Legal

Terms of Service

Effective April 22, 2025

These Terms of Service govern your use of FileValet, a secure document exchange platform operated by FileValet, Inc. (“we”, “us”, “our”). By accepting an invitation and accessing FileValet, you agree to these terms. If you do not agree, do not use the platform.

1. Invitation-only access

FileValet is not publicly available. Access requires a direct invitation issued by an Organization Admin at a CPA firm or financial services organization that has contracted for the service. Self-registration is not supported.

You may not share your invitation link, credentials, or session with any other person. You are responsible for all activity that occurs under your account.

2. User roles and responsibilities

Organization Admin

Responsible for inviting and managing users, enforcing acceptable use within their organization, and ensuring that all Staff and Client accounts comply with these terms. Admins bear contractual responsibility for their organization’s use of FileValet.

Staff

May view and manage documents for clients assigned to them by an Admin. Staff may not access records outside their assigned client list. All access is logged and auditable.

Client

May view, upload, and download their own documents only. Clients may not access records belonging to other clients within the same organization.

3. Acceptable use

You agree to use FileValet only for lawful tax and financial document exchange between your CPA firm and its clients. You must not:

  • Upload files containing malware, ransomware, or other malicious code
  • Attempt to access data belonging to other organizations or accounts
  • Use automated tools to scrape, probe, or stress-test the platform
  • Circumvent authentication, session controls, or rate limits
  • Share access credentials or active session tokens with others
  • Use the platform to store or exchange non-tax-related personal data without disclosure to end users

Violations may result in immediate suspension of access without notice.

4. Authentication and multi-factor requirements

FileValet requires multi-factor authentication (MFA) for all accounts as mandated by the FTC Safeguards Rule (16 CFR Part 314). The primary authentication method is passkey (WebAuthn) with email OTP as a fallback. You agree to enroll at least one MFA method and to keep your registered authenticators secure. Passkey private keys are stored on your device only and are never transmitted to FileValet servers.

5. Data ownership

You retain ownership of all documents and data you upload to FileValet. You grant us a limited, non-exclusive license to store, process, and display that data solely to provide the service to you.

We do not claim any intellectual property rights in your uploaded content and will not use it for any purpose beyond delivering the service, complying with law, and maintaining security.

6. Retention obligations

In accordance with IRS Publication 4557, records containing taxpayer data are retained for a minimum of seven years via soft-delete mechanisms. Records within the retention period cannot be hard-deleted. The Organization Admin may request permanent deletion of records after the seven-year retention period by contacting us in writing.

7. Service availability

We target 99.9% uptime during the critical tax filing season (February through April). Planned maintenance windows will be communicated at least 48 hours in advance. We are not liable for disruptions caused by third-party infrastructure providers (AWS, Neon, Railway) or events outside our reasonable control.

8. Limitation of liability

To the maximum extent permitted by law, FileValet, Inc. is not liable for indirect, incidental, special, consequential, or punitive damages arising from your use of the platform. Our total aggregate liability for any claim arising out of or related to these terms shall not exceed the fees paid by your organization in the twelve months preceding the claim.

FileValet is a tool — it is your organization’s responsibility to maintain appropriate internal controls, train staff, and verify that files exchanged through the platform comply with applicable tax regulations.

9. Termination

We reserve the right to suspend or terminate access at any time for violations of these terms or applicable law. Organization Admins may deactivate their account and request data export at any time by contacting us. Following termination, we will retain records only as required by our retention obligations and then permanently delete them.

10. Governing law

These terms are governed by the laws of the State of Delaware, without regard to conflict of law provisions. Any disputes shall be resolved exclusively in the state or federal courts located in Delaware.

11. Changes to these terms

We will notify Organization Admins by email at least 14 days before any material changes take effect. Continued use of FileValet after the effective date of updated terms constitutes acceptance.

Questions?

Email legal@filevalet.app or contact your Organization Admin.