Genthropic Privacy Policy

This Privacy Policy explains what personal data Genthropic ("Genthropic", "we", "our", or "us") processes, why we process it, who receives it, and what rights you have when using our website, services, and ModusBrain AI agent platform.

We do not sell personal data under any circumstances.

Who is responsible for the processing?

Genthropic is the data controller for personal data described in this Privacy Policy when we process data for our own business purposes, such as running our website, managing user accounts, processing billing, providing customer support, enforcing security, and improving our product.

If you interact with an AI agent or workflow created by one of our customers using ModusBrain or Genthropic infrastructure, that customer is the controller of the data collected through the agent. In that scenario, Genthropic acts as a data processor on that customer's behalf according to the customer's instructions and our Data Processing Agreement (DPA).

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at genthropic@gmail.com.

1. As a visitor to the Genthropic website

Data we process

When you visit our website, we may process:

  • Consent preferences stored in local browser storage or essential functional cookies;
  • Anonymized performance metrics, page visits, referral sources, and aggregated usage events;
  • Technical details such as device type, browser version, operating system, and general geographic location (country level); and
  • Technical and security logs generated by our hosting infrastructure and security layers.

Why we process it

We process visitor data to:

  • Operate, maintain, secure, and optimize our website performance;
  • Analyze aggregate usage patterns to enhance user experience;
  • Remember user privacy choices; and
  • Detect and prevent abuse, fraudulent traffic, and cyber security threats.

Depending on your jurisdiction and context, we rely on:

  • Legitimate Interests: Operating, securing, and maintaining a functional website; and
  • Consent: For optional analytics or tracking cookies where required by applicable law.

Cookies & Storage

We utilize strictly necessary session storage and cookies to maintain security and consent choices. Non-essential cookies are only enabled with your explicit consent.

2. As a user of Genthropic & ModusBrain

Data we process

When you register an account, configure AI agents, or use ModusBrain, we process:

  • Account Data: Name, email address, profile picture, organization/workspace details, and authentication credentials;
  • Billing & Transaction Data: Subscription status, invoice history, and payment details processed via secure payment providers (e.g., Stripe);
  • Product Telemetry & Usage: Logs of platform activity, API usage counters, and features accessed;
  • Agent Configurations & Knowledge Base Content: AI agent prompt templates, workflow schemas, uploaded documents, knowledge base data, and integration parameters stored in your workspace; and
  • Third-Party Integration Tokens: Encrypted API keys or OAuth tokens for connected services (e.g., OpenAI, Anthropic, GitHub, Google Workspace, custom webhooks).

Why we process it

We process account data to:

  • Deliver, host, and maintain the ModusBrain platform and Genthropic services;
  • Authenticate users, verify identities, and manage account security;
  • Process subscription payments, manage invoicing, and prevent billing fraud;
  • Provide technical customer support and respond to inquiries;
  • Monitor platform uptime, prevent infrastructure abuse, and investigate technical incidents;
  • Continually improve agent capabilities and user experience; and
  • Comply with legal, financial, and tax obligations.
  • Contract Performance: Fulfilling our commitment to provide requested software and services;
  • Legal Compliance: Satisfying regulatory, tax, and accounting requirements; and
  • Legitimate Interests: Protecting our infrastructure, preventing fraud, and delivering continuous service improvements.

Service Providers & Sub-processors

We engage trusted third-party sub-processors for hosting, database management, file storage, payment processing, error monitoring, and communication.

All sub-processors operate under strict confidentiality and data protection agreements compliant with applicable privacy laws. Our primary infrastructure partners include tier-1 cloud providers, encrypted storage solutions, and secure payment processors.

Third-Party AI Integrations

When you connect external AI models or third-party APIs (such as OpenAI, Anthropic, or custom endpoints) within ModusBrain:

  • Credentials are encrypted at rest using industry-standard AES-256 encryption;
  • Data is transmitted strictly to fulfill the specific workflows you configure; and
  • Third-party model providers process data according to your API agreements and their respective privacy policies. We do not allow third-party model providers to train public models on your private workspace data.

3. As an end-user interacting with a Genthropic AI Agent

If you interact with an AI agent deployed by a Genthropic customer:

  • Customer Control: The customer determines what information is requested, how it is used, and how long it is retained;
  • Processor Role: Genthropic hosts, processes, and transmits your interactions solely on behalf of the customer;
  • No Data Selling: Genthropic never sells end-user conversation data and never uses end-user submissions for targeted advertising; and
  • Inquiries: Requests regarding specific chat data or personal information collected by an agent should be directed to the customer operating that agent.

4. Data Security

We implement rigorous technical and organizational measures to safeguard data against unauthorized access, loss, or alteration:

  • Encryption: All data in transit is protected using TLS 1.3 encryption, and sensitive workspace credentials are encrypted at rest using AES-256;
  • Access Control: Strict role-based access controls and multi-factor authentication for infrastructure access;
  • Monitoring & Auditing: Continuous security monitoring, vulnerability assessments, and automated threat detection; and
  • ISO 27001 Alignment: Information security management practices structured according to ISO/IEC 27001 standards.

5. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes described in this Privacy Policy:

  • Account Data: Maintained for the duration of your active account;
  • Account Deletion: Upon account deletion requests, active data is purged or anonymized within 30 days, except where legal or financial retention obligations apply;
  • Backup Retention: Encrypted fallback backups are retained for up to 30 days as part of disaster recovery cycles before permanent purging; and
  • Customer Agent Data: Customer-managed agent responses and logs are retained according to workspace settings and contract terms.

6. Your Rights

Subject to local privacy laws (such as GDPR, UK GDPR, and CCPA/CPRA), you may have the right to:

  • Request access to personal data held about you;
  • Request correction of inaccurate or incomplete personal data;
  • Request erasure ("right to be forgotten") of your personal data;
  • Request restriction of or object to certain processing activities;
  • Receive a portable, machine-readable copy of your personal data; and
  • Withdraw consent at any time where processing relies on consent.

To exercise your rights, contact us at genthropic@gmail.com.

7. Changes to this Privacy Policy

We may periodically update this Privacy Policy to reflect technical enhancements, service updates, or legal changes. Material revisions will be posted on this page with an updated date.

8. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please reach out to:

Genthropic
Email: genthropic@gmail.com
Community & Support: Join Genthropic Community

Last updated: March 23, 2026