Privacy Policy
1. Who we are
autogovern.io (“autogovern”, “we”, “us”) provides AI governance and risk-management software and advisory services, including this website and the Governance Workbench at autogovern.io/app. The data controller is autogovern.io Governance Systems Inc. [ ● registered address ]. For any privacy question, contact info@autogovern.io.
2. Information we collect
We collect only what we need to run the service and respond to you:
Information you give us
- Consultation & contact requests — your name, email, company, company size, the service you’re interested in, and any project notes you submit through our forms.
- Document & framework downloads — your name, work email, company, industry and maturity level when you request a generated governance document.
- Saved assessments — if you choose to save a governance assessment or risk register, we store
the inputs and computed results you entered, an optional system name, and an optional owner email. Saved
assessments are reachable by an unguessable link (e.g.
/assessment/<id>) that you control and choose whether to share. - Workbench artefacts you save — model cards, LLM-safety evaluations and similar outputs you explicitly choose to persist.
- Messages — text you send to the Governance Copilot or the Agent Hub.
- Newsletter subscription — if you subscribe to the daily briefing: your email address, the topics you selected, and the page you subscribed from. We use double opt-in — we send one confirmation email and nothing else until you click the link in it. If you never confirm, the address is deleted after 30 days. Every email includes a one-click unsubscribe link, and unsubscribing takes effect immediately.
Information collected automatically
- Security & operations logs — limited technical data such as your IP address and request metadata, used for rate-limiting, abuse prevention and debugging.
- First-party usage analytics — we measure how the site is used with our own, self-hosted analytics (no third-party trackers): pages viewed, referring site, browser and device type, language, and approximate location. IP addresses are never stored for analytics — only a salted, daily-rotating hash. Random identifiers kept in your browser’s storage let us count returning visits; they do not identify you personally and are never shared.
- Approximate location — we estimate the country, region, city and network provider your request came from by looking your IP address up in a geolocation database held on our own server. Your IP address is not sent to any third party for this, and is not retained afterwards — only the resulting approximate location is kept. City-level estimates are approximate by nature and often reflect your internet provider’s location rather than yours.
- Automated-traffic classification — we record a log of requests reaching the site (page requested, response status, timing, User-Agent, approximate location and the salted IP hash) and classify each as a person or an automated client, so that crawlers, scrapers and scanners can be told apart from real visitors. We also record whether a visit produced ordinary interaction (a scroll, click or key press) and how long the page was open — not what was typed or clicked. This log is kept for 30 days.
- Newsletter engagement — if you subscribe, our emails contain a small tracking image and links that pass through our own server before redirecting you to the article. This tells us that an email was opened and which post was clicked, so we know what is worth writing. We do not use this to build a profile of you, and it is never shared. If you prefer not to be measured this way, most email clients can block remote images, and you can unsubscribe at any time from the link in every email.
- Local preferences — your light/dark theme choice is stored in your browser’s
localStorage; it never reaches our servers.
3. Data you analyse in the Workbench
Several Workbench tools (for example the Fairness Scanner, Drift & Data-Quality analysis, the Document Gap Scanner, the Shadow AI and Model File scanners, and the on-page Governance & Risk assessors) run entirely in your browser. The datasets, documents, model files, contract text and prompts you analyse are never uploaded to us — they are read, parsed and scored on your own device and never leave it. Keeping raw data on your device is a deliberate design choice and it holds regardless of the settings below.
What we do receive
Two things are sent to our servers when you use the Workbench, and we want to be exact about them because earlier versions of this page were not:
- A summary of each tool run. Which tool you ran, its pass/fail band and headline score, a small structured rollup of the result (for example the number of drifting features, or the count of findings by severity — never the findings themselves), together with the system name and risk tier you entered, and the anonymous browser identifiers described above.
- Your assessment, saved automatically. After each scan the Workbench saves your assessment — intake answers, classification, scores and findings, including the owner email if you entered one — so you can close the tab and resume, and so the dossier share link works. Previous versions of this page said this only happened when you pressed Save. That was wrong: it happens automatically unless you opt out.
How we use it, and when we delete it
We use this to operate and secure the platform, to understand which tools work, and to improve and train the models and scoring engines behind them.
We do not keep the identifying parts. After 90 days, an automated retention job permanently removes the system name, the owner email and your free-text intake answers from tool-run records and from automatically-saved assessments. What remains is anonymous — scores, bands and structured rollups that identify neither you nor your organisation. Assessments you deliberately saved are excluded from this: they are yours, their share links keep working, and they stay until you ask us to delete them (see the contact section below).
Opting out
There is an opt-out checkbox in the Workbench sidebar, visible from every tool. Ticking it stops both of the above immediately and completely — no run summaries are sent, and nothing is auto-saved. Every tool still works. The setting is remembered in your browser.
Two things to be precise about, so this section does not overstate the effect:
- The risk classifier still sends your intake answers to our server, because the obligation mapping is computed against our regulation catalogue there. That request stores nothing — it reads the catalogue, returns your result, and keeps no copy.
- The “Save & get shareable link” button still saves, because that is you actively choosing to. Records created that way while you are opted out are flagged and are never used for product improvement or training.
Separately, three tools (Model Risk Management, Fair Lending and FS AI RMF) save only to your browser’s local storage and never contact our server at all.
Our downloadable scanner, Aegis, runs fully offline and sends nothing to us by default. If you
explicitly choose to upload a report (the opt-in -submit option), the scan results are stored under an
anonymous, randomly-generated install identifier that contains no host or personal information.
4. How we use information
- To provide, operate and secure the platform and the Workbench.
- To respond to your enquiries and deliver requested documents or advisory engagements.
- To send transactional emails (e.g. confirmations and the documents you requested) from info@autogovern.io.
- To maintain, troubleshoot and improve the service.
- To comply with legal obligations and enforce our terms.
We do not sell your personal data, and we do not use it for third-party advertising.
5. Legal bases (UK/EU GDPR)
Where GDPR applies, we rely on: consent (e.g. when you submit a form or save an assessment); contract (to deliver a service you requested); legitimate interests (to secure and improve the platform, balanced against your rights); and legal obligation where required.
6. Sharing & subprocessors
We share personal data only with the subprocessors below, under appropriate agreements. This is the complete list — we do not use any subprocessor not named here:
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Railway | Application hosting & PostgreSQL database | All personal data described in §2, at rest |
| Namecheap Private Email (privatemail.com) | Transactional email delivery | Recipient email address, message content |
| Z.ai (GLM), DeepSeek, Google, OpenAI, Anthropic, or Moonshot | AI-assisted features (Copilot, Agent Loop, AI-written blog) — only whichever provider(s) are configured on our server at the time | The text you submit to that feature, plus the minimal assessment context (e.g. risk tier) needed to answer it |
We may also disclose information where required by law, or as part of a corporate transaction, subject to this policy. See our Data Processing Addendum for the contractual terms governing subprocessors.
7. Cookies & local storage
autogovern.io does not use third-party advertising or cross-site tracking cookies. We use strictly-necessary browser
storage (such as localStorage for your theme preference) to make the site work. Your browser settings
let you clear this at any time.
8. Retention
We keep personal data only as long as needed for the purposes above. [ ● retention periods below are a starting template — confirm with counsel before relying on them]:
- Enquiry, lead & consultation data — retained for the duration of our business relationship, plus 24 months of inactivity, then deleted or anonymised.
- Saved assessments & Workbench artefacts — retained until you delete them, or automatically deleted after 24 months of inactivity on that record.
- Security & operations logs — retained for 90 days, then deleted.
- First-party analytics identifiers — retained for 13 months, then deleted (daily-rotating IP hashes are never retained beyond the day they're generated).
- Request & automated-traffic log — retained for 30 days, then deleted.
- Newsletter subscription — retained until you unsubscribe. Signups that are never confirmed are deleted automatically after 30 days; newsletter engagement records are deleted after 12 months.
- Agent Control Plane ledger entries — retained indefinitely by design (the ledger is append-only and hash-chained for tamper-evidence), containing only redacted, non-sensitive summaries.
To request deletion of your data before these periods elapse, email info@autogovern.io; see §10 for your rights.
9. International transfers
Our providers may process data outside your country, including outside the UK/EEA. Where they do, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
10. Your rights
Subject to applicable law (including UK/EU GDPR and, for California residents, the CCPA/CPRA), you may request to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise any right, email info@autogovern.io. You also have the right to complain to your local data-protection authority.
11. Security
Measures we actually have in place today:
- HTTPS/TLS for all data in transit.
- Security headers, rate-limiting, and abuse detection on every endpoint.
- Access to stored data is restricted to what each service needs to operate.
- Tamper-evident, hash-chained logging for the Agent Control Plane ledger, so past entries cannot be silently altered.
- Secrets and API keys are never sent to your browser or logged in plaintext.
We do not currently hold a SOC 2, ISO 27001, or similar third-party security certification, and we have not commissioned an independent penetration test. If you need either as part of a procurement process, contact info@autogovern.io to discuss our roadmap. No method of transmission or storage is perfectly secure, but we work to protect your information.
12. Incident notification
[ ● notification timelines below are a starting template — confirm the exact commitment with counsel]: If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will: (a) investigate and contain it without undue delay; (b) notify affected customers by email as soon as reasonably possible, and in any case within 72 hours of confirming the incident, where required by applicable law (e.g. UK/EU GDPR Art. 33); and (c) provide a description of the incident, the data categories affected, and the remediation steps taken or planned. Notification timing may be adjusted where a law-enforcement or regulatory authority instructs us to delay disclosure.
13. Children
autogovern.io is a business tool and is not directed to children under 16. We do not knowingly collect their data.
14. Changes
We may update this policy from time to time. We will revise the “last updated” date above and, where appropriate, notify you of material changes.
15. Contact
Questions or requests: info@autogovern.io.