Wallace Succession
Data and AI practices
Advisors trust us with the most sensitive thing a practice has: how it works. This page explains, in plain language, exactly what data Wallace Succession touches, where it goes, what never leaves your machine, and the terms under which any of it reaches an AI model. Updated July 31, 2026.
The short version
- Raw client data never leaves your machine. Client files are read and analyzed entirely in your browser. Only anonymized patterns are saved, and the key linking those patterns back to your clients stays in your browser.
- No AI model is trained on your data. We call the AI through Anthropic's commercial API, whose terms prohibit training models on customer content.
- Your playbook belongs to you. Export it as a PDF any time. Cancel any time. We never sell data, never share it for advertising, and never use one firm's data to benefit another.
Client data: read in your browser, never uploaded
When you upload CRM exports, custodian files, or client emails on the Content page, those files are parsed by code running in your own browser. The raw files are never transmitted to our servers. What leaves your machine is a set of anonymized patterns: each household becomes an anonymous code with an asset range, and dates are reduced to months. No names, no email addresses, no account numbers.
The key that links anonymous codes back to your clients is stored only in your browser. We could not identify a client from the data we hold even if we wanted to. This is an architectural property, not a policy promise: the identifying information is never in our possession.
Firm documents: stored, because that is their job
Firm documents are different from client data, and we treat the difference honestly. When you upload SOPs, policy manuals, or procedure documents, their text is stored with your account. That is what makes the product useful: the twin quotes your documents back word for word, with receipts pointing at the exact section and sentence.
Firm documents describe how your firm works, not who your clients are. We tell you to keep client files out of that section, and the client-data pipeline described above remains browser-only regardless. You can delete any stored document at any time from the Content page, and you can see exactly what was extracted from each document before your playbook is compiled from it.
What the AI actually sees
Wallace Succession uses Claude, a model built by Anthropic, to compile your playbook and answer questions about it. The AI receives four kinds of material, and only these: the anonymized patterns described above, the text of firm documents you chose to store, your interview answers, and the questions typed into chat. It never receives raw client files, client names, account numbers, or the key linking anonymous codes to clients, because none of those ever reach our servers in the first place.
The AI provider's obligations
We access Claude exclusively through Anthropic's commercial API, which is governed by Anthropic's Commercial Terms of Service. Three facts about that arrangement matter to advisors:
- No training. Under the Commercial Terms, Anthropic may not train models on customer content. Data sent through the API is not used to improve or train any AI model. This is the default for commercial API customers, not an opt-out we had to configure.
- Limited retention. Anthropic's standard API retention is seven days, held for trust and safety screening, then deleted. It is not retained for training under any circumstances.
- Output ownership. The Commercial Terms assign ownership of outputs to the customer. Your compiled playbook is yours.
These statements describe Anthropic's published commercial terms as of July 2026. We monitor them and will update this page if they change.
Where your data lives
Your account data, compiled playbook, and stored firm documents live in a dedicated PostgreSQL database hosted by Supabase, protected by row-level security policies that scope every record to your firm. One firm's data is never readable by another. The application is hosted on Vercel, and all traffic is encrypted in transit with TLS. Transactional email, such as sign-in links, is delivered through Resend.
Our subprocessors are: Anthropic (AI processing), Supabase (database hosting), Vercel (application hosting), and Resend (transactional email). We do not sell data to anyone, share it with advertisers, or grant any third party access beyond these named processors.
Access, roles, and the audit trail
Wallace Succession is invite-only. Each firm controls its own seats: the advisor account, and a successor seat the advisor grants and can revoke. Successors can read the playbook and ask the twin questions; they cannot upload data, change settings, or alter the record.
The playbook itself carries an audit trail. Every version records where each rule came from, whether it was observed in data, said in an interview, or extracted from a document, and the advisor signs the compiled result. If the substance of the playbook changes, the signature is required again. Questions the twin could not answer are logged as anonymous topics only, with no record of who asked.
Deletion and portability
Export your playbook as a PDF at any time; it is yours to keep. You can delete stored firm documents yourself from the Content page. If you cancel, your subscription simply stops; if you want your data deleted, email us and we will remove your firm's records from our systems and confirm when it is done.
What this page is not
This page describes how we handle data. It is not legal advice, and Wallace Succession is not a compliance program: the product documents and measures how closely your practice follows its own stated process, and your compliance obligations remain governed by your own policies and counsel. Where we describe another company's terms, such as Anthropic's, we are summarizing their published commitments, which those companies control.
Questions
Ask us anything about this page at matt@wallacefinance.io. If your compliance officer wants to walk through it on a call, we are glad to.