Privacy Policy

Last updated: September 16, 2026

This Privacy Policy applies to www.apexgenius.ai and related domains owned by GAT Solutions LLC, a Florida limited liability company ("ApexGenius," "we," "us," "our").

ApexGenius provides an authenticated application programming interface (API), Model Context Protocol (MCP) gateway, and skills library (the "Services"). This policy describes the types of information we collect, how we use it, who we share it with, how we secure it, and your rights regarding your information.

How the authenticated API and MCP gateway handle your data

  • The ordinary MCP path does not intentionally retain your AI conversation. Your AI provider handles the prompt and model response under your agreement with that provider. ApexGenius receives the selected tool call and returns the tool result, not the full conversation transcript by design.
  • The ordinary MCP path does not intentionally retain Salesforce record results. Record data transits our infrastructure to perform the requested operation and return the result. Proposed writes, staging, approvals, errors, and diagnostics have the limited exceptions described below.
  • ApexGenius does retain service data. This includes operational, account, connection, encrypted credential, configuration, staging, usage, security, audit, and error data needed to operate and protect the Services.
  • We do not use Customer Data to train AI models. Your chosen AI agent and connected services handle data under your separate agreements with them.

1. Scope of This Policy

This Privacy Policy governs personal information collected through the Platform, including the website, web application, APIs, and any related services. By accessing or using the Platform, you acknowledge that you have read and understood this policy. If you do not agree, you should not use the Platform.

This policy may be amended from time to time. Updates are effective upon posting. Continued use of the Platform after updates constitutes acceptance of the revised policy. We will notify users of material changes at least 30 days in advance via email or in-app notification.

2. Types of Information Collected

2.1 Account Information

When you create an account, we collect:

  • Email address (for authentication and communications)
  • Display name (if provided via Google OAuth)
  • Organization name and project names you create
  • Subscription and billing information (processed by Stripe; we do not store full payment card numbers)

2.2 Information from Salesforce and Other Integrations

When you connect a Salesforce organization, we access and process:

  • Salesforce metadata: Apex classes, triggers, Flows, custom objects, fields, Lightning Web Components, Visualforce pages, permission sets, profiles, validation rules, and related configuration data
  • Salesforce record data: Only when an authenticated tool call requests records or performs an approved record operation. The ordinary MCP path does not intentionally write record results into conversation history or the application database. Proposed writes, error records, and diagnostic telemetry may retain limited request details as described in this policy.
  • Object schemas and field definitions

Gateway Content Boundary

  • The ordinary MCP path does not intentionally retain Salesforce record results or AI conversation content
  • Salesforce passwords are not stored. Supported connections use OAuth tokens or other approved credentials stored in encrypted form
  • Full payment card numbers are handled by Stripe and are not stored by ApexGenius

When you connect other integrations (e.g., Jira, Confluence), we access data as authorized by the OAuth scope you approve during connection.

YouTube API Services

ApexGenius uses YouTube API Services for its read-only YouTube and YouTube Analytics connections. With your Google authorization, it accesses channel identity and metadata, videos and playlists, non-monetary channel performance reports, and supported existing analytics groups and reporting resources. This access lets you request authorized channel information and reports through the API or your chosen AI client. The connections do not offer video uploads, publishing, comments, subscriptions, live-stream management, channel changes, or monetary analytics.

Requested YouTube results pass through the ApexGenius gateway to the AI client or API client that made the request. Your chosen AI provider may process and retain those results under your agreement with that provider. Review that provider's data practices before requesting YouTube data. Our hosting, database, encrypted credential storage, caching, and operational service providers described in Section 7 support this data flow.

We retain connection details, channel and resource identifiers, encrypted authorization credentials, and usage, audit, and error records. Previously imported reports may also remain stored separately from an ordinary tool response. The Salesforce-specific non-retention statements above do not mean that no YouTube data is stored. Section 9.3 explains disconnection, revocation, and deletion requests.

Google handles information under the Google Privacy Policy. You can review or revoke ApexGenius access through your Google account permissions. Use of the YouTube connection is also subject to the YouTube Terms of Service.

2.3 Gateway Requests, Staging, and Operational Data

  • Tool names and task-specific arguments selected by your AI agent
  • Metadata, files, configuration, and provider identifiers that you choose to stage, upload, sync, or save
  • Exact proposed write arguments while an approval is pending, when an approval feature is used
  • Content-minimized usage and audit records, including operation, outcome, timing, trace, and selected resource identifiers
  • Error summaries and diagnostic telemetry, which may contain limited request fragments when an operation fails

2.4 Usage and Technical Information

  • Tool names, query counts, feature usage, and service metering
  • Security, audit, error, trace, and performance records
  • Browser type, IP address, and device information (collected automatically)
  • Pages accessed and time spent on the Platform

3. How We Collect Information

We collect information through the following methods:

  • Directly from you: When you create an account, connect integrations, configure tools, stage content, invoke the Services, or contact support
  • From Salesforce and integrations: When you authorize OAuth access, we retrieve metadata and configuration data from your connected organizations
  • Automatically: Through essential authentication cookies, local or session storage used for product preferences and first-party attribution, and operational server logs. Google Analytics measures visits and conversion events on our public production website
  • From payment processors: Stripe provides us with subscription status and billing information (not full card numbers)

3.1 Cookies and Browser Storage

The Platform uses essential authentication cookies plus local and session storage for product preferences, safe return paths, setup progress, and first-party attribution. Google Analytics measures visits and conversion events on our public production website. Google Analytics loads automatically on public production pages and uses analytics cookies to measure visits and conversions. It is excluded from private product routes and development or preview sites. Our manually sent page-view and conversion events exclude account identifiers, form values, URL query strings, prompts, tool arguments, and connected-system data. Google Analytics also measures public-page interactions such as scrolls, outbound links, site searches, videos, and downloads. Advertising personalization and Google signals are disabled. You can control cookies through your browser or use the Google Analytics opt-out browser add-on. Clearing browser storage can sign you out or reset saved preferences.

4. How We Use Your Information

We use collected information to:

  • Provide, operate, and improve the Platform and Services
  • Create and manage your account, projects, connections, and approved staging
  • Authenticate and route authorized tool calls between your AI agent and connected services
  • Apply connection, permission, rate-limit, staging, and approval rules
  • Facilitate metadata analysis, code generation, documentation, and deployment assistance through the AI agent you select
  • Process payments and manage subscriptions
  • Provide technical support and respond to inquiries
  • Monitor for security incidents, fraud, and abuse
  • Maintain audit logs for compliance purposes
  • Communicate product updates and policy changes
  • Comply with legal obligations and enforce our Terms of Service

AI Model Training

We do not use Customer Data to train AI models. Aggregated operational patterns, such as feature popularity and error rates, may be used to improve the Services.

5. AI Agents and Connected Services

5.1 Your Chosen AI Agent

ApexGenius does not provide a public Chat product or select an AI model on your behalf for the ordinary MCP path. Your AI agent and AI provider handle your prompt, model response, and any conversation history under your separate agreement with that provider. The client sends a selected ApexGenius tool call to the gateway and receives the tool result.

5.2 Connected Services

A tool call may send authorized data to Salesforce or another connected service that you select. Each connected service handles that data under your agreement with it. ApexGenius records the operational, usage, security, audit, and error information described in this policy.

5.3 Credentials

Supported OAuth tokens, API credentials, and vault references are stored in encrypted form and are used only to operate the connection you authorize. They are not intentionally written to application logs in plaintext.

5.4 Google User Data and Limited Use

ApexGenius's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms: data from a Google connection (Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat, Contacts and Workspace directory, Tasks, Meet, Forms, Google Ads, YouTube, Analytics, or Search Console) is used only to carry out the request your AI agent makes through that connection and to show you the result. Each Google product is a separate connection that asks only for its own permissions, and ApexGenius reads or changes only the accounts, properties, lists, and files you enable for it. We do not use it for advertising, we do not sell it, and we do not transfer it to anyone other than your chosen AI provider as part of fulfilling your request, to service providers acting on our behalf, or as required by law. No person at ApexGenius reads it unless you ask us to for support, we need to for security or abuse investigation, or the law requires it.

You can revoke a Google authorization at any time from your Google account permissions or by disconnecting the connection in ApexGenius. Section 9 describes deletion.

6. Sensitive Data and Data Minimization

The Platform is designed to operate on Salesforce metadata (code, flows, objects, fields, and configuration) rather than on record-level data. Salesforce record data is only processed when you explicitly run a data query, and you control which records are returned.

Before processing Protected Health Information (PHI), confirm that the intended workflow, AI provider, Salesforce environment, and connected services meet your organization's policies and applicable law.

Contact us at support@apexgenius.ai before enabling a PHI workflow.

7. Information Sharing and Disclosure

We do not sell your personal information. We share information only in the following circumstances:

7.1 Third-Party Service Providers (Sub-Processors)

We use the following service providers to operate the Platform. Each provider accesses only the data necessary to perform their function:

ProviderPurposeData Accessed
Supabase (AWS)Database, authentication, storage, and vault encryptionAccount, configuration, staging, encrypted credential references, usage, security, audit, and error data
StripePayment processingBilling information, subscription status
Google AnalyticsPublic website audience and conversion measurementPublic page paths, referral origins, browser and device information, analytics cookie identifiers, and public signup or purchase events
VercelFrontend hosting and CDNStatic assets, IP addresses (standard web serving)
DigitalOceanGateway and backend hostingGateway content in transit and operational records
UpstashCaching, OAuth state, and rate limitingRequest identifiers, counters, temporary connection state, and approved cached content

7.2 Legal Requirements

We may disclose information to courts, law enforcement, regulatory authorities, or government agencies to comply with legal obligations, subpoenas, court orders, or lawful requests; to enforce our Terms of Service; or to protect the rights, safety, or property of GAT Solutions LLC, our users, or the public.

7.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or asset sale, your information may be transferred to the successor entity. We will notify you of any such transfer and any changes to this Privacy Policy.

7.4 With Your Consent

We may share information when you direct us to, including through integrations you authorize (e.g., connecting Jira, exporting data).

8. How We Secure Your Information

We implement the following technical and organizational security measures:

ProtectionImplementation
Encryption at restIndustry-standard encryption for credentials and stored metadata; OAuth tokens held as encrypted vault references
Encryption in transitTLS on supported ApexGenius web, API, database, and provider connections; HSTS on configured ApexGenius responses
Credential storageSupported OAuth tokens and API keys stored through encrypted vault or credential paths; legacy and provider-specific paths remain subject to review
Multi-tenant isolationTenant-scoped database policies on supported customer tables
Access controlJWT authentication, role-based access control (RBAC), per-user Salesforce authentication
Rate limitingPer-user and per-API-key rate limits to prevent abuse
Audit loggingRPC call logs, RBAC change logs, error logs with retention policies
Credential handlingSecrets are prohibited in prompts, source, evidence, and logs; runtime structured-field sanitization is an open verification item
Security headersSecurity-header middleware on primary web and API paths; complete response-path coverage remains a regression-evidence item
Incident responseFormal Incident Response Policy with severity-based SLAs (Critical: 24-72hrs, High: 7-14 days)

While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents per our Incident Response Policy.

9. Data Retention and Deletion

The ordinary MCP path does not intentionally retain Salesforce record results or AI conversation content.

ApexGenius does retain operational, account, connection, encrypted credential, configuration, staging, usage, security, audit, and error data. Historical web Chat records remain encrypted and are handled under the applicable retention, deletion, backup, and legal requirements.

9.1 Retention Periods

Data TypeRetention Period
AI conversation contentNot intentionally retained by ApexGenius on the ordinary MCP path; your AI provider applies its own retention terms
Salesforce record resultsNot intentionally retained on the ordinary MCP path; proposed writes, errors, and diagnostics may retain limited request details
Staged metadata and configurationRetained while needed for the selected staging, project, approval, or connection feature and then deleted under the applicable policy
Encrypted credentials and connection recordsRetained while the connection is active and for any limited period required for security, recovery, or legal obligations
Account informationRetained while needed to provide, secure, support, and evidence the account, then handled under the applicable deletion, backup, contractual, dispute, and legal requirements
Usage, security, audit, and error recordsRetained under documented operational, security, contractual, and legal requirements
Encrypted historical web Chat recordsNo new public or legacy web Chat content is accepted; existing records remain encrypted until an approved retention or deletion process handles them

9.2 Deletion Requests

You may request immediate deletion of your data at any time by contacting support@apexgenius.ai. We will process deletion requests within 30 days, except where retention is required by legal, regulatory, or compliance obligations.

9.3 YouTube Access and Stored Data

Disconnecting the YouTube Analytics connection stops its use in ApexGenius. It does not revoke the shared Google authorization used by your other Google connections, and it does not mean that all previously stored data has been deleted. To revoke Google authorization, use your Google account permissions. Revoking a shared authorization may also interrupt other Google connections in ApexGenius.

To request deletion of YouTube data held by ApexGenius, email support@apexgenius.ai with your ApexGenius account email and the relevant channel. Do not send passwords or authorization tokens. Deleting data held by ApexGenius does not delete your channel, videos, or data held by YouTube. Manage that content directly on YouTube. Data already returned to your chosen AI provider is also subject to that provider's deletion process.

YouTube's developer policies require deletion of stored user data within seven calendar days of a user request or account deletion, and within 30 calendar days of authorization revocation. These YouTube-specific deadlines govern YouTube data and take precedence over the general timeframe in Section 9.2. Disconnecting or revoking access is not a confirmation that deletion has finished; contact support for the status of your request.

YouTube's policies permit retention of authorized analytics only for the authorized purpose and require authorization checks at least every 30 days; other stored YouTube API data is subject to refresh or deletion limits. See the YouTube Developer Policies for these requirements.

10. PHI Use

Before processing Protected Health Information (PHI), confirm all of the following:

  • The intended workflow is authorized by your organization
  • Your AI provider, Salesforce environment, and connected services are approved for the intended use
  • Your configuration and operating procedures meet applicable privacy and security requirements

Contact us at support@apexgenius.ai before enabling a PHI workflow.

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of all personal information we hold about you
  • Correction: Request correction of inaccurate personal information
  • Deletion: Request deletion of your personal information and account data
  • Data portability: Request an export of your data in a machine-readable format
  • Withdraw consent: Revoke Salesforce access, disconnect integrations, or close your account at any time
  • Opt-out of communications: Unsubscribe from marketing emails (transactional emails about your account will continue)

11.1 California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at support@apexgenius.ai.

11.2 Exercising Your Rights

To exercise any of these rights, contact us at support@apexgenius.ai. We will respond within 30 days. We may verify your identity before processing requests. Rights may be restricted where retention is required by legal obligations.

12. Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information. If you believe a child has provided us with personal information, please contact us at support@apexgenius.ai.

13. Third-Party Links

The Platform may contain links to third-party websites or services (e.g., Salesforce, Jira). We are not responsible for the privacy practices or content of these third-party services. We recommend reviewing their privacy policies before providing them with your information.

14. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the State of Florida, United States, without regard to its conflict of law principles. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of the State of Florida.

15. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Material changes will be communicated at least 30 days in advance via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after changes become effective constitutes acceptance of the revised policy.

16. Contact Us

If you have any questions about this Privacy Policy or how we handle your data:

  • Email: support@apexgenius.ai
  • Company: GAT Solutions LLC, Florida, United States
  • We typically respond within 24-48 hours

© 2026 GAT Solutions LLC. All rights reserved.