Privacy Policy

Your data belongs to you. Full stop.

geneworks.ai reads your ServiceNow estate to do work on your behalf, and holds the results in an environment dedicated to you alone. We do not pool your content with anyone else’s, we do not train models on it, and we do not profile or monetize it. Every analysis is read-only, and nothing changes in your instance without a named person approving it.

1 July 2026
Effective Date
9 August 2026
Last Updated
3.0
Version
01 · Scope

Scope of This Policy

This Privacy Policy describes how geneworks.ai (“we”, “us”) handles information when you use the geneworks.ai platform (“the Service”): the website, the project workspace, and the agents that plan, build, test, document and remediate work on your ServiceNow estate.

It covers two different kinds of information, and the distinction runs through everything below. Personal data means the small amount of information about the people who use the platform: names, work emails, roles. Customer content means everything the platform holds about your estate and your delivery work: configuration metadata, analysis results, requirements, designs, code, tests and evidence.

The premise in one line. Personal data is minimal and used only to run your account. Customer content is substantial, and it lives in an environment provisioned for you alone, under encryption keys you control.
02 · Architecture

The Architecture Behind This Policy

A privacy policy is only as good as the architecture underneath it. geneworks.ai runs a single-tenant model: each customer receives a dedicated environment on AWS that holds all of their content. There is no shared application runtime, and no shared database in which one customer’s content sits alongside another’s.

// The rule that shapes everything below Your content lives in your own environment, not in a shared system. Encryption at rest runs under keys you manage. The only shared component holds billing and entitlement metadatanever your requirements, designs, code, evidence or instance data. Your ServiceNow instance remains the system of record throughout.

Two consequences follow. First, cross-tenant exposure is not a defect we defend against at the application layer; it is a scenario the architecture does not contain. Second, because the keys are yours, you can make your own content unreadable at any time without asking us to act.

03 · What We Process

What We Process

We process the minimum required to operate the Service, and we distinguish clearly between the two categories described above.

CategoryWhat it isWhy
Account dataName, work email, organization, membership and role.To create and administer your account and control access.
Connection dataInstance URL, integration credentials and OAuth secrets.To reach the instances you designate. Encrypted twice and held only in your environment.
Configuration and analysis dataApplication and plugin metadata, configuration records, dependency maps, CMDB structure and quality metrics, catalog scores, test definitions and results.To produce maps, scores, findings and designs. This is the material the platform reasons over.
Project contentMissions, ideas, requirements, business cases, backlogs, designs, decisions and generated documents.To run the workspace and let context compound across a project.
EvidenceTest results, screenshots, video, logs and approval records.To make every change provable. Retained immutably against the run that produced it.
Usage and support dataProduct usage events, and anything you send us for support or billing.To operate, support and bill for the Service.

On personal data inside your instance. The platform reads configuration and metadata, not employee or customer datasets. Production business records are not required for the Service to work and are not replicated wholesale. Where a configuration record incidentally names a person, for example as the owner of a record or a member of an assignment group, it is processed transiently for the task at hand.

04 · What We Do Not Do

What We Explicitly Do Not Do

  • We do not train models on your content. The AI provider is contractually prohibited from training on customer data, and geneworks.ai does not train, fine-tune or improve any model on it. Nothing you do here improves a general model.
  • We do not pool content across customers. Analysis data, run history, decisions and lessons stay in your environment. Cross-tenant learning does not occur, and one customer’s work is never context for another’s.
  • We do not sell, rent or share your data with third parties, and we do not build behavioral profiles.
  • We do not replicate your production business records. The Service reads what it needs to reason about configuration, not your incident, case or HR data in bulk.
  • We do not hold your content in a shared system. There is no multi-tenant database with row-level separation between customers.
  • We do not deploy to your production instance. Promotion follows your own change process and remains your action.
The difference between reasoning over data and harvesting it. “CMDB completeness is 26%, with 1,767 stale configuration items” is the kind of thing the platform produces and stores. It produces it by reading those records in your instance, in your own environment, for your own work. It does not become a dataset that outlives your subscription or informs anyone else’s.
05 · Credentials

Credentials & Instance Access

Access to ServiceNow uses OAuth 2.0 with credentials you supply, operating as a dedicated integration user under a least-privilege scoped role set. The admin role is not required.

  • Credentials and OAuth secrets are stored only inside your dedicated environment, with an application-level layer of authenticated encryption on top of encryption at rest.
  • They never appear in the interface, in logs, or in any shared component, and no agent or model ever holds a raw credential.
  • Every action is performed as the integration user and appears in your own ServiceNow audit log, independently of anything we record.
  • Disabling the integration user or the OAuth application in ServiceNow severs access immediately, without involving us.

Analysis is read-only. The Service writes to your instance only inside work you started, in a workspace where you hold the role for it, and only after the design gate has been approved by a named person.

Least privilege. We recommend a read-scoped integration user for assessment work, with write roles granted only when you move to remediation.
06 · AI Processing

AI Model Processing

The platform reaches frontier models over a private, region-pinned path from your environment. The architecture is model-agnostic and carries no single-vendor dependency, and per-tenant model constraints can be applied where your policy requires them.

  • Task-scoped. What is sent for a given operation is limited to what that operation requires: the configuration records, analysis output or document context in question. We do not send more of your content to a model than the task needs.
  • No training. The provider is contractually barred from training on customer data.
  • No cross-tenant context. Your content is never used as model context for another customer’s work.
  • Server-side only. All model interaction happens inside your environment. You do not need an account with a model provider, and no key of yours is required.

Documents you upload for context, requirements or knowledge are processed to inform the agents’ work and indexed within your workspace. They stay there.

The reference catalog used by Normalize to match company, vendor and software data is geneworks.ai’ own intellectual property. Your raw values are matched against it. It does not contain, and is not enriched with, your data.

07 · Where Data Lives

Where Your Data Lives

All customer content is held in the dedicated environment provisioned for you: account records, connection data, configuration and analysis data, project content, generated artifacts and evidence. The region is set when that environment is provisioned and confirmed with you during onboarding.

The only component shared between customers is the control plane, which holds account, entitlement, billing and usage metering metadata. It never holds project content, instance data, credentials or evidence.

Your ServiceNow instance remains the system of record throughout. If the platform were removed tomorrow, the configuration it built, the update sets it produced and the tests it wrote would all still be in your instance, under your ownership.

08 · Subprocessors

Subprocessors

We use a small number of third parties strictly to operate the Service.

SubprocessorPurpose
Amazon Web ServicesCompute, storage, networking and key management for the dedicated environment.
AI model providerModel inference over a private, region-pinned path. Contractually barred from training on customer data.
Business communicationsContact-form delivery, billing and account email.

The current subprocessor list, naming each provider, is maintained and available on request as part of a vendor review. Material changes are communicated to customers in advance.

09 · Retention

Retention & Deletion

Customer content is retained for the duration of your subscription, because the value of the workspace is that it remembers. On termination, or on verified written request, the dedicated environment is torn down and its content deleted, with certification of destruction provided.

Within a live subscription you can delete uploaded documents, analysis runs and workspace content yourself at any time. The customer-managed key model applies here too: revoking the key is a deletion you can execute on your own timetable, without asking us.

Account and billing metadata in the control plane is retained as required for legal, tax and accounting obligations after an account closes.

Offboarding is symmetrical to onboarding. You disable the integration identities, which severs access immediately, and the environment is decommissioned. There is no residue in a shared system, because there was never a shared system.
10 · Your Rights

Your Data Rights

Depending on your jurisdiction, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any of these rights, email gene@geneworks.ai.

Where geneworks.ai processes personal data contained in your ServiceNow estate, we do so as a processor acting on your instructions, and you remain the controller. Requests from your own end users should be directed to you in the first instance; we will support you in responding to them.

You can also act directly in the product at any time: disconnect an instance, rotate or revoke credentials, and delete uploaded documents, analysis runs and workspace content.

11 · Contact

Privacy Questions & Contact

Questions about this policy, or about how we handle your data, should be addressed to gene@geneworks.ai. Response time: within 5 business days. For a formal vendor privacy review, request the architecture and security overview at the same address.

One environment per customer, keys you hold, no training on your content, and an instance that stays the system of record. These are properties of the architecture, not undertakings in a document.