Data Policy

How GentlyAI handles workspace, brand, and governance data

This Data Policy explains how GentlyAI collects, processes, stores, transfers, protects, and deletes data used in our AI Brand Governance platform, browser extension, reports, and workspace services.

1. Scope of this Data Policy

This Data Policy applies to data processed through GentlyAI’s website, workspace, dashboard, browser extension, governance review tools, reporting products, onboarding flows, payment flows, customer support channels, and related services. It should be read together with our Privacy Policy, Terms of Service, AI Sovereignty Policy, Security Policy, Cancellation Policy, and any customer agreement or data processing agreement that applies.

2. Data roles

GentlyAI may act as a service provider, processor, or equivalent role when processing customer workspace content on behalf of a customer. GentlyAI may act as a controller, business, or equivalent role for account administration, billing, security, analytics, product operations, legal compliance, and direct customer communications.

The customer remains responsible for determining whether the content submitted to GentlyAI is appropriate for processing under the customer’s internal policies, employment obligations, confidentiality obligations, regulatory requirements, and third-party platform terms.

3. Categories of data we may process

Account data

Name, work email address, login credentials, company domain, selected plan, workspace role, billing status, and authentication metadata.

Workspace data

Brand settings, workspace configuration, governance preferences, team roles, review history, reports, saved rules, and plan entitlements.

Brand and governance inputs

Company domains, Brand Memory, tone guidance, claim rules, uploaded brand materials, approved language, avoided language, category positioning, policy guidance, and customer-provided reference materials.

AI workflow content

Prompts, drafts, generated outputs, rewritten variants, content selected for review, and related contextual information submitted through the workspace or browser extension.

Browser extension data

Data required to provide governance functionality inside supported AI platforms, including selected page content, prompts, AI-generated responses, review actions, extension state, and workspace connection metadata.

Governance telemetry

Scores, drift indicators, claim-risk classifications, review outcomes, user actions, timestamps, channels, rewrite decisions, approval activity, and aggregated workspace usage metrics.

Commercial and support data

Sales inquiries, contact forms, support messages, onboarding notes, customer relationship records, invoices, subscription events, and payment-provider metadata.

Technical data

IP address, device and browser information, logs, diagnostic events, performance data, error reports, session information, and security events.

4. How we use data

GentlyAI uses data to provide AI Brand Governance functionality, operate customer workspaces, authenticate users, generate reports, analyze content for trust and brand drift, provide rewrite guidance, support browser extension functionality, maintain security, process payments, support customers, improve product reliability, and comply with legal obligations.

We may use aggregated or de-identified information to understand product performance, improve governance workflows, identify reliability issues, and develop generalized product improvements, provided that such information does not identify a customer, workspace, individual, or confidential customer content.

5. Browser extension data handling

The GentlyAI browser extension is designed to provide governance review inside supported AI-assisted workflows, including web-based AI platforms and related publishing workflows. Depending on the page, permissions, user action, and enabled workspace configuration, the extension may access prompts, AI-generated outputs, selected content, page context, and review actions that are necessary to provide governance scoring, drift detection, claim review, rewrite guidance, and workspace telemetry.

Extension data is used only to provide and improve the disclosed GentlyAI functionality, maintain security, support the workspace, and produce governance outputs. GentlyAI does not use extension access to collect unrelated browsing history, unrelated page content, personal communications outside supported workflows, or sensitive data unrelated to the governance function.

GentlyAI will disclose extension data practices in Chrome Web Store materials and in customer-facing policies. Extension permissions should be limited to the access required for supported AI workflow governance.

6. AI provider and model processing

GentlyAI may use internal systems, third-party infrastructure, and third-party AI service providers to deliver governance analysis, content review, rewrite recommendations, classification, enrichment, summarization, and reporting functionality. Depending on enabled integrations and workspace configuration, customer content may be processed through AI service providers such as OpenAI, Anthropic, Google, Microsoft, or other providers selected by GentlyAI or enabled for the customer.

GentlyAI does not sell customer workspace content. GentlyAI does not use customer workspace content to train third-party foundation models unless this is explicitly disclosed, enabled by the customer, or required by a separately agreed customer configuration.

Third-party AI providers may have their own terms, security controls, processing locations, and retention rules. GentlyAI will select providers based on product requirements, security posture, availability, and customer configuration, and will disclose material subprocessors where required.

7. Subprocessors and infrastructure providers

GentlyAI uses third-party service providers to operate the platform. These providers may process data only as needed to deliver hosting, database, authentication, storage, payment, analytics, customer support, security, communications, AI processing, or related services.

ProviderPurposeData category
SupabaseAuthentication, database, workspace records, product data, and related infrastructure.Account, workspace, governance, technical data.
Amazon Web ServicesCloud infrastructure, storage, backups, assets, reports, exports, and future data processing infrastructure.Workspace, uploaded files, reports, backups, technical data.
StripePayment processing, subscriptions, invoices, billing events, and payment-provider records.Billing metadata, subscription data, payment status.
HubSpotCRM, sales inquiries, customer communications, onboarding, support, and enterprise pipeline management.Contact, company, sales, support, onboarding data.
GoogleChrome extension distribution, extension review, account ecosystem services, analytics or productivity integrations where enabled.Extension metadata, support and operational data, depending on configuration.
AI service providersGovernance analysis, classification, rewrite support, summarization, enrichment, and future model-based services.Prompts, outputs, selected content, governance inputs, workspace context.

GentlyAI may update this list as the product develops. Before public launch, GentlyAI should maintain a separate Subprocessors page or customer-facing subprocessor schedule.

8. Data residency and international transfers

GentlyAI is headquartered in Australia but may process and store data in other countries through its infrastructure providers and subprocessors. Data may be processed in Australia, the United States, the European Union, Singapore, or other locations where our providers operate infrastructure or support services.

Supabase projects may be deployed in available infrastructure regions, including regions such as East US, Central EU, and Southeast Asia depending on project configuration and provider availability. GentlyAI will describe applicable production infrastructure regions in this policy or related subprocessor and data-residency disclosures where required.

Where required by applicable law, GentlyAI will use appropriate safeguards for cross-border transfers, which may include contractual protections, data processing agreements, standard contractual clauses, subprocessor due diligence, regional hosting choices, or other legally recognized transfer mechanisms.

9. Workspace administrator visibility

Workspace administrators may have visibility into workspace configuration, user roles, review history, governance activity, reports, policy settings, review outcomes, account status, usage metrics, and organizational telemetry. Customers are responsible for providing any required notices to employees, contractors, or users where workplace monitoring, acceptable-use, or internal compliance laws require such notice.

10. Data retention

GentlyAI retains data for as long as necessary to provide the service, operate workspaces, maintain reports, support customers, satisfy legal obligations, resolve disputes, enforce agreements, maintain security, and preserve audit or billing records.

Customers may request deletion of workspace data subject to legal, security, billing, backup, dispute, and legitimate business retention requirements. Deleted data may remain in backups or logs for a limited period before being overwritten or removed according to normal backup cycles.

11. Security controls

GentlyAI uses technical and organizational measures designed to protect customer data, including authentication controls, access restrictions, secure infrastructure providers, encrypted transport where supported, logging, permission controls, and administrative safeguards.

No system is completely secure. Customers should avoid submitting content that they are not authorized to process through GentlyAI and should configure internal access controls, user roles, and employee usage policies appropriately.

12. Customer rights and requests

Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about how their personal data is processed. These rights may apply under Australian privacy law, the GDPR, UK GDPR, state privacy laws, or other privacy frameworks.

Requests should be sent to GentlyAI through the contact details published on the Contact page. Where GentlyAI processes data on behalf of a customer, GentlyAI may refer the request to the customer or assist the customer in responding, depending on the applicable agreement and legal role.

13. Incident response and breach notification

If GentlyAI becomes aware of a security incident affecting customer data, GentlyAI will investigate, take appropriate mitigation steps, and notify affected customers or regulators where required by applicable law. Notification timing and content may depend on the nature of the incident, legal obligations, affected data, and customer agreements.

14. Changes to this policy

GentlyAI may update this Data Policy as the product, infrastructure, subprocessors, integrations, extension permissions, or legal requirements change. Material updates will be reflected on this page. Customers should review this policy periodically.