Business Guru is a business-to-business productivity tool that Spur Logic LLC provides to licensed accounting and tax firms. It helps a firm review filed tax returns, find missed deductions, categorize expenses, and prepare advisory deliverables. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to our website and application at https://bg.spurlogic.net (the “Service”).
Plain-language summary: We sell Business Guru to accounting firms — not to their clients. Highly sensitive identifiers (Social Security numbers, EINs, bank and account numbers) are removed in your browser before anything is sent to us or to our AI provider — we are built so that this data never reaches our servers, our database, or the AI model. We never sell personal information. Access to client data requires multi-factor authentication, and every access is logged.
Who we are, and who controls the information
Business Guru is operated by Spur Logic LLC. It is a multi-tenant platform sold to accounting firms (each a “Firm”). The Firm is the controller of its own clients’ information; Spur Logic LLC acts as a service provider / processor that stores and processes that information on the Firm’s behalf and under the Firm’s instructions. Business Guru has no direct relationship with a Firm’s clients — clients are records inside a Firm’s workspace, never account holders.
Our zero-knowledge approach to sensitive data
Business Guru is designed so that the most sensitive taxpayer identifiers are never transmitted to or stored by us:
- When a Firm uploads a return or statement, the document is read and parsed inside the user’s browser.
- Tier-1 identifiers — Social Security numbers, ITINs, EINs, bank routing and account numbers, and the names of taxpayers/spouses/dependents the Firm flags — are redacted (replaced with neutral tokens) in the browser before any text leaves the device.
- The token-to-value mapping that would let anyone reverse the redaction stays only in the user’s local browser storage. It is never uploaded.
- Our servers, our database, and our AI provider receive redacted text only.
Redaction reduces risk but is not a guarantee that every name a Firm did not flag is caught. For that reason we are moving paid client-data processing onto an in-tenancy AI deployment (see “AI processing”), and Firms remain responsible for what they upload.
Information we collect
Firm account information
- Email address — we use passwordless “magic link” sign-in. We do not collect or store passwords.
- Firm name, the name/role of each authorized user, and multi-factor authentication enrollment.
Client and engagement information (entered by the Firm)
- Client/business name, entity type, filing state, and business-context answers the Firm provides to scope an analysis.
- Redacted return text and statement text (Tier-1 identifiers already removed in the browser, as described above), categorized transactions, and the findings/deliverables generated from them.
- Records that the Firm obtained the required client consent before a return or statement is analyzed (see “Tax-information consent”).
Technical and audit information
- Basic log and device data needed to operate and secure the Service.
- An append-only audit log of access to client data and of authentication events. The audit log records the acting user, the Firm, and the resource — never Tier-1 identifiers.
AI processing
Business Guru uses a large-language-model provider (currently Anthropic’s Claude API) to reason over redacted return and expense text and to draft deliverables. Only redacted text is sent. Before any real client data is processed at scale, Spur Logic LLC routes these calls through an in-tenancy / zero-data-retention deployment and executes a data processing agreement with the provider, so client data is not retained or used to train models.
Tax-information consent (IRC §7216)
U.S. law (Internal Revenue Code §7216 and Treas. Reg. §301.7216) restricts how a tax-return preparer may use or disclose tax-return information. Business Guru enforces this in software: before any analysis that uses a client’s tax-return information, the Firm must record that it has obtained the client’s consent for that year. The Firm is responsible for obtaining valid consent from its clients; Business Guru blocks the analysis and logs the block if consent is not on file.
How we use information
- To provide the Service: audits, deduction analysis, expense categorization, and deliverables.
- To authenticate users and secure the Service (magic-link sign-in, MFA, rate limiting, audit logging).
- To operate, maintain, debug, and improve the Service.
- To meet legal, tax, and recordkeeping obligations.
We do not sell personal information, and we do not use client information for advertising or to train third-party models.
How we share information
- Within the Firm: client data is visible only to authorized users of the Firm that owns it. Firms are isolated from one another at the database level (row-level security on a firm identifier).
- Service providers who help us operate the Service, under contract and only as needed: hosting and database (Supabase, U.S. region), application hosting (Vercel), and AI reasoning over redacted text (Anthropic). When billing is enabled, payment processing (Stripe);Spur Logic LLC does not store card numbers.
- Legal: when required by law or to protect the rights, safety, and integrity of the Service.
- We do not sell or rent personal information, and we do not act as a consumer data broker.
How we protect information
- Browser-side redaction of Tier-1 identifiers before transmission (see above).
- Passwordless authentication (magic links) plus mandatory multi-factor authentication for any access to client data.
- Database-level access controls isolate each Firm’s data; an append-only audit log records access.
- Encryption in transit; data processed and stored in the United States.
No system is perfectly secure, but we work to protect information and to collect as little as possible.
Data breaches
If a breach affects personal information, we will notify the affected Firm without undue delay and — where required by law — assist with notifications to affected individuals and authorities.
Data retention
We keep information for as long as the Firm maintains its account and as needed for the Firm’s recordkeeping, dispute resolution, and legal obligations. A Firm may request export or deletion of records that are no longer required, subject to legal retention limits.
Your choices and rights
- A Firm may access, correct, export, or delete the client records in its workspace.
- Because Business Guru has no direct relationship with a Firm’s clients, individuals should direct access or deletion requests to the Firm that holds their records; we will assist the Firm.
- Authorized users may opt out of non-essential email; transactional messages (like sign-in links) are required to use the Service.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be posted here with a new effective date.
Contact us
Questions or requests: privacy@spurlogic.net.