How we use AI.

We use AI heavily, and we would rather say exactly how than let an investor discover it. This is the precise account: what our systems send to AI providers, what those providers are permitted to do with it, how long it is kept, and where a person is required.

1. Scope and effective date

This policy describes how Bambu Capital uses artificial intelligence across the systems we operate: our investor data room, our internal investment platform, and this website. It covers what our systems send to AI providers, what those providers are permitted to do with it, how long it is kept, and where a person is required.

It does not cover software our counterparties choose to run, and it does not cover AI features inside third-party tools we use for ordinary business purposes except where we name them here.

Effective date: 27 August 2026. Version 1.0.

We wrote this because we use AI heavily and we would rather say exactly how than let an investor discover it. If you are reading this alongside our founder's essay on the subject, this document is the precise version and it governs.

2. The decision rule

People decide. AI informs.

That sentence is common enough in our industry to be worthless on its own, so here is the mechanism that makes it enforceable rather than aspirational.

3. What our AI is not permitted to do

4. What our AI does automatically

This section exists because section 3 would be misleading without it.

Some of our AI processing runs without a person triggering it:

We record every one of those assistant exchanges and review them. That is a control after the fact, not before it, and we would rather say so than claim an approval step we do not have.

5. Who receives your information

We use two AI providers directly, and no others:

Anthropic (Claude), through Anthropic's commercial API. Receives, depending on the feature:

Cloudflare, through Workers AI on the platform our systems run on. Receives:

Both providers therefore receive data room content, for different purposes: Anthropic receives verbatim excerpts when the assistant answers a question about a document, and Cloudflare receives chunks of every indexed document to build the search behind it.

We also use Fellow, a third-party meeting notetaker, which holds the recording and transcript of meetings we record with it; transcript content from Fellow is sent to Anthropic when we draft reasoning for a decision gate. Fellow's published sub-processor list names Anthropic, OpenAI, Google, Groq and Together.ai for its own AI features, and AssemblyAI and Recall AI for recording and transcription, so those vendors can be indirect recipients of meeting content held by Fellow, on Fellow's systems rather than ours; Fellow does not publish which vendor handles which feature, so we cannot tell you which of them has actually processed our meetings. Fellow states that customer data is not used to train AI models, but that statement sits on its sub-processor and product pages rather than in its privacy policy or terms, and we do not hold a signed data processing agreement with Fellow that says so; Fellow's default is also to keep recordings and transcripts indefinitely until an administrator sets a deletion schedule.

We use no other AI provider directly. Specifically, our own platform sends nothing to OpenAI, Google, Amazon Bedrock, Cohere, Mistral, or any other model vendor; the only route by which any of them can reach our content is the Fellow route described immediately above.

6. Training

No AI provider we use is permitted to train models on your information.

Two clarifications we think matter:

We use commercial API endpoints only. We do not use consumer AI products for firm data. Consumer plans at these vendors have different defaults; those defaults do not apply to us because we do not use those products.

Nothing of yours is training any model of ours either. We are accumulating a record of our own investment decisions and the reasoning behind them, and we expect one day to use it to help our own systems reason about our own judgment. That record is our reasoning, not your documents. No model, ours or anyone else's, is being trained on your information today.

These are the terms that govern commercial API use, and our systems call the commercial API exclusively. We hold the executed agreements and our account records on file.

7. Retention

At our providers. Anthropic's standard retention for commercial API traffic is 30 days. There are carve-outs an investor is entitled to see in the same sentence: content flagged by trust-and-safety processes may be retained for up to two years, and safety classification scores for up to seven years. We do not currently hold a zero-data-retention arrangement.

At Bambu. We keep what our systems generate: document summaries, extracted document text and its search index, assistant questions and answers, and decision records. Today we keep these indefinitely, until we delete them on request. We are building a retention schedule and this section will state it when we have one.

8. Open-web research

Five of our research features let the model compose and run its own web searches. We constrain what we put into the prompt; we do not pre-approve each query the model then writes.

When we research a target company, an enforced list withholds our economics and our criteria: our EBITDA floors, enterprise-value bands, tolerances, operating-margin targets, platform slots, criteria sets, team assessments, and the firm's own name. A scanner refuses the request if any of them appear. This applies to our sourcing, company-research and comparables features.

9. The data room, specifically

If you are an investor or a counterparty in our data room, this is the section that concerns you.

10. What we do not do

Each of these is verified in our own source code, not merely intended:

11. Your rights, and how to reach us

You may ask what we hold about you, ask us to delete it, or ask how a particular output was produced. Requests are handled by a person, not a form. Write to [email protected].

12. How this document is kept honest

This policy was written against our source code, and every factual claim in it was verified against that code or against a provider's contract on the date above.

Code changes. This document is re-verified against the platform quarterly, and on any material change to how we use AI. When we find a divergence we correct the document and note what changed.

We hold ourselves to one rule in particular: if this document says a control exists, that control is enforced in software, not in a habit.

Questions About This Policy

A person will answer.

Ask what we hold, ask us to delete it, or ask how a particular output was produced. Requests are handled by a person, not a form.

Contact us