Who we are
GetsIt AI is an early-access workspace for engineering teams. It connects meetings, tasks, documents, chat, and code workflows so teams can supervise AI-assisted work with clearer context.
This policy explains what information we collect, why we collect it, and the choices you have. It is provided as a practical privacy notice for the current product and should be reviewed as the product and company mature.
Information we collect
Account information
When you register or sign in, we collect your email address, first name, last name, job position, company or workspace details, a hashed password, and session token. We do not store your password in plain text.
Workspace content
You may add tasks, roadmaps, documents, comments, meeting records, transcript text, knowledge-base images, skills, and other content needed to use the product. We process this content to provide the workspace features you request.
AI chat and agent logs
When you run AI chat sessions or agent tasks, we store the messages, questions, answers, tool calls, and execution logs generated during that session. These logs are scoped to your workspace and used to display history, support debugging, and improve reliability.
Meeting and call data
Calendar events store title, description, start and end times, attendee names, and meet links. During live calls, audio is processed transiently by the transcription service. We store transcript text (speaker name, text, timestamp, room name) but not the raw audio after transcription. Guests who join a call without an account provide only a display name; that name may appear in transcripts and be sent for meeting analysis.
Connected integrations and credentials
If you connect a GitHub or GitLab repository, dev server, bring-your-own API key, or Codex subscription, we store the relevant access token or authorization state, host information, SSH port, username, root path, and in the case of server integrations, an SSH private key. Codex authorization state is protected with envelope encryption. Provider API keys are moving to the same protection through a controlled rollout and guarded legacy-record backfill. Other integration credentials are protected by database access controls while application-level encryption is extended to those fields.
Retrieval index
Knowledge-base documents, tasks, skills, calendar events, transcripts, and connected repository content are chunked, embedded, and stored in a retrieval index to power semantic search and agent context. This derived data is scoped to your organization.
Invite email addresses
When a workspace member invites colleagues by email, we store those email addresses as pending invites. These individuals have not yet registered. We store their address only to match it on registration and to avoid sending duplicate invites.
Chat messages
The built-in workspace messenger routes messages through a self-hosted XMPP server. User display names, email addresses, and organization membership are synced to this server to operate the messaging service.
Usage and device information
If you consent to analytics cookies, we use Microsoft Clarity to understand how visitors use the site and improve the product. Clarity may collect interaction data such as page views, clicks, scroll behavior, browser information, approximate location, and device details.
Local preferences
We store interface choices such as theme, board view, temporary call metadata, and cookie consent preferences in your browser storage so the app behaves consistently between visits.
Legal basis for processing (GDPR)
For users in the European Economic Area and the United Kingdom, we process personal data under the following lawful bases:
Contract performance (Art. 6(1)(b))
Account creation, session management, workspace delivery, task and document storage, meeting scheduling, transcription, chat messaging, agent execution, and integration management. Processing in this category is necessary to provide the service you requested.
Legitimate interests (Art. 6(1)(f))
Security logging, abuse prevention, debugging, product reliability, and storage of pending invite email addresses for the purpose of completing a user-initiated invitation. Our legitimate interest is operating a secure and functional product; we have assessed that this interest is not overridden by your rights in these contexts.
Consent (Art. 6(1)(a))
Microsoft Clarity analytics. We only activate Clarity after you opt in through the cookie banner. You can withdraw consent at any time by opening Cookie preferences; withdrawal causes the page to reload so Clarity does not run in that session.
How we use information
We use information to create and secure accounts, provide workspace features, operate meetings and task workflows, preserve user preferences, troubleshoot issues, improve product quality, and communicate with users about access or support.
We do not use workspace content to target advertising. If that changes, we will update this policy and the cookie consent experience before using new tracking technologies for that purpose.
AI and workspace processing
GetsIt AI processes workspace content with AI systems to help generate task suggestions, summarize context, analyze meeting transcripts, retrieve relevant documents, and assist with agent workflows. The product is designed so significant actions remain reviewable by a human before they take effect.
Meeting analysis
After a meeting, an organizer can request that transcript text be sent to our managed AI provider, Cloudflare Workers AI, to extract task suggestions. Only the organizer can trigger this action.
Agent execution
When you assign an agent to a task, the agent may read workspace context and retrieved chunks, clone and read a connected repository, run commands and edit files on a connected dev server, open or update pull requests on GitHub or merge requests on GitLab, and call external APIs using a key or subscription you have connected. Workspace content and task context are sent to the provider hosting the model you selected. For GetsIt-managed models this is Cloudflare (Workers AI) or Microsoft Azure (Azure OpenAI Service); if you have connected your own key or subscription it is that provider, such as Anthropic (Claude) or OpenAI (Codex). These actions only occur when you have connected the relevant integration and assigned the agent.
Shared Codex subscription
A workspace administrator may connect one eligible paid Codex subscription for the organization. All authorized workspace members can start and continue Codex-backed conversations associated with that organization, including conversations another member began. GetsIt records which member initiated each message and turn, while prompts, repository or server context, tool results, and outputs are processed by OpenAI under the connected account. Disconnecting stops new Codex turns but does not automatically delete GetsIt chat history.
Bring-your-own key (BYOK)
If you connect your own provider key, content relevant to your request is sent to that provider (OpenAI or Google Gemini) according to the action you perform and the terms of your account with that provider.
AI provider data use
Product AI features run on a paid tier of Cloudflare Workers AI. GetsIt-managed agent execution runs on paid tiers of Cloudflare Workers AI and the Microsoft Azure OpenAI Service, and agents may additionally use the Anthropic API. Cloudflare states that it does not use customer content submitted to Workers AI to train models. Microsoft states that prompts and outputs sent to the Azure OpenAI Service are not used to train OpenAI or Microsoft models. Anthropic states that data submitted through its commercial API is not used to train generative models. If you connect a third-party key, those provider policies apply to that key.
Cookies and analytics
We use strictly necessary cookies for authentication and security. These are required for the service to work and are not optional.
We use Microsoft Clarity analytics only if you consent to analytics cookies. You can change your cookie choices at any time using Cookie preferences. More detail is available in our Cookie Policy.
We do not use advertising cookies or retargeting pixels.
Subprocessors and sharing
We share information with the following categories of service providers only as needed to operate the product:
Anthropic
Receives workspace context, task content, retrieved chunks, repository context, and user messages during agent execution. Used for AI reasoning in the agent runner.
Cloudflare (Workers AI)
Hosts the models behind product AI features. Receives meeting transcript text when an organizer requests post-meeting analysis, and receives task text, document text, and messages when you use task suggestions, writing assistance, document review, or managed agent conversations.
Microsoft (Azure OpenAI Service)
Hosts the frontier models offered through GetsIt-managed AI. When you select one of those models, it receives your messages together with the workspace, repository, or server context assembled for that turn, and returns the model output.
Google (Gemini API)
Receives content sent by users who connect a Google Gemini BYOK key.
OpenAI
Receives content sent by users who connect an OpenAI BYOK key or an organization Codex subscription. For Codex agent runs this can include prompts, retrieved workspace context, repository or server content, tool inputs and results, and agent outputs.
LiveKit
Provides video and audio infrastructure for live calls. Audio is processed transiently for transcription; raw audio is not stored after transcription.
XMPP messenger service
User display names, email addresses, and organization membership are synced to a self-hosted Prosody XMPP server that operates the workspace messaging feature. Chat messages pass through this server.
Microsoft Clarity
Receives browser interaction data only if you have consented to analytics cookies. Microsoft may process this data according to its own privacy documentation.
Hosting and database
Infrastructure providers store all application data and run the product.
We may also disclose information if required by law, to protect rights and security, or in connection with a corporate transaction such as financing, merger, acquisition, or sale of assets.
International data transfers
GetsIt AI and most of its subprocessors are based in or route data through the United States. If you access the service from the European Economic Area or the United Kingdom, your personal data is transferred internationally.
We rely on standard contractual clauses and the data processing terms of each subprocessor to provide appropriate safeguards for these transfers where required. Where a subprocessor operates under an adequacy decision or equivalent mechanism, we rely on that instead.
You can request information about the transfer mechanisms we use by contacting us at the address in the Your rights section.
Retention
We keep information for as long as needed to provide the service, comply with legal obligations, resolve disputes, maintain security, and improve the product. The following periods apply unless a longer legal retention obligation exists:
Sessions
Session tokens expire 30 days after they are issued. Expired sessions are deleted automatically.
Pending invites
Stored until the invited user registers, until the inviting workspace admin removes the invite, or until the workspace is deleted.
Account and workspace data
Retained while your workspace is active. Upon account or workspace deletion, we will delete primary application data. Derived retrieval index chunks, agent logs, and uploaded files are also deleted as part of workspace deletion.
Meeting transcripts and AI chat logs
Retained while the associated workspace is active. We are working to add configurable retention periods for these data types.
Uploaded files
Knowledge-base images and other uploaded files are retained until deleted by a workspace member or until the workspace is deleted.
Credentials and keys
API keys, Codex authorization state, GitHub and GitLab tokens, and server credentials are retained until removed by a workspace admin or until the workspace is deleted. Disconnecting Codex removes its stored authorization state from the active connection record.
Early-access customers can contact us to request deletion or export of workspace information, subject to security, legal, and operational limits.
Your rights
Depending on where you are located, you may have the following rights regarding your personal data:
EEA and UK (GDPR / UK GDPR)
Right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21), and rights related to automated decision-making (Art. 22). You also have the right to lodge a complaint with your local supervisory authority. If you are in the EU and do not know which authority applies, you may contact the Irish Data Protection Commission (dataprotection.ie) as a starting point.
California (CCPA)
Right to know what personal information is collected and how it is used, right to delete personal information, right to correct inaccurate personal information, and right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under CCPA.
Other US states
Residents of Virginia, Colorado, Connecticut, and other states with consumer privacy laws have similar rights to access, delete, correct, and opt out of certain processing. Contact us to make a request.
To exercise any of these rights, contact the GetsIt AI team using your normal support or founder contact channel. We will verify your identity and respond within the timeframe required by applicable law (30 days under GDPR; 45 days under CCPA).
Security
We use practical technical and organizational measures designed to protect accounts and workspace content, including HTTP-only session cookies, database access controls, org-scoped data isolation, and separation of product data from browser analytics consent.
Codex authorization state is envelope-encrypted using a cloud key-management key in production. Once that key is configured, new provider API keys use the same envelope encryption; guarded migration handles legacy records. Plaintext Codex state exists only in a process-specific restricted temporary directory while its App Server is active. GitHub and GitLab tokens and server SSH keys remain protected by database and host access controls while application-level encryption is extended to them.
No system is perfectly secure. Users should avoid adding secrets or highly sensitive information unless it is necessary for the workflow and appropriate protections are in place.
Changes to this policy
We may update this Privacy Policy as GetsIt AI changes, as we add providers or integrations, or as legal requirements evolve. The updated date above shows when this page was last revised. For material changes, we will provide notice through the product or by email.