Privacy Policy

How AI x GTM collects, uses, stores, and protects data.

This policy describes our data practices for account data, user content, technical data, billing-related processing, third-party AI processing, and security.

Last updated: January 21, 2026

1. Data We Collect

When you use the Application, we may collect and process account and contact information you provide, such as your name, email address, and company name, in order to create and manage your account.

We may also collect User Content that you submit through the Application, including prompts, questionnaire responses, uploaded text, and other information you choose to provide.

We collect usage and technical data, such as device and browser information, IP address, log data, and approximate location derived from IP, to operate, maintain, secure, and improve the Application.

If billing applies, we collect billing-related information necessary to process payments. Payment details are typically processed by our payment processor rather than stored directly by us.

2. How We Use Data

We use the data described above to provide, operate, and maintain the Application and its features.

We use your inputs to generate outputs, including persona generation and marketing workflow outputs, and to store and retrieve your projects, personas, and related application state.

We also use data to prevent fraud, enforce our agreements, troubleshoot issues, and protect the security and integrity of the Application.

We do not sell your personal data.

3. Data Used for Persona Enrichment

The Application may enrich outputs using our proprietary datasets and models, including internal persona, occupation, industry, and descriptor data.

Your User Content is used to process your request and generate outputs, but enrichment data sources are primarily our own internal resources.

4. Where Data Is Stored

Application data, including account data and Application state such as saved projects and personas, is stored in a Heroku Postgres database.

Heroku indicates that data-at-rest encryption is provided at the disk level for most Heroku Postgres plans.

5. Security: Encryption In Transit

We use HTTPS/TLS encryption to protect data transmitted between your device and the Application.

Data is also encrypted in transit when sent to third-party processors as described in this policy.

6. Third-Party AI Processing (OpenAI API)

The Application connects to OpenAI via API to generate certain outputs. When you submit User Content for an AI-powered feature, relevant portions of that content and related instructions may be transmitted to OpenAI to process your request.

OpenAI states that, by default, business/API data is not used to train its models unless the customer explicitly opts in.

OpenAI also states that API prompts and responses may be retained in abuse monitoring logs for up to 30 days, unless legal requirements require longer retention.

Your use of AI-powered features is also subject to OpenAI's applicable terms and data practices.

7. Data Sharing

We share data only with service providers and processors needed to operate the Application, such as hosting and database providers, payment providers, and OpenAI for AI processing.

We may also share data where required to comply with law, enforce our agreements, or protect the rights, safety, and security of the Company, users, or others.

We do not sell user data.

8. Data Retention

We retain account data and saved Application state, such as projects and personas, for as long as your account remains active or as needed to provide the Application.

We may retain certain records longer where required for security, fraud prevention, dispute resolution, backups, or legal compliance.

Data sent to OpenAI is handled according to OpenAI's retention practices for API usage, including the up-to-30-day abuse monitoring log retention described above.

9. Your Responsibilities Regarding Sensitive Information

You agree not to submit sensitive personal information, such as health information, government ID numbers, or other highly sensitive data, unless doing so is necessary and you have a lawful basis to provide it.

You are responsible for the content you provide and for ensuring that you have the rights and permissions needed to submit it.