Privacy and data handling
Technical minimization and scope principles, separate from the formal legal Privacy Policy that must be approved before final commercial launch.
How to interpret this document
This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.
Controlled prompts
Measurement uses prompts configured in the platform. The product does not depend on access to private consumer conversations.
Audit minimization
AUD-2.0 removes sensitive patterns from generic snapshots and can correlate actor email through a hash, reducing unnecessary exposure.
Scope
Operational data is associated with organization and, where applicable, workspace and department. Email domain alone is not the tenant boundary.
External providers
When models or integrations are invoked, necessary data can leave the application boundary. Each provider's contractual and privacy terms should be evaluated during deployment.
Legal policy
Controller/processor roles, lawful bases, data-subject rights, cookies, international transfers, subprocessors and privacy contacts belong in the approved legal Privacy Policy.