AI Policy
Effective date: September 01, 2026
Francis includes AI features to help you work faster with your financial data, including an AI agent that can work alongside you in your Workspace. This AI Policy explains how those features handle your data, how the agent works, and the commitments we make when you use them.
It works alongside our Terms of Service and Data Processing Addendum (DPA), and uses the same defined terms (such as Customer Data, Workspace and Services). Where this Policy and the Terms of Service overlap, they're intended to say the same thing.
You're in control
AI features are optional and off by default. The Workspace Owner chooses whether to turn them on, and can turn them off at any time. Until an Owner turns them on, no AI feature processes your Customer Data.
Turning AI features on means that when you use them, your Customer Data is processed by the sub-processors we use to deliver them. Today the agent runs on Claude, from Anthropic. The current list, with where each sub-processor processes data and the safeguards that apply, is in Schedule 3 of our DPA.
Turning them off stops any further Customer Data reaching those sub-processors.
We never train AI models on your data
We do not use your Customer Data to train or fine-tune AI models, ours or our providers'. Our AI providers are contractually barred from training their models on your data. Any data they do hold is kept for a limited period, and only to deliver the feature, to detect and prevent misuse of their services, or where the law requires it. This matches the commitment in our Terms of Service.
How the AI agent works
The agent works inside Francis, on your data, so the rules it operates under matter as much as what it can do. These are those rules:
- It never has more access than the user it ties to. The agent acts for the person using it and inherits that person's permissions. It cannot see or change anything that person could not see or change themselves.
- It works in the Platform, the way you do. The agent uses the same features and tools that are available to you, not a separate route into your data.
- The Platform does the calculations, not the AI agent. Figures are calculated by Francis's own engine, which produces the same result every time. Where the agent works something out itself instead of using the engine, it tells you.
- You check its work, and you stay accountable for it. AI can make mistakes or produce incomplete results, so its output should always be reviewed by a person before you rely on it.
- Every change is logged. Changes are recorded in the model edit log, showing what changed and who or what changed it, so you can review, compare and roll back.
- You always know when you're talking to an AI. We make it clear when a feature uses AI, and when content was generated by it.
- It shows its work. The agent explains what it's doing as it goes, so you can follow along and check it.
- It supports you, it doesn't decide for you. Our AI features are there to assist your analysis, not replace your judgement. What you publish, even when produced with AI, remains yours.
Keeping AI features accurate and safe
We check prompts and responses so we can catch and correct errors and keep outputs accurate and safe. Some of these checks are automated. Some involve review by our technical product team, usually when a problem is detected or reported, and sometimes as a routine check on quality. This is part of providing the feature, not model training. It happens only if your Workspace Owner has turned AI features on, and access is limited to the people who need it for this purpose.
Your data stays as protected as the rest of Francis
When you use an AI feature, your Customer Data gets the same protection as everywhere else in Francis:
- it's processed only to deliver the feature you've chosen to use, on your instructions;
- the AI providers we use act as our sub-processors, under the same confidentiality and security obligations, and are listed in (or referenced by) our DPA;
- it's covered by the same security measures and access controls as the rest of the platform.
Where AI processing happens
AI processing takes place in the United States. Because that is outside the EU/EEA, we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses, as described in our Terms of Service and DPA. Schedule 3 of the DPA names each AI provider, where it processes data, and the transfer mechanism that applies. AI processing is otherwise subject to the same data-protection safeguards as the rest of the platform.
Changes to this Policy
We may update this Policy as our AI features develop. We'll post changes here with a new effective date.
Contact
Questions about this Policy? Email us at support@francis.app.