Website privacy / Public release
Collect less by design.
This site collects only the information needed to operate optional visitor accounts, review an inquiry, protect the submission path, and understand aggregate website use. It does not use advertising trackers or session replay.
The opportunity brief
The opportunity-brief form asks for your name, company, work email, optional role, and high-level information about the workflow, operating constraint, systems involved, existing measures, control needs, and result you want to improve. It does not accept file uploads.
Aumenza uses this information to evaluate and respond to the inquiry, decide whether a next conversation is useful, maintain an intake record, and protect the submission service. It is not added to a marketing list. Do not submit credentials, regulated information, confidential customer records, private links, or production datasets.
Before submission, the current brief is kept only in same-tab browser session storage so an accidental refresh or step change does not erase it. The draft is not sent to Aumenza or website analytics, and it clears after the brief is successfully saved or when that tab's session ends.
Optional visitor accounts
When visitor accounts are enabled, the available method may be a one-time code sent to your email, an identity provider that Aumenza has explicitly enabled, or both. Supabase Auth processes the email address, provider identity response, authentication events, and essential session cookies needed to keep you signed in. The website expires its host-only Supabase session cookies when you sign out and on your next account or opportunity-brief request after visitor accounts are turned off. Cloudflare Turnstile protects requests to send a code or begin provider sign-in. If you choose Google, Microsoft, Apple, or another enabled provider, that provider also processes the sign-in request under its own terms.
An account is optional. It is used to show opportunity briefs that were submitted while that verified account was signed in. It does not subscribe you to marketing and does not grant employee, customer-system, or internal-company access.
The website links a new inquiry to the authenticated Supabase user identifier present when the server accepts it. It does not trust a user identifier sent by the browser, and it does not automatically claim an older anonymous inquiry merely because its work email matches a later account.
How a submission is handled
The website is hosted by Vercel. Cloudflare Turnstile checks whether an inquiry submission or visitor sign-in request appears legitimate. An accepted brief is stored in a dedicated Aumenza inquiry database operated by Supabase. Resend then routes a copy of the submitted contact details and form answers, together with the submission reference and review direction, to Aumenza's Google Workspace inbox. These services provide the site's hosting, security, storage, delivery, and mailbox functions.
The database is the system of record for the inquiry. Notification failure does not erase an accepted record, and an anonymous browser event is never treated as proof that a brief was received.
Retention and requests
Each accepted inquiry database row is assigned an expiry 180 days after receipt and is deleted on the next successful maintenance run after that time. Submissions that are not successfully saved—including automated honeypot responses and validation or verification failures—are not stored in the inquiry database. After an active row is deleted, a copy may remain in Supabase's managed backups until that backup ages out under the provider's current retention.
Visitor authentication records remain while the account is active or as otherwise required to secure and operate the service. Deleting an account and deleting an inquiry are separate requests: account deletion removes the sign-in identity and disassociates its inquiry ownership, while an inquiry continues under the 180-day rule unless it is also deleted in response to an applicable request. Aumenza does not use a matching email address to restore that association automatically.
If an inquiry becomes an active opportunity or engagement, Aumenza may retain only the information needed for that relationship through a separate, approved operating process; this website does not automatically promote a submission into another system. The routing email contains a notification copy of the submitted contact details and answers so the operator can triage the inquiry from the inbox; Supabase remains the system of record for the inquiry. Infrastructure, delivery, and mailbox providers may retain the submitted email copy, delivery, backup, or security records under their own service terms.
You may ask Aumenza to correct or delete an inquiry or visitor account by emailing hello@aumenza.ai. State which record you want addressed and include the submission reference if you have it. Aumenza may need to verify that you control the relevant email account before acting.
Website measurement
Aumenza uses Vercel Web Analytics to understand aggregate traffic and navigation, and Vercel Speed Insights to measure real-user page performance. In its Web Analytics documentation, reviewed August 21, 2026, Vercel describes the service as cookie-free and designed without collecting or storing personal information. The resulting dashboard can include pages and routes viewed, referrer, approximate country, device type, browser, operating system, and performance measurements.
Aumenza also uses Google Search Console and Microsoft Bing Webmaster Tools to review their respective search performance, crawling, indexing, and sitemap status for this domain. These services use data their providers already hold from search and crawling systems; the Aumenza website does not add a Google or Bing tag, send form data, or send visitor identifiers to either service. Bing's connection to Search Console has view-only access to the verified-site and submitted-sitemap lists, not Search Console analytics.
The site uses a limited, predefined set of browser interaction events: primary call-to-action source; fixed primary-navigation surface and destination; homepage chapter reached; explicit Leverage Engine jump; Business Atlas function opened; field-note open and completion; demonstration workbench use, first video play, and staged browser-only decision; quick-contact or detailed-brief selection; opportunity-brief start, saved-draft reopen, step completion, step blocked by client validation, submit attempt, accepted browser response, generic failure category, successful local copy, and direct email or LinkedIn contact-link click.
After the inquiry database confirms that a new inquiry record has been saved, the server sends one property-free receipt-counter event to Vercel Analytics. It passes no form data, submission reference, event properties, or visitor request headers. The inquiry endpoint accepts no query parameters, so this event can inherit only the fixed query-free API path. Duplicate submissions, automated honeypot acknowledgements, validation failures, query-bearing requests, and storage failures do not send this event. The database—not analytics—remains the system of record for the inquiry.
Some Aumenza links include one approved public campaign code. The site accepts only exact codes from a fixed allowlist, stores the recognized code in same-tab session storage until that tab's session ends, and sends it with a fixed funnel-stage label. This distinguishes a small number of Aumenza distribution tests without retaining a person, company, recipient, search term, or other free-form value. Unknown campaign values are ignored.
Aumenza does not send the visitor's name, company, email address, form answers, selections, free text, submission reference, email content, clipboard contents, or arbitrary campaign value to website analytics. URL query parameters and fragments are removed before pageview or performance events are sent, and query-bearing requests to the inquiry endpoint are rejected before storage or measurement.
When account pages are enabled, website measurement may count the fixed account route in aggregate. Authentication tokens, account email addresses, provider identity data, and the contents or references of a person's inquiries are not configured as analytics properties.
Hosting data
Like most hosted websites, infrastructure providers may process request data needed to serve and protect the site, such as an IP address, timestamp, requested path, and browser information. This operational request data is separate from the allowlisted website-measurement events described above.
Direct email
If you contact Aumenza by email instead, the message and contact details you provide are used to evaluate and respond to the request. Ordinary email is not an appropriate channel for credentials, regulated information, confidential customer records, or production datasets.
Changes and questions
This notice will be updated before adding session replay, advertising technology, or materially different data collection. Questions can be sent to hello@aumenza.ai.
Effective: August 15, 2026. Visitor-account description updated September 3, 2026.