diagnostic Telemetry Data is deidentified within the meaning of Cal. Civ. Code § 1798.140(m) and is not “personal information” subject to CCPA/CPRA rights and obligations.
12. CHILDREN’S PRIVACY
The Services are intended for use by professional fiduciaries, attorneys, accountants, and similar professionals. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided information to us, please contact support@balanced.law and we will take appropriate steps to delete it.
13. INTERNATIONAL USERS
The Services are offered solely to users located in the United States. We do not direct the Services to, and the Services are not intended for use by, individuals located in the European Union, the United Kingdom, or any other jurisdiction whose data-protection laws impose obligations beyond those set forth in this Policy or the EULA. See EULA Section 4.19.
14. SECURITY
We use industry-standard security practices to protect information in our custody, including TLS encryption for data in transit, encrypted storage for diagnostic telemetry and One-Time Accounting data, restricted access controls, and reasonable administrative safeguards. However, no system of electronic data transmission or storage is 100% secure, and we cannot guarantee absolute security. Use of the Services is at your own risk.
In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law.
15. THIRD-PARTY LINKS
The website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.
16. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The “Last Updated” date at the top of this Policy indicates when it was last revised. Material changes will be highlighted on the website. Your continued use of the Services after a change takes effect constitutes acceptance of the revised Policy.
17. CONTACT
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your information, please contact us:
Balanced Legal Technology, LLC
Email: support@balanced.law