Adhoc

Privacy & Data Commitments

Privacy & Data Commitments

Our commitments

We do not use your personal data to show you ads. We do not sell your personal data. We do not use your workspace content or conversations to train models unless you explicitly opt in to a contribution tier that covers that content. New workspaces start at Tier 0: no contribution. Free and paid accounts can stay at Tier 0. You can change the setting yourself in Settings > Privacy & Data; Poly and automations cannot change it for you.

What an opt-in means

The contribution ladder is additive. Tier 0: no contribution. Tier 1: pseudonymized structure, such as resource types and field schemas, without field values. Tier 2: Tier 1 plus pseudonymized usage patterns and AI reliability metadata, without prompt or response text. Tier 3: Tier 2 plus pseudonymized content with personal identifiers stripped, including conversation content. Pseudonymized data is still personal data. It is not the same as data that can never be linked back to a person.

What happens when you use AI

When you ask Poly or another AI feature for a result, the prompt and relevant context are sent to the selected model provider so it can answer. In the current development deployment, the covered model-call path passes through Cloudflare AI Gateway with request and response body collection disabled. Post-deployment network proof showed empty request and response fields and no stored prompts in Cloudflare's logs for every call in the proof window. The gateway setting limits Cloudflare's gateway logs; it does not prevent the selected model provider from reading the request. Zero-data-retention agreements with OpenAI and Anthropic have not been completed. We therefore do not promise that model providers retain nothing. The currently recorded standard endpoints are OpenAI Chat Completions and Text-to-Speech, and Anthropic Messages; none is marked contract-approved for zero retention yet. Three known paths are outside the covered gateway route today: OpenAI Realtime and HeyGen live voice/avatar sessions, direct Workers AI binding calls, and non-LLM provider capability calls. Those services receive the data needed to perform the feature you request.

Chat is not private from every operator yet

Direct-message users are represented to GetStream with opaque identifiers, but GetStream still processes message content. Chat content has not yet shipped the client-side encryption planned for a later privacy wave. Poly is gated by channel membership, but this is not a claim that the chat service cannot read messages.

Your choices

You can keep contribution at Tier 0, change it later, download your workspace data, or request erasure of prior contributions from Settings > Privacy & Data. Questions and rights requests can be sent to support@adhoc.app.