Firstweek
Log in
How it works Use cases Blog Pricing
Legal

Privacy Policy

Effective 2026-06-12 · Firstweek, Inc.

Firstweek, Inc. ("Firstweek," "we," "our," or "us") is a Delaware corporation. This Privacy Policy explains how we collect, use, share, and protect information when you use our software platform and related services (the "Service").

By accessing or using the Service, you agree to this policy. If you are using the Service on behalf of an organization (a "Workspace"), your organization's agreement with us governs data processing, and this policy applies to the extent not superseded by that agreement.


1. Information We Collect

Account and workspace information

When you create an account or set up a workspace, we collect your name, work email address, company name, and any single sign-on (SSO) identity information provided by your identity provider. Billing contacts and payment method details are collected during subscription setup.

New-hire onboarding data

Workspace administrators submit information about new hires to generate personalized onboarding letters. This includes names, job titles, start dates, role context, department, manager information, LinkedIn profile URLs (when LinkedIn enrichment is enabled), and any other onboarding-related content entered into the Service. This data is provided by the workspace and processed by Firstweek on behalf of the workspace. The workspace is responsible for informing individuals whose data it submits and for ensuring it has the lawful basis to do so.

Integration data

When a workspace administrator connects a third-party integration (such as Slack, GitHub, Notion, Atlassian, or Google Drive), we access content from those services within the scopes you authorize — for example, repository content, channel messages, or documents. This access is read-only, limited to the repositories, channels, or folders you explicitly select, and used solely to generate onboarding content. Raw integration content is not stored in our systems after the generation process completes; only AI-derived analysis and the generated letter are retained as part of the onboarding record. You may revoke any integration at any time from your workspace settings.

Google user data (Google Drive integration)

When a workspace administrator connects the Google Drive integration, Firstweek collects the following Google user data via the Google OAuth 2.0 flow:

  • File names and metadata — the names and MIME types of files in the folder(s) you select, used to identify which documents to read.
  • File content — the text content of files in selected folders, including Google Docs (exported as plain text), Google Sheets (exported as CSV), Google Slides (exported as plain text), PDF documents, Microsoft Office files (.docx, .xlsx, .pptx), and plain text, Markdown, and CSV files. Access is granted via the drive.readonly OAuth scope, which is limited to read operations only. We do not write to, modify, delete, or share any files in your Google Drive.
  • Account email address and display name — collected via the userinfo.email and userinfo.profile OAuth scopes to authenticate and identify the Google account used to connect the integration.

How Google user data is used: Google user data is used solely to generate personalized onboarding letters on behalf of your workspace. File content is read into memory during the letter generation process and discarded immediately after — it is never written to our database. Only AI-derived analysis and the final onboarding letter are retained as part of the onboarding record. The connecting user's email and display name are stored as part of the integration record to support re-authentication and revocation.

Limits on use of Google user data: Google user data is not used for advertising or to build advertising profiles; is not sold, rented, or transferred to data brokers or information resellers; is not used to train or evaluate AI or machine learning models; and is not used for any purpose unrelated to generating onboarding letters for your workspace. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Usage, analytics, and diagnostic data

We collect information about how you interact with the Service — including pages visited, features used, and session duration — to improve the product. We use Google Analytics 4 (GA4) across the authenticated application and public marketing site (see Analytics and Cookies below). Internal staff super-administrator accounts operated by Firstweek are excluded from analytics tracking. No personally identifiable information is embedded in URL paths within the authenticated application.

We also collect anonymized error and crash reports via Bugsnag to identify and resolve application defects. These reports include exception types, messages, and request context. They are automatically redacted to exclude names, email addresses, OAuth tokens, credentials, and any other sensitive field values before transmission.

Communications

If you contact us by email or through the Service, we retain those communications to respond to your inquiry and improve support.

Children's data

The Service is not intended for use with personal data of individuals under 13 years of age (under U.S. COPPA) or under 16 years of age in the EEA or UK (under GDPR Article 8). If you become aware that personal data of a child below these ages has been submitted to the Service, contact [email protected] immediately and we will delete it promptly.


2. Data Controller vs. Processor

Firstweek operates as both a data controller and a data processor, depending on the data:

  • Controller: We are the controller of account registration data, billing information, usage analytics, and diagnostic data — information we collect to operate and improve the Service.
  • Processor: For new-hire onboarding content and integration data submitted by workspace administrators, we act as a processor on behalf of the workspace (the controller). The workspace determines the purposes and means of that processing and is responsible for ensuring it has the rights and lawful basis to submit that data.

Legal basis for processing (GDPR / UK GDPR)

For data subjects in the European Economic Area, United Kingdom, or Switzerland, we process personal data under the following legal bases:

  • Contract performance (Article 6(1)(b)): Account registration data, workspace data, and data necessary to deliver the Service under our agreement with you.
  • Legitimate interests (Article 6(1)(f)): Usage analytics (GA4) and error monitoring (Bugsnag), to improve product quality and service reliability. Our legitimate interest is not overridden by your privacy interests because the data is not linked to named individuals in the reports we receive, no user profiles are built, we do not use it for advertising, and you can opt out of analytics tracking.
  • Legal obligation (Article 6(1)(c)): Data retained to comply with applicable law, including financial record-keeping requirements.
  • Contract performance as processor (Article 6(1)(b)): New-hire onboarding content and integration data are processed on your instruction as part of our contractual obligation to provide the Service. The lawful basis determination for this processing rests with you as the data controller; we process it solely on your behalf under Article 28.

Data Processing Agreement

Enterprise customers and workspaces subject to GDPR who require a Data Processing Agreement (DPA) — including Standard Contractual Clauses for international data transfers and processor obligations per GDPR Article 28 — may request one by contacting [email protected].


3. How We Use Your Information

  • Provide, operate, and improve the Service
  • Generate AI-powered onboarding letters on behalf of workspace administrators
  • Process payments and manage subscriptions
  • Send transactional notifications (onboarding delivery emails, system alerts)
  • Respond to support requests and inquiries
  • Monitor for security incidents, application errors, and system defects
  • Comply with legal obligations

We process your data only for the purposes described above. If we need to use your data in a materially different way, we will update this policy and notify you before doing so.

We do not sell, rent, license, or otherwise monetize your data or your users' data to any third party, for any reason, ever. We do not use customer data — including new-hire information, integration content, or usage data — to build data products, conduct advertising targeting, or derive insights that benefit any party other than you. We do not use your data to train AI models without your explicit prior written consent. Your data exists in our systems solely to provide the Service to your workspace.


4. AI Processing

Onboarding content is transmitted to third-party AI providers to generate personalized letters. By using AI-powered features, workspace administrators authorize this processing.

Firstweek uses one or more third-party AI inference providers to power features including onboarding letter generation. When a workspace administrator initiates letter generation, the relevant onboarding content — including role context, focus areas, and content retrieved from connected integrations — is transmitted to an AI provider for inference. Our current primary AI provider is Anthropic. We may engage additional AI providers for specific features as the Service evolves; any new provider will be listed on our Subprocessors page before it processes customer data.

We select AI providers that operate under zero-retention or equivalent commitments. Under Anthropic's API terms, submitted content is not used to train their models and is not retained for any purpose beyond what is minimally required for safety and abuse monitoring. Customer data transmitted for AI inference is used solely to generate the requested output.

AI training and your data

Customer data — including onboarding content, integration data, and new-hire information — will not be used to train, fine-tune, or evaluate AI models without your explicit prior written consent. This means a separate signed agreement (email confirmation, DocuSign, or equivalent) specifying the data categories, model or training technique, vendor, and retention period. A checkbox during signup or language buried in these terms does not constitute this consent. Running data through a pre-trained model to generate output (inference) does not require training consent when we use zero-retention providers.

AI-generated outputs are suggestions. The workspace administrator is responsible for reviewing generated content before delivering it to a new hire. Firstweek makes no guarantee as to the accuracy, completeness, or fitness of AI-generated content for any particular purpose.


5. Analytics and Cookies

Cookies we use

The Service uses the following types of cookies:

  • Essential cookies: Session and authentication cookies required for the Service to function. These cannot be disabled without impairing core functionality.
  • Analytics cookies: Google Analytics (GA4) sets cookies to collect usage statistics. GA4 analytics cookies persist for up to 2 years; session cookies expire when you close your browser.

Google Analytics

Firstweek uses Google Analytics 4 (GA4), operated by Google LLC, to understand how the product is used and guide product improvements. GA4 receives IP addresses to determine approximate geographic location; Google does not log or store raw IP addresses in GA4. GA4 also collects browser and device identifiers, pages visited, feature interactions, and session duration. Page-level data only is collected within the authenticated application; no personally identifiable information is embedded in URL paths. This data is processed by Google subject to its privacy policy.

Managing cookies and opting out

You can opt out of Google Analytics tracking using the Google Analytics opt-out browser add-on. You may also disable analytics cookies through your browser's privacy settings. Essential session and authentication cookies cannot be disabled without affecting your ability to use the Service.


6. Third-Party Services and Subprocessors

We share data with third-party subprocessors only to the extent necessary to provide the Service. A complete, current list of our subprocessors — including the data they process and their locations — is available at firstweek.app/subprocessors. We conduct due diligence on all subprocessors and require them to maintain appropriate data protection and confidentiality obligations.

Key subprocessors include:

  • Amazon Web Services (AWS) — cloud hosting and data storage (United States)
  • Anthropic (and other AI providers) — AI inference for letter generation; content retrieved from connected integrations is included in inference requests
  • Stripe — payment processing
  • Resend — transactional email delivery (processes recipient addresses and email content)
  • Google Analytics 4 (Google LLC) — product analytics across the full Service, including the authenticated application; transfers data to the United States subject to Google's data processing terms and Standard Contractual Clauses

Additional subprocessors — including error monitoring, URL extraction, and LinkedIn enrichment services — are listed on the Subprocessors page.

LinkedIn profile enrichment (Coresignal)

When the LinkedIn enrichment feature is enabled, workspace administrators may provide a new hire's LinkedIn profile URL. Firstweek uses Coresignal to retrieve publicly available profile data (employer history, education, skills) for use in letter generation. Workspace administrators are responsible for informing new hires that their LinkedIn profile will be accessed for onboarding purposes, and for ensuring this is compliant with their jurisdiction's laws and their organization's obligations. Firstweek acts as a processor in this context; the workspace is the data controller and assumes responsibility for appropriate notice and lawful basis.

URL content extraction (Jina AI)

When you add a link to onboarding content, Firstweek uses Jina AI to fetch and summarize the content at that URL for use in letter generation. Only provide URLs to public, non-confidential content. Do not provide URLs to private, password-protected, or internal confidential documents; doing so would cause that content to be transmitted to Jina AI outside your organization's control.

Subprocessor changes

We keep the Subprocessors page current and update it when vendors are added or removed. For additions or changes that materially affect how your data is processed, we will also post notice in the application. Enterprise customers requiring advance notice and objection rights for subprocessor changes may address this in a Data Processing Agreement.


7. Data Security and Breach Notification

We design our systems with security as a core requirement, applying controls aligned with SOC 2 Trust Service Criteria.

  • Data in transit: All communications between your browser and our servers use TLS. Data exchanged with third-party services and AI providers is transmitted exclusively over encrypted connections.
  • Data at rest: Our database is encrypted at rest. Fields containing personally identifiable information — including new-hire details, SSO configuration, and identity data — are additionally encrypted at the application layer using AES-256 before being written to the database.
  • Tenant isolation: All customer data is scoped to your workspace at every layer of the application. Data from one workspace is never accessible to another. Tenant boundaries are enforced at the query level on every database read and write.
  • Access controls: Access to production systems is restricted to authorized personnel. Administrative access is logged and audited.
  • Data minimization: We collect only data necessary to provide the Service. Analytics data is not linked to named individuals. Error reports are stripped of sensitive field values before transmission.

Data breach notification

In the event of a security incident that compromises personal data, we will:

  • Contain and assess the incident as quickly as practicable;
  • Notify affected workspace owners by email within 72 hours of determining that a breach poses a risk to individuals' rights or freedoms (consistent with GDPR Article 33); and
  • Include in that notification: the categories of data affected, the approximate number of individuals affected, likely consequences, and the steps we have taken or plan to take to address the breach.

For workspaces subject to GDPR, we will provide all information you need to fulfill your own obligations to notify your data protection authority and affected data subjects. To report a suspected vulnerability, contact [email protected].


8. Data Retention

We retain different categories of data for different periods based on their purpose:

  • Account and workspace data: Retained while your subscription is active. Following cancellation or non-renewal, retained for 30 days (export window), then deleted from production systems. Backups purge within an additional 30 days (60 days total from cancellation).
  • New-hire onboarding records: Retained as part of your workspace data and deleted with the workspace, or earlier upon your request.
  • Integration content: Raw content fetched from connected integrations during letter generation is not retained after generation completes. Derived AI analysis and generated letters are stored as part of the onboarding record.
  • Analytics data: GA4 analytics data is subject to Google's standard retention settings (up to 14 months by default).
  • Diagnostic data: Anonymized error reports in Bugsnag are retained for up to 12 months.
  • Billing records: Retained for 7 years to comply with financial record-keeping requirements.
  • Support communications: Retained for up to 3 years.

You may request deletion of your workspace data at any time by contacting [email protected]. We will fulfill deletion requests within 30 days, subject to any legal obligation to retain specific data (such as billing records).


9. Your Rights

We will respond to all verified rights requests within 30 days of receipt, or within any shorter period required by applicable law. To exercise any right, contact [email protected] from the email address associated with your account. We will acknowledge your request within 2 business days and may require identity verification before fulfilling it. We do not charge a fee unless a request is manifestly unfounded or excessive.

All users

  • Access: Request a copy of the personal information we hold about you and how it is used.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information, subject to any legal obligation to retain it.
  • Portability: Request a copy of personal data you provided to us in a structured, machine-readable format (CSV or JSON).
  • Opt out of analytics: Disable analytics tracking via the Google Analytics opt-out tool or your browser's privacy settings.

California residents (CCPA / CPRA)

If you are a California resident, you have the following additional rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Portability: Receive personal information in a portable format.
  • Right to Opt Out of Sale or Sharing: We do not sell personal information and do not share it for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information (as defined by CPRA) for any purpose beyond providing the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
  • Authorized Agent: You may designate an authorized agent to submit rights requests on your behalf by providing written authorization.

To submit a California privacy request, contact [email protected]. We will respond within 45 days; we may extend by an additional 45 days with written notice and explanation.

European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR or UK GDPR:

  • Right of access (Article 15): Obtain confirmation of whether we process your personal data and, if so, a copy along with information about how and why it is used.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete personal data without undue delay.
  • Right to erasure (Article 17): Request deletion of personal data in certain circumstances — for example, if it is no longer necessary for the purpose collected, or if you withdraw consent on which processing is based.
  • Right to restriction (Article 18): Request that we restrict processing of your personal data while a dispute about accuracy or lawfulness is pending.
  • Right to portability (Article 20): Receive personal data you provided to us in a machine-readable format, and transmit it to another controller where technically feasible.
  • Right to object (Article 21): Object to processing based on legitimate interests. We will cease that processing unless we can demonstrate compelling legitimate grounds that override your rights and interests.
  • Rights related to automated decision-making (Article 22): We do not make solely automated decisions that produce legal or similarly significant effects. AI-generated onboarding letters are reviewed and approved by a human workspace administrator before delivery to any individual.
  • Right to withdraw consent (where applicable): Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing. Note that our core Service operations rely on contract performance and legitimate interests, not consent.
  • Right to lodge a complaint: If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with your local data protection supervisory authority — in the EU, the DPA in your country of residence; in the UK, the Information Commissioner's Office (ICO) at ico.org.uk. We encourage you to contact us first so we have the opportunity to address your concern.

10. International Data Transfers

Firstweek, Inc. is based in the United States. If you access the Service from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with restrictions on cross-border data transfers, your personal data will be transferred to and processed in the United States.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, as incorporated into our Data Processing Agreement;
  • The UK International Data Transfer Agreement (IDTA) for UK-origin data; or
  • Other transfer mechanisms recognized by applicable law.

We also require subprocessors that receive EEA/UK personal data to implement equivalent transfer safeguards. Enterprise customers may request copies of applicable transfer documentation by contacting [email protected].


11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes — changes that affect how your personal data is collected, used, or shared — by posting a prominent notice in the application or by email to the address on your account, before the change takes effect. The "Effective" date at the top of this page reflects when the policy was last updated. Continued use of the Service after a material change takes effect constitutes acceptance of the updated policy.


12. Contact

Questions about this policy, data rights requests, or data protection concerns:

  • Email: [email protected]
  • Security disclosures: [email protected]

Firstweek, Inc., a Delaware corporation

© 2026 Firstweek, Inc., a Delaware corporation
Blog Pricing Trust Privacy Policy Terms of Service Subprocessors [email protected]
Get started

Book a demo.

We'll walk you through what Firstweek builds from your actual tools - tailored to your team, in 30 minutes.

30 minutes. No sales pitch - just a live walkthrough built from your actual tools.