AI Sovereignty Policy

How GentlyAI approaches AI control, governance, and customer ownership

This policy explains GentlyAI’s position on AI governance, customer ownership, model interaction, human oversight, and the operational safeguards used to reduce uncontrolled AI behavior across enterprise communication workflows.

1. Customer ownership of workspace content

Customers retain ownership and control over the prompts, drafts, uploaded materials, governance inputs, reports, rewrite outputs, configurations, and workspace content processed through GentlyAI.

GentlyAI does not claim ownership over customer brand assets, communication strategies, institutional language, internal policies, or AI-assisted outputs generated within customer workflows.

2. Human oversight remains required

GentlyAI is designed to support human decision-making, not replace it. Governance scoring, rewrite recommendations, risk indicators, drift analysis, and trust assessments are decision-support tools.

Customers remain responsible for legal review, compliance review, factual verification, editorial approval, disclosure obligations, employment obligations, and final publishing decisions.

3. AI provider interaction

Depending on enabled integrations, workspace configuration, and future product capabilities, GentlyAI may interact with third-party AI providers including OpenAI, Anthropic, Google, Microsoft, or other providers necessary to support governance functionality, rewrite recommendations, classification, summarization, or analysis.

GentlyAI does not control the infrastructure, independent retention rules, or internal model policies of third-party AI providers. Customers should review the policies of integrated AI providers separately where applicable.

4. AI training position

GentlyAI does not sell customer workspace content. GentlyAI does not use customer workspace content to train third-party foundation models. If a customer independently submits content to third-party AI platforms outside GentlyAI, that use is governed by that provider and the customer’s configuration.

GentlyAI may use aggregated or de-identified operational data to improve governance systems, product reliability, workflow quality, detection accuracy, platform performance, and generalized product functionality, provided that such information does not identify a customer, individual, or confidential customer material.

5. Governance telemetry and organizational visibility

GentlyAI may generate governance telemetry related to AI-assisted communication activity within a workspace. This may include review activity, governance scoring, rewrite usage, risk classifications, approval workflows, workspace usage patterns, and governance history.

Workspace administrators may have visibility into governance activity, review history, usage metrics, and organizational settings depending on the customer configuration and selected plan. Customers are responsible for ensuring that internal usage policies, employee disclosures, and workplace monitoring obligations are satisfied where required by law.

6. Brand governance philosophy

GentlyAI is built on the position that AI scale without governance creates institutional risk. Repeated AI-generated communication can gradually weaken distinctiveness, inflate claims, flatten brand language, and reduce trust consistency across teams and channels.

GentlyAI is designed to help organizations preserve institutional identity while still benefiting from AI-assisted productivity and workflow acceleration.

7. Supported governance functions

Trust scoring and institutional continuity analysis
Brand drift and tone inconsistency detection
Claim inflation and risk analysis
Governance rewrite recommendations
Channel-specific communication variants
Governance telemetry and reporting
Workspace-level governance visibility
Human review and approval workflows

8. Data residency and sovereignty

GentlyAI is headquartered in Australia but may use international infrastructure providers and subprocessors. Depending on deployment configuration, data may be processed or stored outside Australia, including in the United States, European Union, Singapore, or other supported infrastructure regions.

Enterprise customers with specific sovereignty, residency, regulatory, or regional hosting requirements may require custom deployment, dedicated infrastructure, contractual controls, or enterprise configuration.

9. Security and access controls

GentlyAI uses administrative, organizational, and technical measures designed to protect workspace data, including authentication controls, access restrictions, encrypted transport where supported, infrastructure security controls, and operational safeguards.

No platform can guarantee absolute security. Customers are responsible for managing workspace access appropriately and avoiding submission of content they are not authorized to process through the platform.

10. Future integrations and infrastructure evolution

GentlyAI may evolve its infrastructure, governance models, integrations, AI providers, browser extension capabilities, reporting systems, telemetry systems, or deployment architecture as the platform develops.

Material changes affecting customer data handling, governance behavior, AI processing, extension permissions, or infrastructure practices will be reflected in updated policies or customer notices where appropriate.