Privacy Policy.
What we collect, why, where it lives, and your rights over it.
1. Who is responsible
GENESIS ("we", "us"), operating at genesishq.net, is the data controller for the personal data described here. Contact: support@genesishq.net.
2. What we collect
- Account data — name, email address, and a cryptographically hashed password (scrypt; we never store or see the plain password).
- Business data — the company profiles, goals and content you give your agents, plus the plans, actions and work product they generate.
- Usage and audit data — actions taken on the Platform, approval decisions, timestamps and technical logs kept for security and the audit trail the product promises.
- Billing data — handled entirely by Stripe. We receive plan, status and revenue-event metadata; we never receive or store card numbers.
When your team acts on your behalf we also hold:
- Your contacts' data. The names, email addresses and messages of leads, customers and other people your team writes to, and the list of anyone who unsubscribes. For this data you are the controller and we are your processor.
- Connected-account tokens. When you connect Stripe, X, Facebook, Instagram, LinkedIn, Google or an ad account, we store the access keys sealed with encryption. We read only what the hand needs: for Stripe, your open invoices and the customer name and email on each.
- Team members. The email address, role and invitation status of anyone you invite, and who invited them.
- What the hands did. Which emails were sent, to which domain, whether they were a first contact; which posts went to which network; which campaigns were planned and approved. Kept on the signed record.
3. Why we process it (lawful bases)
- To provide the service you signed up for — running your agents, gate, briefings (contract).
- To bill you and prevent abuse (contract, legitimate interests).
- To send service email — welcome, briefings, alerts (contract); marketing email only with consent and always with an unsubscribe.
- To meet legal obligations, including tax and accounting records (legal obligation).
- To send email, chase invoices and post on your behalf, because you asked us to (contract). You decide who is contacted; we act on your instruction.
- To honour unsubscribes for your business, which we must keep for as long as your business uses GENESIS (legal obligation).
4. Where your data goes
We use a small set of processors, each bound by contract:
- Render — application and database hosting (EU, Frankfurt).
- Anthropic — our main AI model provider; receives the business context needed to operate your agents. We do not use your data to train models.
- A second AI provider — used only if the main one is unavailable, so your work does not stop. We name the provider in your dashboard when it is in use.
- Stripe — billing, and your connected Stripe account for invoice chasing.
- Resend — sends the email your team writes and our service email to you.
- X, Meta (Facebook and Instagram), LinkedIn, Google — only the accounts you connect, only for the posts, replies or calendar holds you approve.
- Composio — holds the connection to some of those platforms on our behalf. It sees the connection, not your business data.
- An independent timestamp authority — receives a digest (a hash) of each day's record, never the record itself.
We do not sell personal data. Ever.
5. Cookies
One essential cookie keeps you signed in. Your browser also stores two small preferences on this site: whether motion is on, and a plan you picked before signing up. No advertising or cross-site tracking.
6. Retention
Your account and business data are kept while your account is active and deleted or anonymised within 30 days of your request. Three things are different. Billing records are kept as long as the law requires. Unsubscribe requests for your business are kept for as long as that business uses GENESIS, because honouring them means remembering them. The signed record of actions cannot be edited, because that is what makes it trustworthy; on deletion we remove the personal data inside it and keep only the hashes and the timestamps.
7. Your rights
Under UK/EU GDPR you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. Email us and we'll act within one month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
If a team has contacted you on behalf of a business that uses GENESIS, that business is the controller. Use the unsubscribe link in the email, or write to us and we will pass your request to them and stop sending.
8. Security
TLS in transit, managed encrypted infrastructure at rest, hashed passwords, scoped API keys, spend and access governors, and a full audit trail. Keys to your connected accounts are stored sealed and are never shown in the app or the logs. No system is perfect; if a breach ever affects your data we will notify you and the regulator as the law requires.
9. Changes
We'll post updates here and email you about material changes before they take effect.