Privacy Policy

Effective date: 2026-05-26 · Last updated: 2026-05-26

This Privacy Policy describes how Buxton Management LLC, a Florida limited liability company doing business as Options2Exit (“Options2Exit”, “we”, “our”, or “us”), collects, uses, and discloses information when you use the Options2Exit Inbox Intelligence service (“Service”).

The Service is an automated email-triage platform that classifies inbound email sent to business owners under Options2Exit’s M&A advisory engagement, and routes M&A acquisition solicitations to a dedicated folder so the owner can review them in one place.

If you do not agree with this Policy, do not use the Service or grant access to your email account.

1. Scope of this Policy

This Policy applies to:

This Policy does not cover Options2Exit’s broader advisory engagement, marketing site, or unrelated services, which are governed by separate notices.

2. Information We Collect

2.1 Information You Provide Directly

When you connect your email account or interact with the administrative interface, we collect:

2.2 Information We Access Through Connected Email Accounts

Once you grant the Service access to your email account, we access:

We access only the email messages necessary to perform the classification and action functions described in Section 3. We do not read, store, or process email outside the scope of M&A solicitation triage.

2.3 Information We Generate

2.4 Technical Information

3. How We Use Your Information

We use the information described in Section 2 only for the following purposes:

  1. M&A solicitation classification. Email metadata and snippet content are passed to an AI classifier to determine whether each message is an M&A acquisition solicitation and which sender category applies.
  2. Automated action. Based on the classifier output and your action policy preferences, we apply a label, move the message to a designated folder, optionally send a per-client opt-in auto-reply, and record the action in the audit log.
  3. Operator interface. Aggregated classification results, advisor intelligence summaries, and quarterly reports are presented to authorized Options2Exit operators.
  4. Service operation and security. Technical information is used for monitoring, debugging, security incident response, and capacity planning.
  5. Legal compliance. We may use information as necessary to comply with applicable law, respond to lawful requests, and enforce our Terms of Service.

We do not:

3.1 Google API Services User Data — Limited Use Compliance

The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

A complete list of sub-processors that may have access to your Gmail data appears in Section 4.

4. Disclosure of Information

We share information only as described below.

4.1 Sub-processors

We engage third-party service providers (“sub-processors”) to deliver the Service. Each sub-processor is bound by a written agreement that limits their use of your information to the purposes for which we engage them and requires confidentiality and security safeguards consistent with this Policy.

Sub-processor Function Data accessed Location
Anthropic, PBC AI classification (Claude Haiku 4.5 model or equivalent, as may be updated) Email sender, subject, snippet (≤2,000 chars) United States
Railway Corp. Application hosting + Postgres database All Service data United States (Postgres region: US East)
Google LLC Gmail API access; Pub/Sub message delivery (Gmail integration only) Gmail message metadata and content for connected Gmail accounts United States
Microsoft Corporation Microsoft Graph API access; webhook delivery (Microsoft 365 integration only) Microsoft 365 message metadata and content for connected M365 accounts United States

Anthropic’s processing:

We may engage additional sub-processors or change sub-processors in the future. We will update this list with notice prior to onboarding any new sub-processor.

4.2 Other Disclosures

We may disclose information when we believe in good faith that disclosure is necessary to:

4.3 Business Transfers

If Options2Exit is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will provide notice of any such transfer and your choices, if applicable.

5. Automated Decision-Making and Artificial Intelligence

The Service uses an AI classifier (Claude Haiku 4.5, provided by Anthropic, PBC) to categorize inbound messages. The classification produces:

5.1 Colorado Artificial Intelligence Act (HB 24-205)

The Service’s classifier is an “artificial intelligence system” as defined under the Colorado AI Act. Options2Exit operates it as a deployer.

5.2 California SB-942 (AI Transparency Act)

We disclose proactively that classification, routing, and auto-reply decisions are made by an artificial intelligence system. This disclosure appears in:

5.3 Conservative Defaults

The classifier is deliberately tuned to err toward false negatives (leaving messages untouched in the main inbox) rather than false positives (incorrectly routing a non-solicitation email). Messages classified as “Unknown” are never auto-routed and never labeled, regardless of confidence — a high-confidence “Unknown” verdict means the classifier is certain the message is NOT an M&A solicitation, so the Service takes no action. Conservative thresholds, privilege-domain protection (auto-excluding correspondence from attorneys, CPAs, bankers, and lenders), and the per-mailbox 30-day pilot mode further reduce the risk of misclassification affecting time-sensitive communications.

6. Data Retention

Data type Retention
Message metadataIndefinitely while the account is connected; deleted within 30 days of disconnection
Message body contentNot persistently stored. The body is read in memory to classify the message and, where the message is a solicitation, to forward it to your advisor. It is discarded once the classification is recorded. We retain the classifier output, not the input. Attachments are never stored.
Classifications and action recordsIndefinitely while the account is connected; deleted within 90 days of disconnection. Aggregated, non-identifying statistics may be retained beyond this period.
Audit logs (system actions and reversals)24 months. Required for the 7-day reversal interface and for engagement-level reporting.
OAuth refresh tokens / IMAP credentialsUntil the owner disconnects the account or the credential is rotated. Encrypted at rest with AES-256-GCM.
Anthropic API logs (sub-processor)Up to 30 days at Anthropic, per their commercial terms.
Operator interface logs12 months.

The production database is backed up daily, and the 7 most recent daily backups are kept on a rolling basis; older ones are deleted automatically. Continuous point-in-time recovery is also enabled, which lets us restore to a recent moment rather than only to the last daily backup. We occasionally take a manual backup and retain it beyond the rolling window for a specific operational reason; such backups are deleted once that reason no longer applies.

You may request earlier deletion of specific records subject to Sections 7 and 9.

7. Your Rights

Depending on your location, you may have the following rights:

7.1 California Residents (CCPA / CPRA)

If you are a California resident, you have the right to:

To exercise your rights, contact us using the information in Section 11. We will respond within 45 days, with one possible 45-day extension.

7.2 Other Jurisdictions

Other U.S. state privacy laws (Virginia VCDPA, Connecticut CTDPA, Colorado CPA, Utah UCPA, Texas TDPSA, Florida Digital Bill of Rights, etc.) may grant similar rights. We will honor verified requests under any applicable state privacy law to the extent the law applies to us based on its jurisdictional and revenue-threshold criteria.

The Service is offered for use within the United States and is not directed at or intended for residents of the European Union, United Kingdom, or other non-U.S. jurisdictions. We do not currently support GDPR or UK GDPR data-subject rights workflows; if you are located outside the U.S. and have a privacy concern, please contact us using the information in Section 11.

8. Security

We implement administrative, technical, and physical safeguards designed to protect your information from unauthorized access, disclosure, alteration, or destruction. Specifically:

No system is perfectly secure. We will notify affected owners and applicable regulators of any verified security incident in accordance with applicable law.

9. Children’s Privacy

The Service is not directed at children under 18 and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us using the information in Section 11.

10. Changes to this Policy

We reserve the right to update this Policy from time to time. Material changes will be communicated to connected owners by email at least 30 days before the effective date. The most recent version is always available at https://inbox.options2exit.com/privacy. Continued use of the Service after the effective date of an updated Policy constitutes acceptance of the updated Policy.

11. Contact

Questions, requests, or concerns about this Policy or our handling of your information:

For California residents exercising CCPA / CPRA rights, please include “California Privacy Request” in the subject line.

Appendix A — Sub-processor Update Log

Date Sub-processor Change
2026-05-26Anthropic, PBCInitial — AI classification (Claude Haiku 4.5 or equivalent as may be updated)
2026-05-26Railway Corp.Initial — Application hosting + Postgres
2026-05-26Google LLCInitial — Gmail API + Pub/Sub
2026-05-26Microsoft CorporationInitial — Microsoft Graph API + webhooks