GeneWorks is built on a simple premise: we read your ServiceNow instance to do work on your behalf. We do not copy, harvest, profile, or monetise your instance data — and every scan is read-only.
This Privacy Policy describes how GeneWorks ("we", "us", "the Company") handles information when you use the GeneWorks platform ("the Service") — the website, the application workspace, and the AI agents that scan, build, test, and remediate on your ServiceNow instance.
GeneWorks is designed as a credential-local, read-first platform. The guiding principle throughout this policy is simple:
We collect the minimum information required to operate the Service.
| Category | What it is | Why |
|---|---|---|
| Account information | Name, work email, organisation. | To create and manage your account. |
| Workspace configuration | Instance URL you connect, app and workspace settings, preferences. | To run the apps against your instance. |
| Scan summaries & metrics | Counts, scores, health metrics, findings, dependency maps. | To render Command Center, assessments, and reports. These describe the shape of your instance — not a copy of your records. |
| Usage & support data | Basic product-usage events; anything you send us for support or billing. | To operate, support, and improve the Service. |
We deliberately do not collect or retain the following:
Your credentials are stored in your browser and used only to construct direct, authenticated API calls from your browser to your instance over HTTPS (TLS 1.2/1.3). They never pass through GeneWorks infrastructure.
Every app scans read-only. The Service writes to your instance only when you explicitly approve a change through the human-gated delivery loop. You can remove your credentials and disconnect an instance at any time — an immediate, permanent operation.
Documents you upload (for context, requirements, or the knowledge base) are processed to inform the agents' work and indexed within your workspace.
The Normalization reference database — used to match your company and vendor data — is GeneWorks' own intellectual property. Your raw values are matched against it; the reference database does not contain your data.
AI model processing. Prompts required to complete a task are sent over HTTPS to the AI model provider. We do not send more of your data to a model than a task requires.
| Tier | Model | Processed under |
|---|---|---|
| Fully Managed | Latest Claude Opus (Anthropic) | Anthropic's terms; no training on your data. |
| Bring Your Own LLM | Your own model / provider | Your provider's terms. |
Account and workspace configuration, scan summaries, and app settings are stored in GeneWorks' hosted environment (or, for self-hosted deployments, in the environment you operate). Your ServiceNow records remain on your ServiceNow instance at all times.
We use a small number of third-party services strictly to operate the Service. We do not sell your data, and we do not share it except as required to operate the Service or comply with law.
| Service | Purpose |
|---|---|
| AI model providers (Anthropic; optionally your own) | Generate designs, code, assessments, and documents. |
| Cloud hosting (AWS) | The hosted GeneWorks environment, unless you self-host. |
| Communications | Contact-form delivery, billing, and account email. |
We retain account and workspace data for as long as your account is active, and scan summaries for as long as they are useful to your workspace history (or until you delete them). On termination, or on your request, we delete account and workspace data within a reasonable period, subject to any legal retention obligations.
Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any of these rights, email us at gene@geneworks.ai and we will respond within a reasonable timeframe.
You can also act directly in the product at any time — disconnect an instance, clear your credentials, and delete uploaded documents and scan summaries from the workspace.
Questions about this Privacy Policy or how we handle your data should be addressed to GeneWorks at gene@geneworks.ai. Response time: within 5 business days.
GeneWorks is local-first and read-first by design. Your ServiceNow instance data never leaves your environment — an architectural guarantee, not just a policy promise.