Plain-English privacy commitments for customer workspaces.

This page explains the current operating privacy posture for customer workspaces. It should still be reviewed by counsel before being treated as final negotiated customer terms.

Data we expect to collect

Account details, organisation and workspace details, team memberships, prompts, chat messages, uploaded documents, generated artifacts, durable memories, graph candidates, usage events, billing metadata, audit logs, and support communications.

How data is used

To provide the product, route advisory workflows, ground responses in provided context, maintain audit and billing records, improve launch quality, support users, prevent abuse, and meet operational obligations.

AI processing

Customer prompts, documents, and outputs may be sent to configured model providers when needed to generate responses. Consulting AIOS should not be used for highly sensitive regulated data unless a written customer arrangement confirms the approved providers, controls, and review process.

Access and deletion requests

Organisation owners and admins can request exports, corrections, retention changes, or deletion. Some records may be retained where needed for security, billing, audit integrity, legal holds, backups, or dispute handling.

Retention, subprocessors, and terms should be read together.