MyGentic is built to hold the most useful parts of your professional life, which means the way we handle that material matters more than any feature we ship. This page summarizes how your data is protected. The binding commitments live in the Privacy Policy and the Terms of Use, and where this page and those documents differ, those documents govern.
1. What we store, and what we discard
When you connect a tool through the Model Context Protocol or a standard API pipeline, MyGentic accesses data from that source transiently, screens it for relevance to your professional profile, and stores only the resulting profile field values along with a short note of where each came from.
We do not store the underlying source content. Your emails, messages, documents, and calendar entries are not kept on our systems. Items that do not match a profile field are discarded rather than retained.
This is a deliberate design choice, not only a policy one. A structured profile of how you work is both more useful to an AI and less dangerous to hold than a copy of your inbox.
2. Encryption and access control
- At rest: AES 256-bit encryption.
- In transit: TLS 1.3.
- Server access: gated by zero-trust multi-factor authentication.
No electronic transmission or storage system is completely invulnerable, and we do not claim absolute security. What we commit to is the control set above, applied consistently, and honest disclosure if that ever changes.
3. Your data is not training data
We do not and will not use your inputs, outputs, professional profile, or connected-source data as training or fine-tuning data for any model, whether operated by us or by a third party.
MyGentic does not train foundation models from scratch. Text and audio responses are generated by independent third-party model providers, including Anthropic, OpenAI, and Google, acting as our service providers under agreements that prohibit them from using your submitted content to train their models.
Where we adapt or fine-tune a model to deliver the Services, we do so using our own materials, licensed datasets, or data that is not derived from user content.
4. Retention and deletion
We keep personal data only as long as it is needed for the purposes described in the Privacy Policy.
- Account and profile data: kept while your account is active, then for 90 days after closure so you can reactivate, after which it is deleted or anonymized.
- Billing and transaction records: kept for 7 years to meet U.S. and Canadian tax and accounting requirements.
- Usage, log, and diagnostic data: kept for 24 months, then deleted or anonymized.
- Backups: copies may persist up to 90 days after deletion from active systems, as part of the routine backup cycle.
- Verified deletion requests: completed within 30 days.
We may retain data longer only where necessary to comply with a legal obligation, resolve a dispute, or respond to legal process.
5. We do not sell or share your data
MyGentic does not sell your personal data for monetary consideration, and does not share or disclose it for cross-context behavioral or targeted advertising. We do not use tracking systems to profile your activity across unaffiliated applications or websites.
If those practices ever change, we will add a “Do Not Sell or Share My Personal Information” mechanism and honor global opt-out signals such as Global Privacy Control.
6. Voice and biometrics
Where Sage generates synthetic speech, it does so to speak to you. It does not create a voice model, clone, or replica of your voice, and MyGentic does not extract or retain voiceprints or other biometric identifiers.
Using the Services to imitate, impersonate, or synthesize another person’s voice is prohibited under the Terms of Use, as is initiating automated voice features involving external participants without the consents required by applicable call recording and wiretapping law.
7. Compliance and standards
We handle personal data in line with GDPR and CCPA, including the statutory rights described in the Privacy Policy: access, correction, deletion, portability, and the right to limit the use of sensitive personal information.
Because MyGentic has no establishment in the European Union or the United Kingdom, we maintain representatives for those regions, named in the Privacy Policy.
Our SOC 2 audit is underway. We will publish the report status here when it completes. We do not claim a certification we do not yet hold.
8. Controls you hold
Security is not only what we do on our side. Every connection you make carries a permission scope, and you can change it at any time.
- Scope what each AI sees, per tool, per field, and per timeframe.
- Export everything as structured JSON, on demand.
- Delete anything, including your entire brain, and walk away with what you put in.
- Revoke a connection instantly, without deleting what you have already built.
See Data Controls for how these work in the product.
9. Reporting a vulnerability
If you believe you have found a security vulnerability, email security@mygentic.io with enough detail to reproduce it. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.
For privacy requests, contact privacy@mygentic.io. For questions about these terms, contact legal@mygentic.io.