Is Intercom Fin safe with your data?
Intercom Fin
Intercom Inc.
Weak disclosure · high confidence
Intercom Fin earns a D (43/100) because it leaves much about its data practices unstated.
#146
of 211 apps ranked
43
score · Customer support avg 47
-4
vs category average
Intercom Fin discloses CCPA rights, named transfer safeguards and an age-16 gate, but is silent on model training, breach notice and named security controls, and routes access, portability and legal-basis disclosures through EEA and UK only provisions.
What Intercom Fin's privacy policy and terms of service say about your data
Core rights are region gated
Access, restriction and portability sit under "If you are a resident of the EEA or the UK you have the following data protection rights". Portability appears nowhere in the California list, and access survives outside the EEA only through the separate CCPA "Right to Access".
No named security controls or certifications
No TLS, AES-256, RBAC, SOC 2 or ISO certification appears anywhere in the documents. The only security clause promises "commercially reasonable technical and organizational measures" then defers the detail to an unpublished Schedule 2, and the DPO is said to be appointed but never named.
No breach notification clause exists
A full-text search for breach notice language turns up only indemnification and contract-breach provisions. There is no commitment to notify users of a security incident, and no timeframe.
Training use is left unstated
The policy never says whether customer inputs train models, so the question is unanswered rather than answered badly. The anonymized-data clause permitting use "during and after the term" is a grant to Intercom rather than a minimization pledge.
What the policy is silent or vague on
- Not stated: keeping user inputs out of model training
- Not stated: a way to opt out of training
- Not stated: whether training use differs by plan
- Not stated: a deletion timeline after closure or request
Intercom Fin privacy rating
Details
- Category
- Customer support
- Modalities
- text
- Processes biometrics
- No
- Policy last updated
- 2026-04-01
- Region scored
- Global / US-default
- Last assessed
- 2026-08-13
Documents examined
Other customer support apps
Each grade reflects our analysis of what an app states in its public privacy policy and terms as of the assessment date. It measures the transparency of those documents, not the company's actual data practices, security, or compliance. Grades are our opinion, offered for general information. Full disclaimer.