Autolance.ai ("Autolance", "we", "us") is operated by Francisco Jimenez Cabrera based in the United Kingdom. This policy explains what we collect, why, and what you can do about it. Questions: support@autolance.ai.
What we collect
- Account information. When you sign in via SSO or magic link (Supabase Auth), we receive your email address and, if your SSO provider shares it, your name.
- Conversation content. Anything you type into the intake chat, the consultation chat with our AI architect, or the messaging area inside the project portal. These messages may include personal data you choose to share — please be thoughtful about what you put in them.
- Project data. The scope, quote, status, milestones, and tracking events generated as we work with you, including AI-generated quotes and revisions.
- Vault credentials. API keys and tokens you provide for your own third-party tools so we can build automations against them. See the Credential Vault section below.
- Payments. Stripe handles all card processing. We never see or store card numbers; we only receive payment status, the last four digits, and similar metadata from Stripe.
- Technical data. IP address, browser, device, request logs, and authentication session data collected automatically by Vercel (hosting) and Supabase (auth). We use a small number of cookies that are strictly necessary to keep you logged in. We do not use advertising or cross-site tracking cookies.
How we use it
To run your account, hold consultations, generate and deliver quotes, build the automations you hire us to build, take payment, communicate about your project, keep the service secure, and meet our legal and tax obligations.
AI processing
Your chats are sent to Anthropic (Claude) to power the intake and consultation experience and to draft your fixed-price quote. Anthropic does not train its models on API inputs by default.
The AI drafts quotes; quotes that look borderline or unusual are reviewed by the founder before you see them. You can also request a human-reviewed quote at any point before you pay — just ask in the chat or email support@autolance.ai. You will never be locked into an automated decision: you choose whether to accept a quote and pay.
Please do not submit special-category data in chats — health, biometric, genetic, political opinions, religious beliefs, sexual orientation, trade union membership, or precise government identifiers. The product is not designed to handle that kind of data.
Credential vault
To deliver automations across your stack, we let you store API keys, tokens, and similar credentials for your own SaaS tools.
- Encryption. Vault entries are encrypted at rest with AES-256-GCM.
- Access. Decryption happens server-side so the founder and any people working under the Autolance brand on your project can use those credentials to build and run your automations. This is not zero-knowledge storage — please assume that someone delivering the work can read what you put in the vault.
- Your responsibility. You confirm that you have authority to share these credentials with us and that doing so does not breach the terms of the underlying tool. Where possible, please create scoped or limited-permission keys rather than full-admin ones.
- After the project. When a project ends, you should rotate or revoke the keys you shared. You can also ask us to delete vault entries at any time by emailing support@autolance.ai.
Sub-processors
We rely on the following providers to run the service. All are US-based.
- Anthropic — large language model provider (Claude) for the chat and quoting flows.
- Supabase — Postgres database, authentication, realtime messaging.
- Stripe — payment processing.
- Vercel — hosting, deployment, logs.
- Sentry — error monitoring, performance tracing, and session replay so we can diagnose and fix issues. Sentry receives diagnostic data such as request metadata, stack traces, and short replays of sessions where errors occurred.
- Google — only if you choose to sign in with Google SSO.
For users in the EEA, UK, or Switzerland, transfers to these US providers rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or the equivalent safeguard each provider offers.
Sharing and selling
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose data only to the sub-processors listed above to run the service, to the founder and contractors working on your project, and where we are legally required to (for example, to respond to a valid legal request or to defend our rights).
Your rights
Wherever you live, you can email support@autolance.ai to exercise the rights described here. We will verify your identity using your account email before we act.
If you are in the EEA or UK, the GDPR gives you the right to access your data, correct it, delete it, port it to another service, object to or restrict our processing, and withdraw consent where we relied on it. You can also complain to your local supervisory authority — for UK users that is the ICO (ico.org.uk).
If you are in California, the CCPA/CPRA gives you the right to know what we collect, request a copy, request deletion, correct inaccurate data, and opt out of sale or sharing. As stated above, we do not sell or share personal information for advertising, so there is nothing to opt out of on that front, but the right exists. You can also designate an authorised agent to make a request on your behalf.
We will not discriminate against you for exercising any of these rights.
Retention
We keep your account, project data, and conversation content while your account is active and for a reasonable period afterwards so we can handle disputes, support, and tax and accounting obligations. Vault credentials can be deleted on request at any time and are not retained beyond what is needed to deliver the work. Once operations stabilise we will publish a more specific retention schedule here.
Security
We use encrypted connections (TLS) in transit, AES-256-GCM for vault entries at rest, and rely on the security controls of Supabase, Vercel, and Stripe for the underlying infrastructure. No system is perfectly secure — please use a strong, unique password (or SSO) and tell us quickly if you suspect your account has been compromised.
Children
Autolance is for adults running businesses. We do not knowingly collect personal data from anyone under 18. If you believe a child has used the service, email support@autolance.ai and we will delete the data.
Changes to this policy
We will update this page as the product evolves. Each version carries an effective date at the top. For material changes, we will email registered users in advance.
Contact
Questions, requests, or complaints: support@autolance.ai.
Service operated by Francisco Jimenez Cabrera, based in the United Kingdom.