Firstweek, Inc. ("Firstweek," "we," "our," or "us") is a Delaware corporation. This Privacy Policy explains how we collect, use, share, and protect information when you use our software platform and related services (the "Service").
By accessing or using the Service, you agree to this policy. If you are using the Service on behalf of an organization (a "Workspace"), your organization's agreement with us governs data processing, and this policy applies to the extent not superseded by that agreement.
When you create an account or set up a workspace, we collect your name, work email address, company name, and any single sign-on (SSO) identity information provided by your identity provider. Billing contacts and payment method details are collected during subscription setup.
Workspace administrators submit information about new hires to generate personalized onboarding letters. This includes names, job titles, start dates, role context, department, manager information, LinkedIn profile URLs (when LinkedIn enrichment is enabled), and any other onboarding-related content entered into the Service. This data is provided by the workspace and processed by Firstweek on behalf of the workspace. The workspace is responsible for informing individuals whose data it submits and for ensuring it has the lawful basis to do so.
When a workspace administrator connects a third-party integration (such as Slack, GitHub, Notion, Atlassian, or Google Drive), we access content from those services within the scopes you authorize — for example, repository content, channel messages, or documents. This access is read-only, limited to the repositories, channels, or folders you explicitly select, and used solely to generate onboarding content. Raw integration content is not stored in our systems after the generation process completes; only AI-derived analysis and the generated letter are retained as part of the onboarding record. You may revoke any integration at any time from your workspace settings.
When a workspace administrator connects the Google Drive integration, Firstweek collects the following Google user data via the Google OAuth 2.0 flow:
drive.readonly OAuth scope, which is limited to read operations only. We do not write to, modify, delete, or share any files in your Google Drive.userinfo.email and userinfo.profile OAuth scopes to authenticate and identify the Google account used to connect the integration.How Google user data is used: Google user data is used solely to generate personalized onboarding letters on behalf of your workspace. File content is read into memory during the letter generation process and discarded immediately after — it is never written to our database. Only AI-derived analysis and the final onboarding letter are retained as part of the onboarding record. The connecting user's email and display name are stored as part of the integration record to support re-authentication and revocation.
Limits on use of Google user data: Google user data is not used for advertising or to build advertising profiles; is not sold, rented, or transferred to data brokers or information resellers; is not used to train or evaluate AI or machine learning models; and is not used for any purpose unrelated to generating onboarding letters for your workspace. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We collect information about how you interact with the Service — including pages visited, features used, and session duration — to improve the product. We use Google Analytics 4 (GA4) across the authenticated application and public marketing site (see Analytics and Cookies below). Internal staff super-administrator accounts operated by Firstweek are excluded from analytics tracking. No personally identifiable information is embedded in URL paths within the authenticated application.
We also collect anonymized error and crash reports via Bugsnag to identify and resolve application defects. These reports include exception types, messages, and request context. They are automatically redacted to exclude names, email addresses, OAuth tokens, credentials, and any other sensitive field values before transmission.
If you contact us by email or through the Service, we retain those communications to respond to your inquiry and improve support.
The Service is not intended for use with personal data of individuals under 13 years of age (under U.S. COPPA) or under 16 years of age in the EEA or UK (under GDPR Article 8). If you become aware that personal data of a child below these ages has been submitted to the Service, contact [email protected] immediately and we will delete it promptly.
Firstweek operates as both a data controller and a data processor, depending on the data:
For data subjects in the European Economic Area, United Kingdom, or Switzerland, we process personal data under the following legal bases:
Enterprise customers and workspaces subject to GDPR who require a Data Processing Agreement (DPA) — including Standard Contractual Clauses for international data transfers and processor obligations per GDPR Article 28 — may request one by contacting [email protected].
We process your data only for the purposes described above. If we need to use your data in a materially different way, we will update this policy and notify you before doing so.
We do not sell, rent, license, or otherwise monetize your data or your users' data to any third party, for any reason, ever. We do not use customer data — including new-hire information, integration content, or usage data — to build data products, conduct advertising targeting, or derive insights that benefit any party other than you. We do not use your data to train AI models without your explicit prior written consent. Your data exists in our systems solely to provide the Service to your workspace.
Onboarding content is transmitted to third-party AI providers to generate personalized letters. By using AI-powered features, workspace administrators authorize this processing.
Firstweek uses one or more third-party AI inference providers to power features including onboarding letter generation. When a workspace administrator initiates letter generation, the relevant onboarding content — including role context, focus areas, and content retrieved from connected integrations — is transmitted to an AI provider for inference. Our current primary AI provider is Anthropic. We may engage additional AI providers for specific features as the Service evolves; any new provider will be listed on our Subprocessors page before it processes customer data.
We select AI providers that operate under zero-retention or equivalent commitments. Under Anthropic's API terms, submitted content is not used to train their models and is not retained for any purpose beyond what is minimally required for safety and abuse monitoring. Customer data transmitted for AI inference is used solely to generate the requested output.
Customer data — including onboarding content, integration data, and new-hire information — will not be used to train, fine-tune, or evaluate AI models without your explicit prior written consent. This means a separate signed agreement (email confirmation, DocuSign, or equivalent) specifying the data categories, model or training technique, vendor, and retention period. A checkbox during signup or language buried in these terms does not constitute this consent. Running data through a pre-trained model to generate output (inference) does not require training consent when we use zero-retention providers.
AI-generated outputs are suggestions. The workspace administrator is responsible for reviewing generated content before delivering it to a new hire. Firstweek makes no guarantee as to the accuracy, completeness, or fitness of AI-generated content for any particular purpose.
The Service uses the following types of cookies:
Firstweek uses Google Analytics 4 (GA4), operated by Google LLC, to understand how the product is used and guide product improvements. GA4 receives IP addresses to determine approximate geographic location; Google does not log or store raw IP addresses in GA4. GA4 also collects browser and device identifiers, pages visited, feature interactions, and session duration. Page-level data only is collected within the authenticated application; no personally identifiable information is embedded in URL paths. This data is processed by Google subject to its privacy policy.
You can opt out of Google Analytics tracking using the Google Analytics opt-out browser add-on. You may also disable analytics cookies through your browser's privacy settings. Essential session and authentication cookies cannot be disabled without affecting your ability to use the Service.
We share data with third-party subprocessors only to the extent necessary to provide the Service. A complete, current list of our subprocessors — including the data they process and their locations — is available at firstweek.app/subprocessors. We conduct due diligence on all subprocessors and require them to maintain appropriate data protection and confidentiality obligations.
Key subprocessors include:
Additional subprocessors — including error monitoring, URL extraction, and LinkedIn enrichment services — are listed on the Subprocessors page.
When the LinkedIn enrichment feature is enabled, workspace administrators may provide a new hire's LinkedIn profile URL. Firstweek uses Coresignal to retrieve publicly available profile data (employer history, education, skills) for use in letter generation. Workspace administrators are responsible for informing new hires that their LinkedIn profile will be accessed for onboarding purposes, and for ensuring this is compliant with their jurisdiction's laws and their organization's obligations. Firstweek acts as a processor in this context; the workspace is the data controller and assumes responsibility for appropriate notice and lawful basis.
When you add a link to onboarding content, Firstweek uses Jina AI to fetch and summarize the content at that URL for use in letter generation. Only provide URLs to public, non-confidential content. Do not provide URLs to private, password-protected, or internal confidential documents; doing so would cause that content to be transmitted to Jina AI outside your organization's control.
We keep the Subprocessors page current and update it when vendors are added or removed. For additions or changes that materially affect how your data is processed, we will also post notice in the application. Enterprise customers requiring advance notice and objection rights for subprocessor changes may address this in a Data Processing Agreement.
We design our systems with security as a core requirement, applying controls aligned with SOC 2 Trust Service Criteria.
In the event of a security incident that compromises personal data, we will:
For workspaces subject to GDPR, we will provide all information you need to fulfill your own obligations to notify your data protection authority and affected data subjects. To report a suspected vulnerability, contact [email protected].
We retain different categories of data for different periods based on their purpose:
You may request deletion of your workspace data at any time by contacting [email protected]. We will fulfill deletion requests within 30 days, subject to any legal obligation to retain specific data (such as billing records).
We will respond to all verified rights requests within 30 days of receipt, or within any shorter period required by applicable law. To exercise any right, contact [email protected] from the email address associated with your account. We will acknowledge your request within 2 business days and may require identity verification before fulfilling it. We do not charge a fee unless a request is manifestly unfounded or excessive.
If you are a California resident, you have the following additional rights:
To submit a California privacy request, contact [email protected]. We will respond within 45 days; we may extend by an additional 45 days with written notice and explanation.
If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR or UK GDPR:
Firstweek, Inc. is based in the United States. If you access the Service from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with restrictions on cross-border data transfers, your personal data will be transferred to and processed in the United States.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards, which may include:
We also require subprocessors that receive EEA/UK personal data to implement equivalent transfer safeguards. Enterprise customers may request copies of applicable transfer documentation by contacting [email protected].
We may update this Privacy Policy from time to time. We will notify you of material changes — changes that affect how your personal data is collected, used, or shared — by posting a prominent notice in the application or by email to the address on your account, before the change takes effect. The "Effective" date at the top of this page reflects when the policy was last updated. Continued use of the Service after a material change takes effect constitutes acceptance of the updated policy.
Questions about this policy, data rights requests, or data protection concerns:
Firstweek, Inc., a Delaware corporation
We'll walk you through what Firstweek builds from your actual tools - tailored to your team, in 30 minutes.