Privacy Policy
Last updated
This policy explains what information Anchor Angels collects when you use our website and member platform, how we use it, who we share it with, and the choices you have.
01Who we are
Anchor Angels is an angel network for the Vanderbilt community, operated by Anchor Angels, a 501(c)(6) member-based professional association (“Anchor Angels”, “we”, “us”). This policy covers anchorangels.com, the member platform, our emails and the Anchor Angels connector for Claude (together, the “Services”).
We are based in Nashville, Tennessee. You can reach us about privacy at hello@anchorangels.com.
02Information we collect
Information you give us.
- Account details: name, email address, password (stored as a hash by our authentication provider) and your role on the platform.
- Profile details: phone, company, occupation, LinkedIn URL, city, state and region, Vanderbilt relationship, school, degree and graduation year, profile photo, and investing interests such as stages, sectors, past investment count and amounts, and goals.
- Investor information: whether you are an accredited investor and which accreditation criteria you meet, as you state them.
- Applications: founder applications (company name, website, sector, stage, region, what you are building, the problem you solve, logo and pitch deck) and investor or associate membership applications (experience, investment range, interests and reasons for joining).
- Documents and deal content: pitch decks, data room documents and other files you upload, and the notes, tasks, votes, RSVPs and chat messages you create in the platform.
- Messages you send us through the contact form or by email.
Information collected automatically.
- Usage data: pages viewed, features used, device and browser type, referring page, and approximate location derived from IP address.
- Email engagement: whether our emails are delivered, opened or clicked, which we use to keep lists healthy and to calculate a member engagement score.
- Shared document views: when someone opens a document through a share link, we record the link used, the visitor’s email if the link requires one, IP address, browser user agent, visit times, and which pages were viewed and for how long.
- Error and performance data, including session replays, described under Analytics, monitoring and cookies.
Information from third parties.
- Google: if you sign in with Google, we receive your name, email address and profile picture from Google.
- Polar: our payment processor tells us the status of your subscription (plan, billing interval, renewal and cancellation dates). We do not receive or store full card numbers.
- Research providers: when our team reviews a company, we may look up publicly available information about the company and its founders using Exa (web search) and Apollo (professional and company profiles). These lookups cover professional history and company information only.
03How we use information
- To run the Services: create and secure accounts, apply role-based access, process applications, and host deals, data rooms, events and committee votes.
- To connect founders and members: share founder applications, decks and deal materials with members of the network who are permitted to see them.
- To manage memberships and billing, including checking subscription status before granting paid features.
- To send email: account and transactional messages, event and deal announcements, digests and newsletters, subject to your email preferences.
- To provide AI features such as deal scorecards, document extraction, search and chat, described below.
- To understand and improve the Services, fix errors, and prevent abuse, fraud and security incidents.
- To meet legal obligations and enforce our Terms of Service.
04AI processing of documents and deal data
The platform uses AI models to help our team and members review deals. When a pitch deck or data room document is uploaded, or when someone runs a scorecard, asks the deal chat a question or uses an in-app agent, relevant content is sent to these providers:
- Anthropic (Claude) reads documents, extracted data and deal records to produce scorecards, summaries, extracted fields and chat answers.
- OpenAI converts document text into numerical embeddings so the platform can search documents by meaning. The embeddings and text chunks are stored in our database.
- Exa and Apollo receive company names, websites and founder names when an agent researches a company. Results are stored for reuse for a limited period so the same lookup is not repeated.
We use these providers under their commercial API terms, under which they do not use our inputs to train their models by default. AI output can be wrong, and it is used to assist human review, not to make decisions on its own. We keep a record of each AI run (what it processed, the model used and what it produced) so results can be checked.
05Connecting Claude (MCP and OAuth)
Members can connect Claude (for example Claude Code, Claude Desktop or claude.ai) to Anchor Angels through our Model Context Protocol (MCP) server. You authorize the connection by signing in and approving it on our consent screen.
- The authorization asks only for your identity, email address and basic profile (the openid, email and profile scopes).
- An authorized client can read what you could read in the app, and nothing more: deals and documents you have access to, pipeline summaries, record search results and your notifications. Staff accounts can also read tasks, notes, applications, deal activity and committee votes.
- The only actions a client can take are two staff-only operations: running a deal scorecard and changing a deal’s stage. Member accounts cannot make changes through the connector.
- Information returned to Claude is then processed by Anthropic under your own agreement with Anthropic, not this policy.
- You can disconnect an app at any time from Profile, Connect Claude. Disconnecting stops its access immediately.
07Service providers
- Supabase: database, authentication and file storage for accounts, profiles, uploaded decks and data room documents.
- Vercel: website and application hosting, and privacy-focused page analytics.
- Google: optional sign-in with a Google account.
- Polar: subscription checkout, billing and payment processing. Polar handles your payment details under its own privacy policy.
- Resend: sending email and reporting delivery, opens and clicks.
- PostHog: product analytics.
- Sentry: error monitoring, performance tracing and session replay.
- Anthropic: AI analysis, scorecards and chat.
- OpenAI: text embeddings for document search.
- Exa and Apollo: company and founder research lookups.
09Email and your choices
We send transactional email (account, application, billing and security messages) and, where you have not opted out, marketing email such as newsletters, digests, event invitations and deal announcements.
Every marketing email includes an unsubscribe link and a link to your email preference center, where you can choose which kinds of email you receive. We stop sending to addresses that bounce permanently or report our email as spam. Transactional messages continue while you have an account.
10Retention
We keep account and profile information while your account is active. Applications, deal records, documents and votes are kept for as long as needed to run the network and keep an accurate record of deals reviewed.
When you ask us to delete your account, we delete or de-identify your personal information within 30 days, except where we must keep it for legal, tax, accounting or security reasons, or where it is part of a record other members rely on (for example a vote on a closed deal). Stored research lookups expire and are refreshed on a schedule. Backups are overwritten on our providers’ normal cycles.
11Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information or your account;
- receive a copy of your information in a portable format;
- object to or restrict certain processing; and
- withdraw consent where we rely on it, such as marketing email.
You can update most profile details yourself from your profile page and manage email from the preference center. For anything else, email hello@anchorangels.com. We will verify your request and respond within the time the law requires. We will not treat you differently for exercising these rights.
12Security
We protect information with role-based access controls and row-level database security, private file storage, encrypted connections, hashed passwords and share-link passwords, signed links, and audit logging of sensitive actions. No system is perfectly secure. If you believe your account or data has been compromised, contact us right away.
13Children
The Services are intended for adults and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.
14International transfers
We are based in the United States, and our service providers process data in the United States and other countries. If you use the Services from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
15Changes to this policy
We may update this policy as the Services change. We will post the new version here with a new “Last updated” date and, for material changes, tell members by email or in the platform before the change takes effect.
16Contact
Questions or requests about privacy can go to hello@anchorangels.com or write to Anchor Angels in Nashville, Tennessee. See also our Terms of Service.