Privacy Policy
1. Who we are
autogovern.io (“autogovern”, “we”, “us”) provides AI governance and risk-management software and advisory services, including this website and the Governance Workbench at autogovern.io/app. The data controller is autogovern.io Governance Systems Inc. [ ● registered address ]. For any privacy question, contact info@autogovern.io.
2. Information we collect
We collect only what we need to run the service and respond to you:
Information you give us
- Consultation & contact requests — your name, email, company, company size, the service you’re interested in, and any project notes you submit through our forms.
- Document & framework downloads — your name, work email, company, industry and maturity level when you request a generated governance document.
- Saved assessments — if you choose to save a governance assessment or risk register, we store
the inputs and computed results you entered, an optional system name, and an optional owner email. Saved
assessments are reachable by an unguessable link (e.g.
/assessment/<id>) that you control and choose whether to share. - Workbench artefacts you save — model cards, LLM-safety evaluations and similar outputs you explicitly choose to persist.
- Messages — text you send to the Governance Copilot or the Agent Hub.
- Newsletter subscription — if you subscribe to the daily briefing: your email address, the topics you selected, and the page you subscribed from. We use double opt-in — we send one confirmation email and nothing else until you click the link in it. If you never confirm, the address is deleted after 30 days. Every email includes a one-click unsubscribe link, and unsubscribing takes effect immediately.
Information collected automatically
- Security & operations logs — limited technical data such as your IP address and request metadata, used for rate-limiting, abuse prevention and debugging.
- First-party usage analytics — we measure how the site is used with our own, self-hosted analytics (no third-party trackers): pages viewed, referring site, browser and device type, language, and approximate location. IP addresses are never stored for analytics — only a salted, daily-rotating hash. Random identifiers kept in your browser’s storage let us count returning visits; they do not identify a verified person or customer and are never shared.
- Approximate location — we estimate the country, region, city and network provider your request came from by looking your IP address up in a geolocation database held on our own server. Your IP address is not sent to any third party for this, and is not retained afterwards — only the resulting approximate location is kept. City-level estimates are approximate by nature and often reflect your internet provider’s location rather than yours. The offline fallback uses IP Geolocation by DB-IP under CC BY 4.0.
- Automated-traffic classification — we record a log of requests reaching the site (page requested, response status, timing, User-Agent, approximate location and the salted IP hash) and classify each as a person or an automated client, so that crawlers, scrapers and scanners can be told apart from real visitors. We also record whether a visit produced ordinary interaction (a scroll, click or key press) and how long the page was open — not what was typed or clicked. This log is stored in our database; retention is described below.
- Newsletter engagement — if you subscribe, our emails contain a small tracking image and links that pass through our own server before redirecting you to the article. This tells us that an email was opened and which post was clicked, so we know what is worth writing. We do not use this to build a profile of you, and it is never shared. If you prefer not to be measured this way, most email clients can block remote images, and you can unsubscribe at any time from the link in every email.
- Local preferences — your light/dark theme choice is stored in your browser’s
localStorage; it never reaches our servers.
3. Data you analyse in the Workbench
Several Workbench tools (for example the Fairness Scanner, Drift & Data-Quality analysis, the Document Gap Scanner, the Shadow AI and Model File scanners, and the on-page Governance & Risk assessors) run entirely in your browser. The datasets, documents, model files, contract text and prompts you analyse are never uploaded to us — they are read, parsed and scored on your own device and never leave it. Keeping raw data on your device is a deliberate design choice and it holds regardless of the settings below.
Private assessment saving
Assessment cloud auto-save is off by default. You can enable it separately or press Save privately. Saved assessments are excluded from training. Signed-in assessments belong to your organization; anonymous assessments require the owning browser's HttpOnly cookie. Clearing that cookie removes your access to anonymous saved work. An assessment ID alone does not grant access.
The intake classifier sends your answers to our server for obligation mapping even when auto-save is off. Hosted and AI-assisted tools may also send their inputs to our server or an external model provider; check each tool's data-handling label. Browser-only dataset analysis does not upload your source files.
Optional improvement and training summaries
Optional tool-run summaries are off by default and independent of saving. If you enable summaries, we receive the tool name, score/band, compact result rollup, system name/risk tier and browser identifiers for product improvement. A separate training checkbox controls whether those summaries may also be used for training. This excludes raw uploaded datasets, documents and model files. Turning the option off stops future summaries; it does not retract records already sent. Full saved assessments are not made available for training by this option.
Sharing and public benchmarks
Saving does not create a public link. The Dossier can create a separate, read-only summary link containing only the system name, risk tier, score and dates. Anyone holding that link can view the summary for the selected 1–30 days. Creating a replacement invalidates the prior link; Revoke summary link ends access immediately. Intake answers, contact details and detailed findings are not included. Downloaded copies cannot be recalled.
Public assessment benchmarks require a separate opt-in on the saved assessment. Organizational effectiveness benchmarks retain their separate organization-level opt-in. Disabling participation excludes the record from future aggregate queries; it cannot recall published copies of earlier reports.
Retention and deletion
Automatically saved assessments have identifying fields removed after 90 days by the retention job. Assessments deliberately saved remain until deleted. The Dossier's Delete saved assessment removes the source assessment's intake, findings, contact information and scores and revokes its summary link. An empty reference record remains for linked audit artifacts. Separately issued passports, other artifacts and downloaded copies are not deleted by this action; revoke passports separately. Optional tool-run records have identifying fields removed after 90 days.
Existing anonymous assessments that predate ownership cookies are locked because ownership cannot be verified from their old IDs. Organization members retain access to their organization's saved assessments. These changes do not withdraw separately published signed artifacts.
Trust Passports
Issuing a passport is a separate disclosure: its attestation can be read by anyone with the verification link. Public directory listing is a separate opt-in. A valid cryptographic signature establishes issuer and integrity; it does not certify accuracy, safety or legal compliance. Reviewer identity and accreditation are not independently verified by AutoGovern.
Separately, three tools (Model Risk Management, Fair Lending and FS AI RMF) save only to your browser’s local storage and never contact our server at all.
Our downloadable scanner, Aegis, runs fully offline and sends nothing to us by default. If you
explicitly choose to upload a report (the opt-in -submit option), the scan results are stored under an
anonymous, randomly-generated install identifier that contains no host or personal information.
4. How we use information
- To provide, operate and secure the platform and the Workbench.
- To respond to your enquiries and deliver requested documents or advisory engagements.
- To send transactional emails (e.g. confirmations and the documents you requested) from info@autogovern.io.
- To maintain, troubleshoot and improve the service.
- To comply with legal obligations and enforce our terms.
We do not sell your personal data, and we do not use it for third-party advertising.
5. Legal bases (UK/EU GDPR)
Where GDPR applies, we rely on: consent (e.g. when you submit a form or save an assessment); contract (to deliver a service you requested); legitimate interests (to secure and improve the platform, balanced against your rights); and legal obligation where required.
6. Sharing & subprocessors
We share personal data only with the subprocessors below, under appropriate agreements. This is the complete list — we do not use any subprocessor not named here:
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Railway | Application hosting & PostgreSQL database | All personal data described in §2, at rest |
| Namecheap Private Email (privatemail.com) | Transactional email delivery | Recipient email address, message content |
| Z.ai (GLM), DeepSeek, Google, OpenAI, Anthropic, or Moonshot | AI-assisted features (Copilot, Agent Loop, AI-written blog) — only whichever provider(s) are configured on our server at the time | The text you submit to that feature, plus the minimal assessment context (e.g. risk tier) needed to answer it |
We may also disclose information where required by law, or as part of a corporate transaction, subject to this policy. See our Data Processing Addendum for the contractual terms governing subprocessors.
7. Cookies & local storage
autogovern.io does not use third-party advertising or cross-site tracking cookies. We use strictly-necessary browser
storage (such as localStorage for your theme preference) to make the site work. Your browser settings
let you clear this at any time.
8. Retention
We keep personal data only as long as needed for the purposes above. [ ● retention periods below are a starting template — confirm with counsel before relying on them]:
- Enquiry, lead & consultation data — retained for the duration of our business relationship, plus 24 months of inactivity, then deleted or anonymised.
- Saved assessments & Workbench artefacts — retained until you delete them, or automatically deleted after 24 months of inactivity on that record.
- Security & operations logs — retained for 90 days, then deleted.
- First-party analytics and automated-traffic records — retained in our database for historical usage analysis until removed by the operator or an explicitly configured retention period applies. Daily IP hashes use a different salt each day; stored hashes remain with their records. Raw IP addresses are not retained in analytics.
- Newsletter subscription — retained until you unsubscribe. Signups that are never confirmed are deleted automatically after 30 days; newsletter engagement records are deleted after 12 months.
- Agent Control Plane ledger entries — retained indefinitely by design (the ledger is append-only and hash-chained for tamper-evidence), containing only redacted, non-sensitive summaries.
To request deletion of your data before these periods elapse, email info@autogovern.io; see §10 for your rights.
9. International transfers
Our providers may process data outside your country, including outside the UK/EEA. Where they do, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
10. Your rights
Subject to applicable law (including UK/EU GDPR and, for California residents, the CCPA/CPRA), you may request to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise any right, email info@autogovern.io. You also have the right to complain to your local data-protection authority.
11. Security
Measures we actually have in place today:
- HTTPS/TLS for all data in transit.
- Security headers, rate-limiting, and abuse detection on every endpoint.
- Access to stored data is restricted to what each service needs to operate.
- Tamper-evident, hash-chained logging for the Agent Control Plane ledger, so past entries cannot be silently altered.
- Secrets and API keys are never sent to your browser or logged in plaintext.
We do not currently hold a SOC 2, ISO 27001, or similar third-party security certification, and we have not commissioned an independent penetration test. If you need either as part of a procurement process, contact info@autogovern.io to discuss our roadmap. No method of transmission or storage is perfectly secure, but we work to protect your information.
12. Incident notification
[ ● notification timelines below are a starting template — confirm the exact commitment with counsel]: If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will: (a) investigate and contain it without undue delay; (b) notify affected customers by email as soon as reasonably possible, and in any case within 72 hours of confirming the incident, where required by applicable law (e.g. UK/EU GDPR Art. 33); and (c) provide a description of the incident, the data categories affected, and the remediation steps taken or planned. Notification timing may be adjusted where a law-enforcement or regulatory authority instructs us to delay disclosure.
13. Children
autogovern.io is a business tool and is not directed to children under 16. We do not knowingly collect their data.
14. Changes
We may update this policy from time to time. We will revise the “last updated” date above and, where appropriate, notify you of material changes.
15. Contact
Questions or requests: info@autogovern.io.