Privacy Policy
Effective date: August 4, 2026 · Last updated: August 8, 2026
1. Who we are
GOVERNBOX.ai (“the Service,” “we,” “us”) is a product of Gradient Descent LLC (“Gradient Descent,” “the Company”), a privately held company that develops and operates software services. The Service helps organizations such as nonprofits, associations, public-sector bodies, and small and mid-size businesses build and maintain governance programs.
The Service is organized into five modules. Four are licensed individually or together — AI Governance, Enterprise Risk Management, IT Inventory & Management, and Data Management — and each collects a different category of information, described in Section 2. The fifth, Privacy, is included with the Professional and Agency plans rather than licensed separately, and collects no category of information beyond those described for the other modules.
This policy explains what personal information we collect through the Service, why we collect it, how it is used and shared, and the choices and rights available to you.
This policy applies to the Service itself. It does not apply to Gradient Descent LLC’s other activities, or to the separate federal service of Gradient Descent’s founder, which is entirely unrelated to the Service (see Section 14).
2. Our role: controller and processor
Our relationship to personal information differs depending on whose information it is:
- Where we act as a controller (we decide why and how information is used): account and identity information about the individuals who sign in to the Service; billing information; prospect and marketing information collected through our public website and free tools; and our own analytics and advertising data.
- Where we act as a processor (your organization decides why and how, and we act on its instructions): the governance content your organization enters into the Service, including information your organization records about its own personnel and other individuals. For example: staff members it enrolls in a policy attestation, individuals named as system owners, or individuals whose privacy requests it logs. Your organization is the controller of that information and is responsible for having a lawful basis to provide it to us.
3. Information we collect
3.1 Account and identity information. When you or your organization sign up, we collect information through our authentication provider (Clerk): name, email address, and organization/workspace membership. We store your access role and account status (active, invited, suspended) directly, along with the date of your most recent sign-in.
The roles available in the Service are “Admin, Editor, or Viewer.” In practice our identity provider currently offers two assignable organization roles, Administrator and Member, and a third internal value is not reachable. The organization’s Admin role has the ability to assign and remove CRUD capabilities from each member that they invite into the Service.
3.2 Organization profile information. During onboarding and in the Organization Profile settings, your organization provides: organization name, sector, size, data sensitivity level, risk appetite, fiscal year start, mission statement, selected compliance frameworks, an optional organization logo, and contact details for a primary business contact (name, title, business email address, business phone number, website).
3.3 Billing information. Subscription billing is operated by Clerk Billing, which settles payment through Stripe as its own downstream processor. We store your subscription tier, module entitlement, billing interval, plan identifier, and customer/subscription identifiers. We never receive or store payment card numbers. Those are handled entirely within the Clerk and Stripe environments under their own privacy policies.
3.4 Governance content your organization submits. The core of the Service is content your organization enters to generate governance artifacts. Depending on the modules licensed, this includes:
- AI Governance: AI use case inventory entries, risk register entries, impact assessment responses, AI project and AI agent inventory records, incident log entries, training plan records, policy documents and the inputs used to generate them, cost records, and Readiness Scorecard answers.
- Enterprise Risk Management: organization-wide risk register entries across risk categories, and key risk indicators including current values, thresholds, and review dates.
- IT Inventory & Management: device and hardware asset records, software subscription records (including seat counts, costs, and renewal dates), system records (including hosting, backup posture, single sign-on and multi-factor authentication status, and data classification), and access records.
- Data Management: data inventory entries, data flow records (including cross-border transfer indicators and processors), retention schedules, and individual rights request (DSAR) records.
3.5 Information your organization records about individuals. Several features are specifically designed to record information about people, most of whom are not users of the Service. Your organization is the controller of this information. Specifically:
- Attestation roster. To run a policy attestation campaign, your organization uploads a roster of staff consisting of name, business email address, and department by typing them into a text field or importing a spreadsheet. Roster members do not have accounts and do not sign in; they receive a unique one-time link by email.
- Attestation signatures. When a person completes an attestation, we record the name they type as their signature and the date and time. This record is intentionally permanent and cannot be edited or re-signed, because its purpose is to serve as evidence. The signer’s email address is also written to your organization’s audit log (see Section 3.9).
- Training completion. Completion of a training item can be recorded against each person on that same roster. Training records may also contain a free-text trainee name.
- IT access records. The IT module records a person’s name, business email address, which systems they can access, their access level, and whether and when they were offboarded.
- Individual rights requests. The Data Management module records the name and email address of the person making a privacy request to your organization, the type of request, the applicable legal regime, deadlines, and free-text notes and resolution details about that person’s request.
- Named individuals throughout. Many records include a free-text field naming a responsible person — for example a use case owner, risk owner, task assignee, data steward, system administrator, or the name and title of the person approving a policy document.
- External document reviewers. If your organization shares a document for review using a share link, anyone holding that link can submit a comment along with their name and email address, without signing in.
3.6 Prospect and marketing information. We collect information from visitors to our public website who are not customers:
- Readiness Scorecards (AI, Risk, IT, and Data): your answers, resulting score, and — to see your full results — your business email address, and optionally your name.
- Gated content: your business email address, and optionally name and organization, to download our executive briefing.
- Module waitlists and Regulatory Watch digest signups: business email address, optionally first name and organization, your topic and jurisdiction interests, and whether you affirmatively consented to marketing email.
- Contact and demonstration requests: name, business email address, organization, industry, and the content of your message. Some of our contact forms are hosted by our CRM provider and submit directly to that provider rather than to us.
We require a business email address for these forms and reject addresses from disposable/temporary email services. Rejected submissions are discarded and no record is retained.
3.7 Usage and product analytics. We use PostHog to record product usage events — for example which features are used, and when a document is generated and exported. When you are signed in, these events are associated with your user identifier, email address, and name, so that we can understand how individual accounts adopt the product. These events do not include the substantive content of the governance documents or records you create.
Session recordings. On our public website — our marketing pages and the free Readiness Scorecards — we also record a visual replay of the browsing session (page views, mouse movement, clicks, scrolling, and navigation) through the same product analytics provider. We do not record sessions anywhere inside the signed-in Service, so pages showing your organization’s governance records are never captured. On the public pages where recording does occur, all page text and every form field value are masked in your browser before anything is transmitted, so the characters you type are not captured in the recording; information you deliberately submit through a form is handled as described in Section 3.6. Recordings are retained for 30 days and then deleted. You can prevent recording entirely by opting out of analytics in the banner shown on our website; opting out also stops any recording already in progress.
3.8 Advertising, attribution, and cookies. Our public website loads third-party tags for advertising measurement and analytics, including Google Tag Manager (which in turn may load Google Analytics, the Meta pixel, and the LinkedIn Insight Tag) and a Google Ads conversion tag. We also store, in your browser’s local storage, the marketing campaign parameters and advertising click identifiers (including Google, Meta, and LinkedIn click identifiers), the page you first landed on, and the referring website. These are recorded on your first visit and retained until you clear your browser storage.
When an account is created, we send a conversion event to Google Ads that includes the account holder’s email address (Google’s “enhanced conversions” feature) together with a plan identifier and value. Campaign and click identifiers are also transmitted to our CRM alongside a submitted lead.
Website visitor identification. Our public website also loads a website-visitor tracking tag from Apollo.io. This tag does something different from the advertising tags described above, and we want to be direct about it: rather than counting an anonymous visit, it attempts to work out who is visiting. It sends your IP address and the pages you view to that provider, which matches them against its own third-party business datasets to identify the organization you are browsing from and, where its data allows, an individual and their business contact details — even if you have never contacted us, filled in a form, or clicked one of our emails. Any identification it returns is used for one purpose: so that our sales team can follow up with organizations that have shown interest in the Service.
Three limits apply to this tag, and they are enforced in our code rather than left to configuration:
- Public pages only. It runs on our marketing pages and free tools. It does not run anywhere inside the signed-in Service, so it is never active on a page showing your organization’s governance records.
- Never on pages your organization shares with its own people. It is disabled on attestation links, shared-document links, and Trust Pages. Someone signing an attestation for their employer, or an auditor reading a document you shared, is that organization’s audience — not a prospect of ours — and we do not attempt to identify them.
- It respects the opt-out. If you opt out of analytics using the banner on our website, this tag does not load. Because a script already running in the page you are currently viewing cannot be recalled, an opt-out takes full effect from your next page view onward.
Under some U.S. state privacy laws, including California’s, this kind of identification may be treated as “sharing” or a “sale” of personal information even though no money changes hands. The banner opt-out described above is how you exercise that right on our website; Section 10 describes your rights more fully, and Section 17 tells you how to reach us if you would rather we deleted any identification already recorded about you.
3.9 Audit log. Every create, edit, export, approval, and role-change action within your organization is recorded in an append-only audit log (actor, action, entity type, entity identifier, timestamp, and a short description). Through the Service, these entries cannot be modified or deleted by your organization or by us; the database enforces this directly. The log exists to give your organization a reliable accountability record. Note that audit entries can contain an email address — for example, the email of a person who completed an attestation, or of a person who was invited to the account.
3.10 Communications. If you contact us for support, book an advisory session, request a demonstration, or subscribe to a newsletter, we collect the information you provide in that communication.
3.11 Information we do not collect. We do not store IP addresses or device fingerprints. Within the Service, an IP address is used transiently, in memory only, to rate-limit public endpoints, and is never written to our storage. Our product analytics provider discards the IP address of website and product usage events rather than storing it; before discarding it, that provider derives and retains an approximate location — country, region, city, and time zone — which we use to understand where interest in the Service comes from. Third-party advertising and analytics tags loaded on our public website receive your IP address directly, as described in Section 3.8. One of them — the visitor-identification tag described in that section — receives it specifically in order to identify you, which is a different matter from the transient, in-memory use described above; that provider, not us, performs and stores that identification. We do not store payment card numbers. We do not have a phone number field on customer records other than the single business contact number in the organization profile and, where provided, on a demonstration request.
4. How we use information
- Provide, operate, and maintain the Service, including authenticating users and enforcing access controls
- Generate governance documents by retrieving entries from our control library and using an AI model to tailor and phrase that language to your organization’s context (Section 5)
- Evaluate generated documents against regulatory requirements and surface coverage gaps and regulatory changes affecting your documents
- Process payments and manage subscriptions and module entitlements
- Deliver policy attestation invitations to the roster your organization provides, and record completion
- Provide customer support and respond to inquiries
- Monitor for and prevent fraud, abuse, and security incidents
- Improve and develop the Service, using aggregated or de-identified data wherever possible
- Send administrative communications (billing notices, security alerts, service updates) and, where you have opted in, marketing communications
- Measure the effectiveness of our advertising, attribute signups to marketing campaigns, and manage our sales pipeline
- Comply with legal obligations and enforce our Terms of Service
5. How AI processing works
Generating a governance document involves sending relevant portions of your organization’s profile and inputs to a third-party large language model (currently Anthropic’s Claude) and to a third-party embedding provider used for semantic search across our control library. This is necessary to tailor plain-language document text to your organization.
Three commitments govern this process:
- Grounded generation only. The model retrieves and rephrases controls from our proprietary, human-authored control library. It does not invent new compliance controls, and every generated clause is required to cite a specific control from the library. Where retrieval finds nothing relevant, the Service is designed to say so rather than fabricate language.
- No training on your content. Your content is not used to train or fine-tune any AI model — ours or any third party’s. It is submitted to the AI provider solely to generate your requested output.
- Separation of generation from verification. Documents are drafted only from our control library. A separate, independent process compares the draft against the text of official regulations and standards to flag possible gaps. Official regulatory text is never used as source material for drafting.
Generated documents are always presented for human review before they are finalized or exported. The Service does not represent AI-generated output as legal or compliance advice.
6. How we share information
We do not sell your organization’s governance content, and we do not sell personal information in exchange for money. Note that “sale” and “sharing” are defined broadly under some U.S. state privacy laws and can cover exchanges where no money changes hands — see Section 6.9, which describes the one activity on our public website that may fall within those definitions. We share information as follows:
6.1 Service providers. We use a limited number of third-party providers to operate the Service. Each is contractually and technically limited to using information only as necessary to perform its function for us. As of this revision they perform the following functions: identity and authentication; subscription billing and payment settlement; application and database hosting; AI document generation; semantic search embeddings; transactional email delivery; product analytics; error monitoring; customer relationship management; interactive product demonstrations; advertising measurement; and website visitor identification and sales outreach.
6.2 Advertising and analytics providers. As described in Section 3.8, information including an email address, campaign identifiers, and advertising click identifiers is transmitted to advertising and analytics providers. See Section 10 for the choices available to you.
6.3 Sales and customer relationship management. Information you submit through our public forms and the business contact details in a customer’s organization profile is synchronized to our CRM so we can respond and manage the customer relationship. This includes name, business email address, business phone number where provided, job title, organization details, and the marketing campaign that led to the inquiry.
6.4 Attestation delivery. When your organization launches an attestation campaign, we transmit each roster member’s name and email address to our transactional email provider in order to deliver their individual attestation link.
6.5 Advisory hand-off. If you click a “talk to an expert” call-to-action, a summary of your organization’s profile and identified gaps is sent to our sales pipeline so a member of our team can follow up with product support and guidance. This only happens when you initiate it.
6.6 Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or where we believe in good faith it is necessary to protect the rights, property, or safety of Gradient Descent, our users, or the public.
6.7 Business transfers. If Gradient Descent is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy of which you will be notified.
6.8 Platform administration. A small number of authorized Gradient Descent staff have cross-tenant administrative access for support and platform-maintenance purposes. Every platform-administrator action is written to your organization’s audit log so it is visible to you.
6.9 Website visitor identification. As described in Section 3.8, when you browse our public website your IP address and the pages you view are transmitted to our visitor-identification provider, which returns the organization and, where its data allows, the individual it believes is behind the visit. We receive and retain that identification in our sales tooling in order to follow up. This applies to our public marketing pages only, never to the signed-in Service, and never to attestation links, shared documents, or Trust Pages. Depending on your state, this may be “sharing” or a “sale” of personal information; you can stop it using the opt-out on our website, and Section 10 sets out your rights.
7. Information you publish yourself
Two features publish information at your organization’s election:
- Trust Page and badge. If your organization publishes a Trust Page, a public web page becomes available at an unlisted address showing your organization’s name and sector, governance maturity scores, the framework names you have selected, counts of approved documents and inventory records, the generic types of documents you have approved (never their titles or contents), the date of your most recent approval, and your attestation completion rate and the campaign name you chose. No individual’s name and no document content is published. You can unpublish at any time, and the page automatically stops presenting your organization as current if your subscription lapses.
- Document share links. If you share a document for external review, anyone holding the link can read the full document and submit a comment with their name and email address. Treat these links as sensitive.
8. Multi-tenancy and data isolation
Your organization’s data is logically isolated from every other organization’s data using per-tenant access controls enforced both in application code and at the database level, through a database account that has no ability to bypass those controls. The isolation fails closed: a request without a valid organization context returns no records rather than another organization’s records. No organization can query or view another organization’s records through the Service. Authorized platform administrators are the documented exception described in Section 6.8.
9. Data retention and deletion
We retain information for as long as your account is active or as needed to provide the Service. We want to be precise about what deletion currently means:
- Deleting a record in the Service marks it inactive and removes it from the application. Most records are not immediately erased from the underlying database.
- Closing an organization account marks the organization inactive and ends access. It does not, by itself, erase the organization’s underlying records.
- We do not currently operate an automated retention schedule or purge process. Complete erasure of a specific record or of an organization’s data is performed manually on request.
- Audit log entries are retained permanently and are not deleted when the underlying record is deleted, because the log is designed as an append-only accountability record.
- Attestation records are retained permanently as evidence, including the signer’s typed name and the timestamp.
- Backups. Residual copies persist in encrypted backups and transaction archives after deletion from active systems, and are removed on our hosting provider’s backup retention cycle.
You can export your organization’s data at any time through the Admin Console, and account Owners can initiate deletion of organizational data through the Admin Console. To request complete erasure, contact us using Section 17 and we will process it manually.
10. Your rights and choices
All users. You may access, correct, or request deletion of your account information by contacting us or, where available, directly within the Service. You may opt out of marketing email at any time using the unsubscribe link; you will still receive administrative and billing communications necessary to the Service.
Individuals whose information was entered by an organization. If your employer or another organization has recorded information about you in the Service — for example on an attestation roster, in an access record, or in a privacy request log — that organization, not Gradient Descent, controls that information. Please direct access, correction, and deletion requests to that organization. If you contact us directly, we will refer you to them and will assist them in responding.
European Economic Area, UK, and Switzerland (GDPR). You have the right to access, rectify, erase, or port your personal data, to restrict or object to certain processing, and to lodge a complaint with your local supervisory authority. Our lawful bases include performance of a contract (providing the Service), legitimate interests (securing and improving the Service, and direct marketing to business contacts), and consent (marketing communications).
California and other U.S. state privacy laws. California residents have the right to know what personal information we collect and how it is used, to request deletion, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the sale or sharing of personal information. We will not discriminate against you for exercising these rights.
To exercise any of these rights, contact us at the address in Section 17. We may need to verify your identity before fulfilling a request.
11. Sensitive data and regulated industries
The Service supports optional frameworks relevant to regulated data — including HIPAA, GDPR, and CCPA — to help you draft governance documentation that references those frameworks. Supporting a framework in generated documents does not mean the Service’s own infrastructure carries a corresponding certification. If your use involves protected health information, government records subject to special handling, or other regulated personal data, contact us before submitting that data so we can discuss whether appropriate contractual protections are in place.
We ask that you not enter sensitive personal data about identifiable individuals into free-text fields. Note the tension this creates with the Data Management module: a privacy request record inherently identifies the requester. Where you use that feature, record only what you need.
12. Security
We apply administrative and technical safeguards designed to protect information, including:
- Encryption of data in transit between your browser and the Service
- Encryption at rest, as provided by our hosting provider’s managed database platform
- Per-tenant data isolation enforced at the database level through a least-privileged database account that cannot bypass it, verified to fail closed
- Role-based access to administrative functions
- An append-only audit log that cannot be altered through the application, enforced by the database itself
- Multi-factor authentication, enforced by our identity provider
- Optional enterprise single sign-on (SAML/OIDC) for organizations on our Agency plan
- Error monitoring configured to exclude personally identifiable information; our backend explicitly disables the collection of such data in error reports
- Responses from our application programming interface are marked as non-cacheable so that one organization’s data cannot be served from a shared cache to another
- Automated daily backups with continuous transaction-log archiving
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. International data transfers
Our infrastructure and service providers process data in the United States. Where we transfer personal data out of the European Economic Area, UK, or Switzerland, we intend to rely on appropriate safeguards such as Standard Contractual Clauses.
14. Independence from federal service
GOVERNBOX.ai is a product of Gradient Descent LLC, a privately held company that develops and operates software services. The Service is not sponsored, endorsed, funded, or supported in any manner by the United States Government or by any federal agency, and no such endorsement is stated or implied.
Gradient Descent LLC’s founder, Jim Tunnessen, serves separately as a federal Senior Executive. That service is entirely unrelated to this Service and to Gradient Descent LLC. All work on the Service is performed on personal time and in a personal capacity, and is connected to Gradient Descent LLC and not to any federal position or official duties. No federal government data, systems, facilities, funding, personnel, or official-duty information is used in, or informs, the Service. Any views expressed in or through the Service are those of Gradient Descent LLC and not of the United States Government or any federal agency.
Organizations using the Service are commercial customers of Gradient Descent LLC, governed solely by this policy and your service agreement with Gradient Descent LLC.
15. Children’s privacy
The Service is intended for business use by organizational personnel and is not directed to children. We do not knowingly collect personal information from individuals under 16.
16. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify account Owners by email or through an in-app notice before the changes take effect. The “Last updated” date at the top reflects the most recent revision.
17. Contact us
Gradient Descent LLC
Email: info@gradientdescent.biz
Web: gradientdescent.biz
For access, correction, or deletion requests, email info@gradientdescent.biz with the subject line “Privacy Request,” or use our Contact page.