PRIVACY POLICY

SELNA CONSULTING LLC d/b/a LNC ACCELERATOR
StephanAI Platform

Last Updated: July 2026


1. INTRODUCTION

Selna Consulting LLC, doing business as LNC Accelerator ("Company," "we," "us," or "our"), a Florida limited liability company, respects your privacy and is committed to protecting the personal information you share with us through the StephanAI platform ("Platform").

This Privacy Policy explains what information we collect, how we use it, how we store it, who we share it with, and the rights you have regarding your information. By accessing or using the Platform, you consent to the data practices described in this Privacy Policy.

This Privacy Policy should be read together with our Terms and Conditions and, if applicable to you, our Business Associate Agreement ("BAA") governing Protected Health Information ("PHI").

2. INFORMATION WE COLLECT

2.1 Information You Provide Directly

Name, email address, phone number, and billing information

Account credentials

Onboarding and business planning information

Chat messages, prompts, and conversations with StephanAI

Documents, reports, and case-related materials you upload

Survey responses, check-in submissions, and testimonials

Voice recordings, if you use voice-enabled features

2.2 Information Collected Automatically

IP address, device type, browser type, and operating system

Usage data, including pages visited, features used, and session duration

Log data generated by the Platform's hosting and database infrastructure

2.3 Protected Health Information (PHI)

If you access the HIPAA-compliant section of the Platform, you may submit case-related information that constitutes PHI under the Health Insurance Portability and Accountability Act ("HIPAA"). PHI is only accepted after you have executed a BAA with the Company. See Section 6 below for how PHI is specifically handled.

3. OUR TECHNOLOGY INFRASTRUCTURE

To operate StephanAI, we use the following third-party and proprietary infrastructure. Understanding this infrastructure helps you understand exactly how your data flows through our systems:

Function Provider What It Does
Primary AI (Chat,
Coaching, Onboarding,
Documents)
Anthropic (Claude) Generates conversational responses, coaching guidance, and document assistance based on relevant information provided by our system.
Embeddings
(Search/Memory)
OpenAI Used solely to power search and memory retrieval functions - does not generate chat replies.
Voice ElevenLabs Powers voice-enabled features, where applicable.
Image Generation
(Optional)
Ideogram Powers optional image generation features.
Hosting Railway Hosts our web application and API infrastructure.
Database PostgreSQL (on Railway) Stores user accounts, chat history, and uploaded documents.
Knowledge Base Separate PostgreSQL instance with vector storage Stores proprietary program content and frameworks used to inform AI responses.

How your data flows: When you interact with StephanAI, relevant information from your account and conversation history is retrieved from our database and transmitted to Claude to generate an appropriate response. We do not transmit your entire chat history or unrelated account data — only the information reasonably necessary to generate a relevant, accurate response.

4. HOW WE USE YOUR INFORMATION

We use the information we collect to:

Provide, operate, and maintain the Platform and StephanAI

Generate AI-powered coaching responses, document feedback, and business guidance

Process payments and manage your account

Communicate with you regarding your account, program updates, and support

Improve StephanAI's performance, accuracy, and relevance through internal review

Conduct required check-ins, surveys, and program obligations under your enrollment

Comply with legal, regulatory, and HIPAA obligations

Detect, prevent, and address technical issues, fraud, or misuse of the Platform

We do not sell your personal information. We do not use your personal data to train any third-party AI model owned by Anthropic, OpenAI, ElevenLabs, or Ideogram beyond what is necessary to generate your requested response.

Note that under some legislations, we may be allowed to process information until you object to such processing (by opting out), without having to rely on consent or any other of the following legal bases below. In any case, we will be happy to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Information is a statutory or contractual requirement, or a requirement necessary to enter into a contract. You further understand that this is a soft pull and will not harm your credit in any way whatsoever.

5. HOW WE SHARE YOUR INFORMATION

We share information only in the following circumstances:

5.1 With Our Service Providers

We share relevant data with Anthropic, OpenAI, ElevenLabs, Ideogram, and Railway solely as necessary to operate the Platform's features described in Section 3. Each of these providers is contractually bound to handle data in accordance with their own privacy and security commitments, and — where PHI is involved — under a Business Associate Agreement executed between the Company and the applicable vendor.

5.2 For Legal Reasons

We may disclose information if required by law, subpoena, court order, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public.

5.3 Business Transfers

If the Company is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

5.4 With Your Consent

We may share your information for any other purpose disclosed to you at the time of collection, with your consent.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6. PROTECTED HEALTH INFORMATION (PHI) AND HIPAA COMPLIANCE

6.1 PHI Restrictions

You may not upload PHI to the Platform unless the HIPAA-compliant section has been activated for you and you have executed a BAA with the Company. Until that time, all case materials must be fully de-identified in accordance with 45 CFR §164.514.

6.2 Flagged Chat Content

Any chat, upload, or conversation flagged by you or by the system as containing medical record content ("Flagged Content") receives enhanced protection:

Flagged Content cannot be exported, downloaded, or shared outside the Platform by you or by the Company

Flagged Content is subject to restricted internal access, limited to what is necessary to operate the Services

Flagged Content is excluded from general product-improvement review processes

6.3 Business Associate Agreements

Where PHI is processed by third-party infrastructure (including Anthropic, for AI-assisted responses involving PHI), the Company maintains a Business Associate Agreement with that vendor as required under 45 CFR Parts 160 and 164.

6.4 Your BAA

If you access the HIPAA-compliant section, you separately execute a BAA directly with the Company. That agreement governs the Company's specific obligations as your Business Associate and controls in the event of any conflict with this Privacy Policy regarding PHI handling.

6.5 Notice of Privacy Practices

A separate Notice of Privacy Practices is provided to you prior to activation of the HIPAA-compliant section, describing your rights regarding PHI in greater detail.

7. DATA RETENTION

We retain your personal information for as long as your account remains active or as needed to provide the Services. We retain data after account closure only as necessary to:

Comply with legal, tax, or regulatory obligations

Resolve disputes and enforce our agreements

Maintain accurate business records

PHI and Flagged Content are retained in accordance with the retention terms specified in your executed BAA and applicable HIPAA requirements. Upon a valid deletion request (see Section 9), we will delete or de-identify your information within the timeframe required by applicable law, except where retention is legally required.

8. DATA SECURITY

We implement reasonable administrative, technical, and physical safeguards designed to protect your information, including:

Encrypted data storage on Railway-hosted PostgreSQL databases

Access controls limiting internal staff access to PHI and Flagged Content

Separation of general program knowledge base data from user account and chat data

Vendor-level security commitments from Anthropic, OpenAI, ElevenLabs, Ideogram, and Railway

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach involving PHI, we will follow the breach notification procedures required under HIPAA and applicable state law, notifying affected users without unreasonable delay and in accordance with legal timeframes.

9. YOUR PRIVACY RIGHTS

Depending on your state of residence, you may have the right to:

Access the personal information we hold about you

Correct inaccurate personal information

Delete your personal information, subject to legal retention requirements

Opt out of certain data processing activities

Receive a copy of your data in a portable format

9.1 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to delete personal information, and the right to non-discrimination for exercising your privacy rights. We do not sell personal information as defined under the CCPA.

9.2 Other State Privacy Laws

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, and others) may have similar rights under applicable state law. We honor all such rights to the extent legally required.

9.3 How to Exercise Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law.

10. CHILDREN'S PRIVACY

The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a child under 18, we will delete it promptly.

11. COOKIES AND TRACKING TECHNOLOGIES

We may use cookies and similar tracking technologies to operate the Platform, remember your preferences, and analyze usage patterns. You may control cookie preferences through your browser settings; disabling cookies may affect Platform functionality.

12. THIRD-PARTY LINKS

The Platform may contain links to third-party websites or services not operated by the Company. We are not responsible for the privacy practices of any third party. We encourage you to review the privacy policies of any third-party site you visit.

13. INTERNATIONAL USERS

The Platform is hosted in the United States and intended for use by individuals located in the United States. If you access the Platform from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

14. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. Material changes will be communicated to you via email or through a notice on the Platform at least fourteen (14) days before the effective date. Continued use of the Platform after changes take effect constitutes your acceptance of the updated Privacy Policy.

15. CONTACT US

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

Selna Consulting LLC d/b/a LNC Accelerator
PO BOX 12, Sparr, FL. 32192

[email protected]

(229)586-8846

Copyright 2026 | LNC Accelerator™  |  Privacy Policy  |  Terms and Conditions | Acceptable Use Policy