Privacy Policy
Last updated: June 27, 2026
This Privacy Policy applies to www.apexgenius.ai and related domains owned by GAT Solutions LLC, a Florida limited liability company ("ApexGenius," "we," "us," "our").
ApexGenius provides a Model Context Protocol (MCP) server and skills library (the "Services") that securely connect your Salesforce org to the AI client of your choice — such as ChatGPT, Claude, or Cursor — for metadata analysis, code generation, deployment, and administration. This policy describes the types of information we collect, how we use it, who we share it with, how we secure it, and your rights regarding your information.
How the MCP Server handles your data
- Your AI conversation stays between you and your AI provider. When you use ApexGenius through an AI client (ChatGPT, Claude, Cursor, etc.), the prompts you send and the responses the model returns are exchanged directly between your AI client and the AI provider. They do not pass through ApexGenius's systems, and we do not store or log them. Your agreement with the AI provider governs its handling of that conversation.
- Salesforce record data is not persistently stored. When a tool you invoke needs record data, it transits our infrastructure only to perform that operation and may appear briefly in short-lived operational logs or caches; it is not stored in a database.
- What we retain is limited: the Salesforce metadata you choose to stage or index (code, flows, objects, fields — not record data), encrypted OAuth tokens for your connected org, account details, and high-level tool-usage logs that do not include record content.
- We never use your data to train AI models, and we contractually prohibit our sub-processors from doing so.
1. Scope of This Policy
This Privacy Policy governs personal information collected through the Platform, including the website, web application, APIs, and any related services. By accessing or using the Platform, you acknowledge that you have read and understood this policy. If you do not agree, you should not use the Platform.
This policy may be amended from time to time. Updates are effective upon posting. Continued use of the Platform after updates constitutes acceptance of the revised policy. We will notify users of material changes at least 30 days in advance via email or in-app notification.
2. Types of Information Collected
2.1 Account Information
When you create an account, we collect:
- Email address (for authentication and communications)
- Display name (if provided via Google OAuth)
- Organization name and project names you create
- Subscription and billing information (processed by Stripe; we do not store full payment card numbers)
2.2 Information from Salesforce and Other Integrations
When you connect a Salesforce organization, we access and process:
- Salesforce metadata: Apex classes, triggers, Flows, custom objects, fields, Lightning Web Components, Visualforce pages, permission sets, profiles, validation rules, and related configuration data
- Salesforce record data: Only when you explicitly use data query features (e.g., SOQL queries). Query results appear in chat responses and are subject to the same retention policy as all chat messages, which are deleted on request. You control which records you query.
- Object schemas and field definitions
What We Do NOT Permanently Store
- Salesforce record data is not persistently stored. It transits our infrastructure only to perform a requested operation and is returned to your AI client
- Salesforce login credentials (authentication uses OAuth 2.0 tokens only)
- Full payment card numbers (processed by Stripe)
When you connect other integrations (e.g., Jira, Confluence), we access data as authorized by the OAuth scope you approve during connection.
2.3 Chat and Conversation Data
- Queries, prompts, and messages you send through the Platform
- AI-generated responses and tool outputs
- Uploaded documentation files (.md format)
2.4 Usage and Technical Information
- Query counts and feature usage statistics
- Error logs and performance metrics
- Browser type, IP address, and device information (collected automatically)
- Pages accessed and time spent on the Platform
3. How We Collect Information
We collect information through the following methods:
- Directly from you: When you create an account, connect integrations, send messages, upload files, or contact support
- From Salesforce and integrations: When you authorize OAuth access, we retrieve metadata and configuration data from your connected organizations
- Automatically: Through authentication cookies. We do not use third-party tracking cookies, analytics pixels, or advertising trackers
- From payment processors: Stripe provides us with subscription status and billing information (not full card numbers)
3.1 Cookies
The Platform uses only essential authentication cookies. We do not use marketing cookies, analytics cookies, or third-party tracking cookies. No cookie consent banner is required because we only use strictly necessary cookies.
4. How We Use Your Information
We use collected information to:
- Provide, operate, and improve the Platform and Services
- Create and manage your account and workspace
- Process Salesforce metadata for AI-powered analysis, search, and recommendations
- Generate AI responses to your queries using third-party LLM providers
- Facilitate code generation, documentation, and deployment assistance
- Process payments and manage subscriptions
- Provide technical support and respond to inquiries
- Monitor for security incidents, fraud, and abuse
- Maintain audit logs for compliance purposes
- Communicate product updates and policy changes
- Comply with legal obligations and enforce our Terms of Service
AI Model Training
We do NOT use your queries, Salesforce data, or conversation history to train AI models. Anonymized, aggregated usage patterns (e.g., feature popularity, error rates) may be used for service improvement, but individual data is never used for training.
5. AI Providers and Data Processing
5.1 Which AI Providers We Use
The Platform uses the following large language model (LLM) providers via their enterprise API endpoints:
- Anthropic (Claude) — Privacy Policy
- OpenAI — Enterprise Privacy
- Google (Gemini) — Cloud Privacy Notice
- xAI (Grok) — Privacy Policy
- Groq (inference acceleration) — Privacy Policy
5.2 How Data Flows to AI Providers
When you use the Services through an AI client (ChatGPT, Claude, Cursor, etc.), your prompts and the model's responses are exchanged directly between your AI client and the AI provider — they do not pass through ApexGenius. ApexGenius exposes the tools the model calls to read and act on your Salesforce org, and returns the results of those tool calls to your AI client. Your agreement with the AI provider governs its handling of your prompts and responses. (We may separately use an AI provider for server-side functions such as generating search embeddings over your metadata; those providers act as our sub-processors and do not receive your AI conversation.)
Zero-Retention API Usage
All AI providers listed above operate under API terms that prohibit using customer data for model training. Prompts and responses are processed and discarded by the AI providers — they are not stored, logged, or used to improve their models. This is a contractual commitment from each provider under their enterprise/API data processing terms.
5.3 Bring Your Own Key (BYOK)
Enterprise customers may provide their own LLM API keys. When BYOK is enabled, your data is sent directly to the AI provider under your own account and API agreement. Your keys are stored using enterprise-grade encryption and are never stored in plaintext or shared.
6. Sensitive Data and Data Minimization
The Platform is designed to operate on Salesforce metadata (code, flows, objects, fields, and configuration) rather than on record-level data. Salesforce record data is only processed when you explicitly run a data query, and you control which records are returned.
We follow data-minimization principles, and you control which records you query. ApexGenius maintains HIPAA-compliant safeguards; Protected Health Information (PHI) is processed only under a signed Business Associate Agreement (BAA). If your use case involves PHI, contact us at support@apexgenius.ai to put a BAA in place.
Salesforce record data returned by a query transits our infrastructure only to fulfill your request and is not persistently stored. It is returned to your AI client, where your agreement with the AI provider governs its handling.
7. Information Sharing and Disclosure
We do not sell your personal information. We share information only in the following circumstances:
7.1 Third-Party Service Providers (Sub-Processors)
We use the following service providers to operate the Platform. Each provider accesses only the data necessary to perform their function:
| Provider | Purpose | Data Accessed |
|---|---|---|
| Supabase (AWS) | Database, authentication, vault encryption | All application data (encrypted at rest) |
| Anthropic | AI language model (Claude) | Prompts containing metadata context + user queries |
| OpenAI | AI language model | Prompts containing metadata context + user queries |
| AI language model (Gemini) | Prompts containing metadata context + user queries | |
| xAI | AI language model (Grok) | Prompts containing metadata context + user queries |
| Groq | AI inference acceleration | Prompts containing metadata context + user queries |
| Stripe | Payment processing | Billing information, subscription status |
| Vercel | Frontend hosting and CDN | Static assets, IP addresses (standard web serving) |
| DigitalOcean | Backend application hosting | Application runtime (all data encrypted in transit) |
| Upstash | Redis caching and rate limiting | Rate limit counters, metadata cache (no sensitive data) |
7.2 Legal Requirements
We may disclose information to courts, law enforcement, regulatory authorities, or government agencies to comply with legal obligations, subpoenas, court orders, or lawful requests; to enforce our Terms of Service; or to protect the rights, safety, or property of GAT Solutions LLC, our users, or the public.
7.3 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or asset sale, your information may be transferred to the successor entity. We will notify you of any such transfer and any changes to this Privacy Policy.
7.4 With Your Consent
We may share information when you direct us to, including through integrations you authorize (e.g., connecting Jira, exporting data).
8. How We Secure Your Information
We implement the following technical and organizational security measures:
| Protection | Implementation |
|---|---|
| Encryption at rest | Industry-standard encryption for credentials and stored metadata; OAuth tokens held as encrypted vault references |
| Encryption in transit | TLS encryption on all connections; HSTS enforced |
| Credential storage | OAuth tokens and API keys stored as encrypted vault references (never plaintext) |
| Multi-tenant isolation | Row-Level Security (RLS) on all database tables; per-user, per-organization, per-project scoping |
| Access control | JWT authentication, role-based access control (RBAC), per-user Salesforce authentication |
| Rate limiting | Per-user and per-API-key rate limits to prevent abuse |
| Audit logging | RPC call logs, RBAC change logs, error logs with retention policies |
| Credential handling | OAuth tokens and API keys stored as encrypted vault references; not written to application logs in plaintext |
| Security headers | Industry-standard security headers on all responses |
| Incident response | Formal Incident Response Policy with severity-based SLAs (Critical: 24-72hrs, High: 7-14 days) |
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents per our Incident Response Policy.
9. Data Retention and Deletion
We don't persistently store your Salesforce record data or your AI conversation.
Record data transits only to fulfill a request; your AI conversation stays between you and your AI provider. You can request deletion of the limited data we do retain at any time.
9.1 Retention Periods
| Data Type | Retention Period |
|---|---|
| AI prompts and responses | Exchanged directly between your AI client and the AI provider; not stored or logged by ApexGenius |
| Salesforce record data | Transits only to perform a requested operation; not persistently stored |
| Salesforce metadata | Duration of active project connection; deleted upon disconnection or account termination |
| Account information | Duration of account; deleted within 30 days of account termination |
| Audit logs (RBAC) | 90 days |
| Error logs | 30 days (critical errors retained longer) |
9.2 Immediate Deletion
You may request immediate deletion of your data at any time by contacting support@apexgenius.ai. We will process deletion requests within 30 days, except where retention is required by legal, regulatory, or compliance obligations.
10. HIPAA Compliance
ApexGenius maintains HIPAA-compliant safeguards for the Platform. HIPAA does not provide an official certification. These safeguards include:
- No record-data storage: Salesforce record data transits only to perform your request and is not persistently stored; connection credentials are encrypted at rest (AES-256-GCM)
- Audit logging: Access events and permission changes are logged
- Per-user Salesforce auth: Each team member authenticates with their own Salesforce credentials, respecting existing permission models
A signed Business Associate Agreement (BAA) is required before the Platform may be used to process Protected Health Information (PHI). If you connect the Platform to a third-party AI service such as ChatGPT, you are also responsible for using a HIPAA-eligible service and maintaining any separate BAA required with that provider. An ApexGenius BAA covers ApexGenius services only. Contact us at support@apexgenius.ai before any PHI use.
11. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of all personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your personal information and account data
- Data portability: Request an export of your data in a machine-readable format
- Withdraw consent: Revoke Salesforce access, disconnect integrations, or close your account at any time
- Opt-out of communications: Unsubscribe from marketing emails (transactional emails about your account will continue)
11.1 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at support@apexgenius.ai.
11.2 Exercising Your Rights
To exercise any of these rights, contact us at support@apexgenius.ai. We will respond within 30 days. We may verify your identity before processing requests. Rights may be restricted where retention is required by legal obligations.
12. Children's Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information. If you believe a child has provided us with personal information, please contact us at support@apexgenius.ai.
13. Third-Party Links
The Platform may contain links to third-party websites or services (e.g., Salesforce, Jira). We are not responsible for the privacy practices or content of these third-party services. We recommend reviewing their privacy policies before providing them with your information.
14. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the State of Florida, United States, without regard to its conflict of law principles. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of the State of Florida.
15. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Material changes will be communicated at least 30 days in advance via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after changes become effective constitutes acceptance of the revised policy.
16. Contact Us
If you have any questions about this Privacy Policy or how we handle your data:
- Email: support@apexgenius.ai
- Company: GAT Solutions LLC, Florida, United States
- We typically respond within 24-48 hours
© 2026 GAT Solutions LLC. All rights reserved.