Privacy Policy

Last updated: July 23, 2026

This Privacy Policy explains what personal data Your Business Scaling System (the "Service") collects, why we collect it, who we share it with, and the choices and rights you have. We have tried to keep it short and plain. If anything is unclear, please reach out (see Contact).

1. Who we are

The Service is operated by Magnum Opus LLC, a limited liability company registered in the State of New Mexico, United States ("we", "us", "the operator"). For the purposes of the EU/UK General Data Protection Regulation (GDPR), Magnum Opus LLC is the data controller for the personal data described here.

You can contact us about privacy, or to exercise any of your rights, through the contact channel at WhatsApp (+381 65 205 4445).

2. Who this policy covers

The Service is invitation-only and offered to authorised members of a participating business. A person joins through a one-time claim or invitation link, or is added by a tenant administrator. Even though the Service is used in a business context, the people who use it are individuals, so this policy and applicable privacy laws apply to them.

3. What we collect

We collect the information needed to create and operate your account, provide the AI service, transcribe voice input, keep contractual records, and handle billing.

  • Account and membership data. When you claim or accept access, we collect your email address, company name, assigned role, internal user and tenant identifiers, and any profile or settings information you choose to provide. A signer name may also be collected when an existing member accepts a new agreement version. The claim endpoint sends your chosen password to Supabase Auth to create the login; the readable password is not stored in our application tables. One-time claim and invitation tokens are stored as cryptographic hashes. Legacy access-code hashes may remain while older sessions are migrated.
  • Agreement and security records. When you accept an agreement, we record the tenant and user (where available), agreement identifier and version, company and email where provided, acceptance date and time, IP address, and browser user-agent. These details provide an audit trail of the electronic acceptance. A signer name is recorded only when that acceptance flow asks for one.
  • Your chat content. The messages you send to the AI and the replies it generates are stored so you can return to past conversations. This includes any business details, questions, or text you choose to type in.
  • Your workspace and uploads. The Service keeps a private, persistent "workspace" for your account (for example a profile and notes about your business that the AI builds over time), plus any files you upload (such as documents, images, or PDFs). This is stored on your behalf so future answers fit your situation.
  • Voice-input audio and transcripts. When you use the microphone in the guided interview or an advisor chat, your audio is sent to ElevenLabs to produce a transcript. We do not intentionally keep the raw audio recording in our own database or storage after transcription, although ElevenLabs processes it under its terms and privacy practices. A guided-interview transcript, answer duration, and related onboarding state are saved as part of Setup. A chat transcript returns to the composer and is stored as chat content only if you send it.
  • Billing data. When you add credits or hold a subscription, we store your prepaid credit balance, plan status, internal Stripe customer identifier, and transaction reconciliation records. Payments are processed by Stripe. Card and payment-method details are entered directly with Stripe and do not pass through our application server. Stripe also receives the internal account identifier and purchase metadata needed to process and reconcile the transaction.
  • Settings and interface preferences. Account or member settings such as model choice, formatting preference, custom instructions, and saved tab layout may be stored with your account. Theme and some display preferences are stored only in your browser.
  • Essential cookies and technical data. We use cookies needed for Supabase authentication, active chat/session state, and owner support access. We also process IP address, browser/device information, and ordinary request and error logs where needed for agreement evidence, security, support, and reliable operation. We do not use advertising or cross-site tracking cookies, third-party analytics, marketing pixels, or device fingerprinting.

4. How we use your data and our legal bases

We use the data above only to run the Service:

  • To provide the Service (sign you in, run the AI, save and show your chats, keep your workspace and files). Legal basis: performance of our agreement with you (GDPR Art. 6(1)(b)).
  • To transcribe voice input in guided Setup and advisor chats and use the resulting text as you direct. Legal basis: performance of our agreement with you (GDPR Art. 6(1)(b)).
  • To record agreement acceptance and maintain evidence of the parties' relationship. Legal basis: performance of our agreement and our legitimate interest in keeping accurate contractual records (GDPR Art. 6(1)(b) and (f)).
  • To keep the Service secure and working (prevent abuse, debug problems, maintain reliability). Legal basis: our legitimate interests in operating a safe, functional service (GDPR Art. 6(1)(f)).
  • To handle billing for credits and subscriptions. Legal basis: performance of our agreement and compliance with legal/tax obligations (GDPR Art. 6(1)(b) and (c)).

We do not use your data for advertising, and we do not sell it.

5. AI processing (Anthropic)

The Service generates answers using Anthropic's Claude API. To do this, the content you send (your messages, and any files, images, or PDFs you provide, together with relevant context from your workspace) is transmitted to Anthropic for processing.

Anthropic states that, by default, it does not use inputs or outputs from its commercial products to train its models. Anthropic's standard API retention period is currently up to 30 days, subject to exceptions for agreed retention settings, safety-policy enforcement, feedback, and legal obligations. This Service also uses Anthropic Managed Agents, sessions, and Memory Stores: session history and workspace/store content may remain available to provide the persistent product until we or you delete the relevant data. Provider terms and retention controls can change, so the linked provider notices are authoritative.

You can read Anthropic's privacy practices at anthropic.com/legal/privacy and their sub-processor list at trust.anthropic.com.

Because the AI processes whatever you type, please avoid pasting sensitive personal data about third parties (for example customers or employees) unless you have a lawful reason to do so.

6. Service providers

We rely on a small number of service providers to run the Service. Depending on the service and applicable law, a provider may act as our processor or as an independent controller for part of its work (for example, payment compliance and fraud prevention).

ProviderPurposeWhereMore info
Anthropic, PBCAI processing, agent sessions, and persistent Memory StoresProvider infrastructure and selected regionsanthropic.com/legal/privacy
ElevenLabs, Inc. and affiliatesBatch speech-to-text processing of guided-setup and advisor-chat voice inputProvider infrastructure and selected regionselevenlabs.io/privacy-policy
Supabase, Inc.Authentication, database, and application recordsProject's configured region and provider infrastructuresupabase.com/privacy
Vercel, Inc.Application hosting, delivery, and technical request logsProvider infrastructure and selected regionsvercel.com/legal/privacy-policy
Stripe entities applicable to your locationCheckout, billing, fraud prevention, and transaction recordsProvider infrastructure and applicable payment regionsstripe.com/privacy

7. International data transfers

The operator is based in the United States, and the providers above may process data in the United States and other countries outside your own. Where cross-border transfer safeguards are required, we rely on the contractual and legal mechanisms made available by the relevant provider, which may include Standard Contractual Clauses, UK/Swiss transfer addenda, or an applicable Data Privacy Framework certification. You can request more information through our contact channel.

8. How long we keep it

  • Account, chats, transcripts, settings, and workspace files are generally kept while the tenant account is active so the Service remains useful. You can delete individual chats and editable workspace files in the app. Closing a tenant triggers deletion of its application records and cloud stores, subject to the exceptions below.
  • Agreement acceptances, billing records, and transaction records may be kept for as long as needed to establish the agreement and meet legal, tax, accounting, fraud-prevention, or dispute-resolution obligations.
  • Provider copies, backups, and security logs follow the relevant provider's retention controls and may remain for a limited period after application data is deleted. Anthropic, ElevenLabs, Stripe, Supabase, and Vercel publish their own current retention details in the notices linked above.

If you would like your account and its stored data deleted, contact us (see Contact).

9. Your rights

If you are in the EEA, UK, or Switzerland (GDPR), you have the right to: access your data; correct it; delete it; restrict or object to processing; and receive a portable copy. Where we rely on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your local data protection authority.

If you are a US resident (for example under the California CCPA/CPRA, or similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and other states), you have the right to: know what personal information we collect and how we use it; access and delete it; correct it; and not be discriminated against for exercising these rights.

To exercise any right, contact us through WhatsApp (+381 65 205 4445). We will respond within the timeframe required by applicable law.

10. We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California and other US state privacy laws. We have no "Do Not Sell or Share" obligation because we do neither.

11. Cookies

We use only cookies needed to authenticate you, maintain active chat/session state, and support authorised owner access. Supabase Auth manages its authentication cookies; application-specific session and support cookies are signed and HTTP-only. Cookie lifetimes vary by purpose and may be refreshed while you are signed in. We do not use cookies for advertising, analytics, or cross-site tracking.

12. How we protect your data

We use reasonable technical and organisational measures appropriate to a service of this size, including: Supabase password authentication; cryptographically hashed one-time tokens; signed, HTTP-only application session cookies; encryption of data in transit (HTTPS/TLS); role-based access controls; and logical separation of tenant workspaces and deliverable stores. No method of transmission or storage is perfectly secure, but we work to protect your data and to address issues promptly.

13. Children

The Service is for business users and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under 16 in the EEA). If you believe a minor has used the Service, contact us and we will delete the data.

14. Changes to this policy

We may update this policy as the Service evolves or the law changes. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continuing to use the Service after an update means you accept the revised policy.

15. Contact

For any privacy question or request, or to exercise your rights, contact us through WhatsApp (+381 65 205 4445).

Back to sign in