Privacy Policy

Last updated: April 28, 2026

1. Who We Are

Auriflow Digital LLC dba Auriflow Studio ("Company," "we," "us") operates studio.auriflow.com. Contact: studio@auriflow.com.

2. What We Collect

  • Account information: Email address, full name, company name, role title.
  • Uploaded documents: Contract PDFs and term sheets uploaded during an engagement.
  • Intake conversation: Your responses during the structured intake process.
  • Payment information: Payment processing is handled by Stripe. We do not store card numbers. We retain payment intent IDs and amounts.
  • Usage data: IP address, user agent, timestamps for audit log entries.

3. How We Use Your Data

  • To deliver the financial modeling service described in your engagement brief.
  • To authenticate your account and secure your data.
  • To send transactional emails related to your engagement (NDA execution, brief confirmation, delivery notifications).
  • To maintain audit records as required by our legal obligations.

We do not use your data for marketing. We do not sell your data to third parties. We do not share your contract data with anyone other than the operator building your model and Anthropic's API processing systems (subject to their commercial terms).

4. AI Processing

Contract data is processed by Anthropic's Claude API for extraction and intake conversation generation. Under Anthropic's Commercial Terms, API inputs and outputs are not used to train AI models. Anthropic retains API data for a maximum of 30 days for trust and safety review, then deletes it. See privacy.claude.com for Anthropic's privacy documentation.

5. Data Retention and Deletion

We retain engagement data for as long as your account is active. You may delete your engagement data at any time from your dashboard. Uploaded files are purged from storage immediately upon deletion. Database records are anonymized within 24 hours. Anonymized audit log entries required for legal record-keeping are retained indefinitely.

6. Third-Party Services

  • Supabase: Database and file storage. Data stored in US-East region.
  • Anthropic: AI processing via API. Commercial terms apply.
  • Stripe: Payment processing. Stripe's privacy policy applies to payment data.
  • DocuSign: NDA execution. DocuSign's privacy policy applies to signature data.
  • Resend: Transactional email delivery.
  • Vercel: Application hosting.

7. Your Rights

You have the right to access, correct, and delete your personal data. To exercise these rights, use the data deletion button in your dashboard or contact studio@auriflow.com. We will respond within 30 days.

8. Security

See our Security page for a detailed description of our technical and organizational security measures.

9. Contact

Privacy questions: studio@auriflow.com. We do not have a formal privacy officer. Contact Mike DeLong, Member, Auriflow Digital LLC.