Version 1.1, effective September 2, 2026. This policy applies to the Wallace Understudy service only (formerly marketed as Wallace Succession). The Wallace investing platform has a separate privacy policy at wallacefinance.io.
Wallace Understudy is business software sold to firms. This policy explains what we do with information about the people who use it: advisors, team members, successors, and administrators.
The most important thing to understand is what we do not have.
What we do have is your account information, the firm documents you choose to upload, the de-identified patterns, the method statements your advisor confirms, your playbook, your recent chats, practice memory if your firm turns it on, and operational data about how the software is running.
Wallace Finance Co., a Delaware corporation doing business as Wallace Understudy ("Wallace," "we," "us"), provides the Wallace Understudy service, a digital twin of an advisory practice used for training, continuity, and succession (the "Services"). Our mailing address is 8 The Grn, Ste B, Dover, DE 19901. You can reach us at support@wallacefinance.io.
This policy covers personal information we handle in connection with the Services and our marketing website, including information about:
This policy does not cover the subscribing firm's own clients, because we do not receive information about them. It also does not cover a firm's own privacy practices; each firm is responsible for its own.
With respect to firm documents, de-identified patterns, confirmed method statements, practice memory, playbooks, chats, and output, we act as a service provider and processor on behalf of the subscribing firm, which is the business and controller. We process that material only on the firm's documented instructions and only to provide the Services. With respect to account registration data, billing data, support communications, marketing contacts, and service telemetry, we act as the business and controller for our own limited purposes.
Account and identity. Name, business email, job title, firm name, role, seat assignment, credentials and authentication data. Why and how long: To create and secure accounts, provision seats, and provide support. Retained for the subscription term plus the periods in Section 7.
Billing. Billing contact, billing address, subscription plan, invoice and payment history. Card data is handled by our payment processor; we do not store full card numbers. Why and how long: To bill and collect, and to meet tax and accounting record requirements. Retained seven years.
Firm Documents. Standard operating procedures, policy manuals, checklists, service calendars, and process documentation that a firm uploads, and the policy items distilled from them on our servers. Why and how long: To compile and maintain the playbook. Retained until the firm deletes them or the account closes.
Interview and playbook content. Answers a Subject gives during capture, candidate method statements distilled from meetings that the Subject confirms or rejects, the compiled rules, their sources, confidence levels, item-level sign-offs, rulings, exclusions, and version history. Why and how long: To build and maintain the playbook and its provenance record. Retained for the subscription term.
Meeting transcripts. Transcripts a Subject supplies from any notetaker. Names, account identifiers, and balances are replaced on the Subject's own computer before anything is transmitted. Why and how long: To distill candidate method statements for the Subject to confirm. The transcript itself is not stored. Where Practice Memory is turned on, the pseudonymized version is retained as described in Section 3.
Practice Memory. An opt-in, retained record of pseudonymized meeting transcripts and written walk-throughs, available on the Digital Twin and Enterprise tiers, visible and deletable item by item. Why and how long: To give the playbook lived examples to draw on. Off by default. Retained until the firm deletes the item, turns the feature off, or the account closes.
De-identified Patterns. Household and account codes, asset and transaction ranges, month-level dates, activity counts and sequences, produced in the browser from client data files. Column headings from an unrecognized file layout may be sent to suggest a mapping; cell contents are not. Why and how long: To support validation against the playbook. The re-identification key stays on the firm's device. Retained for the subscription term.
Queries and output. Questions Users ask the playbook or the firm's enabled sources, the answers returned with their citations, quiz answers and grades, and questions routed to the Subject. Why and how long: To operate the chat, research, checks, and routing features. Chat and research conversations are retained for thirty (30) days. Routed questions, answers, and quiz records are retained for the subscription term.
Source settings. Which entries in the sources catalog the firm has enabled, and who changed each setting and when. Why and how long: To answer research questions only from the sources the firm has enabled and to keep a governance record. Retained for the subscription term.
Service telemetry. Feature usage counts, page and session metrics, error and exception logs, latency and performance data, device and browser type, IP address, approximate region derived from IP. Why and how long: To operate, secure, debug, and improve the software. Not configured to capture the substance of your content. Retained up to twenty-four months.
Security and audit logs. Sign-in events, access and permission changes, administrative actions, export events. Why and how long: To detect and investigate unauthorized access and to support your own recordkeeping. Retained at least twelve months, longer where you or the law require it.
Communications. Emails, support tickets, and demo or sales correspondence. Why and how long: To respond, support, and maintain a record of the relationship. Retained three years after last contact.
Website data. Pages viewed, referring source, and information from strictly necessary and analytics cookies on our marketing site at wallaceunderstudy.io. Why and how long: To operate and measure the website. See Section 6.
We do not collect, capture, purchase, receive through trade, or otherwise obtain any of the following, and the Services are not designed to produce them:
We do not process sensitive personal information for the purpose of inferring characteristics about an individual.
When a firm supplies client files for capture, those files are read and analyzed by JavaScript running in the User's own browser, on the User's own device. The contents of those files are not transmitted to us, received by us, or stored on our infrastructure.
What leaves the device is a de-identified pattern. Direct identifiers are removed before transmission: households and accounts are replaced with codes that cannot be reversed without a key, monetary values are expressed as ranges rather than exact figures, and dates are reduced to the month. The re-identification key that would connect a code to a real person is generated and held on the User's device, is never transmitted to us, and is technically inaccessible to us. When a file arrives in a layout the software does not recognize, the column headings alone may be sent to suggest a mapping; the cell contents are not.
An honest statement about de-identification.
We say "de-identified" rather than "anonymized" on purpose. A re-identification key exists; it exists only on your device, and we cannot reach it. We design the de-identified pattern so that we cannot identify any individual from what we hold, and we assess that design periodically against the risk that someone holding other information could re-identify a record. No de-identification technique is mathematically perfect for every dataset. We do not attempt re-identification, we contractually prohibit our subprocessors from attempting it, and we treat any information that could reasonably be linked back to an individual as personal information under this policy.
Meeting and call transcripts follow the same principle. When a Subject supplies a transcript from a notetaker, names, account identifiers, and balances are replaced on the Subject's own computer before anything is transmitted. The pseudonymized text is used to distill candidate method statements, which the Subject confirms or rejects; unconfirmed candidates never become part of the playbook. On the Playbook tier the transcript is not retained in any form. On the Digital Twin and Enterprise tiers, a firm may turn on Practice Memory, in which case the pseudonymized transcript or walk-through is retained as an item the firm can see and delete individually. Practice Memory is off unless the firm turns it on.
Firm documents are different, and we say so plainly. When a firm uploads a standard operating procedure or a policy manual, the document is distilled on our servers into quotable policy items, and those items and the underlying document are stored with the account, because storing them is what makes the product work. A firm can see exactly what was extracted from each document, can exclude any item, and can delete any stored document at any time.
We use personal information to:
These are commitments, not descriptions of current practice, and we will not change them without giving subscribing firms advance notice and the right to terminate.
(a) No AI training on content. We do not use firm documents, interview answers, meeting-derived content, practice memory, de-identified patterns, playbooks, queries, or output to train, fine-tune, evaluate, or improve any artificial intelligence or machine learning model, and we do not permit any subprocessor to do so. This applies to identified, de-identified, and aggregated forms alike.
(b) No cross-customer use. We do not use one firm's information to provide, improve, or benchmark the Services for any other firm. We do not build cross-firm comparisons, industry benchmarks, or peer cohorts from customer content.
(c) No sale, no sharing, no advertising. We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined in California Civil Code sections 1798.140(ad) and (ah). We have not sold or shared personal information in the preceding twelve months. We run no advertising business, serve no third-party ad pixels in the Services, and do not participate in any advertising network.
(d) No employment or eligibility use. We do not provide personal information or output to anyone for the purpose of evaluating an individual for employment, credit, insurance, housing, or any other purpose enumerated in 15 U.S.C. 1681b.
The Services use artificial intelligence to compile a playbook, compare recent activity against it, and answer questions. Every rule in the playbook traces to material the firm supplied or an item the Subject confirmed; the Subject's item-level sign-offs, rulings, and interview answers are the record of authorship, and the Services do not generate rules on their own initiative. The Services do not make decisions about any individual, do not replace or substantially replace human decision-making, and are contractually prohibited from being used as a basis for employment, compensation, or eligibility decisions. Validation output asks whether a captured rule is still right; it is a quality check on the playbook, not an evaluation of a person.
On request we provide subscribing firms with documentation of the Services' intended uses, known limitations, categories of data processed, and guidance on human review, sufficient to support the firm's own notice and documentation obligations.
We disclose personal information only to the following categories of recipients, each under a written contract that limits use to providing services to us, prohibits sale and sharing, prohibits use for any other purpose, prohibits combining our data with data from other sources, and requires equivalent protections and flow-down to any subcontractor.
Anthropic PBC. Artificial intelligence processing What it receives: De-identified patterns, stored firm document text, interview answers, pseudonymized meeting content, practice memory items where enabled, and queries, for the purpose of compiling the playbook and answering questions. Accessed under Anthropic's commercial terms, which prohibit training on customer content. Standard API retention is short and for trust and safety screening only.
Supabase. Database hosting and authentication What it receives: Account data, stored firm documents, playbooks, de-identified patterns, practice memory where enabled, chats, and logs, held in a database protected by row-level security scoping every record to a single firm. Sign-in is by emailed magic link; we do not store passwords.
Vercel. Application hosting and delivery What it receives: Application traffic, request metadata, and telemetry. Firm content transits but is not persisted by this provider.
Resend. Transactional email What it receives: Recipient email address and message content for account, security, billing, and service notices, including invitation links, routed-question notifications, and the weekly digest where a User has opted in.
Stripe. Billing What it receives: Billing contact, subscription plan, and payment instrument data. We do not store full card numbers.
We also disclose information:
We maintain a current list of subprocessors in Exhibit B of the Data Protection and Security Addendum, published at wallaceunderstudy.io/legal/data-protection-addendum, and will give subscribing firms at least thirty (30) days' notice before adding a new one, with the right to object.
When a User asks a research question, the Services search only the sources the firm has enabled, through a server-enforced allowlist, and cite each answer to a named source. We do not store the text of pages retrieved from those sources, other than verbatim excerpts of public government materials that we keep in the product. Citing a source is not an endorsement of it.
A team member can route a question the playbook does not cover to the Subject. The Subject sees the question without the name of the User who asked it. The record of the question and its answer remains associated with the firm's account, and the answer, once given, is added to the playbook and may be shown to the whole firm as recently taught material.
Inside the Services we use only strictly necessary cookies and local storage: authentication, session management, security, and user preferences. We do not run advertising cookies, cross-site trackers, or session-replay tools that capture keystrokes or screen content inside the Services.
On our marketing website we use strictly necessary cookies and privacy-preserving analytics to measure traffic. We honor Global Privacy Control and other recognized opt-out preference signals as a valid opt-out of sale and sharing where applicable law requires. Because we do not sell or share personal information, this does not change how we handle your data, but we honor the signal regardless.
We keep personal information only as long as needed for the purpose it was collected, and then delete or de-identify it. Specific periods appear in the table in Section 2. Beyond those:
We maintain administrative, technical, and physical safeguards designed to protect personal information, described in detail in the Data Protection and Security Addendum. They include encryption in transit and at rest, magic-link sign-in with no stored passwords, multi-factor authentication for administrative access, row-level tenant isolation, least-privilege access control with periodic review, logging and monitoring, secure development practices, vendor due diligence, and a written incident response plan.
If we confirm a security incident affecting a firm's information, we will notify that firm without undue delay and in any event within seventy-two (72) hours of confirmation, provide the information the firm needs to meet its own notification obligations, and reasonably cooperate in its response. We will not notify a firm's clients or regulators on the firm's behalf without its written consent unless we are independently required to.
No system is perfectly secure. We do not warrant that the Services will be immune from every threat, and our obligations are those stated in the Terms of Service and the Data Protection and Security Addendum.
Depending on where you live and in what capacity you interact with us, you may have some or all of the rights below. We honor these rights for all U.S. residents regardless of state, rather than making you prove residency in a qualifying state.
Know and access. Ask what personal information we hold about you, the categories of sources, the purposes, the categories of recipients, and receive a copy in a portable format.
Correct. Ask us to correct inaccurate personal information.
Delete. Ask us to delete personal information about you, subject to exceptions where we must keep it to complete a transaction, provide a service you requested, detect security incidents, comply with law, or exercise or defend legal claims.
Portability. Receive personal information in a structured, commonly used, machine-readable format.
Opt out of sale, sharing, and targeted advertising. We do none of these, so there is nothing to opt out of. We honor opt-out preference signals regardless.
Limit use of sensitive personal information. We do not use sensitive personal information to infer characteristics, so this right is not engaged. We will still honor a request.
Opt out of profiling. Ask not to be subject to profiling in furtherance of decisions producing legal or similarly significant effects. The Services are not designed to make such decisions.
Non-discrimination and non-retaliation. We will not deny service, charge a different price, provide a different quality of service, or retaliate against you for exercising a privacy right.
Appeal. If we deny a request, you may appeal by replying to our decision. We will respond within forty-five (45) days with our decision and reasoning, and will tell you how to contact your state attorney general if you disagree.
Email support@wallacefinance.io with the subject line "Privacy Request." Tell us which right you are exercising and give us enough information to locate your records. We will verify your identity in a manner proportionate to the sensitivity of the request, generally by confirming control of the email address associated with your account. We will not ask for more information than we need, and we will not use information you give us for verification for any other purpose.
We respond within forty-five (45) days, and may extend once by another forty-five (45) days where reasonably necessary, with notice to you. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you before proceeding.
An authorized agent may submit a request on your behalf with written permission signed by you, and we may ask you to verify the agent's authority directly.
A note for Users at subscribing firms.
Much of the information in your account belongs to your firm and we hold it as a service provider. Where that is the case, the fastest route is to raise the request with your firm, which can act directly in the product. If you contact us instead, we will help, and where we are acting as a service provider we will forward your request to your firm and support its response rather than acting unilaterally on records it controls.
As of the date of this policy, twenty states have comprehensive consumer privacy laws in effect: California, Virginia, Colorado, Connecticut, Utah, Florida, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. Oklahoma and Louisiana take effect January 1, 2027, Alabama on May 1, 2027, and Vermont on January 1, 2028. Most of these laws do not apply to individuals acting in a commercial or employment context, which is the capacity in which most Users interact with us. We extend the rights in Section 9 to all U.S. residents regardless.
California is the one state whose law covers personal information about individuals acting in a business or employment capacity, so it applies to Users in full.
Residents of these states have the rights in Section 9, including the right to appeal a denial. We do not process sensitive data as those laws define it, do not sell personal data, do not process personal data for targeted advertising, and do not engage in profiling in furtherance of decisions producing legal or similarly significant effects. Minnesota residents additionally have the right to obtain a list of the specific third parties to which we have disclosed personal data; that list is Section 5. Maryland residents should note that we do not sell sensitive data or the personal data of anyone under 18, both of which Maryland prohibits outright.
Residents of these states have the rights in Section 9 to the extent their laws provide them. As noted, these laws generally exclude individuals acting in a commercial or employment context; we extend the rights anyway.
Nevada residents may direct a covered operator not to make a future sale of covered information. We do not sell covered information and have no plans to. You may still submit a request to support@wallacefinance.io.
Where a security incident affects personal information and notification is required by the law of your state, we will notify the affected individuals or, where we hold the information on behalf of a subscribing firm, notify that firm so it can notify. We will do so within the shortest period any applicable state law requires.
Wallace Finance Co. is registered with the Securities and Exchange Commission as an investment adviser and is subject to Regulation S-P with respect to its own advisory clients. Those clients are covered by a separate privacy notice available at wallacefinance.io. Wallace Understudy subscribers are not advisory clients of Wallace Finance Co. by virtue of subscribing, and subscribing creates no advisory or fiduciary relationship. Registration does not mean that the SEC or any other agency has approved, reviewed, or endorsed the Services.
Where a subscribing firm is itself subject to Regulation S-P, the Gramm-Leach-Bliley Act, or the Federal Trade Commission Safeguards Rule, we act as its service provider. We maintain the safeguards described in the Data Protection and Security Addendum, we notify the firm of a confirmed security incident within seventy-two hours, and we support the firm's own incident response and notification obligations. Because we do not receive the firm's client data, the volume of nonpublic personal information in our possession is designed to be zero.
We identify the Services as artificial intelligence at the point of interaction, and we will disclose on request whether any particular interaction involves a generative model.
We are not a "covered provider" under the California AI Transparency Act, California Business and Professions Code section 22757 et seq., because the Services are not a publicly accessible generative AI system with more than one million monthly users. We are not a "developer" subject to obligations under Colorado's automated decision-making technology law unless a subscribing firm uses output to materially influence a consequential decision, which our Terms of Service prohibit. We nonetheless maintain and will supply the developer-style documentation described in Section 4.2 so that any firm subject to that law, to Illinois's artificial intelligence employment notice requirements, or to California's automated decision-making technology regulations can meet its own obligations.
We send marketing email only to business contacts and only where permitted. Every marketing email contains a working unsubscribe link and our physical mailing address, and we honor unsubscribe requests within ten business days as required by the CAN-SPAM Act. We do not send marketing text messages without prior express written consent. Unsubscribing from marketing does not stop transactional and service messages, which are necessary to the subscription.
The Services are business software offered only to firms and their authorized personnel. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn we have collected such information, we will delete it. If you believe a minor has provided information to us, contact support@wallacefinance.io.
We process and store personal information in the United States. We do not offer or permit offshore access to customer environments, and support is provided from the United States.
We may update this policy. If we make a material change, we will post the updated policy with a new effective date and notify subscribing firm administrators by email at least thirty (30) days in advance. We will not apply a materially less protective practice to information already collected without giving the affected firm notice and the right to terminate without penalty.
Privacy questions and requests, security matters, and legal notices: support@wallacefinance.io. By mail: Wallace Finance Co., Attn: Privacy, 8 The Grn, Ste B, Dover, DE 19901.
If you are not satisfied with our response, you may contact your state attorney general. California residents may also contact the California Privacy Protection Agency.
Wallace Finance Co. is an SEC-registered investment adviser. Registration does not imply a certain level of skill or training and does not mean any government agency has approved or endorsed the Services. Wallace Understudy documents and validates how closely a practice follows its own stated process; it is not a compliance, supervision, or surveillance system, and it does not guarantee any regulatory, training, productivity, growth, or client-retention result. Figures shown in the Services and in our materials are illustrative.