FormationDocumentsComplianceOwnershipGovernance
Log InSign Up

EntityEngine Privacy Policy

Effective Date: August 27, 2026

EntityEngine, Inc. ("EntityEngine," "we," "our," or "us") builds software that helps founders and nonprofit organizers form entities, obtain tax identification numbers, stay compliant, and govern their organizations. Doing that means we handle sensitive information — including, in some cases, Social Security Numbers. This policy explains exactly what we collect, why, who else sees it, how long we keep it, and what you can make us do about it.

EntityEngine is not a law firm. Nothing you share with us is protected by attorney-client privilege. See Section 14.

1. Who We Are

EntityEngine, Inc., United States. Privacy questions and rights requests: privacy@entityengine.ai. Security reports: security@entityengine.ai.

EntityEngine is the controller of personal information about our own account holders, and a processor acting on your instructions for the content you upload into your organization's workspace — documents, board minutes, cap table records, and meeting content.

The Services are offered to businesses and nonprofit organizations formed in the United States. We do not target or market the Services to individuals in the European Economic Area or the United Kingdom.

2. Information We Collect

A. Information You Provide

  • Account identifiers — name, email, password (stored hashed), phone number.
  • Entity and formation data — entity name, jurisdiction, purpose, principal and officer and member names and addresses, ownership percentages, capital contributions.
  • Sensitive identifiers — the Social Security Number or ITIN of the "responsible party," and a date of birth where a filing requires one. Required by IRS Form SS-4. See Section 3, which explains this in detail.
  • Governance content — board minutes, resolutions, decisions, votes, committee records, meeting recordings and transcripts, and documents you upload.
  • Equity and fundraising data — cap table records, share classes, grants, 83(b) election details, investor records.
  • Payment information — billing name and address, card brand and last four digits. We never receive or store your full card number; Stripe collects it directly.
  • Communications — support requests, contact and demo form submissions, feedback, survey responses.
  • AI interactions — messages you send to Max and other AI features, and the documents those features retrieve on your behalf.

B. Information We Collect Automatically

  • Usage data — pages visited, features used, timestamps, referring page.
  • Device and technical data — IP address, browser type and version, operating system, device identifiers.
  • Diagnostic data — error reports and stack traces, which may incidentally include data you were working with when the error occurred.

C. Information We Do Not Collect

We do not collect biometric identifiers, precise geolocation, health information, or information about your race, religion, sexual orientation, union membership, or political affiliation. We do not buy personal information from data brokers.

3. Social Security Numbers

We want to be specific about this, because it is the most sensitive information we handle.

  • When we collect it. If you apply for an Employer Identification Number (EIN) through EntityEngine, IRS Form SS-4 requires the SSN or ITIN of the entity's "responsible party." We collect it at that point. This applies to all entity types, including nonprofit organizations — the IRS requirement is not limited to LLCs and corporations. If you are not applying for an EIN through us, we do not ask for your SSN.
  • What we do with it. We use it solely to prepare and submit the specific filing you authorized. We do not use it for identity verification, credit checks, marketing, or analytics. It is never included in AI prompts or retrieval corpora.
  • How we store it. Encrypted with a dedicated key, in its own field, separate from the rest of your application record.
  • How long we keep it. We delete it as soon as the EIN is issued. After that we retain only the last four digits, so we can match the record to your entity.
  • Your rights over it. Under the CPRA you may direct us to limit the use of sensitive personal information to what is necessary to provide the Services. We already limit ours to that.

4. How We Use Information

  • Provide, operate, secure, and improve the Services
  • Prepare and submit state filings, tax registrations, and compliance documents you authorize
  • Generate documents and give AI-assisted guidance within your organization's workspace
  • Process payments, manage subscriptions, and handle billing disputes
  • Send transactional messages about your account, filings, and deadlines
  • Send marketing messages, which you can opt out of at any time
  • Detect, investigate, and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our agreements

We process this information to perform our contract with you, to meet legal obligations around tax, recordkeeping, and filings, and for the legitimate purposes of securing the Services and improving them. Where we rely on your consent — non-essential cookies, and marketing email where the law requires it — you may withdraw that consent at any time without affecting processing already carried out.

5. Artificial Intelligence

EntityEngine uses AI to draft documents, answer questions about your organization, and guide you through filings. Here is precisely how that works.

  • Which models. AI features are powered by Google Cloud Vertex AI (Gemini models), operating under Google Cloud's enterprise terms as our processor. Your content is transmitted to and processed by that service on our behalf, and stored in Google Cloud regions in the United States.
  • No model training. Neither EntityEngine nor Google uses your content to train, fine-tune, or improve any general-purpose or third-party foundation model. Google Cloud's enterprise terms prohibit this and we do not opt out of that protection.
  • Per-organization isolation. Each organization's AI knowledge base is a separate retrieval corpus scoped to that organization. Queries are filtered to the requesting organization before any content is retrieved.
  • Role-based filtering. Within your organization, retrieval is further filtered by the requester's role. Board-level and committee material is not surfaced to users without the corresponding clearance. If we cannot resolve a user's role, the system defaults to the most restrictive access.
  • What is excluded. Social Security Numbers, ITINs, and full payment details are never placed in AI prompts or retrieval corpora.
  • Human review. AI output is a draft. A person reviews anything before it is filed. We do not make decisions producing legal or similarly significant effects about you solely by automated means.
  • Aggregate improvement. We may use de-identified, aggregated usage data to improve our own workflows. This data cannot reasonably be re-associated with you.
  • Not legal advice. AI output is not legal or tax advice, and no attorney-client privilege attaches to it. See Section 14.

6. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

  • Subprocessors — third parties that perform services on our behalf, each receiving only what its function requires. Our current list is published at entityengine.ai/subprocessors.
  • State agencies — to make filings you authorize. Information on a formation filing, including your entity name and your registered agent's name and address, becomes part of the public record.
  • The IRS — Form SS-4 contents, including the responsible party's SSN or ITIN, to obtain your EIN.
  • Registered agent providers — your name, entity name, jurisdiction, and contact details, to appoint and maintain your agent and forward legal correspondence to you.
  • Professional advisors — legal, accounting, and audit services, under confidentiality obligations.
  • Legal compliance — when required by law, regulation, subpoena, or court order, or to protect rights and safety.
  • Business transfers — in a merger, acquisition, financing, or sale of assets. We will notify you before your information becomes subject to a different privacy policy.
  • At your direction — sharing you initiate, such as collaborator invitations and document shares.

We give at least 30 days' notice before adding a subprocessor that processes customer content. To be notified, email privacy@entityengine.ai.

7. Data Retention

We keep information only as long as we need it.

  • Account and profile data — life of the account, plus 90 days after closure.
  • Social Security Numbers and ITINs — deleted as soon as the EIN is issued; only the last four digits are retained. See Section 3.
  • Formation and filing records — seven years after the filing, to satisfy recordkeeping obligations and support you in an audit.
  • Governance content — life of the account, or until you delete it. Deleted items are purged from backups within 35 days.
  • Payment and invoice records — seven years, as required for tax and accounting.
  • Support communications — three years from last contact.
  • Marketing and lead records — three years from last engagement, or until you unsubscribe.
  • Application logs — 90 days. Security and audit logs — 400 days.
  • AI retrieval corpora — life of the organization; purged on account deletion.

Where a legal hold, dispute, or regulatory obligation applies, we retain the affected data until it is resolved.

8. Data Security

We protect your information with administrative, technical, and physical safeguards, including encryption in transit and at rest, role-based access control, multi-factor authentication, per-organization data isolation enforced at the query layer, audit logging, automated dependency and secret scanning, and a documented incident response and rollback procedure. Full detail is on our Trust & Security page.

Breach notification. If we determine that a breach has compromised your personal information, we will notify you without undue delay, and within any deadline the applicable state breach-notification law sets. Notice will describe what happened, what data was involved, what we have done, and what you should do.

No system is perfectly secure, and we cannot guarantee absolute security. To report a vulnerability, email security@entityengine.ai.

9. Cookies and Similar Technologies

  • Strictly necessary cookies — authentication, session management, security, CSRF protection. These cannot be switched off.
  • Preference cookies — remembering your settings.
  • Analytics cookies — understanding how the product is used so we can improve it.

We do not use advertising or cross-site tracking cookies. If that changes, we will update this policy and provide an opt-out before doing so.

Optional analytics stays off until you allow it. You can change that choice at any time using the button below or through your browser settings. Blocking strictly necessary cookies will prevent sign-in from working.

Global Privacy Control. We honor GPC and similar browser opt-out signals as a valid request to opt out of sale or sharing, to the extent one applies.

10. Where Your Information Is Processed

We operate entirely in the United States. Your information is processed and stored here, and all of our subprocessors process it here. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your own jurisdiction.

11. Your Rights and How to Exercise Them

Depending on where you live, you may have the right to:

  • Know and access what personal information we hold, where we got it, why we have it, and who we share it with
  • Correct inaccurate personal information
  • Delete your personal information, subject to filing and recordkeeping obligations
  • Receive a copy in a portable, machine-readable format
  • Limit the use of sensitive personal information to what is necessary to provide the Services
  • Opt out of marketing communications at any time
  • Object to or restrict certain processing, and withdraw consent where we rely on it
  • Not be discriminated against for exercising any of these rights. We will not deny service, charge a different price, or provide a lesser experience because you did

How to make a request. Email privacy@entityengine.ai. An authorized agent may submit on your behalf with proof of authorization.

What happens next. We log every request when we receive it. We will confirm receipt within 10 business days and respond substantively within 45 days, extendable once by another 45 days if we tell you why. To protect you, we verify identity before acting, with additional verification for deletion requests and requests touching a Social Security Number.

If we decline, we will tell you which exemption we are relying on. You may appeal by replying to our response with the word "Appeal"; we will answer within 45 days. If we deny your appeal, you may complain to your state Attorney General.

12. Data Processing Addendum

For customers who need contractual data protection commitments under the CCPA/CPRA or similar US state privacy laws, we offer a Data Processing Addendum covering subprocessors, security measures, audit rights, breach notification, and deletion on termination. Request one at privacy@entityengine.ai.

13. Children's Privacy

The Services are for business use and are not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn that we have, we will delete it promptly. Contact privacy@entityengine.ai if you believe a child has provided us information.

14. Not Legal Advice; No Privilege

EntityEngine is not a law firm and does not provide legal or tax advice. Using the Services does not create an attorney-client relationship, and communications with EntityEngine — including with our AI features — are not protected by attorney-client privilege . This means they may be discoverable in litigation. If you need privileged advice, consult a licensed attorney. See our Terms of Service.

15. Changes to This Policy

We review this policy at least annually. If we make a material change — a new category of data, a new purpose, or a new class of recipient — we will notify you by email or in-product notice at least 30 days before it takes effect, and will not apply it retroactively to information already collected without your consent where consent is required. Non-material changes take effect when we update the Effective Date above.

16. California Notice at Collection

Categories of personal information we have collected in the last 12 months, using the CCPA/CPRA categories:

  • Identifiers (name, email, IP address, account ID) — collected; not sold or shared.
  • Customer records (address, phone, payment information) — collected; not sold or shared.
  • Sensitive personal information (SSN or ITIN, for EIN filings only) — collected; not sold or shared; retained per Section 3.
  • Commercial information (subscriptions, purchases) — collected; not sold or shared.
  • Internet activity (usage, device, diagnostics) — collected; not sold or shared.
  • Professional information (title, role) — collected; not sold or shared.
  • Biometric data, precise geolocation, education records, inferences, and protected classifications — not collected.

Sources: you; other users in your organization; automatic collection; our service providers. Purposes: Section 4. Recipients: Section 6. Retention: Section 7.

We have not sold or shared personal information, and have no actual knowledge of selling or sharing the personal information of consumers under 16, in the preceding 12 months.

17. Contact Us

Privacy questions and rights requests: privacy@entityengine.ai
Security and vulnerability reports: security@entityengine.ai
General support: support@entityengine.ai

EntityEngine, Inc., United States.

Platform

OverviewEntityMax AISecurity & AuditPricing

Formation

LLCCorporationNonprofit501(c)(3) Determination

Governance

Meetings & AgendasVoting & ResolutionsDocumentsE-SignaturesEquity & Cap Table

Compliance

Federal BOI StatusRegistered AgentLicense Intelligence

Resources

Information CenterLicense LibraryState Filing GuidesTax RegistrationBusiness BlogCompare EntityEngine

Company

AboutPricingContact
Join our PlatformSchedule a DemoStart Any FormationGet Your EIN #Get Your 501(c)(3) Determination
© 2026 EntityEngine, Inc.
Privacy PolicyTerms of Service