Last updated: July 23, 2026
This Privacy Policy explains what personal data Your Business Scaling System (the "Service") collects, why we collect it, who we share it with, and the choices and rights you have. We have tried to keep it short and plain. If anything is unclear, please reach out (see Contact).
The Service is operated by Magnum Opus LLC, a limited liability company registered in the State of New Mexico, United States ("we", "us", "the operator"). For the purposes of the EU/UK General Data Protection Regulation (GDPR), Magnum Opus LLC is the data controller for the personal data described here.
You can contact us about privacy, or to exercise any of your rights, through the contact channel at WhatsApp (+381 65 205 4445).
The Service is invitation-only and offered to authorised members of a participating business. A person joins through a one-time claim or invitation link, or is added by a tenant administrator. Even though the Service is used in a business context, the people who use it are individuals, so this policy and applicable privacy laws apply to them.
We collect the information needed to create and operate your account, provide the AI service, transcribe voice input, keep contractual records, and handle billing.
We use the data above only to run the Service:
We do not use your data for advertising, and we do not sell it.
The Service generates answers using Anthropic's Claude API. To do this, the content you send (your messages, and any files, images, or PDFs you provide, together with relevant context from your workspace) is transmitted to Anthropic for processing.
Anthropic states that, by default, it does not use inputs or outputs from its commercial products to train its models. Anthropic's standard API retention period is currently up to 30 days, subject to exceptions for agreed retention settings, safety-policy enforcement, feedback, and legal obligations. This Service also uses Anthropic Managed Agents, sessions, and Memory Stores: session history and workspace/store content may remain available to provide the persistent product until we or you delete the relevant data. Provider terms and retention controls can change, so the linked provider notices are authoritative.
You can read Anthropic's privacy practices at anthropic.com/legal/privacy and their sub-processor list at trust.anthropic.com.
Because the AI processes whatever you type, please avoid pasting sensitive personal data about third parties (for example customers or employees) unless you have a lawful reason to do so.
We rely on a small number of service providers to run the Service. Depending on the service and applicable law, a provider may act as our processor or as an independent controller for part of its work (for example, payment compliance and fraud prevention).
| Provider | Purpose | Where | More info |
|---|---|---|---|
| Anthropic, PBC | AI processing, agent sessions, and persistent Memory Stores | Provider infrastructure and selected regions | anthropic.com/legal/privacy |
| ElevenLabs, Inc. and affiliates | Batch speech-to-text processing of guided-setup and advisor-chat voice input | Provider infrastructure and selected regions | elevenlabs.io/privacy-policy |
| Supabase, Inc. | Authentication, database, and application records | Project's configured region and provider infrastructure | supabase.com/privacy |
| Vercel, Inc. | Application hosting, delivery, and technical request logs | Provider infrastructure and selected regions | vercel.com/legal/privacy-policy |
| Stripe entities applicable to your location | Checkout, billing, fraud prevention, and transaction records | Provider infrastructure and applicable payment regions | stripe.com/privacy |
The operator is based in the United States, and the providers above may process data in the United States and other countries outside your own. Where cross-border transfer safeguards are required, we rely on the contractual and legal mechanisms made available by the relevant provider, which may include Standard Contractual Clauses, UK/Swiss transfer addenda, or an applicable Data Privacy Framework certification. You can request more information through our contact channel.
If you would like your account and its stored data deleted, contact us (see Contact).
If you are in the EEA, UK, or Switzerland (GDPR), you have the right to: access your data; correct it; delete it; restrict or object to processing; and receive a portable copy. Where we rely on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your local data protection authority.
If you are a US resident (for example under the California CCPA/CPRA, or similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and other states), you have the right to: know what personal information we collect and how we use it; access and delete it; correct it; and not be discriminated against for exercising these rights.
To exercise any right, contact us through WhatsApp (+381 65 205 4445). We will respond within the timeframe required by applicable law.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California and other US state privacy laws. We have no "Do Not Sell or Share" obligation because we do neither.
We use only cookies needed to authenticate you, maintain active chat/session state, and support authorised owner access. Supabase Auth manages its authentication cookies; application-specific session and support cookies are signed and HTTP-only. Cookie lifetimes vary by purpose and may be refreshed while you are signed in. We do not use cookies for advertising, analytics, or cross-site tracking.
We use reasonable technical and organisational measures appropriate to a service of this size, including: Supabase password authentication; cryptographically hashed one-time tokens; signed, HTTP-only application session cookies; encryption of data in transit (HTTPS/TLS); role-based access controls; and logical separation of tenant workspaces and deliverable stores. No method of transmission or storage is perfectly secure, but we work to protect your data and to address issues promptly.
The Service is for business users and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under 16 in the EEA). If you believe a minor has used the Service, contact us and we will delete the data.
We may update this policy as the Service evolves or the law changes. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continuing to use the Service after an update means you accept the revised policy.
For any privacy question or request, or to exercise your rights, contact us through WhatsApp (+381 65 205 4445).