Privacy Policy

Last updated 22 August 2026

The short version. Venture Command is a private business tool. Your data is stored in Australia, is not sold, is not shared for advertising, and is not used to train anyone’s AI models. There are no tracking pixels and no analytics scripts — we do not know which pages you visit. The one meaningful risk to understand is that when you use an AI feature, the text involved is sent to an AI provider to be processed.

This is a working draft, not legal advice. It was written from what the software actually does — the data list comes from the database schema and every third party named is one the code really calls. Have a lawyer review it before relying on it commercially, and fill in the ABN and contact address marked [to confirm].

1.Who we are

Venture Command is a portfolio operations platform operated by Bright Lotus Ventures Pty Ltd (“we”, “us”), registered in Queensland, Australia. This policy covers the application at venture-command.vercel.app and any custom domain a workspace connects to it.

It is a business tool. Most of what it holds is information about companies, not about consumers — but that information routinely names people, so this policy is written with the Australian Privacy Principles in mind.

2.What we collect

Almost everything here is information you put in, or that we fetch from a service you connected. We do not buy data and we do not enrich it from third-party sources.

CategoryWhat it is
AccountYour name, email address, password hash, and the role you hold in a workspace. Handled by Supabase Auth.
Business recordsEverything a workspace stores about its ventures: financial periods and accounts, contracts, documents, directors, shareholders, cap tables, board minutes, risks, licences, insurances, tasks, decisions and operating manuals.
Commercial contactsLeads, deals and their activity history — which can include a person's name, email, phone and the notes you write about them.
Email, only if you connect a mailboxIf you connect an Outlook or Gmail mailbox to a venture, we store a copy of the messages we sync, along with any AI summary, category or draft reply generated for them. Nothing is ever sent without a person clicking send.
Credentials for services you connectAccess and refresh tokens for the accounts you link (see section 4). Encrypted at rest with AES-256-GCM. Never shown in the browser, never written to a log.
AI conversationsYour messages to the assistants, the replies, which tools ran, and the outcome of each AI call — provider, model, latency, tokens, and whether it succeeded.
Activity logA record of significant actions taken in a workspace — who did what, and when. This is how a workspace owner audits their own team.
TechnicalStandard server request logs kept by our hosting provider. We do not run analytics, advertising or session-replay scripts of any kind.

3.Where it is stored

The database, authentication and file storage are provided by Supabase and are hosted in the Sydney region (ap-southeast-2), Australia. The application itself runs on Vercel, whose servers are distributed globally, so a request may be handled outside Australia even though the stored data is not.

Every table is scoped to a workspace and enforced in the database itself, not only in the application. Where a venture has restricted access, records are scoped to the specific ventures a person has been granted.

4.Who we share it with

We do not sell your data and we do not share it for advertising. We share it with the services below only to the extent needed to do the thing you asked for.

ServiceWhat reaches it, and when
SupabaseAll stored data, authentication and files. Australia.
VercelApplication hosting and request logs.
AI providers — Groq, Mistral, Google (Gemini), OpenRouter, Anthropic, CloudflareThe prompt and context of an AI request at the moment you make one. Which provider handles it depends on availability; the order is visible in the app.
ResendThe content of emails the platform sends, such as invitations.
StripeBilling details, if a workspace subscribes to a paid plan.
Services you connect yourselfGitHub, Vercel, Netlify, GoDaddy, Xero, Stripe, Supabase, Microsoft/Outlook, Google (Gmail, Drive, Calendar), GoHighLevel, Canva, Twilio. Nothing reaches these until you connect them, and each connection can be removed at any time.

On AI and training. We do not use your data to train any model. Content sent to an AI provider is governed by that provider’s own terms; providers differ, and some free tiers reserve broader rights than paid ones. If that matters to your business, choose the provider on the AI settings screen — and treat anything genuinely sensitive as something not to put into a prompt.

5.How it is protected

Access tokens and third-party credentials are encrypted with AES-256-GCM before storage. Row-level security is enforced in the database, so a request that should not see a record does not see it even if the application has a bug. Privileged database access is limited to server-side code and is never exposed to a browser. Passwords are checked against known breach lists at sign-up.

No system is perfectly secure, and we would rather say so than imply otherwise. If you believe an account or a connection has been compromised, remove the connection in the app and contact us.

6.How long we keep it

Workspace data is kept for as long as the workspace exists. Delete a record in the app and it is deleted from the database; delete a workspace and its data is removed with it. Backups may retain a copy for a short period afterwards. Invitations expire automatically after 14 days.

The activity log is deliberately not user-editable — an audit trail that can be edited is not an audit trail.

7.Your rights

You may ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Workspace owners can export their data from the app at any time without asking. We will respond within a reasonable period, and we will not charge you for a reasonable request.

Some information cannot be deleted on request where we are required to keep it — for example, records relating to a paid subscription.

8.Cookies

We set the cookies needed to keep you signed in, and nothing else. There are no advertising cookies, no analytics cookies and no third-party trackers. Your theme choice is stored in your own browser and never reaches us.

9.Changes

If we change this policy in a way that materially affects you, we will say so in the app rather than quietly updating the date at the top.

99.Contact

Questions about this document, a request to access or correct your information, or a complaint:

Bright Lotus Ventures Pty Ltd
ABN [to confirm]
Queensland, Australia [address to confirm]
admin@brightlotusventures.com

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner.

Privacy Policy·Terms of Service