Plain language, no fine print. A version of this charter is attached to every client agreement, and we hold ourselves to every line of it.
Leads, contacts, deals, messages your team sends or forwards, reminders, and files you attach. Nothing is captured from sources you haven't connected.
In a database that holds only your business's data, on infrastructure operated by us, in-region where available. Your data is never mixed with another client's — isolation is how the system is built, not a policy promise.
Yours. Every lead, contact, deal and message is your property. Export everything, any time, in open formats (CSV/JSON). On ending the service, we export your data to you and then delete it on a fixed schedule you can see.
Named operators access your data only to run, support and configure your service — and that access is logged. Your data is never sold, never shared, never used to market to your contacts, and never used to train AI models.
AI here is layered, and each layer sees only what it needs. Much of the product runs on deterministic code with no model at all. When raw content — messages, forwarded emails, photos, PDFs, voice notes — needs to be read by a model, that happens within our infrastructure tenant on Cloudflare, the same named subprocessor that runs the rest of the product; it is never routed to any additional AI provider. Cloudflare commits in writing that this content is not used to train models and is never shared. When the system researches a contact's public profile, the application payload is restricted to six named fields — name, firm, role, email, email domain and location — an allowlist enforced in code, so phone numbers, message content, prices and deal terms are never part of any outbound payload.
How deep the AI goes on each surface is a configuration you choose — in-account by default, external or self-hosted lanes only as explicit choices, your own AI keys welcome — with the cost shown before you say yes. And AI only ever proposes, and proposals can be wrong: a human on your team confirms every write — a review step, not a guarantee — which is why every AI-originated write is attributed, evidenced, and undoable. Model calls are logged as metadata only; prompts and outputs are not written to logs.
The software, prompts, workflows and configurations — including ones built specifically for you — are our licensed product. You license its use; ownership stays with us. That's the other half of the symmetry above, and it's what lets us keep every client's machinery sharp.
Raw message logs are kept for a fixed window (default 90 days, configurable). CRM records stay for as long as you keep them. Deletion requests are honoured within 7 days.
Our compute, database and edge providers, your chosen AI provider, and the chat platforms you use. The full subprocessor list is maintained per client and shared whenever it changes. Formal privacy documentation aligned to India's DPDP Act — and UK GDPR for UK engagements — is available on request.
Any security incident affecting your data: we tell you within 48 hours — what happened, what it touched, what we're doing about it. Nothing is swallowed silently; that is an engineering rule here, not a slogan.
Proof over promises, even here: this website loads no third-party scripts, sets no cookies, and runs no trackers — the fonts are served from our own infrastructure. Questions about the charter: nav@goxero.co.