Privacy Policy
Effective date: 2026-05-26 · Last updated: 2026-05-26
This Privacy Policy describes how Buxton Management LLC, a Florida limited liability company doing business as Options2Exit (“Options2Exit”, “we”, “our”, or “us”), collects, uses, and discloses information when you use the Options2Exit Inbox Intelligence service (“Service”).
The Service is an automated email-triage platform that classifies inbound email sent to business owners under Options2Exit’s M&A advisory engagement, and routes M&A acquisition solicitations to a dedicated folder so the owner can review them in one place.
If you do not agree with this Policy, do not use the Service or grant access to your email account.
1. Scope of this Policy
This Policy applies to:
- Owners (“you” / “your”) — business owners under Options2Exit advisory engagement who connect their email account (Gmail, Microsoft 365, or IMAP) to the Service to enable automated M&A solicitation triage.
- Senders — third parties whose email enters a connected owner’s inbox and is processed by the Service.
- Operators — Options2Exit staff and advisors who log into the Service’s administrative interface.
This Policy does not cover Options2Exit’s broader advisory engagement, marketing site, or unrelated services, which are governed by separate notices.
2. Information We Collect
2.1 Information You Provide Directly
When you connect your email account or interact with the administrative interface, we collect:
- Account credentials — OAuth refresh and access tokens (for Gmail and Microsoft 365 accounts) or IMAP credentials, stored encrypted at rest (AES-256-GCM) and never displayed in plaintext outside the secure vault.
- Account metadata — your email address, display name, and the provider type (Gmail / Microsoft 365 / IMAP).
- Exclusion preferences — domains, addresses, or sender categories you instruct us to exclude from automated processing.
2.2 Information We Access Through Connected Email Accounts
Once you grant the Service access to your email account, we access:
- Message metadata — sender address and display name, recipient addresses, subject line, message ID, thread ID, received timestamp, and selected RFC 822 headers (
Reply-To,List-Unsubscribe,List-ID). - Message body content — to the extent required to classify whether the message is an M&A acquisition solicitation, and to forward a solicitation to your advisor intact. Up to roughly the first 6,000 characters are read in memory for classification. Neither the body nor any attachment is written to storage.
- Folder / label structure — to apply labels and folder moves as part of the automated action layer.
We access only the email messages necessary to perform the classification and action functions described in Section 3. We do not read, store, or process email outside the scope of M&A solicitation triage.
2.3 Information We Generate
- Classifications — for each processed message, a sender-type label (e.g., “Search Fund”, “PE Associate”, “Broker”), a confidence score, and a brief reasoning statement.
- Action records — which actions the Service took on a message (label applied, folder moved, no action) and when.
- Audit logs — every action and reversal, retained for the period described in Section 6.
2.4 Technical Information
- IP addresses (operator interface only — owners do not interact with the web UI)
- Request timestamps, response times, request IDs
- Error logs (with personal information redacted per Section 5)
3. How We Use Your Information
We use the information described in Section 2 only for the following purposes:
- M&A solicitation classification. Email metadata and snippet content are passed to an AI classifier to determine whether each message is an M&A acquisition solicitation and which sender category applies.
- Automated action. Based on the classifier output and your action policy preferences, we apply a label, move the message to a designated folder, optionally send a per-client opt-in auto-reply, and record the action in the audit log.
- Operator interface. Aggregated classification results, advisor intelligence summaries, and quarterly reports are presented to authorized Options2Exit operators.
- Service operation and security. Technical information is used for monitoring, debugging, security incident response, and capacity planning.
- Legal compliance. We may use information as necessary to comply with applicable law, respond to lawful requests, and enforce our Terms of Service.
We do not:
- Use your email content for any purpose unrelated to M&A solicitation triage as described above.
- Train, fine-tune, or otherwise improve any artificial intelligence model on your email content. (Our AI sub-processor, Anthropic, also does not use customer email content for model training — see Section 4.1.)
- Sell, rent, or lease your personal information.
- Use your email content for advertising or marketing.
3.1 Google API Services User Data — Limited Use Compliance
The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Gmail data only to provide and improve the M&A solicitation triage feature described in this Policy.
- We do not transfer Gmail data to third parties except (i) as necessary to provide or improve the M&A triage feature, (ii) to comply with applicable law, or (iii) as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use or transfer Gmail data for serving advertisements, including retargeting or personalized advertising.
- Humans do not read Gmail data unless (i) we have your explicit consent to read specific messages, (ii) doing so is necessary for security purposes (such as investigating abuse), (iii) doing so is necessary to comply with applicable law, or (iv) Gmail data is aggregated and used for internal operations in compliance with the Google Limited Use Policy.
A complete list of sub-processors that may have access to your Gmail data appears in Section 4.
4. Disclosure of Information
We share information only as described below.
4.1 Sub-processors
We engage third-party service providers (“sub-processors”) to deliver the Service. Each sub-processor is bound by a written agreement that limits their use of your information to the purposes for which we engage them and requires confidentiality and security safeguards consistent with this Policy.
| Sub-processor | Function | Data accessed | Location |
|---|---|---|---|
| Anthropic, PBC | AI classification (Claude Haiku 4.5 model or equivalent, as may be updated) | Email sender, subject, snippet (≤2,000 chars) | United States |
| Railway Corp. | Application hosting + Postgres database | All Service data | United States (Postgres region: US East) |
| Google LLC | Gmail API access; Pub/Sub message delivery (Gmail integration only) | Gmail message metadata and content for connected Gmail accounts | United States |
| Microsoft Corporation | Microsoft Graph API access; webhook delivery (Microsoft 365 integration only) | Microsoft 365 message metadata and content for connected M365 accounts | United States |
Anthropic’s processing:
- Email snippets are sent to Anthropic’s API for AI classification.
- Anthropic does not use customer data sent through its API for training or improving its models. (See Anthropic’s Commercial Terms of Service.)
- Anthropic retains API logs for up to 30 days for abuse prevention and operational purposes, after which they are deleted.
We may engage additional sub-processors or change sub-processors in the future. We will update this list with notice prior to onboarding any new sub-processor.
4.2 Other Disclosures
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, or legal process (e.g., subpoena, court order)
- Enforce our Terms of Service
- Protect the rights, property, or safety of Options2Exit, our users, or others
- Respond to a verified security incident
4.3 Business Transfers
If Options2Exit is involved in a merger, acquisition, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will provide notice of any such transfer and your choices, if applicable.
5. Automated Decision-Making and Artificial Intelligence
The Service uses an AI classifier (Claude Haiku 4.5, provided by Anthropic, PBC) to categorize inbound messages. The classification produces:
- A sender type label (one of: Search Fund, PE Associate, Broker, Independent Buyer, Aggregator, Strategic, Unknown)
- A confidence score between 0 and 1
- A brief reasoning statement explaining which signals drove the classification
- An action tier (Auto-Route, Label-Only, or Leave-Untouched)
5.1 Colorado Artificial Intelligence Act (HB 24-205)
The Service’s classifier is an “artificial intelligence system” as defined under the Colorado AI Act. Options2Exit operates it as a deployer.
- Consequential decisions: The classifier does not determine eligibility for credit, employment, housing, healthcare, insurance, education, or essential government services. It determines email-folder placement only. Consequential-decision provisions of the Act do not apply.
- Right to human review: All automated actions are reversible within 7 days through Options2Exit’s administrative interface. Owners may request immediate reversal of any classification by contacting Options2Exit at the email in Section 11.
5.2 California SB-942 (AI Transparency Act)
We disclose proactively that classification, routing, and auto-reply decisions are made by an artificial intelligence system. This disclosure appears in:
- The owner onboarding flow at the time of email-account connection
- The privacy policy (this section)
- The optional “under advisement by Options2Exit” auto-reply, when enabled
5.3 Conservative Defaults
The classifier is deliberately tuned to err toward false negatives (leaving messages untouched in the main inbox) rather than false positives (incorrectly routing a non-solicitation email). Messages classified as “Unknown” are never auto-routed and never labeled, regardless of confidence — a high-confidence “Unknown” verdict means the classifier is certain the message is NOT an M&A solicitation, so the Service takes no action. Conservative thresholds, privilege-domain protection (auto-excluding correspondence from attorneys, CPAs, bankers, and lenders), and the per-mailbox 30-day pilot mode further reduce the risk of misclassification affecting time-sensitive communications.
6. Data Retention
| Data type | Retention |
|---|---|
| Message metadata | Indefinitely while the account is connected; deleted within 30 days of disconnection |
| Message body content | Not persistently stored. The body is read in memory to classify the message and, where the message is a solicitation, to forward it to your advisor. It is discarded once the classification is recorded. We retain the classifier output, not the input. Attachments are never stored. |
| Classifications and action records | Indefinitely while the account is connected; deleted within 90 days of disconnection. Aggregated, non-identifying statistics may be retained beyond this period. |
| Audit logs (system actions and reversals) | 24 months. Required for the 7-day reversal interface and for engagement-level reporting. |
| OAuth refresh tokens / IMAP credentials | Until the owner disconnects the account or the credential is rotated. Encrypted at rest with AES-256-GCM. |
| Anthropic API logs (sub-processor) | Up to 30 days at Anthropic, per their commercial terms. |
| Operator interface logs | 12 months. |
The production database is backed up daily, and the 7 most recent daily backups are kept on a rolling basis; older ones are deleted automatically. Continuous point-in-time recovery is also enabled, which lets us restore to a recent moment rather than only to the last daily backup. We occasionally take a manual backup and retain it beyond the rolling window for a specific operational reason; such backups are deleted once that reason no longer applies.
You may request earlier deletion of specific records subject to Sections 7 and 9.
7. Your Rights
Depending on your location, you may have the following rights:
7.1 California Residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell or share. The categories collected appear in Section 2 and the disclosures in Section 4.
- Delete personal information we have collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA / CPRA.
- Limit use of sensitive personal information. The Service does not process sensitive personal information as defined under the CCPA.
- Non-discrimination. We will not discriminate against you for exercising any of these rights.
To exercise your rights, contact us using the information in Section 11. We will respond within 45 days, with one possible 45-day extension.
7.2 Other Jurisdictions
Other U.S. state privacy laws (Virginia VCDPA, Connecticut CTDPA, Colorado CPA, Utah UCPA, Texas TDPSA, Florida Digital Bill of Rights, etc.) may grant similar rights. We will honor verified requests under any applicable state privacy law to the extent the law applies to us based on its jurisdictional and revenue-threshold criteria.
The Service is offered for use within the United States and is not directed at or intended for residents of the European Union, United Kingdom, or other non-U.S. jurisdictions. We do not currently support GDPR or UK GDPR data-subject rights workflows; if you are located outside the U.S. and have a privacy concern, please contact us using the information in Section 11.
8. Security
We implement administrative, technical, and physical safeguards designed to protect your information from unauthorized access, disclosure, alteration, or destruction. Specifically:
- Encryption at rest. OAuth refresh tokens, access tokens, and IMAP credentials are encrypted using AES-256-GCM. Encryption keys are held in secured, access-controlled configuration managed by our hosting provider and are never exposed to application logs or the user interface; migration to a dedicated key-management service (KMS) is planned. Plaintext credentials are never written to disk or logs.
- Encryption in transit. All connections between Service components and between the Service and external APIs use TLS 1.2 or higher.
- Tenant isolation. Each owner’s data is partitioned at the database level by tenant identifier, and every query against tenant-scoped tables is enforced through application-layer scope checks.
- Access controls. Access to the production environment is limited to authorized personnel using multi-factor authentication.
- Audit logging. Every system action and operator action is logged with actor, timestamp, target, and metadata.
- Vendor diligence. We use only sub-processors that maintain industry-standard security certifications (SOC 2 Type II or equivalent).
No system is perfectly secure. We will notify affected owners and applicable regulators of any verified security incident in accordance with applicable law.
9. Children’s Privacy
The Service is not directed at children under 18 and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us using the information in Section 11.
10. Changes to this Policy
We reserve the right to update this Policy from time to time. Material changes will be communicated to connected owners by email at least 30 days before the effective date. The most recent version is always available at https://inbox.options2exit.com/privacy. Continued use of the Service after the effective date of an updated Policy constitutes acceptance of the updated Policy.
11. Contact
Questions, requests, or concerns about this Policy or our handling of your information:
- Email: support@options2exit.com
- Mail: Buxton Management LLC, 16186 Andalucia Ln, Delray Beach, FL 33446
For California residents exercising CCPA / CPRA rights, please include “California Privacy Request” in the subject line.
Appendix A — Sub-processor Update Log
| Date | Sub-processor | Change |
|---|---|---|
| 2026-05-26 | Anthropic, PBC | Initial — AI classification (Claude Haiku 4.5 or equivalent as may be updated) |
| 2026-05-26 | Railway Corp. | Initial — Application hosting + Postgres |
| 2026-05-26 | Google LLC | Initial — Gmail API + Pub/Sub |
| 2026-05-26 | Microsoft Corporation | Initial — Microsoft Graph API + webhooks |