Skip to content

Privacy Notice

Last updated

Version d276f77cd52e

This notice can change. The version reference above is calculated from the wording of this notice — in every language it is published in, and including the alternative wordings used depending on how this deployment is set up — so it is different whenever any of that wording is different. If it does not match the version you read before, this notice has been revised since then. It does not cover how this deployment is configured: the operator's own name and address, the processing location it publishes, and which wording is used for each of them below, are set by whoever runs this deployment and can change without the version changing.

This deployment is a private workspace for its organization. Signing in collects the personal data needed to operate your account.

What we collect

  • Your email address, used to send the sign-in code and identify your account.
  • If you sign in with Google, the name and email address of your Google account.
  • The questions you ask and the documents you upload, stored so your chats and library work.

How it is used

This data is used to provide the service: authentication, answering your questions, and keeping your workspace.

To answer your questions, the questions you ask and relevant excerpts — including images of pages from documents you upload — are sent to a third-party AI provider that generates the responses on this deployment's behalf.

This deployment can also use an Internet search and page-retrieval service, which can receive a query derived from what you ask. When Internet search is switched on and the assistant uses it, the search query is sent to the service this deployment is configured to use, along with the addresses of any pages that service is then asked to fetch so their contents can be read back. That service may be operated by a third party or run by the operator of this deployment itself, and depending on how it is set up, the searches and page fetches it makes may reach the public Internet. The query is written by the AI provider's model from your question and the material it is working with, so it can carry wording from one or both. The search service is separate from the AI provider that produces the response you are shown. Whether Internet search is switched on, and which service is used, are set by whoever runs this deployment; while it is on, an answer can draw on what that service returns as well as on your organization's documents.

Separately from this service, your own web browser may process what you type. Browsers offer spell-check and writing-assistance features that can send typed text to the browser vendor, and whether they are on is a setting on your device, not something this deployment controls. The sign-in code and email address fields ask your browser to turn all of these off. The fields where you type a question, feedback, or an issue report ask it to leave spell-check available but turn off automatic correction and writing suggestions. A browser is free to ignore these requests, and browser extensions are not covered by them.

Your browser may also keep a copy of what you type on the device itself. When a form is submitted, browsers commonly save the text of fields such as an email address into their own form history, so it can be offered as a suggestion the next time — including when the sign-in was abandoned and nothing ever reached this service. That history belongs to the browser profile rather than to this deployment: it is shared across the sites that profile visits, and this service can neither read it nor erase it. If you sign in on a device other people also use, open a guest session — a window with its own empty profile — and close it when you finish, or ask your administrator to set that device up so form history is not kept. A private or incognito window is not enough on its own: it usually avoids saving anything new, but it can still offer entries already saved on that device.

What is stored on your device

This notice sets no cookie of its own and writes nothing to this site's storage in your browser. Your language and appearance are stored on this device once you choose them; your language is also stored without any choice on your part when the sign-in page opens, because it keeps the language it is showing you, and again when you arrive here from that page, which carries the same language across. Each of these is held by this site and separately by the sign-in page, which is a different address with its own copies: some stay until you clear them, some for as long as your browser treats the visit as the same session — which can outlast closing and reopening it — and the rest expire on their own within a year. Signing in adds cookies from the sign-in service that hold your session, tie each request to it, and record security decisions made about your browser. Using the workspace saves more on this device: the mode, persona, model and skill you last used, your notification and answer-detail preferences, the topics you are working through, which chats have attachments, whether the side panel is open and how wide it is, scroll positions, and cards you have dismissed. An appearance chosen while you are signed in is also saved to your account. To remove what is held on the device you have to clear browsing data for this site and for the sign-in page, and that still leaves what is saved to your account. Your browser also keeps its own history of the addresses you visit here, together with the title of each page, and cached copies of the files these pages serve, for as long as its own settings and those files' cache settings allow. A chat page is titled by the kind of page it is rather than by what you asked; a page that opens a document may be titled with that document's own name, and titles recorded before that was so may still hold the text of a question. That history and that cache belong to your browser profile rather than to this site: signing out does not clear them, and the route below for removing your data does not reach them either, because this deployment does not hold them. Clearing them is done from the browser's own settings, on each device you have used — by you, or by whoever administers that device.

How long it is kept

This deployment applies no deletion timeline to your chats: the questions you ask and the answers you are shown stay available to you until you delete the chat holding them. Deleting one takes it out of your workspace, and the chat's own text goes with it — the questions, the answers, the passages quoted inside them, and whatever was saved out of that chat into your notebook or your practice questions — but not at the instant you ask: a scheduled clean-up removes it a short time afterwards, and how long that window is, is set by whoever runs this deployment. Once that has run, the text is gone from the store that serves your chats and cannot be brought back to you; what the systems around the service still hold is a separate matter, stated at the end of this section. A document you attached to that chat is not removed by deleting it, and this notice does not claim otherwise: the document goes when its own expiry passes, described next. Documents are treated differently. A document you attach to a chat is given an expiry when you upload it, and once that passes it is deleted on its own; how long that window is, is set by whoever runs this deployment. Documents added to your organization's library carry no expiry at all and are kept until the organization deletes them. For both kinds of document the deletion is recorded first, and a scheduled clean-up then removes the stored file and what the search index holds of it a short time afterwards, rather than at the instant it is requested. Files the assistant produces for you to download are not put into the search index and are not part of that clean-up; they expire on their own after a period the operator likewise sets, and are removed then. Two things sit outside all of that, and this notice states them rather than leaving them to be assumed. What the systems around the service retain — the operator's backups, and the logs their infrastructure writes — is decided by whoever runs this deployment. And how long anything that receives your data keeps it is decided by whoever operates that recipient rather than here: for the AI provider that is a separate organization under its own terms, and for an Internet search service, when one is switched on, it is whichever party runs that service — a third party under theirs, or this deployment's own operator. Those retention periods are not published here.

Where it is processed

Your data is not handled in a single place. This deployment stores your chats and documents on infrastructure chosen by the organization that runs it. The AI provider that writes the answers is a different organization running on infrastructure of its own, so the questions you ask — and the images of pages from documents you upload — are processed on computers this deployment does not control, in whichever country that provider operates. Where the Internet search and page-retrieval service described above is switched on, whatever reaches it is processed wherever that service runs, which is a further organization's infrastructure when a third party provides it and the operator's own when they run it themselves. Any of these places can be a country other than yours and other than your organization's, which means your data can be processed outside the legal jurisdiction you are in and be reachable by authorities there under laws that may differ from the ones you expect. Which countries are involved follows from where this deployment is hosted and which providers it is configured to use, and both are decided by whoever runs it.

This deployment has not published where it hosts and processes your data.

This deployment has not published an address for privacy questions or requests to remove your data.