Successor.pro
Your data & our boundaries
Plain English, no legalese — what Successor.pro does with your information, and the one line it won’t cross. If anything here gives you pause, tell me.
What we never do
Successor.pro never gives financial, legal, tax, or valuation advice — not once, not anywhere. It records what you say your business is worth and what you want from an exit, clearly labelled as your own figures. It will never tell you what your business is worth or whether your plans add up. When something needs a professional, it says so and points you to one. That boundary is the design, not a limitation — it’s what makes you a better-prepared client.
If the coach ever seems to cross that line, tell me immediately.
What you put in
Over the journey you’ll enter real information: your own financial figures (as you state them), who does what, how your processes work, and honest reflection on stepping away. If you use the microphone, your spoken answers too.
Where it's stored
In a secured cloud database, isolated to your account. Only you — and me, as the operator, for support and quality — can see it. No other user can see anything of yours. It’s never sold or shared; it exists to build your plan and your documents, full stop.
Technically speaking: your data is encrypted on its way to us and where it sits, and every account’s data is walled off from every other’s at the database level — the same row-level security the app is built on.
The outside services we use
To run, the app relies on a few established providers, each doing one job:
- Anthropic runs the AI coaching conversations and helps build your plan.
- OpenAI transcribes your voice — only if you use the microphone. The audio itself isn’t kept.
- Supabase is the database; Vercel hosts the app.
- Sentry receives an error report if something crashes — the crash and where it happened, with personal details stripped out — so I hear about problems fast.
- Resend delivers our email — sign-in links, and (if you ask for it) your assessment results.
Under our terms with the AI providers, your data is not used to train their models.
If you give us your email at the end of the assessment
The assessment itself never asks for contact details. At the end — depending on your result and whether places are open — you’re offered either a place in the private beta or our waitlist. Either way you give us one email address, and we store it on your assessment record.
We use it for three things: sending you your results with a durable link; replying about your application, or telling you when places open; and — only if you also ticked the box — occasional practical guidance.
If you apply for a beta place, the optional note you write about your business is stored on that same record. I read it myself to decide who joins. It is never shown to another user, never used to train any AI, and it goes when the record goes.
Every email carries a one-tap unsubscribe, and unsubscribing also stops us holding your address beyond the standard window. A record with a saved email is kept for up to 12 months from your last visit or email, then deleted; without one, the anonymous record clears after 90 days as below. We never sell or share your address.
How long we keep it
Your working data — plan, documents, profile — stays as long as your account does; it’s your savings account, not something we quietly expire. Behind-the-scenes coaching and debugging logs are kept up to 90 days, then deleted on a rolling basis. If you start an assessment but never create an account, that anonymous record is cleared after 90 days. And if you want out, you’re out — ask me any time and I’ll delete your account and everything in it, no questions asked.
What you can and can't see
You can see your profile, your plan, your Brief, and every document you build. Two things you can’t see directly. One is a per-turn technical log I keep (up to 90 days) to debug and keep quality high. The other is a plain record of which parts of the app you’ve used and when — the activity itself, never what you said in a conversation — which is how I tell what’s working and what isn’t; it stays as long as your account does. Both are operator-only, both are yours to ask me for, and both are deleted on the same request as everything else.
Two promises about security
The app will never ask you to store a password or login for any of your business systems — if it ever appears to, stop and tell me, that’s a bug. Where documents record access, they record where things are and who has access — pointers, never the keys themselves.
And bear in mind what you type into a conversation or document is sent to the AI provider to do its work, so keep to that pointers-not-passwords rule.
What we don't have yet
No third-party security certification yet — SOC 2 and its relatives are enterprise audits, and one is on the roadmap as this grows. And account deletion is email-me today rather than a button: it works, same day, but I want you to know which it is.
An honest caveat
This is a young product run by one person. I take your data seriously, but I won’t dress it up in enterprise language it hasn’t earned yet. If that gives you pause, tell me and we’ll talk it through.
— Matt