Privacy & AI
AI Privacy Notice & Disclaimer
Last updated: July 4, 2026
What AI features do
Our AI assistants (Ava, Alex, and related tools) generate text responses to your prompts using large language models routed through our secure AI gateway. All AI calls are made from our backend — API keys are never exposed to the browser.
What we store
- Your prompts and the AI's responses, associated with an anonymous session id.
- Usage metadata: model name, latency, token counts, cost, and status.
- For client-portal users: the company id linked to the conversation.
Before storage, we automatically redact common patterns of personal data (email addresses, phone numbers, government IDs, credit-card-shaped numbers, IP addresses, and secret-looking tokens). Redaction is best-effort — please do not paste confidential information into the chat.
Who can see the logs
Only Umfress Business Solutions LLC administrators, authenticated through our portal, can view conversation logs and usage analytics. Every admin view is recorded in an audit log (who accessed what, and when).
Security controls
- HTTPS-only with strict transport security.
- All AI requests routed server-side; secrets never leave the backend.
- Admin dashboard gated by encrypted, http-only session cookies and role checks.
- Rate limits protect against abuse and runaway usage.
- Input validation, prompt-injection hardening, and payload size caps on every AI request.
- Row-level security locks conversation data behind the service role — never exposed to browsers.
Disclaimer — AI responses are informational only
AI-generated content may be inaccurate, incomplete, or out of date. It is provided for general informational purposes only and does not constitute legal, medical, financial, tax, accounting, or HR-compliance advice, and should not be relied on as such. Always consult a qualified professional before making decisions based on AI output.
Contact
Questions or requests about your data: contact us.
