Privacy (summary)
1. Client-confidential information
Client-confidential information you upload is used to perform the analysis you requested. It is not shared externally and not disclosed to other firms. Your firm remains responsible for its own confidentiality obligations.
2. De-identified usage data
To continuously improve service quality, de-identified usage data may be used to improve the system — with client confidentiality preserved.
3. What the contact form collects
The homepage has one form. It runs three errands — a WorkpaperIQ demo, trouble signing in, and a request about the data we hold on you — and which of the three you want is the first thing it asks, as a choice of three, so nothing has to be guessed from what you write. It collects what you type into it: the errand you pick, your work email, your name and your firm where you fill them in, and any note you choose to leave. Only the errand and the email address are needed; the name, the firm and the note are optional and marked as such on the form. All of it reaches the same small team by email — that is how we answer you — and we use it to reply and to follow up, and for nothing else. If you arrive from an advertisement or a shared link, the campaign tags already present in that link (for example utm_source) are submitted with the form so we know which channel to credit.
Alongside what you typed we record the IP address the request arrives from, and keep it with the request as a spam control — it is what tells a script filling the team's inbox apart from three colleagues at one firm writing in the same week. It is cleared from the stored request after 90 days. The form also carries the two anti-bot checks described in §5 — how long the form was open, and a decoy field hidden from people — and both are read at the moment you submit. We do not run third-party ad trackers, analytics scripts, or advertising pixels on this site.
4. What a free account collects
Creating a free account is optional, and it is the only place on this site where we ask you for a password. The signup form requires three answers, and nothing else on the page has to be filled in at all:
- your work email address — which is also your sign-in name;
- a password — stored only as described below;
- your name.
Everything else sits behind an optional section headed “Tell us a bit more”, closed until you choose to open it. It helps us tune the inspection themes to your kind of firm, and you can create the account without ever opening it. What it asks, if you do:
- your firm — offered as a guess made in your own browser from the domain of the address you typed, and yours to correct or clear;
- your job title, and the size of your firm, each chosen from a list;
- whether your firm is PCAOB-registered — yes, no, or not sure;
- the one thing you would most like to fix, chosen from a list (with a line of your own if you pick “Something else”);
- if you ask for a WorkpaperIQ demo at the same time, whatever you would like that demo to cover.
An optional answer you leave blank records nothing. The field is simply empty on your account: there is no value for us to count, sort, segment or follow up on, and skipping the section costs you nothing — the free account, the daily analysis and the knowledge-base search are the same either way.
Alongside those answers we store three things about the act of registering: a record of which version of the Terms of Use and these privacy notes you agreed to, and when (the one version string those two pages share — see the block at the foot of this page); whether you ticked the box asking for occasional product news, which is never ticked for you; and the invite code, if a colleague's invite link brought you here — so we know to credit them the extra daily analysis.
Your password is stored only as a salted one-way hash. We cannot read it, and nobody here can tell you what it is.
We do not send a verification email today, so we cannot confirm that an address really belongs to you — please check yours carefully when you register. Trouble signing in is handled by a person — there is no reset link yet: use the contact form, write from the address the account is under, and we will sort it out with you.
When you sign in, we record the time of the sign-in and the IP address it came from, so that an account and its free daily allowance can be traced if something looks wrong.
5. What your browser tells us automatically
When you open the signup page and when you submit it, your browser passes along a handful of technical signals. We record them with your account. Nothing here is a cookie set for tracking, and none of it follows you to other websites — but you should know it is collected, because it is:
- IP address — the network address your request arrives from;
- user-agent — the browser and operating system your device reports;
- screen size and pixel ratio, and your device's time zone, as your browser reports them;
- the page you came from (the referrer) and the page on our site you landed on;
- campaign and click parameters carried in the link you followed — utm_source, utm_medium, utm_campaign, utm_term, utm_content, and ad-click identifiers such as gclid;
- how long the signup form was open before you submitted it, together with a decoy form field that is hidden from people and only ever filled in by an automated script. Both are checked at the moment you submit, as a bot filter.
We use these for three purposes, and no others:
- Preventing abuse and fraud. The free tier costs us real money per analysis. These signals are how we notice a script registering accounts in bulk rather than an accountant signing up.
- Running the free daily allowance. Free analyses are metered per account per day, and there is a shared ceiling on what the whole free tier can spend in a day. Keeping the signals with the account is what lets us see which usage was ordinary and which was not.
- Product and channel analysis. Which pages and campaigns bring people here, which screen sizes and time zones our audience actually has, and which parts of the signup people abandon.
We do not sell this information, do not share it with data brokers or advertising networks, and do not use it to build a profile of you across other sites. If several people from the same firm register, our team is alerted internally so that one of us can follow up — that is decided from the domain part of a work email, and addresses at public mailbox providers (Gmail, Outlook, Yahoo, QQ, 163 and the like) are excluded from it entirely.
6. Marketing email
We email you about your own account when it matters — a demo you asked for, a problem with sign-in. Product news and inspection-theme write-ups go only to people who ticked that box at signup, and every one of those emails carries a one-click unsubscribe link that takes effect immediately; you can also ask us to switch it off through the contact form.
7. Third-party requests your browser makes here
The homepage, the workspace, and InspectionIQ load their typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). That request is made by your browser directly to Google and, like any web request, carries your IP address and browser user-agent. It is used to deliver the font files and nothing else — it sets no cookie, carries no identifier from us, and no workpaper, engagement, or account information is involved. The signup page and these Terms and Privacy pages load no third-party resources at all — deliberately, because the signup page is where you choose your password. The sign-in card is different: it sits inside the workspace page itself, so opening it makes the Google Fonts request described above — that request, and no other. Nothing else on this site fetches from a third-party host.
8. Where analysis runs
Analysis for client firms runs on vetted enterprise AI providers under the terms of the services agreement; client tiers are pinned to providers selected for confidentiality posture.
Free InspectionIQ analyses work from the industry, audit area and short description you type in — they are not a place to upload workpapers, and you should not enter client names or other client-identifying detail there. What you enter is sent to the same AI providers to produce your result.
9. How long we keep things, and how to have them removed
Session records for client firms support your firm's review trail, and deletion on request is honored per the services agreement.
For free accounts, trial usage records — which day an analysis ran, the technical signals in §5, and the daily cost ledger behind them — are kept for 90 days and then cleared. Your account record itself (your email, the answers you gave on the form, and the record of the terms you accepted) is kept for as long as the account exists, because it is what the account is.
The analyses themselves are not on that 90-day clock. What you type into a free InspectionIQ run — the industry, the audit area, and your description of the engagement — and the memo it produces are kept with your account, so that a run from last month is still there to reopen rather than to repeat. They stay until you ask us to remove them, or until the account is deleted, which removes them with it.
To get a copy of what we hold on you, to correct it, or to have one analysis — or the whole account and its records — deleted, ask us through the contact form. We handle these by hand today — there is no self-service button yet — so please write from the address on the account, since that is the only way we can tell it is you. We will confirm when it is done.
One version string, two pages. This string covers the text on the Terms of Use page and on these Privacy notes together — neither page carries a number of its own. When you create a free account, this exact string is recorded with your account alongside the date and time you accepted it.
It moves only when the substance of either page moves, and when it moves, both pages and the signup record move with it. A correction that changes the wording without changing what we do is shown as a revision date instead: the revision of 4 September 2026 rewrote §3, because the homepage now has one contact form rather than two, and §4, to separate the three answers the signup form requires from the optional ones and to say what happens to an optional answer left blank.
Whatever string you accepted stays on your record exactly as it was; a later revision never rewrites it.