Privacy Policy
What Genesis collects, why it is needed, where it goes, and the choices you have.
Effective 15 July 2026 · Version 2026-07-15
Engineering draft · legal approval pending
At a glance
We use account and workspace information to provide and secure Genesis. Connected services receive data only when needed for the connection or action you authorize, and we do not sell personal information.
Scope and who we are
This Privacy Policy explains how AI Centre of Excellence (“AICOE”, “we”, “us”, or “our”) handles personal information when you visit Genesis, create an account, run workflows, connect tools, communicate with us, or use related services. The exact data-controller legal entity, registered address, company number and privacy contact must be confirmed by AICOE/Karri Holdings before this draft is approved for production publication.
It does not govern a third-party service you connect to Genesis or visit through a link. Those providers apply their own privacy terms. If your organization provides your Genesis account, it may control your workspace and the content processed there; contact that organization about its policies and your access rights.
Information we collect
Depending on how you use Genesis, we collect:
- Account information: name, email address, organization details, authentication events, legal-policy acceptance records, and account preferences.
- Customer Content: prompts, files, requirements, business information, generated deliverables, comments, approvals, and workflow history.
- Connector information: the services you connect, granted permissions, connection status, encrypted credentials or tokens where required, action requests, and approval records.
- Usage and device information: interactions with features, timestamps, browser and device details, IP address, diagnostic events, and security logs.
- Communications: support requests, feedback, contact-form submissions, and related correspondence.
- Billing information: plan, transaction, and invoice details. Payment processors may collect payment-card information directly under their own privacy terms.
Where information comes from
We receive information directly from you, from other members of your organization, automatically when you use the service, and from services you choose to connect. A connected service sends only the data allowed by its authorization flow and your selected permissions, but its available scopes may be broader than a single action. Review permissions before connecting and disconnect access you no longer need.
How we use information
- provide accounts, workspaces, AI workflows, document generation, software builds, connectors, and support;
- process the instructions and actions you request and preserve review, approval, and execution history;
- record the version and time of legal-policy acceptance;
- authenticate users, enforce permissions, prevent abuse, investigate incidents, and protect Genesis and its users;
- operate, troubleshoot, measure, and improve service reliability, usability, and quality;
- manage subscriptions, communicate service notices, and respond to questions; and
- comply with law, protect rights, and enforce our agreements.
Legal bases
Where data-protection law requires a legal basis, we process information to perform our contract with you, pursue legitimate interests such as service security and improvement, comply with legal obligations, and act on your consent where requested. You may withdraw consent for future processing, but withdrawal does not affect processing already completed or processing supported by another lawful basis.
AI systems and service providers
Genesis may send relevant Customer Content to AI model, hosting, storage, communications, authentication, build-environment, monitoring, and support providers so they can perform services for AICOE. We limit information to what is reasonably needed for the requested function and require providers to protect it through contractual or technical controls appropriate to their role.
When you bring your own provider account, API key, or connector, that provider may process data as an independent service under the settings, agreement, and retention choices for your account. Review those terms before enabling the connection. We do not sell personal information or use Customer Content for third-party advertising.
Sub-processors we use
The engineering inventory currently identifies:
- AI models: Xiaomi MiMo and OpenRouter, which may route to underlying model providers, generate documents, analysis, and software from prompts and context.
- Hosting and database: self-hosted Convex on AICOE infrastructure stores accounts, projects, and generated artifacts.
- Transactional email: Resend delivers sign-in links and service notifications.
- Build environments: E2B and CodeSandbox run and build generated software in isolated sandboxes.
- Avatars: DiceBear renders agent avatars from non-identifying seeds.
- Connectors you authorize: third-party services such as GitHub, Google, Slack, Notion, and X receive data only within the OAuth scopes you approve.
Legal and operations must verify this list, each provider’s legal entity, processing location, transfer mechanism and retention terms before approval.
When we disclose information
We may disclose information:
- to service providers that help operate Genesis under appropriate restrictions;
- within your organization according to workspace roles, sharing settings, and administrator controls;
- to third-party services when you connect them or approve an external action;
- when you intentionally publish or create a share link for content;
- to comply with lawful process or protect the rights, safety, and security of AICOE, users, or others; or
- as part of a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality safeguards.
Retention and deletion
We retain account information and Customer Content while needed to provide Genesis and for legitimate operational purposes such as security, dispute resolution, legal compliance, and enforcing agreements. Retention depends on the type of record, your plan and workspace settings, legal obligations, and whether the information remains necessary.
Disconnecting a tool stops new access by Genesis but may not delete information already imported into your workspace or retained by that third party. Deleted records may remain for a limited period in protected backups before routine deletion. We may retain de-identified or aggregated information that cannot reasonably identify you.
The production retention schedule—including exact periods for active accounts, deleted workspaces, authentication/audit records, support communications and backups—must be approved against actual deployed deletion and backup behaviour before this draft is approved.
Security
We use administrative, technical, and organizational measures designed to protect information, including access controls, session protections, encrypted transport, credential handling controls, audit records, and service monitoring where appropriate. No online service is completely secure. Protect your email account and credentials, grant connectors the narrowest practical permissions, and notify us at hello@aicoe.io if you suspect unauthorized access.
Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; and appeal a denied request. You may also manage workspace content, connector permissions, and communications through available product controls.
Send a request to hello@aicoe.io. We may need to verify your identity and authority before completing it. Authorized agents may submit requests where local law permits. You may also complain to your local data-protection authority.
International use and transfers
Genesis and its providers may process information in countries other than where you live. Where required, we use recognized transfer mechanisms or other safeguards intended to protect personal information across borders. Your organization is responsible for any additional residency or transfer requirements that apply to the content it chooses to process.
The applicable safeguards and data locations for every approved sub-processor must be confirmed before this draft is approved.
Children
Genesis is a business service and is not directed to children under 16. Do not submit a child’s personal information unless your organization has a lawful basis, appropriate safeguards, and any required parent or guardian authorization. Contact us if you believe a child has provided personal information without appropriate authorization.
Changes and contact
We may update this policy as Genesis, our providers, or applicable requirements change. We will revise the effective date and version above and provide additional notice when a change materially affects how we handle personal information.
Questions, privacy requests, or concerns may be sent to hello@aicoe.io. Please include enough detail for us to identify the relevant account and request without sending unnecessary sensitive information.
Questions about this policy?
Contact AICOE and include the name of this policy in your message.