Privacy Policy

Effective Date: December 2, 2025

Last Updated: December 2, 2025

Company: Anso (operated by Bright Idea Sparks, LLC)

Contact: privacy@ideasparks.io

1. Introduction

Anso ("we," "our," or "us") provides an AI-powered enterprise intelligence platform that conducts strategic interviews with employees, analyzes organizational workflows, and delivers transformation insights. We are committed to protecting the privacy and security of all individuals whose data we process — including our clients, their employees, and visitors to our website.

This Privacy Policy explains what information we collect, how we use it, and the choices available to you when you use our website, platform, and services (collectively, "Services").

Scope: This Privacy Policy applies when Anso acts as a data controller (e.g., website visitors, prospective clients) and when Anso acts as a data processor on behalf of enterprise clients. Where Anso acts as a data processor, the client organization is the data controller and their own privacy policies govern the collection and use of their employee data. In those cases, this policy describes the processing Anso performs on the client's behalf.

2. Information We Collect

2.1 Website Visitors

When you visit tryanso.com, we may collect:

  • Usage data: Pages visited, time on site, referral source, browser type, device type, and IP address (anonymized where feasible).
  • Cookies and similar technologies: For analytics, session management, and improving your experience. See Section 9 for details.
  • Contact information you provide: Name, email address, company name, and job title when you submit a form, request a demo, or subscribe to communications.

2.2 Client Organizations

When an enterprise client engages Anso, we collect:

  • Organizational context: Company name, department structures, documentation provided for interview preparation, and project scope details.
  • Administrative contacts: Names, emails, and roles of client stakeholders managing the engagement.
  • Payment information: Billing details and transaction records as needed to process payments for our services.

2.3 Interview Participants (Client Employees)

Our AI interview platform collects data from employees who participate in interviews on behalf of a client organization:

  • Voice recordings and Voice Data: Audio recordings of AI-conducted interviews, including voice characteristics processed by our voice synthesis provider to conduct the interview conversation. Depending on your jurisdiction, Voice Data may constitute biometric data under applicable laws (see Section 11).
  • Transcripts: Text transcriptions generated from interview audio.
  • Interview-derived insights: Workflow descriptions, process steps, time estimates, tool usage patterns, pain points, and operational observations shared during conversations.
  • Participant metadata: Name, role, department, and tenure as provided by the client or participant.

Important: Employee participation is arranged by and through the client organization. Anso acts as a data processor on behalf of the client (the data controller). Employees should consult their employer's internal privacy notices for details on the basis for participation.

2.4 Behavioral and Workflow Data (Where Applicable)

For clients who engage Anso's Workflow Intelligence services:

  • Metadata from enterprise tools: Application usage patterns, document workflow sequences, communication frequency patterns, and task timing — sourced from the client's existing monitoring infrastructure (e.g., DLP, productivity, and compliance tools).
  • No content inspection: We analyze behavioral metadata only. We do not read, access, or inspect the content of emails, documents, or messages.

3. How We Use Your Information

PurposeData UsedLegal Basis (GDPR)
Conduct AI interviews and produce deliverablesVoice recordings, transcripts, organizational contextLegitimate interest / Contract performance
Analyze workflows and identify inefficienciesBehavioral metadata, interview insightsLegitimate interest / Contract performance
Generate client reports and transformation roadmapsAggregated and synthesized interview and workflow dataContract performance
Support ongoing Intelligence Base subscriptionsTranscripts, validated workflows, anonymized behavioral patternsContract performance
Improve our platform and AI capabilitiesAggregated, de-identified usage patterns onlyLegitimate interest
Communicate with prospects and clientsContact informationConsent / Legitimate interest
Comply with legal obligationsAs requiredLegal obligation
Prevent fraud and ensure platform securityTechnical information, usage dataLegitimate interest / Legal obligation

We do not:

  • Sell personal data to third parties.
  • Use one client's data to train models for another client.
  • Use client data to train Anso's own AI models without explicit consent and anonymization.
  • Inspect the content of employee communications, documents, or files.
  • Share identifiable employee-level data outside the client engagement without consent.
  • Process personal data for targeted advertising purposes.

4. Third-Party AI Service Providers and Model Training

4.1 AI Subprocessors

Anso's platform uses third-party AI services to power our interview engine, analysis capabilities, and report generation. These providers process data under contract as subprocessors acting on Anso's instructions. Our current AI subprocessors are:

ProviderRoleData Processed
ElevenLabsVoice synthesis for AI interview conversationsVoice audio, conversation content
Anthropic (Claude API)Interview analysis and synthesisInterview transcripts, organizational context
OpenAI (GPT API)Report generation and analysis supportInterview transcripts, organizational context

A current list of all subprocessors is available upon request.

4.2 No Third-Party Model Training

Anso has contractually ensured that no client data is used to train third-party AI models. Specifically:

  • Anthropic: Under Anthropic's Commercial Terms, data submitted through the API is not used to train Anthropic's models by default. Anso uses the API exclusively; no data flows through consumer-facing products.
  • OpenAI: Under OpenAI's API terms, data submitted through the API is not used to train OpenAI's models. Anso uses the API exclusively; no data flows through consumer-facing products such as ChatGPT.
  • ElevenLabs: Anso has contractually opted out of any use of client voice data or conversation content for ElevenLabs' model training or improvement purposes.

None of these providers retain client data beyond what is necessary to process the immediate request, subject to their respective data retention and safety obligations described in Section 4.4.

4.3 Data Sovereignty

  • Client data is never shared between clients or used to benefit other Anso customers.
  • Fine-tuned models created for a client's Intelligence Base are owned by that client.
  • Training data for client-specific models uses validated, anonymized workflows — not raw personal data.

4.4 Content Moderation by Subprocessors

Our AI subprocessors may review or flag content that their automated systems identify as potentially violating their usage policies (e.g., content involving illegal activity, fraud, or safety concerns). This monitoring is limited to policy enforcement and safety purposes. In rare cases:

  • Anthropic may retain content flagged for safety review to improve its ability to detect harmful content, even where other training opt-outs apply.
  • ElevenLabs may moderate input and output content, and in certain circumstances may share flagged content with third parties for content moderation and safety purposes.
  • OpenAI may monitor content submitted to its API for fraud, illegal activity, or policy violations.

These safety-related reviews are standard across enterprise AI providers and are limited to detecting misuse — they do not involve general-purpose data mining or model training on client content.

5. Data Anonymization and Aggregation

Anso employs anonymization and aggregation throughout our process:

  • Interview transcripts are stripped of personally identifiable information (PII) before analysis, where the engagement scope permits.
  • Behavioral data is anonymized before pattern analysis — individual identities are not required for workflow intelligence.
  • AI model training data (Intelligence Base) uses validated workflows and operational patterns, not raw personal data.
  • Reports and deliverables present findings at the role, team, or department level — not attributed to named individuals — unless explicitly agreed upon with the client.

We maintain and use de-identified information in de-identified form and will not attempt to re-identify it, unless required by law.

6. Data Sharing and Third Parties

We may share data with the following categories of recipients:

  • Client organizations: Deliverables, reports, and synthesized insights are provided to the contracting client. Clients are responsible for how they use these outputs internally.
  • AI subprocessors: As described in Section 4.1, our AI service providers process data under contract solely on Anso's instructions.
  • Cloud infrastructure providers: We use enterprise-grade cloud hosting (e.g., Google Cloud Platform, Supabase) for data storage and platform operations. These providers process data under contract and are obligated to protect it.
  • Professional advisors: Legal, accounting, or compliance advisors as necessary.
  • Legal requirements: Where required by law, regulation, legal process, or governmental request.
  • Business transfers: In the event of a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected parties of any such transfer.

We require all third-party processors to maintain security standards consistent with our own commitments. We do not sell personal data to any third party.

7. Data Retention and Deletion

7.1 Voice Recordings

Voice recordings from AI-conducted interviews are retained for 90 days following completion of the relevant interview session. This period allows for quality assurance, transcript verification, and resolution of any client questions. After 90 days, voice recordings are automatically deleted from Anso's systems and from our voice synthesis provider (ElevenLabs).

7.2 Interview Transcripts

Interview transcripts are retained for the duration of the client service relationship. Transcripts support ongoing intelligence services, including the Anso Intelligence Base subscription. Upon termination of the service agreement, transcripts are deleted within 90 days unless the client requests earlier deletion or extended retention.

For Intelligence Base subscribers, transcripts are retained as part of the active subscription and deleted upon termination plus a 90-day wind-down period.

7.3 Behavioral Metadata

Behavioral and workflow metadata is retained only for the duration of active analysis. It is deleted or returned to the client upon engagement completion.

7.4 Website Visitor Data

Analytics data is retained for up to 24 months. Contact information is retained until you unsubscribe or request deletion.

7.5 Client Account Data

Retained for the duration of the business relationship plus any legally required retention period.

7.6 Subprocessor Retention

While Anso enforces the retention periods above for data within our control, our AI subprocessors may retain limited data pursuant to their own safety, security, and legal obligations:

  • ElevenLabs may retain voice data for up to the period configured in our agreement (currently aligned with Anso's 90-day policy).
  • Anthropic and OpenAI do not retain API input/output data beyond the duration of processing the request, except where content is flagged for safety review.

7.7 Deletion Requests

You or your organization may request deletion at any time by contacting us at the address in Section 14. We will process deletion requests within 30 days and coordinate with subprocessors to ensure data removal across systems.

8. Data Security

We implement appropriate technical and organizational security measures to protect personal data, including:

  • Encryption: Data encrypted in transit (TLS) and at rest.
  • Access controls: Role-based access with principle of least privilege.
  • Audit logging: All data access and model queries are logged.
  • Infrastructure security: Hosted on enterprise-grade cloud infrastructure with SOC 2-aligned practices.
  • Rate limiting and monitoring: Usage monitoring on all platform endpoints.
  • Subprocessor security: Our AI providers maintain their own security certifications. ElevenLabs publishes security measures and audit certifications at their compliance portal. Anthropic and OpenAI implement commercially reasonable technical, administrative, and organizational security measures.

We are pursuing SOC 2 Type II certification and support industry-specific compliance requirements (HIPAA, FINRA, PCI-DSS) through configurable deployment options.

No internet transmission or electronic storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security.

9. Cookies and Tracking Technologies

Our website uses cookies to operate and secure our Services.

Cookie TypePurposeDuration
Strictly necessaryAuthentication, session management, and securitySession-based

We use only strictly necessary cookies to enable user authentication and maintain secure sessions through Supabase. These cookies are essential for the platform to function and do not require consent under applicable privacy laws.

We do not use analytics, marketing, or tracking cookies. You can manage cookie preferences through your browser settings, though disabling authentication cookies will prevent you from using authenticated features of the platform.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request erasure of your personal data ("right to be forgotten").
  • Restriction: Request that we limit processing of your data.
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw consent: Where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.

For interview participants (client employees): Because your employer is the data controller for interview data, rights requests related to that data should be directed to your employer in the first instance. We will cooperate with your employer to fulfill such requests.

To exercise your rights as a website visitor or direct contact, email us at privacy@ideasparks.io.

We will respond to verified requests within 30 days (or as required by applicable law). We may request reasonable information to verify your identity before fulfilling a request. We will not discriminate against you for exercising your privacy rights.

11. Biometric Data

Anso's AI interview platform uses voice synthesis technology provided by ElevenLabs. When employees participate in AI-conducted interviews, their voice recordings are processed to conduct and transcribe the conversation. This Voice Data — including characteristics of an individual's voice — may constitute biometric data under certain state and national laws, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, and similar legislation.

How we handle biometric data:

  • Voice recordings are collected solely for the purpose of conducting and transcribing AI interviews on behalf of the client organization.
  • We do not use Voice Data to identify individuals, infer personal characteristics, or create voiceprints for purposes beyond the interview engagement.
  • Voice recordings are retained for no longer than 90 days after the interview session, after which they are permanently deleted.
  • We do not sell, lease, trade, or otherwise profit from biometric data.
  • Our voice synthesis provider (ElevenLabs) processes Voice Data under contract as a subprocessor. ElevenLabs has certified that Voice Data processed through our integration is not used for their model training.

Consent: Where required by applicable biometric data laws, consent for the collection and processing of biometric data is obtained by the client organization (as data controller) from participating employees prior to interview participation. Anso provides clients with template consent language and supports compliance workflows.

12. International Data Transfers

Anso is based in the United States. Your data may be transferred to and processed in the following jurisdictions:

JurisdictionReason
United StatesAnso platform hosting, Anthropic API processing, OpenAI API processing, ElevenLabs processing
NetherlandsElevenLabs cloud infrastructure
SingaporeElevenLabs cloud infrastructure

For transfers from the EEA, UK, or Switzerland, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • EU-US Data Privacy Framework (DPF): ElevenLabs is certified under the EU-US and Swiss-US Data Privacy Framework, as well as the UK Extension.
  • Data processing agreements with appropriate safeguards with all subprocessors.

For clients requiring data residency, we offer deployment options that keep data within specified geographic boundaries where feasible.

13. Children's Privacy

Anso's services are designed for enterprise use and are not directed at individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe we may have inadvertently processed such data, please contact us at privacy@ideasparks.io.

14. Contact Us

If you have questions about this Privacy Policy or our data practices:

Anso (Bright Idea Sparks, LLC)

Email: privacy@ideasparks.io

Address: 1259 El Camino Real, Unit #1492, Menlo Park, CA 94025

Website: tryanso.com

You may also have the right to lodge a complaint with a supervisory authority in your country of residence or place of work.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via our website and, where appropriate, by direct notice to clients. The "Last Updated" date at the top reflects the most recent revision. Previous versions are available upon request.

16. Supplemental Notices

16.1 California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information.

  • Anso does not sell personal information.
  • Anso does not share personal information for cross-contextual behavioral advertising.
  • Anso does not process sensitive personal data for the purpose of inferring characteristics about a consumer.

To exercise California-specific rights, contact us at privacy@ideasparks.io. We will verify your identity before processing requests and will not discriminate against you for exercising your rights.

16.2 Other U.S. State Privacy Laws

Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Oregon, Montana, and Texas) may have additional rights similar to those described in Section 10. To exercise state-specific rights, contact us at privacy@ideasparks.io.

16.3 Enterprise Clients (Data Processing Addendum)

Enterprise clients may request a Data Processing Addendum (DPA) that governs the processing of personal data under GDPR, CCPA, or other applicable frameworks. DPAs are available upon request and form part of the master services agreement. Our DPA includes standard contractual clauses for international data transfers and details on subprocessor management.

This privacy policy is provided for informational purposes and does not constitute legal advice. Anso recommends that organizations consult qualified legal counsel regarding data protection compliance.