Our Data Promise

Your data is yours.

We never train AI models on it. We never sell or share it. You can export or delete everything, any time, without asking us.

You own your data.

Every document you upload, every client record, every chat transcript: yours. We process it only to run the product for you. Export it any time. Delete it any time.

We do not train AI models on your data. Ever.

Your prompts and documents are never added to training sets, fine-tunes, or evaluation corpora. Not ours, not our model providers'. Google Gemini and OpenAI API calls run under zero-retention, no-training enterprise agreements.

We do not sell, rent, or share your data.

No data brokers. No carrier kickbacks. No ad networks. The only third parties that touch your data are infrastructure subprocessors (hosting, AI inference, email), each under contract and listed publicly.

Tenant isolation at the database layer.

Postgres Row-Level Security tags every row with your agency's tenant ID. Cross-tenant reads are blocked at the database, not just the app. Custom builds for one agency cannot leak into another agency's workspace.

Encrypted in transit and at rest.

TLS 1.2+ everywhere. AES-256 at rest. PII fields (SSN, credit card, DOB, EIN, phone) are masked before chat history is persisted, by default.

Export or delete, on your terms.

One-click export of your org's data as JSON plus generated PDFs. One-click org wipe with a 7-day reversible soft-delete window, then permanent purge. No tickets, no waiting.

What this looks like in practice

  • Documents you upload for the Explainer or Compare flows are stored encrypted and tied to your org. We do not surface them to other tenants. We do not feed them into any training pipeline.
  • Chat transcripts default to redacted logging: PII is masked before write. Your org admin can switch to none (no logs at all) or full (raw).
  • Model providers (Google, OpenAI, Perplexity) are contractually prohibited from using API inputs for training. We send only what is needed for the request, and only for the request.
  • We support data subject access requests (CCPA, GDPR) within statutory windows: access, correction, export, deletion. Email privacy@theintelligentagent.ai or use the in-app Data & privacy panel.
  • If something goes wrong, our DPA commits us to notify you within 72 hours of confirming a security incident affecting your data.

The full legal picture

This page is the plain-English version. The binding documents are below.