Skip to content
epiensos epiensos

Legal

Privacy policy

Effective September 8, 2026

This policy describes how Blue Cielo, Inc. (we, us) handles personal data and customer content in connection with epiensos, the marketing site at epiensos.com, the application at app.epiensos.com, the API at api.epiensos.com, and the iOS app.

What we collect

  • Account data. Name, email address, organization, and role, provided by you or by your team admin and managed through Clerk, our authentication provider.
  • Waitlist data. Email, name, organization, whether the requester is an AI agent, an agent description, and a message, submitted through the invitation form.
  • Customer content. Company profile, facts, opportunities, applications, sections, files, award terms, deliverables, tasks, and emails from a mailbox you choose to connect. You control this content and can export or delete it.
  • Integration data. Tokens and metadata for Dropbox, Todoist, Melina, PolyAccounts, Gmail, and Stripe when you connect them.
  • Usage and diagnostics. Page views, feature usage, and error reports through PostHog. Document content is never included in analytics events.
  • Payment data. Handled by Stripe. We store the Stripe customer and subscription identifiers, not card details.

How we use it

  • To provide the service: discovering opportunities, scoring matches, drafting and submitting applications on your confirmation, tracking deliverables, and sending reminders and digests.
  • To operate the waitlist and to activate accounts from approved organizations.
  • To bill subscriptions and success fees through Stripe.
  • To secure the service, investigate abuse, and meet legal obligations.
  • To improve the product, using aggregated usage data.

AI processing

Customer content is sent to AI providers (Anthropic, OpenAI, xAI) to produce drafts, rationales, reviews, classifications, and deliverable content, or to an agent your team has authorized through the agent driver. We do not use customer content to train models. Where a provider offers a zero retention option we use it. Your team chooses which providers are enabled.

Where content lives

Structured data lives in a PostgreSQL database hosted by Neon in the United States, scoped by team. Working copies of files live in Netlify Blobs during processing. The organized system of record for files is your own Dropbox account. Secrets live in the hosting provider's secret store.

Sharing

We share data only with the subprocessors needed to run the service: Netlify, Neon, Clerk, Stripe, SendGrid, PostHog, the AI providers listed above, Dropbox, Google (Gmail API), Todoist, Melina, PolyAccounts, and Apify for scheduled fetching of public funder pages. We do not sell personal data. We disclose data when required by law.

Retention

Account and customer content are retained while your team's subscription is active and for 90 days after it ends, then deleted, unless you ask for earlier deletion. Waitlist entries are retained until approved or rejected and for 12 months after. Analytics data is retained for 12 months.

Your rights

You can access, correct, export, or delete your personal data and your team's content. Team owners can do this from Settings. Anyone can write to privacy@epiensos.com. If you are in a jurisdiction with statutory rights, such as the EU, the UK, or California, we honor them.

Cookies

The marketing site sets no cookies unless analytics is enabled, in which case PostHog sets a first party cookie. The app sets session cookies through Clerk. We do not use advertising cookies.

Children

The service is for organizations and is not directed at children under 16.

Changes

We will post changes here and, for material changes, notify team owners by email.

Contact

Blue Cielo, Inc., privacy@epiensos.com.