Account and identity
Name, work email, authentication identifiers, organisation membership, workspace role and account security metadata.
This Privacy Policy explains how GentlyAI Marketing Solutions Pty Ltd handles personal information and customer content across the website, customer workspaces and GentlyAI Governance Layer Chrome extension.
GentlyAI Marketing Solutions Pty Ltd, referred to as GentlyAI, provides brand governance software for business and professional use. This policy applies to gentlyai.ai, customer workspaces, governance services, support channels and the GentlyAI Governance Layer Chrome extension.
When we process customer workspace content on an organisation's instructions, we may act as its processor or service provider. We act independently for account administration, security, billing, support, direct commercial relationships and legal compliance.
Name, work email, authentication identifiers, organisation membership, workspace role and account security metadata.
Company and workspace details, approved brand guidance, claims boundaries, uploaded references, roles, permissions and governance configuration.
Prompts, drafts, outputs, variants and other content that a user submits for generation or governance, together with review results and limited workflow metadata.
Purchase intent, billing and subscription metadata, CRM relationship data, support requests and operational communications.
IP address, browser and device information, session and diagnostic data, service logs, security events and performance information.
We use information to authenticate users, enforce organisation and workspace authority, provide Brand Memory and governance services, operate the extension, support customers, manage subscriptions, protect the service and comply with law. We may use aggregated or de-identified operational information to improve reliability and product performance where it does not identify a customer, person or confidential customer content.
Depending on the location and context, processing may be necessary to perform a contract, follow customer instructions, pursue a legitimate business or security interest, comply with law, or act on consent. An organisation using GentlyAI remains responsible for its lawful basis and notices when it submits information about other people.
When a customer uses a relevant Managed AI service, GentlyAI sends the prompt and the minimum approved workspace context needed for that request to the supported provider selected or included for the workspace. Supported Managed AI providers include OpenAI, Anthropic and Google Gemini. Microsoft managed services are not active production processors unless separately enabled and disclosed.
GentlyAI does not sell customer content and does not instruct an AI provider to use customer content to train its foundation models. Provider retention and abuse-monitoring practices remain governed by the provider's business or API terms and the configuration applicable to the service. GentlyAI does not claim zero data retention unless a specific customer configuration and provider agreement support that claim.
In a BYO AI workflow, the customer separately controls its external AI account and that provider's terms. In a GentlyAI-managed workflow, GentlyAI controls the service-side provider connection and the customer remains responsible for ensuring submitted content is lawful and appropriate for external processing.
The extension's single purpose is to let an authorised user capture content from a supported AI workflow and request GentlyAI governance review or governed variants. Content is transmitted only after the user starts the relevant action. The extension does not passively collect unrelated browsing history, unrelated page content or personal communications.
An extension connection is bound to an authorised workspace and its active, approved Brand Memory. Raw submitted and revised content is processed transiently for the production extension review path and is not stored in the extension event record. Limited events may record the supported platform, hostname, action, outcome, content length and similar workflow metadata, but not full page URLs, prompts, selected text or generated output.
The extension uses Chrome storage for connection and workflow state and uses only packaged code. It does not download remote executable code. Copy and open actions do not publish content or obtain a destination password. We do not sell extension-derived data or use it for unrelated advertising, credit, employment or insurance decisions.
We use service providers for application hosting, authentication, database and storage, governance processing, payments and approved business operations. Enterprise customers may request current subprocessor and transfer information through the enterprise due-diligence process.
GentlyAI operates from Australia, while providers may process or store information in other countries. We do not promise that all data remains in Australia. Where applicable, we take reasonable steps to assess providers and use contractual or other safeguards appropriate to the processing. Available regions and transfer terms depend on the provider and customer configuration.
Stripe may process payment and subscription information when paid checkout is activated. GentlyAI does not receive full payment-card details. HubSpot may receive identified person, company, purchase intent, consent and customer-lifecycle summaries when the production CRM integration is activated. Rich Brand Memory, prompts, content reviews and raw AI usage are not intended for HubSpot.
Account, authentication, security, billing, onboarding, support and service notices are transactional communications. Marketing communications are separate. Creating an account, becoming a paid customer or contacting support does not itself grant marketing permission. Any marketing choice must be optional, specific and capable of withdrawal.
Account, workspace, Brand Memory and saved product data are retained while needed to provide the service and manage the customer relationship. Customers may delete supported content or request workspace or account closure. The available method depends on the data type and workspace authority.
Billing, consent, security, audit, support and dispute records may be kept after closure where reasonably necessary for legal, financial, security or record-keeping purposes. Backups and provider systems may retain deleted data for their ordinary protected lifecycle. We do not state a fixed period where an operational period has not been adopted for that data type.
Controls include WorkOS-managed authentication, server-side workspace authority, Supabase row-level security and private storage, restricted service credentials, signed billing webhooks where billing is enabled, and state-bound single-use extension connection codes. No internet service can guarantee absolute security. GentlyAI does not claim a certification that it has not obtained.
Depending on applicable law, you may request access, correction or deletion, object to or restrict certain processing, withdraw a consent, or make a privacy complaint. We may need to verify identity and authority. Where we process on behalf of a customer, we may direct the request to that customer or assist it in responding.
Send privacy requests to privacy@gentlyai.ai. You may also contact the Office of the Australian Information Commissioner or another competent privacy regulator where the law gives you that right.
Submit a privacy requestGentlyAI is intended for business use by adults and is not directed to children. Service availability may vary by country, provider, plan and customer configuration. This policy does not promise universal or region-specific availability.
We may update this policy when the product, providers, processing or law changes. Material changes will be posted here or communicated where required. General contact details are available on the Contact page.