Privacy Policy
Owner: Cien Rios LLC
Effective Date: January 15, 2026
Jurisdiction: United States
Cien Rios LLC ("Company," "we," "us," or "our") operates WindfallOS (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.
1. Information We Collect
1.1 Account Information
When you create an account, we collect your email address and any profile information you choose to provide, such as your name and state of residence.
1.2 Intake Responses
During onboarding, you provide information about your windfall situation, including windfall type, amount range, timing, household composition, and risk factors. This information is used solely to generate educational checklists and coordinate with professionals you invite.
1.3 Uploaded Documents
Documents you upload to the Platform are encrypted on your device before transmission ("client-side encryption"). We store only the encrypted files and cannot access their contents without your encryption keys.
1.4 Usage Logs
We maintain audit logs of actions taken on your account for security and compliance purposes. These logs include timestamps, action types, and IP addresses, but do not include document contents.
2. How We Use Your Information
2.1 Provide Coordination Services
We use your information to generate personalized checklists, track task completion, manage professional invitations, and facilitate secure communication with your invited advisors.
2.2 Maintain Compliance Tracking
The Platform tracks deadlines and important dates to help you stay organized. This includes claim deadlines, tax dates, and annual compliance requirements.
2.3 Improve Platform Reliability
We analyze aggregated, anonymized usage patterns to improve Platform performance, fix bugs, and develop new features.
3. What We Do NOT Do
- ✕We do NOT sell your personal data to third parties for marketing or any other purpose.
- ✕We do NOT provide legal or tax advice. All content is educational and informational only.
- ✕We do NOT share your data without authorization. Only professionals you explicitly invite can access your information, with permissions you control.
4. Data Security
4.1 Client-Side Encryption
Sensitive documents are encrypted on your device before upload using AES-256-GCM encryption. Your encryption keys are derived from credentials you control. We cannot decrypt your documents.
4.2 Role-Based Access Control
Professionals you invite receive scoped permissions that you define. You can limit access to specific document categories, revoke access at any time, and view audit logs of all access.
4.3 Audit Logging
All sensitive actions are logged with timestamps, including document access, permission changes, and data exports. Audit logs are immutable and retained for compliance purposes.
4.4 Infrastructure Security
We use industry-standard security measures including TLS encryption for data in transit, secure hosting with SOC 2 compliant providers, and regular security assessments.
5. Data Retention and Deletion
5.1 Retention Period
We retain your data for as long as your account is active or as needed to provide services. Certain records may be retained longer for legal and compliance purposes.
5.2 Right to Deletion
You may request deletion of your account and personal data at any time through the Platform settings. Upon verification of your identity, we will delete your data within 30 days, subject to legal holds.
5.3 Legal and Compliance Holds
In certain circumstances, we may be required to retain data for legal, regulatory, or compliance purposes. If your data is subject to a hold, we will notify you when permitted by law.
5.4 Confirmation
You will receive confirmation when your data deletion request has been processed. Export requests will provide a downloadable archive of your data before deletion.
6. Third-Party Services
We may use third-party service providers to assist in operating the Platform. These providers are contractually bound to protect your information and use it only for the purposes we specify.
7. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. Continued use of the Platform after changes constitutes acceptance.
8. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Cien Rios LLCEmail: privacy@windfallos.com
Last updated: January 15, 2026