BONDPERMIT · AURUMFLUX AI, INC.
Privacy Policy
Last updated: May 26, 2026
KEY COMMITMENT: We do not sell your data. We do not use your data to train AI models. We do not share your personal information with advertisers. Period.
1. Who We Are
This Privacy Policy applies to BondPermit, operated by AurumFlux AI, Inc. ("AurumFlux," "we," "us") at bondpermit.com and associated subdomains.
1a. BondPermit-Specific Data Practices
If you only use BondPermit (bondpermit.com), the data we collect is limited to what is required to deliver your permit/license research report:
- Business identifiers: business type, city, state (used to generate your report)
- Contact: email address (for report delivery and Watchdog alerts if subscribed)
- Payment: processed by Stripe — we do not store your full card number
- Technical: hashed IP address, user-agent (for fraud prevention only)
For BondPermit customers we do NOT collect: voice recordings, image uploads, emotional/sentiment data, contact lists, calendar data, files, or any other personal data beyond the items above.
2. What We Collect
When you use the Service, we may collect:
- Account information: email address, name (if provided)
- Business inputs: business type, location, goals, and prompts you provide to the Service
- Payment information: processed entirely by Stripe — we never see or store your full card number, CVV, or bank details
- Usage data: pages visited, features used, timestamps, IP address
- AI interaction data: prompts you send to the Service and responses the Service generates (stored for service improvement and your conversation history)
3. What We Do NOT Collect
- Social Security numbers or government-issued ID numbers
- Biometric data
- Data from children under 18 (we do not knowingly serve minors)
- Precise geolocation beyond city-level (derived from IP address)
4. How We Use Your Data
- To provide and improve the Service
- To generate AI-powered reports and business outputs
- To process payments via Stripe
- To send transactional emails (receipts, service updates, compliance alerts)
- To maintain conversation history within your workspace
- To monitor service health and prevent abuse
5. What We Do NOT Do With Your Data
- We do NOT sell your personal data. Not now. Not ever.
- We do NOT use your data to train AI models. Your prompts and outputs are not fed into any model training pipeline.
- We do NOT share your data with advertisers.
- We do NOT use tracking cookies or advertising pixels.
6. Third-Party Services (Sub-Processors)
The Service processes your queries using third-party AI model providers. When you submit a query, your prompt text is sent to one or more of the following providers for AI inference. These providers process your data under their own privacy policies and data processing agreements:
- Fireworks AI — primary AI inference provider. Data retention: queries are not stored after inference. (fireworks.ai/privacy)
- Groq — AI inference provider for fallback models (Llama 70B). Data retention: queries are not stored after inference. (groq.com/privacy-policy)
- Anthropic — AI inference provider (Claude models). API calls use zero-retention by default — Anthropic does not train on API inputs. (anthropic.com/legal/privacy)
- Google (Gemini) — AI inference fallback provider. (policies.google.com/privacy)
- Stripe — payment processing. We never see or store your full card number, CVV, or bank details. (stripe.com/privacy)
- Railway — server hosting and managed PostgreSQL database. (railway.app/legal/privacy)
- Cloudflare — DNS and DDoS protection
- Telegram — internal operational alerts only (no user data transmitted to Telegram)
Important: We do not sell, rent, or share your personal data with any third party for advertising, marketing, or profiling purposes. Third-party services listed above receive only the minimum data necessary to provide the Service.
7. Data Retention and Auto-Purge
We enforce strict data retention limits with automatic purging:
- Account data: retained until you delete your account
- Customer email address: retained for the life of the customer relationship plus a reasonable period afterward for tax and dispute records, then deleted
- IP address collected at checkout: retained for a limited period as fraud-prevention and consent evidence, then deleted
- Query logs (your prompts and the Service's responses): automatically purged after 30 days. No manual intervention required — our system permanently deletes query text on a rolling basis.
- Chat session data: held in memory only with a 2-hour TTL (time-to-live). After 2 hours of inactivity, session data is permanently discarded. Chat sessions are never written to persistent storage.
- Usage telemetry: we store query type (e.g., "equity_research"), model used, response time, and cost — but NOT the query text itself — for 90 days
- Payment records: retained for 7 years (required by US tax law)
- Audit logs: retained for 1 year (append-only, cannot be modified or deleted)
- Server logs: retained for 90 days, then automatically deleted
Data deleted is data that cannot be leaked, subpoenaed, or breached. We believe the safest data protection is not collecting data in the first place, and automatically deleting data we no longer need.
8. Data Security
We use industry-standard security measures including HTTPS encryption in transit, encrypted database connections, API key rotation, rate limiting, input validation, and output sanitization. We maintain a full audit trail of system actions.
9. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify affected users within 72 hours of discovery via the email address on file. We will also notify relevant regulatory authorities as required by applicable law.
10. Your Rights
Regardless of where you live, you have the right to:
- Access: request a copy of all personal data we hold about you
- Correction: request correction of inaccurate data
- Deletion: request deletion of your personal data ("right to be forgotten")
- Portability: request your data in a machine-readable format
- Objection: object to processing of your data for specific purposes
- Withdrawal: withdraw consent at any time where processing is based on consent
To exercise any of these rights, email [email protected]. We will respond within 30 days.
11. California Privacy Rights (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale or sharing of personal information (we do not sell or share your personal information)
- Right to limit the use and disclosure of sensitive personal information
- Right to non-discrimination for exercising privacy rights
We do not sell or share your personal information, and have not in the preceding 12 months.
We share personal information only with service providers who process it on our behalf to operate the Service, under contracts that prohibit them from using it for any other purpose. These service providers include Stripe (payment processing), our hosting provider, our email provider, and our AI inference providers. Disclosing personal information to these service providers for these operational purposes is not a "sale" or "sharing" under California law.
To exercise your CCPA/CPRA rights, email [email protected] with subject line "CCPA Request."
12. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation:
- Legal basis for processing: legitimate interest (service delivery) and consent (where applicable)
- Data transfers: your data may be transferred to and processed in the United States. We rely on standard contractual clauses where required.
- Right to lodge a complaint with your local Data Protection Authority
- Data Protection contact: [email protected]
13. Children's Privacy
BondPermit is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected data from a child under 18, we will delete it immediately.
14. Cookies
We use only essential session cookies required for the Service to function. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
15. Changes to This Policy
We may update this Privacy Policy as our service evolves. Material changes will be communicated to active users via email at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
16. Contact
Privacy questions, data requests, or concerns? Email [email protected].