How we use AI.

We use AI heavily, and we would rather say how than let an investor discover it. This page is the short account, and it is the one that governs: what AI does here, what it is never allowed to do, who receives your information, and where a person is required.

1. What this covers

This policy covers how Bambu Capital uses artificial intelligence in the systems we run: our investor data room, our internal investment platform, this website, and the software we use to build them. It does not cover AI inside third-party tools we use for ordinary business purposes, except where we name them here.

It sets out the rules we hold ourselves to. Underneath it we keep a current, feature by feature account of what each of our systems sends to an AI provider, and we will give that to any investor who asks for it. That account changes as the software changes. This page should not.

Effective date: 28 September 2026. Version 2.1.

We wrote it because we use AI heavily, and we would rather say so plainly than have an investor discover it.

2. The rule

People decide. AI informs.

That sentence is common enough in our industry to be worthless on its own, so here is what makes it enforceable rather than aspirational.

These are enforced in software rather than by habit. Where we rely on a working practice instead, this document says which.

3. What our AI is never allowed to do

4. Where AI runs without anyone asking it to

Section 3 would be misleading without this one. A good deal of our AI processing is not triggered by a person pressing a button.

We record these exchanges and we review them. That is a control after the fact, not before it, and we would rather say so than claim an approval step we do not have.

5. Who receives your information

We use two AI providers directly, and no others: Anthropic (Claude) and Cloudflare, both on commercial terms, through their business APIs and, for a team member who connects it, Anthropic's business workspace. Between them they receive document content from our data room and from our deal records, the records and summaries our platform holds, the correspondence and working files of a partner who has switched the assistant on, and the code, logs and filed requests our engineering agents work on, including screenshots of our own screens attached to those requests. Our systems send nothing to any other model vendor: not OpenAI, Google, Amazon, Cohere or Mistral.

Two other vendors are worth naming. Fellow, the notetaker we use for meetings, holds the recording and the transcript of any meeting we record with it, and transcript content reaches Anthropic when we draft reasoning for a decision, when a partner attaches a meeting transcript to an investor's record so the follow-up actions can be read out of it, and when a partner brings in a meeting about several investors, whether they upload it or take it from the notetaker we record with, so the actions in it can be split between their records. Fellow's own published list of sub-processors names several AI vendors, and Fellow does not publish which of them handles what, so we cannot tell you which has processed our meetings. We do not hold a signed data processing agreement with Fellow, and Fellow's default is to keep recordings and transcripts until an administrator sets a deletion schedule. People Data Labs, a licensed business-data vendor and not an AI provider, receives a business contact's email address when we look up a profile, under its own terms, which we do not summarise and do not vouch for.

From our data room, our platform and this website we send no identifier that would let a provider attribute anything to a particular person. Our own engineering and the partner assistant are the exception, and we would rather name it than let it sit inside a claim it breaks: the names inside our code, our build logs, a filed request, a memo under review or a partner's own mail travel with the text they are part of.

If you want to know exactly what leaves which system, ask us. We keep that account current and we will send it to you.

6. What we do not do

Each of these is verified in our own source code, not merely intended:

7. Training

No AI provider we use is permitted to train models on your information. Anthropic's commercial terms state that it may not train models on customer content submitted through its commercial services. Cloudflare states that content submitted to Workers AI is not used to train any model. We call commercial endpoints exclusively; consumer plans carry different defaults, and those defaults do not apply to us because we do not use those products.

Nothing of yours is training a model of ours either. We are accumulating a record of our own investment decisions and the reasoning behind them, and we expect one day to use it to help our own systems reason about our own judgment. That record is our reasoning, not your documents.

8. Retention

At our providers. Anthropic's standard retention for commercial API traffic is 30 days, with longer periods for content its trust and safety processes flag. We do not currently hold a zero data retention arrangement. What People Data Labs keeps is governed by its own agreement.

At Bambu. We keep what our systems generate: document summaries, extracted text and the search index built from it, assistant questions and answers, decision records, and the run records our software agents write. Today we keep these until we delete them on request. We are building a retention schedule and this section will state it when we have one.

9. If you are in our data room

10. Your rights, and how to reach us

You may ask what we hold about you, ask us to delete it, or ask how a particular output was produced. A person handles the request, not a form. What we hold is ours to answer for; a copy a vendor holds under its own agreement is a request to them. Write to ir@bambu-capital.com.

11. How this document is kept accurate

This policy is written against our own source code. We check it against the platform quarterly, and whenever something material about how we use AI changes. We keep a copy of every published version and any of them can be made available on request.

One rule stands above the rest: if this document says a control exists, that control is enforced in software, not in a habit.

Questions About This Policy

A person will answer.

Ask what we hold, ask us to delete it, or ask how a particular output was produced. Requests are handled by a person, not a form.

Contact us →