Modular Business — Privacy Policy

Modular Business is a product of Big Think Labs LLC. Status: Published for launch; not legal advice Version: 1.5 · 2026-09-06 · effective 2026-09-07

This Policy is published so that the Service can be bought and used, and nothing in it is legal advice. Where a fact or a term is still to be settled, it is listed in the appendix at the end of this document rather than left inside the text; the appendix is part of our own record, not part of this Policy.

Changelog

| Version | Date | What changed | | --- | --- | --- | | 1.5 | 2026-09-06 | The assistive features are disclosed, because one of them now reads free text somebody typed and Section 4 did not describe where it goes. The Service has three features that ask a model on our own account rather than on the customer's: suggesting a business's shape from a typed description, finishing a process on a card, and — new on 2026-09-06 — reading the paragraph a personal canvas starts from into cards the person accepts one at a time. Section 4 named only the house AI provider during a trial, and its neighboring sentence said we do not route business data through AI vendors on the customer's behalf, which was true of agent seats and not true of these three. So Section 4 gains a bullet naming them, says the platform is a setting with Anthropic's Claude as the default rather than a fixture, and the agent-seat bullet is narrowed to agent work so the two no longer contradict each other. Section 8.4 gains one sentence for the paragraph specifically: it is the document the person types rather than one we read from their storage, so it is stored with the canvas, and its text reaches the platform when they ask for the reading. No claim is made about what that platform retains or trains on, and the appendix carries that as an open item beside the trial's, because v1.4's reading was about the house account and whether it governs this use has not been established. | | 1.4 | 2026-09-06 | Section 4 says, for the first time, what a share link carries — and it carries less than it did. On Craig's decision of 2026-09-06 ("This seems too loose. We shouldn't be able to just share a whole scenario, should we?"), a share link now carries the shape of a canvas — its departments, sections, seats and wiring, under the names you gave them — and no longer carries your numbers, the people holding your seats, your providers, your notes, or anything else you typed about a seat. The Policy said nothing at all about share links before this version, which was the more serious gap: a feature that put a whole business model into a URL was described nowhere in the document that is supposed to say where your information goes. The new paragraph also states the two things a reader needs in order to judge the risk: what the link carries sits in the URL fragment, so it never reaches our servers or anybody else's, and a link you created before this change still carries the whole canvas, because a link already sent cannot be reached and withdrawing it would break links you have handed to people. Written from the code rather than from a summary of it: what travels is the allowlist in lib/share-shape.ts, and a test sweeps a packed link for any number or typed name that got through. | | 1.3 | 2026-09-06 | Craig on the retention clauses, verbatim: "Narrow now." Version 1.2 replaced four claims about the provider with a promise to state the real terms once confirmed — and then Sections 4, 5 and 8.2 all leaned on that promise, so what a reader was told still depended on a conversation nobody has had. Each now states only what is true today: which provider, that the content of a trial run goes to that provider to produce the run's result, that what the provider keeps and what it may use it for are governed by that provider's own published terms, and what we retain. Section 8.2 names the published document and the date we read it — Anthropic's Commercial Terms of Service, effective June 17, 2025, read 2026-09-06 — for the one thing those terms do settle, which is training. It also says, in as many words, that we hold no separate arrangement with that provider about how long the content of a request is kept, that this Policy therefore does not say how long it is kept, and that we will say so if that changes. The sentence promising to state the terms here once confirmed is gone: a promise about a future document is not a disclosure. The Terms of Service carries the matching change at Section 12.5(c). | | 1.2 | 2026-09-05 | Four sentences that characterized what the house AI provider does with the content of a trial run are replaced by what we can actually state. Sections 4, 5 and 8.2 described that provider's API terms and what it keeps afterwards; nobody here had confirmed any of that with the provider, and a customer would have been entitled to rely on it. Each now names the provider, says the content reaches it to serve the request, and says that provider's API terms for our account govern — and Section 8.2 carries one sentence saying the retention and training terms are being confirmed and that this Policy will state them here once they are. The Terms of Service carries the matching change at Section 12.5(c). Separately, on Craig's instruction, this Policy no longer refers to a legal review: the status line drops it, the appendix is a list of open items rather than a list for a lawyer, and the review itself is tracked on our own decision record instead of on this page. | | 1.1 | 2026-09-05 | Section 3 describes the first-party visitor identifier that exists before an account does, on Craig's "Agree" of 2026-09-05, written before the code that does it lands — a privacy policy must disclose collection ahead of the collection, never after. Written from the implementation rather than a summary of it: the collected fields are the allowlist in lib/hq-events.ts, and the finding summary capped at 140 characters is named as the one field that could carry a customer's own words, because the code itself identifies it as the only composed value and a policy claiming "no free text of any kind" would have been false. Destination named as Big Think HQ, a Big Think Labs system, not a third-party vendor. No opt-out switch is claimed, because none exists: the control described is the one that works — clearing or blocking local storage — and the Policy says a product switch does not exist today. Section 9's open item is answered rather than left standing. | | 0.1 | 2026-09-04 | First draft, prepared for internal review. | | 0.2 | 2026-09-04 | Adds Section 8 (Sponsored Accounts, the Trial, Gate Participants, and the Brain), the matching collection and sharing entries in Sections 2 and 4, and a retention paragraph in Section 5; renumbers former Sections 8–13 as 9–14. | | 1.0 | 2026-09-05 | Published for launch. The company is named as Big Think Labs LLC. The trial's figures — 50 runs, 14 days — are settled. Section 12 states plainly where the Service is offered from, in place of the GDPR placeholder. Every remaining bracket moves to the appendix, and each sentence that carried one is written in its safest form. | | 1.0, amended | 2026-09-05 | The mailing address inserted in Section 14 on Craig's instruction; no other change. |


1. Who We Are

This Privacy Policy explains how Big Think Labs LLC, a North Carolina limited liability company operating Modular Business (modularbusiness.co), collects, uses, and shares information when you use the Service. Big Think Labs LLC is a small US company based in North Carolina, founded and operated by Craig Mathews. Modular Business is the product; Big Think Labs LLC is the company that holds your information. This Policy should be read alongside our Terms of Service.

2. Information We Collect

Account information. Your email address and any other information you provide when creating an account.

Canvases and business models. The departments, seats, workflows, and configurations you build to model your business, whether saved locally in your browser (free tier without an account) or saved to our servers (any account tier).

Runs. Reports submitted by agents and people through our ingest API: counts, costs, timestamps, and a short free-text description. Free-text is automatically processed to redact detectable email addresses and phone numbers before storage, but this automated process is not guaranteed to catch every instance of personal information, so we ask you and your agents not to submit personal or regulated data in free-text fields.

Connection identifiers. When you connect a third-party application, our connector provider holds the OAuth credentials for that connection. We store only the connection identifier issued by the connector provider, not the underlying credentials, tokens, or the content of your connected application beyond what an agent or integration explicitly reports as a run.

Sponsored canvases. Where an organization pays for an individual's personal canvas, we record who the payer is, which seats the payer holds, and which work area those seats sit in, so that the payer's access can be limited to them. We do not label the rest of the canvas as belonging to the payer and we do not disclose it to the payer. See Section 8.

The brain index. If you point the Service at a folder of your own documents, we store an index of that folder — enough to find and cite a document when an agent or a person asks a question of it — together with the run records of work that read from it. We do not store a copy of the documents themselves; they stay in your storage and are read through the connection you own.

Persons named on a gate. A gate may name a person who is consulted or whose approval is required. Where that person does not hold an account with us, we store the name and address you supply for them, the message sent through your own connected accounts, the answer, and the date. See Section 8.

Usage analytics, and the visitor identifier that exists before an account does. The first time you visit one of our sites we store an anonymous identifier — a random value, in your browser's local storage — whether or not you ever create an account. We use it to tell one visit from another and to understand how people move through our sites. We do not use third-party advertising trackers, and we do not sell your data to ad networks or data brokers.

What we collect with it. The page path you viewed; the host of the site that referred you (for example google.com), never the full referring address; campaign tags (utm_source, utm_medium, utm_campaign, utm_content), captured once, on your first visit; and product events by name, from a closed list — for example an account created, a canvas saved, a first run, a trial started, a subscription started or ended. Each event carries at most a few fields drawn from a fixed vocabulary: a department from our own twelve, a severity of low, medium or high, an outcome of completed, blocked or abandoned, a plan name.

What we do not collect, and the one exception we would rather name than have you find. No canvas content, no documents, no journal text, no run inputs or outputs, and no name you typed. The exception is a finding summary: when the product emits a finding, the event may carry a short description of it, capped at 140 characters, one line, no links. That field is composed rather than chosen from a list, so it is the only one that could contain words drawn from your own business. Every other field is a fixed value from a list we publish.

Where it goes. To Big Think HQ, our own system, operated by Big Think Labs — not to a third-party analytics or advertising vendor. Events are forwarded from our own server rather than sent from your browser to anyone else.

Linking to your account. If you create an account, we link that identifier to it, so what you did before signing up is joined to your account rather than left as a separate anonymous record.

Your control over it, stated as what exists rather than what is planned. The identifier lives in your browser's local storage. Clearing your site data removes it and you are seen as a new visitor; blocking local storage for our sites prevents one being stored at all, and the product keeps working — it simply cannot tell a returning visitor from a new one. There is no switch inside the product today that turns this off. If we add one, this Policy will say so before it is needed.

Payment information. Billing is handled entirely by Stripe. We do not store your full payment card number; we retain only what Stripe provides for account and subscription administration (for example, subscription status and the last four digits of a card).

Support and correspondence. If you contact us, we retain that correspondence to respond and to improve the Service.

3. How We Use Information

We use the information above to: (a) provide, operate, and maintain the Service; (b) process payments and manage subscriptions through Stripe; (c) measure and display run outcomes and cost/time savings; (d) maintain and improve the connector integration and ingest API; (e) provide customer support; (f) detect, prevent, and investigate fraud, abuse, or security incidents; (g) comply with legal obligations; and (h) with your consent, communicate product updates. We do not use your business content (canvases, run detail, connected-application data) to train models for other customers or third parties.

4. How We Share Information

We share information only as follows:

  • Stripe, to process payments and manage billing.
  • Supabase, as our hosting and database infrastructure provider, which stores account, canvas, and run data on our behalf under its own security commitments.
  • The connector provider, which holds OAuth credentials for your connected third-party applications and brokers those connections; it does not receive your canvases or run content beyond what is needed to establish and refresh a connection.
  • The AI vendor or platform you choose for each agent seat receives only what that agent, running on your chosen platform, is configured by you to send it. We do not route your business data through AI vendors on your behalf for agent work; the Service receives run reports back from your agents, not the other way around. The assistive features in the next bullet are the exception, and each of them runs only when you ask for it.
  • The AI platform behind the assistive features. Three features ask a model to answer on our own account rather than on yours: suggesting the shape of a business from a description you type, finishing a process on a card, and reading the paragraph you write at the start of a personal canvas into cards you accept one at a time. When you use one of them, the text you supplied for it is sent to the AI platform configured for the Service — Anthropic's Claude by default; the platform is a setting rather than a fixture — to answer that one request. What that platform keeps of it, and what it may use it for, are governed by that platform's own published terms; the appendix says what has and has not been established about them for this use, as distinct from the trial in Section 8.2. Nothing is sent unless you ask, no other part of your canvas is included, and the credential stays on our servers and never reaches your browser.
  • Certified consultants, only when you grant a specific consultant explicit access to specific business content for a specific engagement, as described in Section 7.
  • An organization that sponsors an individual's canvas, which receives only the run records of the seats it holds in its own work area, and nothing else on that canvas — see Section 8.
  • The house AI provider during a trial. If you take a trial that runs on our own AI account, the content those trial runs send to the model goes to a single AI provider — Anthropic's Claude, through Claude Code on the house account — to produce that run's result. What that provider keeps of that content, and what it may use it for, are governed by that provider's own published terms. We hold no separate arrangement with that provider about how long the content of a request is kept. Section 8.2 names the published document we read, the date we read it, and what is still open.
  • A person you name on a gate, who receives a message sent from your own connected accounts, as you — not from us — as described in Section 8.
  • Service providers who support our infrastructure (for example, email delivery, error monitoring) under confidentiality obligations, limited to what is necessary to provide their function.
  • Legal and safety, where required by law, subpoena, or to protect the rights, property, or safety of Big Think Labs, our customers, or the public.
  • Business transfers, if we are involved in a merger, acquisition, or sale of assets, subject to this Policy or a successor policy with comparable protections.

A share link you create yourself, and the one thing it carries. When you copy a share link for a canvas, the link carries the shape of that canvas — its departments, its sections, its seats, the wiring between them, and the names and units you gave them — and nothing else. It does not carry your numbers (volumes, ratios, capacities, costs, prices, budgets), the names of the people holding your seats, your providers, your notes, your steps, your tasks, or any other free text you typed about a seat. What the link carries sits in the URL fragment, which a browser never sends to a server, so a canvas shared this way does not reach us, our hosting provider, or anyone else along the way; the person you send it to gets their own copy to change, and it is not linked to yours. Two limits we would rather state than have you discover. A link you created before this change carries the whole canvas, numbers included — a link already sent cannot be reached or withdrawn, and breaking it would take away what its recipient was told they were being given. And a link is only as private as the person you send it to: anyone who has the URL can open it, so treat it the way you would treat a document you emailed.

We do not sell your personal information, as "sale" is defined under applicable state privacy law.

5. Data Retention

We retain operational data (accounts, canvases, connection identifiers) for as long as your account is active. Runs and their outcomes are retained in perpetuity in sanitized form, meaning stripped of the free-text redaction described in Section 2 and, where applicable, further de-identified, to preserve long-term measurement history and product improvement without retaining sensitive content indefinitely. If you request deletion of your account and data, we will delete or de-identify your personal information and canvases within 30 days of a verified request, except: (a) sanitized run and outcome data, which is retained under the perpetuity policy above because it no longer identifies you; (b) information we must retain for legal, tax, or accounting compliance; and (c) backups, which age out on our standard backup rotation schedule.

Three retention points specific to Section 8. The brain index is kept while the connection to the folder is live; revoking the connection ends our access to the folder, and the index is then deleted or de-identified. Gate records naming a person who has no account — the name, the answer, and the date — are retained as part of the gate's record for as long as that record is retained. Run records from a trial are retained by us on the same footing as any other run record — that is the sentence above, applied to a trial. What the house account's own provider keeps of the content of a trial request is a separate matter, governed by that provider's own published terms and not by this Section; Sections 4 and 8.2 say what we know about those terms and what we do not.

6. Security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit, access controls, and bearer-token authentication for the ingest API. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we experience a security incident affecting your data, we will notify you as required by applicable law.

7. The Operator-Cannot-Read Commitment

Big Think Labs' operators — including Craig Mathews and any employees or contractors — cannot read the content of your business data (canvases, run detail, connected-application content) as a matter of routine operation. Access is restricted by default. The only exception is when one of our operators is separately engaged by you as a consultant, and you have given that consultant an explicit, scoped grant of access to specific content for a specific engagement. Grants are logged. This commitment is modeled on HIPAA-style minimum-necessary access principles as a matter of our own policy; Big Think Labs is not a HIPAA-covered entity or business associate, and this Policy does not create HIPAA obligations unless a separate agreement says otherwise.

8. Sponsored Accounts, the Trial, Gate Participants, and the Brain

This Section describes four arrangements in which information crosses between parties, and what each party can see. The contractual rules behind them are in our Terms of Service, Section 12.

8.1 What a sponsor can see

Where an organization pays for an individual's personal canvas, the individual is the account holder and, as between them, owns the canvas. The paying organization is a payer, not an owner. It can see the seats it holds in its own work area on that canvas and the run records those seats produce. It cannot see any other area, project, seat, connection, note, document, or run record on the canvas — including anything in an area paid for by a different organization — and the Service provides it no route to them. Nor can it set or read gates, cadences, or budgets outside the seats it holds. When the sponsorship ends, for any reason, the individual keeps the canvas and may convert it to a self-paid account or export it; the paying organization keeps the run records of the seats it held; and the link between the two canvases is severed, ending each side's access to the other.

Connections carry the same rule. Every connection — an AI account, a calendar, a mailbox, a money feed — has an owner, either a business or an individual, and a seat may act only on connections owned by its own scope. An AI account paid for by an employer is not available to that person's personal areas, and a person's own accounts are not available to their employer's work.

8.2 The trial, its provider, and retention

We do not run AI agents, with one exception: a trial in which agents run for a limited period on an AI account we hold. During a trial, the content those runs send to a model goes to one AI provider — Anthropic's Claude, through Claude Code on the house account — to produce that run's result.

What that provider keeps of that content, and what it may use it for, are governed by that provider's own published terms. On the question of training, one of those documents is explicit: Anthropic's Commercial Terms of Service, effective June 17, 2025, which we read on 2026-09-06, state that Anthropic may not train its models on customer content submitted through its services. On the question of how long content is kept, we have not obtained any separate contractual commitment from that provider, so this Policy does not tell you how long that provider keeps it. If we obtain such a commitment we will update this Policy to say so and to say what it covers. What we keep of a trial is in Section 5: the run record, on the same footing as any other.

A trial is capped at 50 runs or 14 days, whichever comes first. On a trial connection, outbound communications are disabled and no recipe may move money, so no message reaches anyone outside your business from our account and no payment can be made from it. When the trial ends, seats must move to a connection you own. Run records made during a trial are yours and stay on your canvas.

8.3 Messages to a person named on a gate

A gate may name a person who is consulted before a decision, or a person whose approval the gate requires. If that person holds an account with us, the gate reaches them inside the Service. If they do not, the message goes out through your connected accounts, from you, at your direction — we are not the sender, and we do not add that person to any list, market to them, or contact them for our own purposes. What we store about such a person is what you supplied and what came back: their name, the address you used, the message, the answer, and the date, held as part of the gate's record. You are responsible for having the right to contact them.

8.4 The brain: an index, not a copy

You may point the Service at a folder of your own documents — standards, handbooks, procedures, personal notes — held in your own storage and read through a connection you own. One document in a brain is different, and it is the first one: the paragraph you type at the start of a personal canvas. That one you give us rather than store yourself, so it is kept with your canvas; and when you ask the Service to read it into cards, its text is sent to the AI platform described in Section 4 to answer that request. Nothing it proposes is written to your canvas until you accept it, card by card. Those documents stay where they are. We do not take or keep a copy. What we hold is an index of the folder, so a question can be answered with a citation back to your document, and the run records of the work that read it. Revoking the connection ends our access to the folder at once; the index is then deleted or de-identified as described in Section 5. The documents in your brain are never used to train models for other customers or for third parties, consistent with Section 3.

9. Cookies and Similar Technologies

We use functional cookies only — for example, to keep you signed in and to remember canvas state saved locally in your browser on the free tier. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling functional cookies may affect the Service's ability to keep you signed in or preserve local canvas state.

10. Children

The Service is intended for business use by adults. You must be at least 18 years old to create an account or use the Service. We do not knowingly collect information from anyone under 18. If we learn we have collected such information, we will delete it.

11. California and Other State Privacy Rights

Depending on your state of residence, you may have rights to know what personal information we hold about you, to request deletion, to correct inaccurate information, and to opt out of certain uses. To exercise these rights, contact us using the details in Section 14. We will verify your identity before fulfilling a request. We do not discriminate against you for exercising these rights.

12. Where the Service Is Offered From

The Service is operated from the United States and is directed to business users in the United States. If you use the Service from outside the United States, your information is transferred to and processed in the United States, where privacy law differs from the law where you live. We will publish the additional terms that European, UK, and other international users are entitled to before offering the Service in those markets.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Version" line and, for material changes, provide notice as described in our Terms of Service. Continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

14. Contact

Questions about this Policy, and requests regarding your data, reach us through the contact details published at modularbusiness.co, or by mail to Big Think Labs LLC, 1227 August Moon Court, Fuquay-Varina, North Carolina 27526.


Appendix: Open items

This appendix is not part of this Policy. It is the list of facts and terms that have not yet been settled, kept here so that the Policy above reads as a customer sees it and nothing open is hidden.

| Where | Open item | | --- | --- | | Section 1 | The registered address of Big Think Labs LLC, and the entity's formation details as they appear on the public record, to be inserted. | | Section 2 | The final connector provider to be confirmed and named. Nango is the planned provider. | | Section 2 | The brain index to be defined precisely: which identifiers, titles, paths, extracted text, summaries, or embeddings are stored, where, and for how long. | | Section 2 | The full list of tracked usage events to be attached as an exhibit. | | Section 3 | Any use of aggregated or de-identified data for benchmarking or product analytics to be disclosed here if it is planned. | | Section 4 | Supabase region and data residency to be confirmed. | | Section 4 | Verified, and stated in Section 8.2: Anthropic's published Commercial Terms of Service, effective June 17, 2025, read 2026-09-06, say Anthropic may not train its models on customer content submitted through its services. Anthropic's Privacy Center article "How long do you store my organization's data?", last updated July 1, 2026, read the same day, publishes a default for its API of deletion within 30 days of receipt or generation, together with the circumstances that displace it — among them a separate agreement between Anthropic and the customer, and a longer period where its usage policy has been violated. That is a default that provider publishes, not a commitment it has made to us, which is why no retention period appears in the Policy above. Still open, and the reason Section 8.2 states no retention period: any separate arrangement with that provider about how long the content of a request is kept, which nobody has obtained; and confirmation of which of that provider's published documents governs the house account, since the answer turns on the kind of account it is. To be settled with that provider before a trial is offered. | | Section 4 | The retention and training terms that apply to our account with the AI platform behind the assistive features, to be confirmed with that platform. The reading recorded above is about the house account for a trial, and whether it governs this use as well has not been established. | | Section 4 | The list of subprocessors to be maintained as an exhibit. | | Section 4 | The "we do not sell your personal information" statement to be confirmed against the CCPA and other state definitions of a sale. | | Section 5 | "Sanitized" to be defined precisely — which fields are stripped and which retained, and whether run-level data is aggregated after a cutoff. The backup rotation schedule to be specified. | | Section 5 | The deletion window for the brain index after a connection is revoked, and whether revocation also ends any cached index held by a subprocessor. | | Section 5 | Whether a person named on a gate may request deletion of their own entry, and how such a request is verified. | | Section 6 | Encryption at rest, employee access controls, and the incident response process to be described in detail, filled in from actual practice. | | Section 7 | Who can issue and revoke a grant, grant expiration, and whether the access audit log is customer-visible in the product or available on request. | | Section 8.1 | Whether a sponsored individual is to be shown, in the product, exactly which items their sponsor can see. | | Section 8.3 | Whether a person named on a gate should receive a short notice explaining why they were contacted and how to reach us, and whether any state or international rule requires one. | | Section 9 | Answered in Section 3: no third-party analytics tool is used, so none sets a cookie. The only similar technology is the anonymous visitor identifier in local storage, described there. | | Section 11 | State-specific rights language to be inserted: California (CCPA/CPRA), and any other states where customers are located — Colorado, Connecticut, Virginia, Utah, and others as applicable. | | Section 12 | GDPR language to be added before any international launch: legal basis for processing, data subject rights, the international transfer mechanism, and an EU representative if one is required. | | Section 14 | The privacy email address to be published on the site. The mailing address is inserted (2026-09-05). |

This page renders our official copy directly, so what is published here can never say something different from what we keep on file.