Privacy Policy

Owner: Cien Rios LLC
Effective Date: January 15, 2026
Jurisdiction: United States

Cien Rios LLC ("Company," "we," "us," or "our") operates WindfallOS (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.


1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address and any profile information you choose to provide, such as your name and state of residence.

1.2 Intake Responses

During onboarding, you provide information about your windfall situation, including windfall type, amount range, timing, household composition, and risk factors. This information is used solely to generate educational checklists and coordinate with professionals you invite.

1.3 Uploaded Documents

Documents you upload to the Platform are encrypted on your device before transmission ("client-side encryption"). We store only the encrypted files and cannot access their contents without your encryption keys.

1.4 Usage Logs

We maintain audit logs of actions taken on your account for security and compliance purposes. These logs include timestamps, action types, and IP addresses, but do not include document contents.


2. How We Use Your Information

2.1 Provide Coordination Services

We use your information to generate personalized checklists, track task completion, manage professional invitations, and facilitate secure communication with your invited advisors.

2.2 Maintain Compliance Tracking

The Platform tracks deadlines and important dates to help you stay organized. This includes claim deadlines, tax dates, and annual compliance requirements.

2.3 Improve Platform Reliability

We analyze aggregated, anonymized usage patterns to improve Platform performance, fix bugs, and develop new features.


3. What We Do NOT Do

  • We do NOT sell your personal data to third parties for marketing or any other purpose.
  • We do NOT provide legal or tax advice. All content is educational and informational only.
  • We do NOT share your data without authorization. Only professionals you explicitly invite can access your information, with permissions you control.

4. Data Security

4.1 Client-Side Encryption

Sensitive documents are encrypted on your device before upload using AES-256-GCM encryption. Your encryption keys are derived from credentials you control. We cannot decrypt your documents.

4.2 Role-Based Access Control

Professionals you invite receive scoped permissions that you define. You can limit access to specific document categories, revoke access at any time, and view audit logs of all access.

4.3 Audit Logging

All sensitive actions are logged with timestamps, including document access, permission changes, and data exports. Audit logs are immutable and retained for compliance purposes.

4.4 Infrastructure Security

We use industry-standard security measures including TLS encryption for data in transit, secure hosting with SOC 2 compliant providers, and regular security assessments.


5. Data Retention and Deletion

5.1 Retention Period

We retain your data for as long as your account is active or as needed to provide services. Certain records may be retained longer for legal and compliance purposes.

5.2 Right to Deletion

You may request deletion of your account and personal data at any time through the Platform settings. Upon verification of your identity, we will delete your data within 30 days, subject to legal holds.

5.3 Legal and Compliance Holds

In certain circumstances, we may be required to retain data for legal, regulatory, or compliance purposes. If your data is subject to a hold, we will notify you when permitted by law.

5.4 Confirmation

You will receive confirmation when your data deletion request has been processed. Export requests will provide a downloadable archive of your data before deletion.


6. Third-Party Services

We may use third-party service providers to assist in operating the Platform. These providers are contractually bound to protect your information and use it only for the purposes we specify.


7. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. Continued use of the Platform after changes constitutes acceptance.


8. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Cien Rios LLC
Email: privacy@windfallos.com

Last updated: January 15, 2026