Security and privacy

Data handling

Encryption, tenant isolation, retention windows, and the commitment that your data never trains a model.

The authoritative versions

This page is the practical summary. The binding documents are the Privacy Policy, the DPA, and the sub-processor list.

Your data never trains models

Your messages, files and connected data are never used to train models, ours or anyone else's.

That's contractual, not a setting you have to find and switch off. It holds for every plan, including Free.

Encryption

TLS 1.3 in transit. AES-256 at rest.

Integration credentials are held separately from everything else, in a vault with per-tenant keys. A run gets the ability to call a tool; it never receives the token itself.

Isolation

Each workspace runs in its own isolated environment. Nothing (memory, files, learnt formats, wiki pages) crosses between customers.

Within your workspace, the wiki and skills are shared with your team by design. Your individual tool connections are not.

What's stored, and for how long

Default retention
Message content Gini wasn't asked to keepNot stored
Run records: steps, tools called, approvals90 days
Wiki pages and skillsUntil you delete them
Files Gini producedWith the run record, and in Slack under your own retention
Integration credentialsUntil you disconnect

Enterprise plans can set custom retention windows.

The first row is the one people ask about. Gini reads a channel to do the work and to learn what's durable from it. The raw messages aren't retained on our side: what persists is what it learnt, and that's readable and deletable at app.ginicomputer.com → Wiki.

Deletion

Deletion requests complete within 30 days. See Deleting your data for how to make one and what it covers.

Sub-processors

Gini runs on infrastructure and model providers we don't own, and they're listed publicly at trust.ginicomputer.com/subprocessors. The list includes what each one handles.

If you need notice of changes to that list, that's part of the DPA. Talk to us.

Compliance

SOC 2 Type II is in progress. We say that rather than displaying a badge wall, because the difference between "pursuing" and "holds" is exactly what your reviewer needs to know.

Current status is on the security page. For a questionnaire or a security packet, security@ginicomputer.com.

GDPR and data subject requests

Access, correction and deletion requests go to privacy@ginicomputer.com.

A DPA is available on Enterprise. If you need one to get through procurement, ask early: it's usually the long pole.

What you control

  • Which channels Gini can read. See Channels and access.
  • What it writes down. See How pages get written.
  • Which tools it can reach. Per person, and revocable in one click.
  • What it keeps. Every wiki page and skill is deletable.
  • Whether it's there at all. See Removing Gini.