Privacy Policy

Your data belongs to you. Full stop.

GeneWorks is built on a simple premise: we read your ServiceNow instance to do work on your behalf. We do not copy, harvest, profile, or monetise your instance data — and every scan is read-only.

1 July 2026
Effective Date
23 July 2026
Last Updated
2.0
Version
01 — Scope

Scope of This Policy

This Privacy Policy describes how GeneWorks ("we", "us", "the Company") handles information when you use the GeneWorks platform ("the Service") — the website, the application workspace, and the AI agents that scan, build, test, and remediate on your ServiceNow instance.

GeneWorks is designed as a credential-local, read-first platform. The guiding principle throughout this policy is simple:

// The one rule that shapes everything below Your ServiceNow instance data stays in your environment. GeneWorks reads it to produce maps, scores, findings, and changes — and holds no copy of it on GeneWorks servers.
02 — What We Collect

Information We Collect

We collect the minimum information required to operate the Service.

CategoryWhat it isWhy
Account informationName, work email, organisation.To create and manage your account.
Workspace configurationInstance URL you connect, app and workspace settings, preferences.To run the apps against your instance.
Scan summaries & metricsCounts, scores, health metrics, findings, dependency maps.To render Command Center, assessments, and reports. These describe the shape of your instance — not a copy of your records.
Usage & support dataBasic product-usage events; anything you send us for support or billing.To operate, support, and improve the Service.
03 — What We Don't Collect

What We Explicitly Do Not Collect

We deliberately do not collect or retain the following:

  • Your ServiceNow credentials — stored only in your browser; never transmitted to or stored on GeneWorks servers.
  • A copy of your ServiceNow records — GeneWorks maintains no database of your incidents, users, CIs, catalog items, or any instance records. Scans read them in place and return summaries.
  • Training data from your instance — no instance data ever trains a model. Your data is used to do your work, not to improve a general model.
  • Behavioural profiles — we do not build profiles or sell any data to third parties.
The difference between a summary and a copy. "CMDB completeness is 26%, with 1,767 stale CIs" is a summary. The 1,767 CI records themselves never leave your instance.
04 — Credentials & Access

ServiceNow Credentials & Instance Access

Your credentials are stored in your browser and used only to construct direct, authenticated API calls from your browser to your instance over HTTPS (TLS 1.2/1.3). They never pass through GeneWorks infrastructure.

Every app scans read-only. The Service writes to your instance only when you explicitly approve a change through the human-gated delivery loop. You can remove your credentials and disconnect an instance at any time — an immediate, permanent operation.

Least privilege. We recommend a dedicated service account with read-only roles for assessment work, and write roles granted only when you move to remediation.
05 — Scans & Knowledge

Scans, Uploads & Agent Knowledge

Documents you upload (for context, requirements, or the knowledge base) are processed to inform the agents' work and indexed within your workspace.

The Normalization reference database — used to match your company and vendor data — is GeneWorks' own intellectual property. Your raw values are matched against it; the reference database does not contain your data.

AI model processing. Prompts required to complete a task are sent over HTTPS to the AI model provider. We do not send more of your data to a model than a task requires.

TierModelProcessed under
Fully ManagedLatest Claude Opus (Anthropic)Anthropic's terms; no training on your data.
Bring Your Own LLMYour own model / providerYour provider's terms.
06 — Data Storage

Where Your Data Is Stored

Account and workspace configuration, scan summaries, and app settings are stored in GeneWorks' hosted environment (or, for self-hosted deployments, in the environment you operate). Your ServiceNow records remain on your ServiceNow instance at all times.

// Two deployment options — you choose the boundary GeneWorks-hosted (AWS) turnkey; scan summaries in our environment; your records stay on your instance. Your cloud / on-prem everything — including scan summaries — stays inside your boundary. Either way: credentials stay local, and GeneWorks never deploys to production.
07 — Third-Party Services

Third-Party Services

We use a small number of third-party services strictly to operate the Service. We do not sell your data, and we do not share it except as required to operate the Service or comply with law.

ServicePurpose
AI model providers (Anthropic; optionally your own)Generate designs, code, assessments, and documents.
Cloud hosting (AWS)The hosted GeneWorks environment, unless you self-host.
CommunicationsContact-form delivery, billing, and account email.
08 — Data Retention

Data Retention

We retain account and workspace data for as long as your account is active, and scan summaries for as long as they are useful to your workspace history (or until you delete them). On termination, or on your request, we delete account and workspace data within a reasonable period, subject to any legal retention obligations.

No instance-data retention on our side. Because GeneWorks holds no copy of your ServiceNow records, there is nothing of yours to retain — those records live and die on your instance under your control.
09 — Your Rights

Your Data Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any of these rights, email us at gene@geneworks.ai and we will respond within a reasonable timeframe.

You can also act directly in the product at any time — disconnect an instance, clear your credentials, and delete uploaded documents and scan summaries from the workspace.

10 — Contact Us

Privacy Questions & Contact

Questions about this Privacy Policy or how we handle your data should be addressed to GeneWorks at gene@geneworks.ai. Response time: within 5 business days.

GeneWorks is local-first and read-first by design. Your ServiceNow instance data never leaves your environment — an architectural guarantee, not just a policy promise.