Privacy Policy
Corply Privacy Policy
Last updated: September 25, 2026
Corply handles sensitive founder, company, filing, payment, and document information. This policy explains what we collect, why we use it, when we share it, and how founders can make privacy requests.
Important Summary
- We use founder and company information to provide incorporation, filing, document, approval, payment, support, security, and company record workflows.
- We do not sell personal information.
- We do not use customer company data, founder documents, or uploaded records to train AI models.
- We share information with service providers and workflow participants only when needed to operate Corply, complete authorized workflows, comply with law, or protect the service.
- Payments for Corply's own charges are entered on Stripe's secure checkout page. For accounts billed through Corply Pay, Corply's payment software, card details are entered into secure payment fields provided by Finix, our card processor, and bank details into a secure bank form provided by Payabli, our bank (ACH) processor. These processors collect and store full card numbers, card security codes, and bank account numbers; Corply does not receive or store them.
- Corply Cards are issued by a sponsor bank through Lithic, our card-issuing processor. Full card numbers and security codes are shown only in Lithic's secure card frame; Corply does not store them.
- Formation workflows can require sensitive information. Do not upload anything you are not authorized to provide.
1. Scope
This Privacy Policy explains how 0Lumen Labs Corp. d/b/a Corply collects, uses, discloses, retains, and protects information when you visit our websites, create an account, use Corply products, communicate with us, or authorize company formation, filing, document, approval, payment, or support workflows.
This policy applies to Corply's services. It does not apply to websites, portals, banks, registered agents, government agencies, payment processors, identity providers, attorneys, accountants, or other third-party services that operate under their own privacy policies.
2. Information We Collect
- Account and contact information, including name, email address, phone number, login metadata, team membership, role, and support communications.
- Founder and company information, including proposed company names, entity details, addresses, founder names, ownership details, equity context, officer/director/incorporator information, tax and filing facts, and workflow instructions.
- Documents and records you provide or generate, including formation documents, founder approvals, signatures, uploaded files, generated drafts, filing evidence, receipts, audit logs, and company memory records.
- Payment and billing records, including Corply Pay checkout, payment, receipt-number, renewal-schedule, invoice, refund, dispute, and bank-return records and the related processor reference identifiers (such as Finix transfer, identity, and payment-instrument identifiers and Payabli transaction, customer, and stored-method identifiers); payment-method type and, when the processor provides them, card brand, card funding type, expiration, and last four digits, or bank name, account type, and last four digits; order amount and currency; billing status; your registered-agent renewal choice; authorization evidence, including the authorization text you accepted (for bank payments, Corply's ACH debit authorization), when you accepted it, the Terms and Billing & Refund Policy versions in effect, and the IP address and browser user agent used; receipts; and limited payment metadata. Card details are entered into secure payment fields provided by Finix and bank details into a secure bank form provided by Payabli, which send them directly to those processors. The processors collect and store full card numbers, card security codes, and full bank account numbers. Corply does not receive or store those full card credentials or full bank account numbers. For payments processed by Stripe, Corply keeps the Stripe customer, Checkout, PaymentIntent, subscription, invoice, refund, and dispute identifiers and descriptors it records.
- Bank account details for ACH payments. You never give Corply your bank login credentials, and Corply does not request your account balances or transaction history. When you enter a bank account in Payabli's secure form, Payabli may check that it is a valid, open U.S. account that can accept debits. Corply keeps its own record of the ACH debit authorization you accepted, including when you accepted it and the IP address and browser user agent used.
- Corply Pay payment requests. If your company uses Corply Pay to send invoices, payment requests, or reimbursement requests, we process the request details you enter (such as the payer's name, email address, and organization, line items, memo, and expense details), the payer's payment status and receipt, and the software fee, gross, and net amounts of each payment. Payers enter card or bank details only in the processors' secure fields. To receive payments, your company completes the processors' own onboarding (identity, ownership, and payout bank account verification), which Finix and Payabli collect under their own terms and privacy policies; Corply keeps the resulting onboarding status, processor references, and the last four digits of the payout account.
- Corply Cards. If your company uses Corply Cards, we process the cardholder's name and email address, card nickname, type, state, spending limits and controls, the last four digits and expiration of each card, card transaction details (such as amount, status, merchant name, merchant category code, city, and country), and a record of each time a card's full details are viewed. Lithic and the sponsor bank that issues the cards process card data and any account-holder information they require under their own terms and privacy policies. Full card numbers and security codes appear only in Lithic's secure card frame, only on the web, and Corply does not store them.
- Usage, device, and security information, including IP address, browser type, device identifiers, session data, pages viewed, product events, error logs, authentication events, and anti-abuse signals.
- AI and automation workflow inputs and outputs, including prompts, extracted facts, summaries, generated drafts, task state, review notes, and operational decisions needed to provide the service.
3. Sources of Information
We collect information directly from you, from other users who invite you or act for the same company, from product usage, from documents you upload, from service providers that support approved workflows, and from public or government sources when needed to complete or verify company workflows.
4. How We Use Information
- Provide, operate, personalize, and improve Corply.
- Prepare, route, review, submit, track, and store company formation, filing, approval, document, registered-agent, EIN, compliance, payment, and support workflows you request or authorize.
- Maintain company records, audit trails, receipts, evidence, deadlines, and workflow history.
- Authenticate users, administer accounts, manage access, prevent fraud and abuse, debug issues, monitor reliability, and protect security.
- Communicate about account activity, support requests, approvals, filings, payments, purchase acknowledgments, renewal reminders and approvals, billing confirmations, policy changes, security notices, and service updates.
- Analyze product usage and business performance. Where analytics is enabled, product events may be associated with your account identifier, email address, and profile information. We also use aggregated usage reports.
- Comply with legal obligations, enforce our Terms of Use, respond to lawful requests, and protect Corply, users, third parties, and the public.
5. AI Providers and Model Training
Corply may use AI providers and automation systems to draft, extract, summarize, classify, check, route, and suggest actions. We use those systems to provide the product and operate approved workflows.
We do not use customer company data, founder documents, uploaded records, or private workflow content to train Corply foundation models or third-party foundation models. When we use AI vendors, we configure and contract for business use cases where customer content is not used to train vendor models.
AI outputs can be incomplete or wrong. Privacy protections do not change your responsibility to review documents, facts, filings, approvals, and instructions before relying on them.
If you connect Corply to an AI agent you choose, that agent's provider processes your conversation and information returned to it under its own terms and your account settings. Corply does not control that provider's independent data-use or model-training settings.
7. No Sale of Personal Information
We do not sell personal information. We also do not share personal information for cross-context behavioral advertising as those terms are commonly used under U.S. state privacy laws.
9. Retention
We retain information for as long as needed to provide Corply, maintain company records and audit trails, comply with legal and tax obligations, resolve disputes, enforce agreements, protect security, and operate our business.
Company formation and approval records may be retained longer than ordinary account data because founders, companies, investors, banks, accountants, counsel, and diligence reviewers may later need evidence of what was approved, signed, filed, paid, or received.
We retain payment processor identifiers (Stripe, Finix and Payabli), order and authorization evidence, receipts, refund, dispute, and bank-return records, and limited payment-method descriptors as needed for accounting, tax, fraud prevention, customer support, legal claims, and audit obligations. Billing authorization records, including renewal choices, renewal approvals, cancellations, and ACH debit authorizations, are kept while the authorization is in effect and afterward for as long as payment-network, Nacha, bank, and dispute rules require. Removing a saved payment method does not require deletion of transaction records we must retain, and Corply cannot delete information retained independently by Finix, Payabli, Lithic, a sponsor bank, or Stripe under their own policies or legal obligations.
10. Security
We use technical, organizational, and administrative safeguards designed to protect information, including access controls, encryption in transit, cloud security controls, logging, and least-privilege operational practices.
No system is perfectly secure. You are responsible for protecting your credentials, limiting access to your account, reviewing invited users, and maintaining your own copies of important company documents.
11. International Users
Corply is operated from the United States and is built for U.S.-connected company workflows. If you use Corply from outside the United States, you understand that your information may be processed in the United States and other jurisdictions where our providers operate.
12. Privacy Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain personal information, or to object to certain processing. These rights may be limited where information is needed for company records, legal obligations, security, fraud prevention, or completed workflows.
To make a privacy request, email founders@0lumens.com with the subject line Privacy Request and include the email address connected to your Corply account. We may need to verify your identity and authority before acting on a request.
13. Children
Corply is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information to Corply, contact us so we can review and delete it where appropriate.
14. Changes
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new last updated date. If changes are material, we may provide additional notice through the product or by email.
15. Contact
For privacy questions or requests, contact founders@0lumens.com.