Privacy Policy

Your privacy

Last updated: June 15, 2026

Analytics by Andy (“we,” “us”) builds analytics dashboards and process automations for small businesses. This policy explains what data we handle, how we use and protect it, and the choices you have. If you’re a client, the contract you sign (MSA, NDA, and Data Processing Addendum) governs in the event of any conflict.

1. Information we handle

Account information — your name, email, and login credentials, used to give you access to your portal.

Your business data — the operational data you connect or share (for example customer, appointment, and transaction records), discovery-call notes and transcripts, and the dashboards, analyses, and automation outputs we produce for you. This is your data; we process it only to do your work.

Technical data — basic logs and security data needed to run and protect the service.

2. How we use it

We use your data solely to provide and improve the services you’ve engaged us for — building and maintaining your dashboards and automations, and surfacing insights for your business.

We never sell your data, and we never use one client’s data for, or share it with, any other client. Each client’s data is isolated and confidential.

3. AI processing

The AI steps in your build run on Anthropic’s Claude models via Anthropic’s commercial API. Per Anthropic’s terms, API inputs and outputs are not used to train its models (without express permission), and prompts and outputs are not retained by default on the Messages API. We don’t fan your data out to other model providers, and we don’t create embeddings or a vector copy of your documents.

Public, pre-engagement research on a prospect’s own website or public listings may use separate tools on publicly available information only — never a signed client’s confidential data.

4. Service providers (subprocessors)

We rely on a small set of vetted providers to run the service. The core ones:

  • Supabase (on Amazon Web Services) — database, file storage, and authentication.
  • Anthropic — AI processing (see section 3).
  • Google Workspace — email and discovery-call transcripts.
  • Stripe — billing (we never store your card details).

We bind subprocessors to confidentiality and can provide a full, current list on request.

5. Data retention and deletion

Inside your portal, your data stays in your isolated scope until you delete it or leave. If you cancel, you can export everything within 30 days, after which we delete your data from our database and file storage; backups age off on their normal cycle, and AI traffic is discarded by Anthropic on its retention cycle.

6. How we protect it

  • Per-client isolation enforced at the database level (row-level security).
  • Encryption in transit (TLS) and at rest (AES-256).
  • Multi-factor authentication and least-privilege access; admin keys are server-side only.
  • Defense-in-depth security headers on every page.

7. Your rights and choices

You can ask us to access, correct, export, or delete your data at any time. Business clients can request a signed NDA and Data Processing Addendum. To exercise any of these, just email us (below).

8. International, cookies, and children

We operate in the United States. We use only essential cookies needed to keep you signed in — no advertising trackers. Our services are intended for businesses and are not directed to children.

9. Changes

We’ll update this policy as our practices evolve and revise the “last updated” date above. Material changes affecting clients will be communicated directly.

10. Contact

Questions or requests: andy@analyticsbyandy.com.