// Legal · Privacy
Privacy Policy
Effective August 27, 2026.
This policy describes how Anomalist Enterprise LLC
("we", "us") handles information on the websites we operate at
anomalistenterprise.com and its subdomains, as well as
the products we ship under that umbrella. It's written in plain
language on purpose. If something isn't clear, email
privacy@anomalistenterprise.com and we'll explain
or fix it.
1. What we collect
1.1 Information you give us directly
- Contact form submissions. Name, email, message, and which services/products you mentioned. Used only to respond and follow up.
- Beta applications. If you apply for access on
/betas, we collect your name, email, the product you're applying for, your reason for applying, and (optionally) your company and role. Used to evaluate the application and, if approved, send a magic-link invite. - Orders and quotes. When you use
/startor/consulting/startwe collect what the engagement documents need: your name, email, phone, business name, the legal entity name, state of formation and entity type that go on the contract, your role, how you'd like to be contacted, your timeline, how you heard about us, and whatever you tell us about your business, your goals and your existing site or tech stack. This is used to generate your scope summary and Statement of Work, to provision your account if you buy, and to do the work. - Electronic signature records. When you accept an agreement by ticking the boxes at checkout, we record — deliberately, as evidence that the acceptance happened — the name you typed, your email, the date and time, your IP address and browser user agent, and the exact version and SHA-256 fingerprint of each document you accepted. This is what makes a tick-box acceptance enforceable under Indiana's Uniform Electronic Transactions Act and the federal E-SIGN Act, and it protects you as much as us: it is how either of us can prove later exactly which words were agreed to. We also record when you open each document, for the same reason.
- Payment details. We never see or store your card. Payment is handled entirely by Stripe on Stripe's own pages; we receive back a confirmation, the amount, and which items you bought.
- Product-level data. Each Anomalist Enterprise product (Berea, Atlas/MentorForge, Compass, Delta, Maximus) collects what it needs to function — conversations, journal entries, account details, etc. Each product surfaces its own data practices on first use; this policy covers the umbrella and any product that does not yet ship its own.
1.2 Information collected automatically
- Server logs. Our edge provider (Cloudflare) logs standard request metadata: IP address, user agent, request path, timestamp. Used for security, abuse prevention, and basic operational visibility. We do not run third-party advertising trackers or analytics scripts on the marketing site.
- Cookies. The marketing site sets no analytics cookie at all — see Section 2. Individual products that require sign-in set a session cookie scoped to that product's subdomain. Session cookies are
HttpOnly,Secure, andSameSite=Lax.
2. Cookies & site analytics
We do not set any analytics or tracking cookie on this site. There is no visitor ID, no pageview log, no profile of what you read, and nothing to opt out of.
This changed on 27 August 2026. Before then we set one optional
first-party cookie (ae_vid) after you accepted a banner,
and recorded which pages you visited. We retired the system behind it
and did not replace it, so the cookie and the banner are gone. If you
accepted previously, that cookie simply expires on its own; you can
also delete it in your browser at any time.
2.1 What we still have
Only what Section 1 describes: standard request metadata that our edge provider (Cloudflare) logs for every website — IP address, user agent, path, timestamp — used for security and basic operational visibility. It is not tied to a visitor ID, and we do not build profiles from it. No third-party trackers, no advertising pixels, no cross-site anything.
2.2 If you contact us
What you type into a contact form is what we receive. We no longer attach a record of which pages you looked at, because we no longer keep one.
2.3 Deleting what we hold
To ask what we hold about you, or to have it deleted, email privacy@anomalistenterprise.com.
3. How we research your business
When you share your business with us — by chatting with us, filling out a form, or signing up — we may review publicly available information about it to prepare proposals, mockups, and recommendations: your website, public business listings (like your Google Business Profile), and public social profiles. We compile this into a working profile of your business that our team and our own tools use to help you.
This is first-party research done for your benefit. We don't sell this information, and we don't share it with third parties for their marketing. You can ask us at hello@anomalistenterprise.com to see, correct, or delete what we've gathered.
4. Where your information goes
We use a small, deliberately chosen set of subprocessors. We do not sell, rent, or trade information about you.
- Cloudflare — hosting, edge delivery, DNS, D1 database storage. Data processed at the edge and stored in Cloudflare's US regions by default.
- Stripe — payment processing for all paid services. Stripe collects and stores your card details directly under its own privacy policy; card numbers never touch our servers. We send Stripe your name, email and what you ordered, and receive back the payment result.
- Resend — transactional email delivery (contact responses, beta invite magic links, account notifications).
- Anthropic — for products that include AI features (e.g., Berea's research replies), prompts and conversation context are sent to Anthropic's Claude API to generate the response. Per Anthropic's API terms in effect at the time of writing, API customer data is not used to train Anthropic's models.
- OpenAI — used by select products for specific narrow features (e.g., Berea's text-to-speech). Subject to OpenAI's API terms, which similarly state API data is not used to train models.
We add or change subprocessors only when there's a real need. If a change materially affects how your data is handled, we'll update this list and the effective date above.
5. AI features and your data
Some Anomalist Enterprise products use generative AI. When you interact with one of those features, the content you send (your message, the surrounding conversation, and any relevant context the product retrieves on your behalf) is transmitted to the model provider listed above so a response can be generated. We do not fine-tune third-party models on your data, and we do not provide your data to model providers for their own training purposes.
AI responses can be wrong, incomplete, or out of date. We design our products to show their sources and let you verify the work. Don't rely on an AI output for medical, legal, financial, or safety-critical decisions without independent verification.
6. Beta products
Atlas/MentorForge, Delta, Nexus, and any other product we label "private beta" are still under active development. That means:
- Features may change, regress, or be removed.
- Data you store in a beta product (sessions, journal entries, account history) could be lost during migrations or schema changes. We do our best to avoid this. We don't guarantee against it.
- Beta access is non-transferable and may be revoked at our discretion.
- Beta accounts and their associated data can be deleted by you at any time — contact us or use the in-product control if available.
7. Retention
- Contact form messages. Up to 24 months from last correspondence, then deleted.
- Beta applications. Pending applications: kept while pending. Approved: kept while the beta is active. Rejected: kept up to 12 months for fraud-prevention and audit, then deleted.
- Orders, agreements and signature records. Kept for the life of the engagement and then for seven (7) years, which is how long we may need to evidence what was agreed for tax, accounting and limitation-period purposes. These are deliberately not deleted on request while that period runs — an agreement you can erase is not evidence of anything. Everything else about you can still be deleted; see Section 9.
- Product data. Kept for as long as your account is active in that product. Deleted on request — see Section 9.
- Server logs. Standard short retention windows at the edge provider (Cloudflare default), typically days to weeks.
8. Children
The marketing site and products are intended for users 18 or older, and we don't knowingly collect information from anyone under 13 via this site. If a product later opens to younger users under a parental account, it will ship its own privacy notice specific to family use, including parental controls and age-appropriate data minimization.
9. Your rights and choices
You can ask us to:
- Show you what information we hold about you.
- Correct anything that's wrong.
- Delete your information (subject to limited retention for legal or fraud-prevention reasons).
- Stop further communication from us.
Send the request from the email address associated with your account or application to privacy@anomalistenterprise.com. We'll respond within a reasonable timeframe — typically within 30 days.
What happens when you delete an account
Where a product gives you a "Delete account" control, that control deletes. Here is the clock it runs on, in full, including the part we can't shorten:
- Immediately. The account is deactivated. You're signed out on every device, any public per-account link stops working, and any subscription is cancelled.
- For 30 days. You can change your mind: sign back in with the same email address and everything is restored exactly as it was.
- After 30 days. Your account and its contents are permanently erased from our live systems by an automated job. That step is irreversible.
- Up to 90 days. Residual copies may remain in our hosting provider's automatic encrypted backups before they age out. Cloudflare's point-in-time recovery is always on and can't be switched off, so we won't claim erasure is instant and permanent when it isn't.
The same 30-day clock applies to a deletion request you send us by email in a product that has no in-app control. Records under a legal retention basis — the orders, agreements and signature records in Section 7 — are the documented exception: they're kept for the period stated there and then deleted.
10. Security
We use encryption in transit (HTTPS everywhere), scoped session cookies, HMAC-signed magic-link invites, and least-privilege access to internal admin tooling. No system is unbreakable. If we ever discover a breach that affects your data, we'll notify affected people without unreasonable delay.
11. International users
Anomalist Enterprise operates from the United States. By using this site, you understand that your information will be processed in the US, which may have different data-protection standards than your home country. If you're a resident of the EU/UK and you'd like to exercise rights under GDPR, contact us and we'll handle the request manually.
12. SMS & text messaging (insurance outreach)
Anomalist Enterprise LLC operates an insurance outreach program in which our licensed insurance agents — and the agency brands they operate under — contact consumers who requested information about Medicare, life, or supplemental insurance and consented to be contacted by phone and text. These terms govern that program.
12.1 How we obtain your consent
We text you only if you provided your phone number and agreed to be contacted by phone and text on an insurance quote or inquiry form — either on a site we operate or a lead form completed with one of our licensed lead providers. For each contact we retain the opt-in language, the date, and the source of consent. We do not text a number for which we cannot evidence consent.
12.2 We do not share your mobile information
No mobile information (your phone number or SMS opt-in / consent data) will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing limited to subcontractors that help us deliver our own messages (for example, our messaging provider) is permitted, and those parties may use it only to deliver our messages on our behalf. Text-messaging opt-in data and consent are never sold or shared with any third party for their own use.
12.3 Frequency, rates, and opt-out
- Message frequency varies based on your interaction with us.
- Message and data rates may apply. We don't charge for messages; your carrier's standard rates apply.
- Reply STOP to any message to opt out at any time — we honor opt-outs immediately and permanently. Reply HELP for help, or email support@anomalistenterprise.com.
- Consent to receive messages is not a condition of any purchase.
12.4 Medicare
Our text and email outreach about Medicare is general only. We do not offer every plan available in your area; any information we provide is limited to the plans we offer. To review all of your options, contact Medicare.gov or 1-800-MEDICARE. Specific plan details and enrollment happen with a licensed agent — never by text.
12.5 No health information by text or email
We do not request, collect, or transmit health conditions, medications, or other protected health information through our text or email outreach. Any health-related discussion happens with a licensed agent through a secure, compliant channel.
13. Changes to this policy
We update this page when something material changes about how we handle data. The effective date at the top reflects the most recent change. Continued use of the site or our products after an update constitutes acceptance of the revised policy.
14. Contact
Privacy questions, requests, or complaints: privacy@anomalistenterprise.com.
Anomalist Enterprise LLC · Evansville, Indiana · United States.