Data Policy

Customer data, clearly bounded

This policy describes GentlyAI's customer-data roles, launch processing boundaries, retention approach and separation between active and activation-gated services.

1. Data roles

For customer workspace content, GentlyAI generally acts on the organisation's instructions as a processor or service provider. The customer decides what authorised content enters the workspace and remains responsible for its lawful basis, notices, permissions and internal policies.

GentlyAI acts independently for its account relationship, service security, billing, support, legal compliance and direct business operations. The Privacy Policy explains personal-information handling.

2. Customer ownership and service licence

Customers retain their rights in brand materials, Brand Memory inputs, prompts, drafts, outputs and uploaded references. GentlyAI does not claim ownership of a customer brand.

Customers provide the limited permission needed for GentlyAI and disclosed service providers to host, transmit, analyse and transform content solely to provide, secure and support the requested service.

3. Production data boundary

The production boundary uses WorkOS for authentication, Vercel for the web application, Supabase for workspace data and private storage, Railway for governance-service hosting, Stripe for enabled billing, HubSpot for limited customer-lifecycle summaries, and approved email services for transactional messages. Chrome distributes the approved extension package.

For Managed AI, the provider selected or included for the customer's workspace may be OpenAI, Anthropic or Google Gemini. Microsoft managed services remain activation-gated unless separately approved and configured. Current subprocessor and transfer information is available to enterprise customers through the due-diligence process.

4. Minimum-necessary processing

GentlyAI uses workspace identity and the minimum approved Brand Memory context needed for an authorised request. A browser cannot supply arbitrary authoritative brand intelligence or workspace access. Service credentials remain server-side.

HubSpot, when activated, receives concise CRM and commercial summaries rather than full Brand Memory, prompts, reviews, raw AI usage or payment-card data. Stripe, when activated, owns payment processing and returns subscription and payment-state metadata to GentlyAI.

5. AI and extension processing

GentlyAI submits a customer prompt and the minimum approved Brand Memory context needed for an enabled request to the Managed AI provider selected or included for that workspace. The provider processes that request to produce a response. GentlyAI separately persists the authorised conversation, response, context references and governance result in the customer workspace. Business or API provider terms and configuration govern provider-side retention. GentlyAI does not promise zero data retention or regional processing unless expressly supported by a provider agreement and customer configuration.

The extension sends captured content only after a user requests review or variants. It does not passively transmit unrelated pages. Event records are limited to operational and governance metadata and do not store the full captured body. Copy and open actions preserve destination authentication and human publishing control.

6. Retention model

Account and workspace

Held while required to provide and administer the service, then deleted or restricted through the applicable closure process subject to required records.

Brand Memory and uploaded files

Customer-controlled workspace data. Deletion or return depends on authority, product capability, backups and any customer agreement.

Extension review content

Raw submitted and revised bodies are transient in the launch extension review path. Limited event metadata may be retained for governance activity, security and reliability.

Managed AI conversations

Prompts, provider responses, selected context references and governance results are saved to the authorised workspace when conversation history is part of the Managed AI service. Provider-side handling remains subject to the applicable business or API service and configuration.

Billing and CRM

Kept as needed for customer administration, accounting, tax, fraud, consent and dispute obligations. Production processing begins only when the corresponding integration is activated.

Security and support

Kept for a proportionate operational period needed for support, reliability, incident response, abuse prevention and legal obligations.

7. Deletion, return and legal records

A customer may use available product controls or contact Support to request account closure, data access, correction, return or deletion. GentlyAI verifies identity and workspace authority before acting.

Deletion may not remove records that must be retained for law, tax, accounting, consent evidence, security, fraud, dispute or audit purposes. Protected backups and provider systems may complete deletion through their ordinary lifecycle. GentlyAI does not publish unsupported fixed deletion periods.

8. Security and isolation

Production controls include WorkOS identity, server-side authority resolution, Supabase row-level security and workspace isolation, private storage, server-only elevated credentials, signed billing webhooks where enabled, and state-bound single-use extension connection codes. These are factual control descriptions, not claims of a certification or an absolute security guarantee.

9. Changes and questions

This policy will be updated before a material new processing path is activated. Questions may be sent to privacy@gentlyai.ai.