01Introduction
AUM Pulse, Inc. ("AUM Pulse," "we," "us," "our") provides a relationship-intelligence platform for independent financial advisors. The product joins prospect meetings as a named participant, synthesizes a structured pre-call brief from each conversation, surfaces relationship intelligence (including the Vital™ relationship-health metric) on the advisor's prospect record, supports advisor-initiated Cadence post-call correspondence from the advisor's connected mailbox, and — when the advisor opts in — syncs marketing-channel spend signals (Trace) for attribution. This Privacy Policy describes how AUM Pulse collects, uses, retains, and shares information in the course of providing the service.
This Policy is written primarily for advisors who use AUM Pulse, advisors' firms, and the compliance and security reviewers who evaluate AUM Pulse on those firms' behalf. The end-prospects whose data flows through AUM Pulse interact with the platform through their advisor, not directly with AUM Pulse; the controller relationship for prospect data sits with the advisor's firm, not with AUM Pulse.
Two roles, one platform
For advisor account data — the information an advisor or their firm provides to set up and use AUM Pulse, including authentication credentials, firm affiliation, settings, and integration connections — AUM Pulse acts as data controller. This Policy describes what we collect, how we use it, and the rights advisors have with respect to that data.
For prospect data — the information that flows into AUM Pulse on behalf of the firm's prospects, including contact details, meeting metadata, and the synthesized intelligence derived from meeting transcripts — AUM Pulse acts as data processor. The advisor's firm is the data controller. AUM Pulse processes prospect data on the firm's documented instructions, subject to the terms of the Data Processing Agreement executed between AUM Pulse and the firm. Data subject requests from prospects (access, deletion, correction) are routed through the firm; AUM Pulse provides reasonable assistance to the firm in responding to such requests.
This Policy is one part of AUM Pulse's compliance documentation set, which also includes the Terms of Service, the Data Processing Agreement, the recording consent flow documentation, the firm compliance brief, and the data architecture document. Documents are available on request.
02Information AUM Pulse Collects
2.1 Advisor account data (AUM Pulse as controller)
- Account identification. Advisor name, email address, authentication metadata (managed via Supabase Auth), and the firm record the advisor belongs to.
- Firm-level configuration. Firm name, fee-model defaults, annual AUM and revenue targets where recorded, branded meeting-type names, and similar configuration.
- Integration credentials. When an advisor connects a third-party scheduling, calendar/mail, or advertising platform, AUM Pulse stores the credentials necessary to perform the opted-in function — for Calendly, Google, Outlook, Meta Ads, Google Ads, and LinkedIn Ads, an OAuth access token and refresh token; for OnceHub, a per-advisor webhook secret. Credentials are stored scoped to the advisor and accessible only to the advisor's authenticated session via row-level security.
- Google (Calendar + Gmail send). One advisor-opt-in OAuth connection covers calendar read/write and Cadence email send. Scopes include
calendar.readonly,calendar.events,gmail.send, plus identity scopes. Disconnect clears credentials from AUM Pulse and revokes the grant at Google. - Microsoft (Outlook Calendar + Mail.Send). One advisor-opt-in OAuth connection covers calendar read/write and Cadence email send. Scopes include Microsoft Graph
Calendars.ReadWrite,Mail.Send,User.Read, plus identity andoffline_access. Disconnect clears credentials from AUM Pulse; the advisor must revoke consent on Microsoft's side separately. - Meta Ads, Google Ads, and LinkedIn Ads (Trace). Advisor-opt-in OAuth connections used solely to pull advertising spend and conversion aggregates for channel attribution. Scopes: Meta
ads_read,read_insights; Google Adsadwordsplus identity scopes; LinkedInr_adsandr_ads_reporting. AUM Pulse does not push prospect personal data to these advertising platforms.
- Google (Calendar + Gmail send). One advisor-opt-in OAuth connection covers calendar read/write and Cadence email send. Scopes include
- Advisor preferences and branding. IANA timezone and personal video-meeting URL (advisor-supplied via Settings); optional email signature appended when sending Cadence mail; optional firm logo and advisor headshot assets uploaded to Supabase Storage bucket
brandingfor public booking identity surfaces. - Optional team-member emails. Used solely to route inbound booking events to the correct advisor record.
- Application interaction data. Server-side timestamps for prospect creation, edits, meeting bookings, and synthesis events; anonymized user identifier for error monitoring.
2.2 Prospect data (AUM Pulse as processor)
- Contact information. Prospect first name, last name, email address, and optionally phone number.
- Household / spouse contact (optional). Advisor-supplied spouse or household-member name and email, used primarily as default Cc recipients on Cadence post-call correspondence when the advisor chooses to include them.
- Advisor-supplied estimates. An estimate of the prospect's investable assets typed by the advisor. AUM Pulse does not query any custodian, brokerage, or banking system.
- Advisor-authored notes. Free-text notes equivalent in scope to a standard CRM notes field.
- Booking context. Booking platform, platform event identifier, UTM tracking parameters from trackable booking links (Trace attribution), and advisor-recorded referral relationships.
- Meeting metadata. Meeting date, time, type, duration, scheduling platform, lifecycle timestamps, meeting outcome the advisor logs, and call-substrate provenance (
recorded|unrecorded). - Synthesized intelligence from meetings. A pre-call brief, a "don't do" note, a psychological-state routing signal, structured claim arrays (goals, concerns, financial picture) each with a brief verbatim excerpt capped at 280 characters, personality read, Opening Move and evidence, rhythm line and rhythm anchor date, structured advisor commitments (ACI), scheduling-intent signals, and a per-meeting talk-ratio aggregate.
- Cadence draft and send metadata. Temporary draft subject, body, and structured paragraph payloads for post-call Cadence letters. After a successful advisor-initiated send (or purge), draft prose is purged; retained fields include send timestamps, provider message identifiers, package/follow-up status, offered scheduling slots / intent signals, and content-purged markers. AUM Pulse does not maintain a long-term archive of full sent message bodies — the durable copy lives in the advisor's Sent folder on Gmail or Outlook.
- Booking tokens. Opaque self-booking tokens minted into certain Cadence letters so a prospect can pick an offered slot. Tokens store hashed values, offered slots, expiry, and use/void state.
- Vital™ metric. A relationship-health score derived from non-conversational signals — meeting recency, stage progression, meeting outcomes, and engagement patterns. Computed without reading any meeting transcript or synthesized text content.
- Audit trail. A record of advisor corrections to synthesized claims, retained as adviser-prepared recordkeeping evidence consistent with SEC Rule 204-2(a)(11).
2.3 What AUM Pulse does not collect
- Government-issued identifiers. No Social Security numbers, tax IDs, dates of birth, or other government-issued identifiers.
- Custodial financial data. No account numbers, holdings, positions, balances, transaction history, or any time-series financial data. AUM Pulse has no integration with any custodian, brokerage, or banking provider.
- Actual transferred assets at close. Only closure status and timestamp are recorded.
- Meeting audio. Never retained on AUM Pulse infrastructure. Recall.ai applies a 24-hour timed-retention floor; AUM Pulse instructs Recall.ai to delete the recording immediately upon successful synthesis.
- Raw meeting transcripts. Exist only in edge-function memory during synthesis; never written to any database, log, or external destination.
- Prospect document vault / engagement files. AUM Pulse does not provide a general file-upload vault for prospect engagement letters, ACATS forms, regulatory delivery items, or similar documents. Those documents live in the advisor's external systems; AUM Pulse records only workflow-state metadata. Separately, AUM Pulse allows two limited advisor-only Storage uploads on Supabase: (a) firm logo and advisor headshot assets in the
brandingbucket (public URLs for booking identity); and (b) support-ticket attachments in thesupport-attachmentsbucket (capped at three files per ticket, 10 MB each, extensions limited to PNG/JPEG/WebP/PDF/CSV/TXT). Support attachments may incidentally contain prospect-related screenshots if an advisor uploads them; they are not a prospect CRM document store. - Protected Health Information (PHI). AUM Pulse is not configured as a HIPAA-covered service.
- Home addresses or precise geolocation. No such columns exist on the prospect record.
03How AUM Pulse Uses Information
- To provide and operate the service. Authenticating advisors, displaying prospect records and meeting schedules, generating synthesized briefs and related relationship intelligence, computing the Vital™ relationship-health metric, hosting limited branding assets, processing advisor support tickets (including capped attachments), and maintaining the advisor-correction audit trail.
- To facilitate scheduled meetings. Using booking metadata to create prospect records, schedule the meeting bot, and prepare briefs in advance. Where Cadence letters include self-booking links, AUM Pulse mints and validates booking tokens so prospects can select offered slots.
- To compose and send Cadence post-call correspondence (advisor-initiated only). AUM Pulse uses Anthropic's Claude API to help compose Cadence letter drafts (e.g., send-times / STI, post-call follow-up, noshow, and reschedule packages). Send occurs only when the advisor explicitly clicks Send; AUM Pulse does not auto-send. Outbound delivery uses the advisor's connected Gmail or Outlook mailbox via
gmail.sendor Microsoft GraphMail.Send. The advisor remains responsible for the content and for the communication with their prospect; AUM Pulse is not the sender of record. - To improve advisor effectiveness. Synthesized intelligence (claim arrays, pre-call brief, psychological-state routing signal, Opening Move, rhythm, talk-ratio aggregate, and related fields) and optional coaching / show-rate copy generated via Anthropic are advisor-facing. They are not investment advice, not a recommendation, and not a clinical or diagnostic assessment of the prospect.
- To sync marketing-channel spend for Trace attribution. When an advisor connects Meta Ads, Google Ads, and/or LinkedIn Ads, AUM Pulse pulls spend, impression, and conversion aggregates into firm/advisor analytics tables and correlates them with booking UTM attribution. Prospect personal data is not sent to the advertising platforms for this purpose.
- To send service-related communications. Transactional and operational communications about the account or material changes to documentation.
- To monitor service health and security. Error events captured by Sentry — method, URL pathname, and stack trace only. No request body, headers, query string, IP, or prospect content.
- To comply with legal obligations. Including retention of the advisor-correction audit trail consistent with SEC Rule 204-2(a)(11).
04Data Architecture Overview
In addition to meeting-transcript synthesis, AUM Pulse invokes Anthropic's Claude API to compose Cadence letter drafts, generate coaching messages, produce show-rate / rhythm copy, and draft lost-reason detail text. In each case, prompt content is in transit to Anthropic only for the duration of the API call (subject to Anthropic's commercial API log retention); AUM Pulse does not use Anthropic feedback channels, and Anthropic's commercial terms provide that customer data is not used for model training.
05Sharing and Subprocessors
AUM Pulse does not sell prospect data. AUM Pulse does not share prospect data with third parties for advertising or marketing purposes. AUM Pulse uses the following subprocessors:
| Subprocessor | Function | Compliance |
|---|---|---|
| Recall.ai | Meeting-bot platform. Audio ≤24 hours on Recall.ai infrastructure; transcripts deleted post-synthesis. | SOC 2 Type 2, ISO 27001, GDPR, CCPA |
| Supabase | Managed database, edge-function runtime, authentication, and object Storage (branding, support-attachments buckets). |
SOC 2 Type 2, ISO 27001, HIPAA-capable |
| Anthropic | Claude API — meeting-transcript synthesis; Cadence letter compose; coaching messages; show-rate / rhythm copy; lost-reason draft. Prompt content in transit only; 7-day commercial API log retention. No model training on customer data. | Commercial Terms |
| Vercel | Frontend hosting. | SOC 2 Type 2, ISO 27001, GDPR/CCPA |
| Sentry | Error monitoring. Method, URL pathname, stack trace only — no payloads, no IPs, no prospect content. | SOC 2 Type 2 |
| Calendly | Booking webhook source. | Calendly trust center |
| OnceHub | Alternative booking webhook source. | OnceHub trust center |
| Google LLC Google Calendar + Gmail |
Advisor-opt-in Google connection — calendar busy-time read; create/update/delete post-call follow-up calendar events; and Cadence email send via Gmail API (gmail.send) on explicit advisor Send. Send is advisor-initiated only. Google retains sent messages in the advisor's Gmail Sent folder; AUM Pulse purges draft prose after send and does not keep a long-term full-body archive. Prospect last name, phone, assets, notes, and synthesized intelligence are not included in calendar payloads. |
SOC 2 Type 2, ISO 27001/27017/27018, GDPR/CCPA |
| Microsoft Corporation Outlook Calendar + Mail.Send |
Advisor-opt-in Outlook connection — calendar busy-time read; create/update/cancel post-call follow-up calendar events; and Cadence email send via Graph Mail.Send on explicit advisor Send. Send is advisor-initiated only. Microsoft retains sent messages in the advisor's Sent Items; AUM Pulse purges draft prose after send. OAuth scopes include Calendars.ReadWrite and Mail.Send. |
SOC 2, ISO 27001, ISO 27018, GDPR/CCPA |
| Meta Platforms, Inc. Meta Ads (Trace) |
Advisor-opt-in Trace ads integration — pull advertising spend and insights via Meta Marketing API (ads_read, read_insights). No prospect personal data is sent to Meta. |
Meta Business / developer trust center |
| Google LLC Google Ads (Trace) |
Advisor-opt-in Trace ads integration — pull advertising spend and conversions via Google Ads API. No prospect personal data is sent to Google Ads. Listed separately from Calendar/Gmail because it is a distinct OAuth grant. | SOC 2 Type 2, ISO 27001/27017/27018, GDPR/CCPA |
| LinkedIn Corporation LinkedIn Ads (Trace) |
Advisor-opt-in Trace ads integration — pull advertising spend and reporting (r_ads, r_ads_reporting). No prospect personal data is sent to LinkedIn. |
LinkedIn trust center |
| Cloudflare | DNS-only proxy. No payload visibility. | Cloudflare trust center |
AUM Pulse will provide firms with thirty (30) days advance notice before adding any new subprocessor that materially affects the processing of prospect data.
06Retention and Deletion
- Application-level retention. Advisor account data is retained for the duration of the account plus a commercially reasonable period thereafter. Prospect records, meeting records, synthesized claims, Cadence send metadata (after draft-body purge), booking-token rows (until used, voided, or expired), and related rows are retained until the advisor explicitly deletes the prospect or the prospect is archived after a firm-configurable staleness threshold. Archival changes status; it does not delete underlying data.
- Cadence draft purge. After a successful advisor-initiated Cadence send (and in certain purge paths), ephemeral draft prose is nulled while send timestamps, provider message identifiers, package/follow-up status, and scheduling-slot / intent metadata are retained. AUM Pulse does not retain a long-term archive of full sent message bodies.
- Booking tokens. Booking tokens expire at the end of the last offered slot (or earlier if voided/used). Advisors can void live unused tokens for a prospect.
- Storage objects. Branding assets persist while the firm/advisor keeps the public URL configured. Support-ticket attachments persist for the life of the support ticket / account unless removed operationally; they are capped at three files per ticket and 10 MB each.
- Database backups. Eight (8) days of daily physical backups managed by Supabase, encrypted at rest.
- Audit-trail retention. The advisor-correction audit trail is append-only and is retained across prospect deletion as recordkeeping evidence consistent with SEC Rule 204-2(a)(11).
- Deletion mechanics. Advisor-invoked deletion executes a Postgres function (
remove_prospect) that cancels Google Calendar and Outlook Calendar follow-up events via organizer-initiated cancellation, deletes meeting history (including Cadence-related fields and advisor commitments), and cascades through related events, document-state rows, notes, and stage checklist completions. Meeting-linked Cadence drafts and related booking-token rows are removed with the meeting/prospect graph under ordinary foreign-key rules where configured. Sent-folder copies of Cadence emails already delivered via Gmail or Outlook remain under the advisor's mailbox control and are not deleted byremove_prospect.
Deletion takes effect immediately at the application layer; data persists in backups for up to eight days, after which it is unrecoverable.
Vendor-side retention
- Recall.ai retains meeting audio for at most twenty-four (24) hours; in normal operation AUM Pulse deletes the recording immediately after synthesis succeeds.
- Anthropic retains commercial API request logs for seven (7) days. AUM Pulse does not submit feedback to Anthropic, so the no-training default applies.
- Google holds the advisor's OAuth grant(s), post-call follow-up calendar events, and Cadence messages in the advisor's Gmail Sent folder until the advisor deletes them.
- Microsoft holds the advisor's OAuth grant, post-call follow-up Outlook events, and Cadence messages in Sent Items until the advisor deletes them.
- Meta Platforms and LinkedIn hold the advisor's ads OAuth grants and advertising-account data already present on those platforms; AUM Pulse pulls aggregates only.
07Security Measures
- Row-level security. Every table in AUM Pulse's Postgres database is protected by row-level security policies that scope reads and writes to the user's firm at the database layer. A formal audit was conducted April 19, 2026; four CRITICAL findings were identified and closed before any external advisor accessed the system.
- Encryption at rest. AES-256, managed by Supabase, covering all database files, indexes, write-ahead logs, and backups.
- Encryption in transit. TLS 1.2 or higher for all HTTP traffic to and from AUM Pulse. Outbound API calls to Recall.ai, Anthropic, Calendly, OnceHub, Google, Microsoft, Meta, LinkedIn, and Sentry all use HTTPS.
- Storage access controls. Supabase Storage buckets are governed by storage RLS policies: the
brandingbucket permits firm-scoped writes for logo/headshot paths and public read of configured booking-identity assets; thesupport-attachmentsbucket permits authenticated advisor upload within size/type caps. Neither bucket is a general prospect document vault. - Authentication and access control. Managed by Supabase Auth. Service-role credentials are stored as Edge Function Secrets and never exposed to the frontend or advisor sessions.
- Observability PII discipline. Sentry captures only HTTP method and URL pathname — never request bodies, headers, query strings, or client IP addresses. Session Replay is intentionally disabled.
- Personal data breach notification. AUM Pulse will notify affected firms within seventy-two (72) hours of becoming aware of a personal data breach.
08Your Rights
8.1 Advisor rights (AUM Pulse as controller)
- Access. Request a copy of the account data AUM Pulse holds.
- Correction. Correct or update account information within the application or by contacting AUM Pulse.
- Deletion. Request deletion of your account, subject to retention obligations described in Section 6.
- Portability. Where applicable law requires, AUM Pulse will provide account data in a structured, commonly used format.
- Objection and restriction. Object to certain processing or request restriction to the extent provided by applicable law.
8.2 Prospect rights (firm as controller)
For prospect data, AUM Pulse acts as processor on the firm's behalf. Data subject requests from prospects are routed through the advisor's firm. AUM Pulse provides reasonable assistance including access production, deletion execution, and correction recording through the advisor-correction audit-trail mechanism.
8.3 Audit and compliance review
Firms may, upon request and not more than once per twelve-month period, review subprocessor attestation reports, AUM Pulse's own attestation reports, and the data architecture and row-level-security audit documentation. AUM Pulse will respond to security questionnaires within thirty (30) days on a reasonable-efforts basis.
09International Data Transfers
AUM Pulse's primary infrastructure and the infrastructure of its subprocessors are operated in the United States. Where personal data is transferred internationally, the transfer is made subject to applicable legal protections, including, where required, the Standard Contractual Clauses approved by the European Commission. Firms with EU, UK, or Swiss data subjects should reach out during onboarding to confirm the applicable transfer mechanism.
10Children's Privacy
AUM Pulse is a business-to-business service intended for use by independent financial advisors. The service is not directed at children, and AUM Pulse does not knowingly collect personal information from children under thirteen (13) years of age. If AUM Pulse becomes aware that it has inadvertently collected personal information from a child, AUM Pulse will delete that information.
11Changes to This Policy
AUM Pulse may update this Policy from time to time. Material changes will be communicated to advisors and firms through the application or through email to the address on file before they take effect. The effective date of the current version is at the top of this document; prior versions are retained internally and are available on request.
12Contact
Questions about this Policy, or requests to exercise the rights described in Section 8, may be directed to:
This Policy is governed by the laws of the State of Arizona, without regard to its conflict-of-laws principles. Any dispute arising under this Policy is subject to the dispute-resolution provisions of the Terms of Service.