Privacy Policy
Effective date: July 3, 2026 · Last updated: July 12, 2026
1. Who we are
AI Governance in a Box (“the Service,” “we,” “us”) is a product of Gradient Descent LLC, an AI/ML consulting firm (“Gradient Descent,” “the Company”). The Service helps organizations — nonprofits, associations, public-sector bodies, and small and mid-size businesses — produce AI governance documentation such as AI use policies, acceptable-use standards, risk registers, and compliance crosswalks.
This policy explains what personal information we collect through the Service, why we collect it, how it is used and shared, and the choices and rights available to you.
This policy applies to the Service itself. It does not apply to Gradient Descent LLC’s separate consulting engagements, which are governed by individual client agreements, or to Jim Tunnessen’s official duties as a federal employee, which are entirely separate from and unaffiliated with this Service (see Section 12).
2. Information we collect
2.1 Account and identity information. When you or your organization sign up, we collect information through our authentication provider (Clerk): name, email address, and organization/workspace membership. We store your role (Owner, Admin, Editor, or Viewer) and account status (active, invited, suspended) directly.
2.2 Organization profile information. During onboarding and in the Admin Console, your organization provides: organization name, sector, size, data sensitivity level, risk appetite, fiscal year start, selected compliance frameworks, and optional contact details (contact name, title, website) captured during setup.
2.3 Billing information. Subscription payments are processed by Stripe. We store your subscription tier, billing interval, and Stripe customer/subscription identifiers. We do not store full payment card numbers — those are handled entirely by Stripe under its own privacy policy.
2.4 Governance content you submit. The core of the Service is content your organization enters to generate governance artifacts, including AI use case inventory entries, risk register entries, impact assessment answers, AI project and agent inventory records, incident log entries, training plan records, generated policy documents and their inputs, and free Readiness Scorecard answers.
We ask that you and your users not enter sensitive personal data about third parties (e.g., customer Social Security numbers, patient health records, or other regulated personal data) into free-text fields unless you have a signed data processing agreement with us covering that data category. See Section 9.
2.5 Usage and analytics data. We use PostHog to record product usage events (e.g., which features are used, when a document is generated and exported) to understand engagement and improve the Service. This is aggregate product-usage telemetry — it does not include the substantive content of the governance documents or records you create.
2.6 Audit log. Every create, edit, export, and role-change action within your organization is recorded in an append-only audit log (actor, action, entity type, entity ID, and timestamp). This log cannot be altered or deleted, including by us, and exists to give you a reliable record for your own audit and compliance purposes.
2.7 Communications. If you contact us for support, book an advisory session, or subscribe to our newsletter, we collect the information you provide in that communication (e.g., name, email, message content).
3. How we use information
We use the information described above to:
- Provide, operate, and maintain the Service, including authenticating users and enforcing role-based access
- Generate governance documents by retrieving relevant entries from our proprietary control library and using an AI model to tailor and phrase that language to your organization’s context (see Section 4)
- Process payments and manage subscriptions
- Provide customer support and respond to inquiries
- Monitor for and prevent fraud, abuse, and security incidents
- Improve and develop the Service, using aggregated or de-identified usage data wherever possible
- Send administrative communications (billing notices, security alerts, service updates) and, where you have opted in, marketing communications
- Comply with legal obligations and enforce our terms of service
4. How AI processing works
Generating a governance document involves sending relevant portions of your organization’s profile and use-case information to a third-party large language model (currently Anthropic’s Claude) and to an embedding provider used for semantic search over our control library. This is necessary to tailor plain-language document text to your organization.
Two commitments govern this process:
- Grounded generation only. The model retrieves and rephrases controls from our proprietary, human-authored control library. It does not invent new compliance controls, and every generated clause is required to cite a specific control from the library.
- No training on your content. Your governance content is not used to train or fine-tune any AI model — ours or any third party’s. It is submitted to the AI provider solely to generate your requested output and is not retained by us for model-improvement purposes.
Generated documents are always presented for your human review before they are finalized or exported — the Service does not represent AI-generated output as legal or compliance advice, and a qualified person at your organization should review any document before adopting or relying on it.
5. How we share information
We do not sell your personal information or your organization’s governance content. We share information only as follows:
Service providers. We use a limited number of third-party service providers to operate the Service — for example, to handle authentication, payment processing, application hosting, AI-powered document generation, and product analytics. Each is contractually and technically limited to using your information only as necessary to perform its function for us, and none is permitted to use it for its own independent purposes.
Advisory hand-off. If you click an “advisory” or “get help” call-to-action, a summary of your organization’s profile and identified gaps is sent to Gradient Descent’s sales pipeline so a member of our team can follow up about a consulting engagement. This only happens when you initiate it.
Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or where we believe in good faith it is necessary to protect the rights, property, or safety of Gradient Descent, our users, or the public.
Business transfers. If Gradient Descent is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy of which you’ll be notified.
Platform administration. A small number of authorized Gradient Descent staff have cross-tenant administrative access for support and platform-maintenance purposes. Every platform-admin action is written to your organization’s audit log so it is fully visible to you.
6. Multi-tenancy and data isolation
Your organization’s data is logically isolated from every other organization’s data using per-tenant access controls enforced both in application code and at the database level (row-level security keyed to your organization ID). No organization can query or view another organization’s records through the Service.
7. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. If you delete a record or your organization deletes its account, that data is marked for deletion and removed from active systems; residual copies may persist for a limited period in backups before being purged.
Audit log entries are retained even after the underlying record is deleted, because the log is designed to be an append-only accountability record; audit entries reference actions and metadata, not necessarily the full deleted content.
You can request export of your organization’s data at any time through the Admin Console’s Data Controls, and account Owners can initiate deletion of all organizational data through the Admin Console’s Danger Zone.
8. Your rights and choices
All users. You may access, correct, or request deletion of your account information by contacting us or, where available, directly within the Admin Console. You may opt out of marketing email at any time using the unsubscribe link in those emails; you will still receive administrative and billing communications necessary to the Service.
European Economic Area, UK, and Switzerland (GDPR). If you are located in these regions, you have the right to access, rectify, erase, or port your personal data, to restrict or object to certain processing, and to lodge a complaint with your local data protection authority. Our lawful bases for processing include performance of a contract (providing the Service), legitimate interests (improving and securing the Service), and consent (marketing communications).
California (CCPA/CPRA). California residents have the right to know what personal information we collect and how it’s used, to request deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information as those terms are defined by California law. We will not discriminate against you for exercising these rights.
To exercise any of these rights, contact us at the address in Section 15. We may need to verify your identity before fulfilling a request.
9. Sensitive data and regulated industries
The Service supports optional frameworks relevant to regulated data — including HIPAA, GDPR, and CCPA — to help you draft governance documentation that references those frameworks. Supporting these frameworks in generated documents does not mean the Service’s own infrastructure carries a specific certification (e.g., a signed Business Associate Agreement, SOC 2 report, or FedRAMP authorization) unless separately stated in your contract with us. If your use case involves protected health information, government records subject to special handling, or other regulated personal data, please contact us before submitting that data so we can discuss whether appropriate contractual protections are in place.
10. Security
We apply administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, role-based access control, per-tenant data isolation, and an append-only audit log that cannot be altered — including by us — through the application. Error monitoring is configured to exclude tenant content and secrets from logs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. International data transfers
Our service providers may process data in the United States and other countries. Where we transfer personal data out of the European Economic Area, UK, or Switzerland, we intend to rely on appropriate safeguards such as Standard Contractual Clauses.
12. A note on federal employment and conflicts of interest
Gradient Descent LLC and this Service are operated entirely independently of any federal government role held by Gradient Descent’s founder. No federal government data, systems, or official-duty information is used in, or informs, this Service. Organizations using this Service are Gradient Descent’s commercial customers, governed solely by this policy and your service agreement with Gradient Descent LLC.
13. Children’s privacy
The Service is intended for business use by organizational personnel and is not directed to children. We do not knowingly collect personal information from individuals under 16.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify account Owners by email or through an in-app notice before the changes take effect. The “Last updated” date at the top of this policy reflects the most recent revision.
15. Contact us
Gradient Descent LLC
Email: info@gradientdescent.biz
Web: gradientdescent.biz
For data subject access, correction, or deletion requests, please email info@gradientdescent.biz with the subject line “Privacy Request,” or use our Contact page.