Data Usage Policy
Effective date: July 3, 2026 · Last updated: July 3, 2026
1. Why this document exists
AI Governance in a Box asks organizations to describe their AI tools, risks, and practices in order to generate governance documentation. That’s sensitive business information, and we think you’re owed a plain-language explanation of exactly what happens to it — separate from the more general legal language in our Privacy Policy.
2. What you put into the Service
Depending on which modules you use, your organization may enter:
- Organization profile details (sector, size, risk appetite, data sensitivity level, selected compliance frameworks)
- An inventory of AI tools and use cases in production or under evaluation
- Risk register entries and risk-treatment plans
- Impact assessment questionnaire responses
- AI project and AI agent registrations
- Incident reports
- Training plan records
- Answers to the free Readiness Scorecard
- The organizational context you provide when generating a document (e.g., through a wizard) — sector, size, priorities, and similar descriptive answers
We ask that this content describe your organization’s AI governance posture — not that it contain sensitive personal data about identifiable third parties (customers, patients, employees’ health information, etc.). See Section 8.
3. How your data is used to generate documents
When you generate a document, the Service does the following, in order:
- Your organization’s profile and the specific inputs you provide (e.g., through a document wizard) are converted into a search query.
- That query is matched, using vector similarity search, against Gradient Descent’s proprietary control library — a set of human-authored governance controls mapped to frameworks like NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
- The matched controls, along with your organizational context, are sent to a third-party AI model (currently Anthropic’s Claude) with strict instructions: tailor the retrieved control language to this organization; do not introduce any control that isn’t in the retrieved set; cite the source control for every clause produced.
- The resulting document sections are saved to your organization’s isolated records, each one tagged with the control(s) it was grounded in.
- You are prompted to review the document before approving, finalizing, or exporting it.
What this means in practice: the Service does not let an AI model freely improvise your governance policy. Every clause traces back to a specific, versioned control that Gradient Descent’s founder authored and reviewed. If the retrieval process doesn’t find a relevant control, the Service is designed to say so rather than invent language to fill the gap.
4. What we do not do with your data
- We do not use your content to train or fine-tune any AI model — not Anthropic’s, not an embedding model, not any model of our own. Your submissions are used only to produce the specific output you requested.
- We do not let one organization’s data reach another organization. Every tenant table in our database is isolated by organization ID, enforced both in our application code and as a database-level access policy. This isn’t a configuration toggle that could be silently misconfigured for one customer — it fails closed: if the isolation context is ever missing, the query gets zero rows back rather than another tenant’s rows.
- We do not sell your data, to data brokers, advertisers, or anyone else.
- We do not log your governance content to our error-monitoring tooling. Our monitoring is configured to capture technical error details (e.g., which endpoint failed) without capturing the substance of what you submitted.
- Gradient Descent staff do not casually browse customer data. A small number of authorized staff have cross-tenant administrative access strictly for support and platform-maintenance purposes, and every such action is written to your organization’s own audit log, which you can review.
5. Where your data physically goes
At a high level, a piece of governance content you submit flows like this:
Your browser → our application servers → our tenant-isolated database, and — only for the specific action of generating or searching a document — outward to our AI provider and embedding provider for that one operation, with the result written back into your isolated database record.
Billing details go to our payment processor. Authentication details go to our identity provider. Product-usage events (not document content) go to our analytics provider. Technical error signals (scrubbed of tenant content) go to our error-monitoring provider. We use a limited, contractually bound set of service providers to operate the Service — see our Privacy Policy for how information is shared with them.
6. Your control over your data
- Export. Organization Owners and Admins can export their organization’s data as a structured file at any time through the Admin Console’s Data Controls tab.
- Deletion. Organization Owners can soft-delete all organizational data through the Admin Console’s Danger Zone (a typed confirmation is required to prevent accidental deletion).
- Audit trail. Every create, edit, export, and role change is recorded in an append-only log that you — not just us — can view, so you always have a record of who did what and when inside your own organization.
- Framework selection. You choose which compliance frameworks apply to your organization at any time, and that selection determines what’s retrieved and generated for you going forward.
7. Analytics, separate from your governance content
We track product usage events — which features get used, whether a document was generated and successfully exported — to understand adoption and improve the product. This is operational telemetry about how the product is used, not the substantive content of what you entered. It is not used to generate your documents and is handled separately from your tenant-isolated governance records.
8. A note on sensitive personal data
Please avoid entering sensitive personal data about identifiable individuals (health records, government identifiers, financial account numbers, biometric data, etc.) into free-text fields, unless you have a specific written agreement with us covering that category of data (for example, a Business Associate Agreement for protected health information). The frameworks the Service can reference — including HIPAA, GDPR, and CCPA — describe governance obligations your organization may have; supporting those frameworks in generated language is not the same as our infrastructure carrying a corresponding certification. If this applies to your organization, contact us before submitting that data so we can discuss what’s needed.
9. Not legal or compliance advice
Documents generated by the Service are drafting aids grounded in a control library, not a substitute for legal review. Every document requires human review before your organization relies on, approves, or publishes it. Gradient Descent LLC is not a law firm, and using the Service does not create an attorney-client relationship.
10. Questions
If you have questions about how your data is used — before or after you sign up — use our Contact page or email info@gradientdescent.biz with the subject line “Data Usage Question.” We’re glad to walk through this in more detail, including for procurement or security-review purposes.