Your Content
• You retain all ownership rights to your uploaded documents, workflow definitions, and other content
• You grant us a limited license to host, store, process, and analyze your content solely to provide the Service
• This includes sending your content to third-party AI providers (OpenAI, Anthropic, Google) for processing
• You represent that you have all necessary rights to upload and process your content
• You are responsible for the legality, accuracy, and appropriateness of your content
AI-Generated Content
• AI-generated content (responses, reports, workflow outputs, artifacts) is provided to you for your use
• We do not claim ownership of AI-generated content created specifically for you
• AI-generated content may be inaccurate, incomplete, or inappropriate
• You are solely responsible for reviewing, validating, and using AI-generated content
• We are not liable for damages resulting from reliance on AI-generated content
Organizational Data Access and Privacy
Administrator Access Rights:
Within your organization (tenant), administrators can access METADATA AND ANALYTICS ONLY:
• Usage statistics (who is using AI, when, and which models) and cost metrics
• Audit logs of actions taken (timestamps, user IDs, action types)
• Workflow execution metadata (start time, duration, status)
• System performance and analytics
Administrators CANNOT access:
• Actual chat content, conversations, or prompts
• Generated reports or AI responses
• Document content or uploaded files
• Specific questions asked or work product created
• Individual messages within chat sessions
Privacy Philosophy:
This privacy-respecting governance approach follows industry standards (Microsoft Copilot, ChatGPT Enterprise) that provide oversight through metrics rather than content surveillance. This enables:
• Effective AI governance and cost control
• User trust and AI adoption
• Compliance with privacy regulations (GDPR, CCPA)
• Protection of intellectual property and confidential work
Exceptions:
In limited circumstances (legal obligations, security incidents, documented policy violations), authorized compliance officers may access content with proper authorization, logging, and user notification where legally required.