A forward-looking draft for the in-development Windows version of VFL Toolkit. The Apple apps are governed by the main Privacy Policy.
Draft · not yet in effect · subject to change before the Windows app ships
The Windows application is in development. This draft describes the privacy approach we intend for the Windows app and is not yet in effect. The final Windows Privacy Policy will be published with the Windows release. For the iPhone, iPad, and Mac apps, the governing document is the VFL Toolkit Privacy Policy.
As on the Apple apps, the Windows app is intended to store matter data locally on your Windows device by default. We do not operate a developer-hosted cloud database for your matter data, and matter data is intended to remain on your device unless you choose to export it, sync it through your own Dropbox, transmit it through an integration you authorize, or otherwise move it outside the app.
If you connect your own Dropbox account, the Windows app is intended to synchronize matter documents and manifests between your devices and, if you turn on firm sharing, share selected matters with teammates by their Dropbox email — the same model as the Apple apps. Your files stay in your own Dropbox; we do not host a copy of your matter data and never receive your Dropbox password. The Dropbox sign-in token is intended to be stored only in your Windows device's secure credential storage.
We intend to receive only limited information necessary to operate the app — for example, subscription and entitlement status from the platform store that bills your Windows subscription, and any information you choose to send us for support. We do not include third-party advertising or tracking SDKs, and we do not use matter data or client content to train generalized machine-learning models. Payment-card and bank details for client payments are entered on the payment processor's own secure pages and are not collected or stored by the app.
If you connect LawPay, authorization occurs on LawPay's website and the Windows app stores an opaque connection token using Windows secure credential storage. A VFL Toolkit integration broker performs the authorized API calls. To create and reconcile hosted invoices, the app may send the amount, currency, selected trust-or-operating account identifier and classification, test-mode status, client name and reference, recipient email, bill or matter reference, and provider request or transaction identifiers. The broker does not intentionally retain payment-request content.
Clients enter card and bank details only on LawPay's hosted page. If LawPay has activated Pay Later and an eligible client chooses it, the financing application powered by Affirm is completed on the client's own device. The app and broker do not receive or store card or bank account numbers, Social Security numbers, income, credit reports, lending decisions, rates, or repayment credentials. LawPay, AffiniPay, Affirm, applicable financial institutions, and their service providers govern information on their systems under their own notices and agreements.
The Windows app is intended to rely on the Windows operating system's security features where available, including local credential storage and encrypted network transport, plus optional app-level access controls. No security measure is perfect. You remain responsible for the security of your devices, accounts, Dropbox account, exported files, and your firm's own information-security practices.
Questions about this draft may be directed to Burroughs Law Office, P.C., 4445 Corporation Ln, STE 225, Virginia Beach, VA 23462 · (757) 363-0077 · support@vfltoolkit.com.