Privacy Policy
Who we are
InCite is a mission-sustainability platform for nonprofit organizations, built and operated by FitProof (“FitProof,” “we,” “us”). This policy describes how we collect, use, store, and protect information when your organization uses InCite, including its integrations with third-party systems and its AI assistant. Questions: Info@fit-proof.com.
Information we collect
Information your organization provides
- Account information: names, work email addresses, and roles of the people your organization authorizes to use InCite.
- Documents your organization uploads: financial statements, IRS filings, audits, contracts, policies, grant records, and similar organizational documents.
- Data your organization enters in the product: programs, budgets, decisions, tasks, notes, and configuration.
Information from connected systems (integrations)
When an administrator at your organization connects a third-party system, InCite reads data from it under credentials your organization controls. Connections are read-only wherever the vendor supports it. Depending on what your organization connects, this may include:
- Accounting and ledger data (for example QuickBooks Online, Microsoft Dynamics GP): chart of accounts, journal entries, vendors, bills, and payments.
- Point-of-sale and payment data (for example Square): sales, tenders, fees, and settlement summaries.
- Accounts-payable data (for example BILL): bills, vendors, approvals, and payment records.
- Payroll and workforce data (for example ADP, Paylocity): payroll cost and its allocation to programs and grants.
- Corporate card and spend data (for example Brex): card transactions and expenses.
- Case-management and service data (for example Foothold AWARDS, Apricot by Bonterra, Therap): program, service, and outcomes records, which may include protected health information (“PHI”) where your organization’s programs involve it.
Information collected automatically
- Sign-in and security records (authentication events, including multi-factor authentication).
- Operational logs needed to run and secure the service (errors, sync results, audit trails of administrative actions).
InCite does not sell advertising and does not use third-party advertising trackers.
How we use information
- To provide the service: organizing your organization’s data, reconciling figures across sources, computing metrics and scores, generating reports, and answering questions through the AI assistant.
- To keep the service secure and reliable: authentication, access control, monitoring, and troubleshooting.
- To support your organization: responding to requests and investigating issues you report.
The AI assistant
InCite includes an AI assistant that analyzes your organization’s data to answer questions and produce reports. Its computations run on our servers; figures it reports come from your organization’s own records and connected systems. Where document content may contain PHI, InCite applies an automated screening layer designed to prevent PHI from being sent to AI providers that are not under a business associate agreement with us.
How information is protected
- Encryption in transit and at rest, using the security infrastructure of Google Cloud, our primary hosting provider.
- Integration credentials (such as OAuth tokens and API keys) are stored server-side in a managed secret store; they are never exposed to web browsers and never sent by email.
- Tenant isolation: each organization’s data is segregated and access-controlled so it is available only to that organization’s authorized users.
- Role-based access and multi-factor authentication for user sign-in.
- Where an organization’s use of InCite involves PHI, we operate under a business associate agreement (BAA) with our hosting provider, and we sign BAAs with customer organizations as required by HIPAA.
Who we share information with
We share information only with service providers needed to run InCite (for example, cloud hosting and AI processing providers), under contracts that restrict their use of the data to providing their service to us. We may disclose information if required by law. We do not sell or rent customer information. If FitProof is involved in a merger or acquisition, customer data would remain subject to commitments at least as protective as this policy.
Your organization’s control
- Your organization owns its data. Administrators control who has access and which systems are connected.
- Integration access can be revoked at any time — either inside InCite or directly in the connected system (for example, disconnecting the app inside QuickBooks or Square).
- Deleting an uploaded document removes the records extracted from it.
- On termination of service, your organization may request export of its data, and we delete customer data from production systems within a commercially reasonable period thereafter, subject to legal retention requirements.
Data retention
We retain customer data while the customer relationship is active and as needed to provide the service. Security and audit logs are retained for a limited period for the protection of the service and its customers.
Individuals’ rights
InCite is a business-to-business service: the data in InCite is controlled by the customer organization. If you are an individual whose information appears in a customer’s data and you wish to exercise privacy rights, please contact that organization; we support our customers in responding to such requests. For questions about FitProof’s own handling of information, contact Info@fit-proof.com.
Children
InCite is a workplace tool for organizations and is not directed to children. Customer organizations may store service records that concern minors served by their programs; that data is controlled by the customer organization and protected as described above.
Changes to this policy
If we make material changes to this policy, we will update this page and notify customer administrators. The effective date above reflects the latest revision.
Contact
FitProof · Info@fit-proof.com
Mobile applications
Some parts of InCite are delivered as a mobile application rather than through a web browser. Our service documentation application for direct support professionals is one of these. Everything stated elsewhere in this policy applies to those applications; this section describes what is specific to them.
What the application collects
The application is used by an employee of a customer organization to record the services that organization delivers. It collects:
- Health information. Records of the services a participant received, the goals those services were delivered against, and staff notes about the session. Where a customer organization is a covered entity or business associate under HIPAA, this is protected health information and is handled under our business associate agreement with that organization.
- Names. The name of the participant receiving a service and the name of the staff member recording it.
- Identifiers. Employee and participant identifiers assigned by the customer organization, used to attribute each record to the right person.
- Photographs. Photographs taken by the staff member, at their initiative, as evidence that a service was delivered. The application does not access the device's existing photo library and does not capture images in the background. The camera is used only when the staff member opens it and takes a photograph.
This information is collected because the application cannot perform its function without it. It is not used for advertising, marketing, or product personalization, and it is not used to build profiles of individuals for any purpose other than the customer organization's own service documentation. We do not track users across other companies' apps or websites, and we do not share this information with data brokers or advertising networks.
Dictation
Staff may dictate notes rather than type them. Speech is converted to text by the device's own operating system. We receive only the resulting text; we do not record, transmit, or store audio.
Signing in on a shared device
These applications are typically installed on a device shared by a team rather than owned by one person. A staff member starts a shift by identifying themselves with an employee identifier and a personal code, or by tapping an assigned badge. The personal code is verified on our servers and is stored only as a cryptographic hash, so it cannot be read back by us or by anyone with access to our systems. Every record created during that shift is attributed to the staff member who signed in.
Information stored on the device
The application keeps a working copy of the day's assignments and the entries made during a shift on the device, so that a staff member can continue working where network coverage is poor. That copy is synchronized to our systems and is not retained on the device beyond what is needed for the current work. Devices used for this purpose are managed by the customer organization, which is responsible for device passcodes, encryption, and the return or wiping of devices when a staff member leaves.
Who controls this information
The customer organization is the controller of the participant and staff information recorded through the application. FitProof processes it on that organization's instructions. A participant, a participant's guardian, or a staff member who wants to see, correct, or delete information recorded about them should contact the organization that provides their services or employs them. We will support that organization in responding.
Children
Some customer organizations serve minors, and service records created in the application may concern them. Those records are created by the organization's employees in the course of delivering services, under that organization's authority and consents. The application is not directed to children, is not offered to consumers, and is not downloaded or used by the individuals whose services it documents.