How GentlyAI protects privacy across AI governance workflows
This Privacy Policy explains how GentlyAI collects, uses, shares, stores, transfers, and protects personal information across our website, platform, browser extension, workspace, reports, and customer support channels.
1. Who we are
GentlyAI provides AI Brand Governance software that helps organizations review AI-generated communication for trust, tone, claims, brand drift, and institutional consistency. GentlyAI is headquartered in Australia and operates a software platform, workspace, browser extension, reports, and related services.
2. Scope of this policy
This Privacy Policy applies to personal information processed through GentlyAI’s website, onboarding flows, signup flows, checkout flows, workspace, dashboard, reports, browser extension, support channels, sales processes, and related services. It should be read with our Terms of Service, Data Policy, AI Sovereignty Policy, Security Policy, and Cancellation Policy.
3. Personal information we collect
Account information
Name, work email address, company domain, password credentials, authentication metadata, workspace role, selected plan, and account status.
Company and workspace information
Company name, domain, brand settings, workspace configuration, governance preferences, Brand Memory, team settings, and workspace activity.
AI workflow content
Prompts, drafts, AI-generated outputs, selected content, rewritten variants, uploaded brand materials, governance inputs, and related content submitted for review.
Browser extension information
Extension connection status, supported AI platform context, selected page content, prompts, generated outputs, review actions, and governance activity necessary to provide extension functionality.
Governance telemetry
Trust scores, claim-risk indicators, drift signals, review history, rewrite actions, approval activity, timestamps, usage metrics, and aggregated workspace reporting signals.
Billing and commercial information
Plan selection, subscription status, invoice metadata, billing records, payment-provider identifiers, sales inquiries, support communications, and enterprise rollout requests.
Technical information
IP address, browser type, device information, session data, log data, diagnostic events, security events, performance data, and error reports.
4. How we collect information
We collect information directly from users when they create an account, submit a company domain, configure a workspace, upload materials, request support, contact sales, use governance review tools, or interact with the browser extension.
We may also collect information automatically through the platform, browser extension, logs, cookies, analytics tools, security systems, payment providers, CRM tools, infrastructure providers, and service providers such as authentication, payment, infrastructure, CRM/support, analytics, and security providers.
Customer workspace records, Brand Governance Memory, uploaded materials, governance activity, and related platform data may be stored in GentlyAI’s database, storage, logging, and infrastructure environments operated by GentlyAI and its subprocessors. Depending on configuration, these environments may be hosted in Australia, the United States, the European Union, Singapore, or other provider regions described in our Data Policy or subprocessor list.
Data may be housed in Supabase, AWS, Stripe, HubSpot, Google/Chrome extension systems, AI service providers selected or enabled by GentlyAI or the customer, depending on workspace configuration, and other disclosed subprocessors where used to provide the service.
5. How we use personal information
6. Legal bases for processing
Contract
Account creation, authentication, workspace access, subscription management, governance services, and support where processing is needed to provide the service.
Legitimate interests
Platform security, fraud prevention, product reliability, customer support, governance telemetry, service improvement, B2B sales, aggregated reporting, and protecting rights, provided those interests are not overridden by individual rights.
Consent
Cookies, marketing communications, optional visual analysis, optional extension permissions, or other features where consent is required.
Legal obligation
Tax, accounting, regulatory, compliance, dispute, and legal request obligations.
Customer instructions / processor role
Where GentlyAI processes customer workspace content on behalf of an organisation, GentlyAI may act as a processor or service provider and the customer may be the controller or business responsible for the lawful basis.
7. Browser extension privacy
The GentlyAI browser extension operates only inside supported AI-assisted workflows or pages where the user has installed, connected, and used GentlyAI functionality.
The extension may process prompts, generated outputs, selected text, page context needed to understand the selected AI workflow, review actions, and workspace metadata required for governance.
GentlyAI does not use the extension to monitor unrelated browsing. GentlyAI does not collect unrelated browsing history, read unrelated page content, collect unrelated personal communications, or track users across websites for advertising.
Extension data is limited to what is required for visible user-facing governance features, security, support, and product reliability. Extension permissions must match the Chrome Web Store listing before submission.
8. Limited Use disclosure for browser extension data
GentlyAI uses data accessed through the browser extension only to provide and improve user-facing AI Brand Governance functionality, including governance scoring, trust analysis, drift detection, claim review, rewrite recommendations, workspace telemetry, support, security, and product reliability.
GentlyAI does not sell browser extension data. GentlyAI does not use browser extension data for unrelated advertising. GentlyAI does not transfer browser extension data except as necessary to provide or secure the service, comply with law, process data through disclosed subprocessors, or support customer-requested functionality. GentlyAI does not use browser extension data for credit eligibility, employment decisions, insurance, or unrelated profiling.
GentlyAI does not conduct human review of customer content except where needed for support, security, abuse investigation, legal obligations, or customer-authorised assistance.
9. AI provider processing
Depending on enabled integrations and workspace configuration, customer content may be processed through AI service providers selected or enabled by GentlyAI or the customer, depending on workspace configuration.
Customer content may be sent to AI providers only where needed for enabled governance analysis, classification, summarisation, rewrite recommendations, visual analysis, enrichment, or reporting.
GentlyAI does not sell customer workspace content. GentlyAI does not use customer workspace content to train third-party foundation models. If a customer independently submits content to third-party AI platforms outside GentlyAI, that use is governed by that provider and the customer’s configuration.
AI provider processing locations and retention may vary. Enterprise customers should review provider configurations, processing locations, retention rules, and subprocessor terms for their workspace before enabling external AI processing.
10. How we share information
We may share personal information with service providers, subprocessors, payment processors, infrastructure providers, AI providers, CRM providers, analytics providers, legal advisers, security providers, and regulators where necessary to provide, secure, operate, support, improve, or comply with obligations related to the service. We do not sell personal information or customer workspace content. Key providers and subprocessor categories may include:
| Provider / category | Purpose |
|---|---|
| Supabase | Authentication, database, workspace records, application data, and backend services. |
| AWS | Cloud infrastructure, storage, backups, exports, assets, and processing systems where enabled. |
| Stripe | Subscription billing, invoice management, payment status, and payment processing. |
| HubSpot | CRM, support, onboarding, sales communications, and enterprise workflows where enabled. |
| Chrome Web Store, browser extension distribution, workspace/security/analytics services where enabled. | |
| AI service providers | Governance analysis, classification, summarisation, rewrite recommendations, visual analysis, enrichment, and reporting where enabled. |
| Analytics, security, and logging providers | Diagnostics, reliability, security monitoring, abuse prevention, and operational logging. |
11. International data transfers
GentlyAI is headquartered in Australia. Personal information may be stored or processed in Australia and other countries depending on provider infrastructure and workspace configuration. Countries may include Australia, the United States, the European Union or European Economic Area, the United Kingdom, Singapore, and other regions used by subprocessors.
Privacy protections may differ by country. Where GDPR or UK GDPR applies, GentlyAI will use appropriate safeguards such as data processing agreements, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, transfer impact or risk assessments, subprocessor review, and regional hosting options where available.
Enterprise customers may request information about subprocessors and hosting configurations for their workspace.
12. Retention
We retain personal information for as long as necessary to provide the service, maintain accounts, operate workspaces, provide reports, support customers, comply with law, resolve disputes, enforce agreements, prevent abuse, maintain billing records, and protect platform security.
Account and workspace data may be retained while an account or workspace remains active. Billing, invoice, tax, and accounting records may be retained as legally required. Support records, security logs, diagnostic data, and operational logs may be retained for limited operational periods based on support, reliability, abuse-prevention, and security needs.
Backups may persist for a defined backup lifecycle. Customer content may be deleted, returned, or exported according to the applicable plan, customer agreement, workspace configuration, or legal obligation. We do not state fixed retention periods here unless they are implemented and documented for the relevant data type.
13. Security
GentlyAI uses administrative, organizational, and technical safeguards designed to protect personal information, including authentication controls, access restrictions, infrastructure security controls, encrypted transport where supported, logging, monitoring, and operational review. No system is completely secure.
14. Your privacy rights
Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about how your personal information is processed.
These rights may arise under the Australian Privacy Act, GDPR, UK GDPR, state privacy laws, or other privacy frameworks. Requests can be submitted through the contact details published on our Contact page. Identity verification may be required before we act on a request. If we process information on behalf of a customer as a processor or service provider, some requests may need to be handled by that customer, or we may assist the customer in responding.
Users may also have complaint rights with the Office of the Australian Information Commissioner, EU or UK supervisory authorities, or another local privacy regulator depending on their location.
15. Children
GentlyAI is intended for business and professional use by adults. The platform is not directed to children or users under 18. Users must not submit children’s personal information, student records, or content directed at children unless expressly authorised under a separate written agreement and legally permitted. If we become aware that children’s personal information has been submitted without authorisation, we will take reasonable steps to delete, restrict, or return it as required.
16. Responsible business and supplier standards
GentlyAI expects its suppliers and service providers to comply with applicable labour, anti-trafficking, anti-slavery, anti-bribery, and human rights laws. Where required or appropriate as GentlyAI grows, we may publish additional supplier, procurement, or modern slavery disclosures. Privacy requests should not be used to report labour or supplier concerns; those concerns should be sent through the Contact page.
17. Complaints
If you have a privacy complaint, contact GentlyAI using the details on the Contact page. We will review and respond where appropriate. If you are located in Australia, you may also have the right to contact the Office of the Australian Information Commissioner. If you are in the EU, UK, or another jurisdiction, you may have the right to contact your local data protection authority.
18. Changes to this Privacy Policy
We may update this Privacy Policy as the product, infrastructure, subprocessors, extension permissions, AI integrations, legal requirements, or business operations change. Material updates will be reflected on this page or communicated where required.