Privacy Policy

Last updated: June 27, 2026

This Privacy Policy applies to www.apexgenius.ai and related domains owned by GAT Solutions LLC, a Florida limited liability company ("ApexGenius," "we," "us," "our").

ApexGenius provides a Model Context Protocol (MCP) server and skills library (the "Services") that securely connect your Salesforce org to the AI client of your choice — such as ChatGPT, Claude, or Cursor — for metadata analysis, code generation, deployment, and administration. This policy describes the types of information we collect, how we use it, who we share it with, how we secure it, and your rights regarding your information.

How the MCP Server handles your data

  • Your AI conversation stays between you and your AI provider. When you use ApexGenius through an AI client (ChatGPT, Claude, Cursor, etc.), the prompts you send and the responses the model returns are exchanged directly between your AI client and the AI provider. They do not pass through ApexGenius's systems, and we do not store or log them. Your agreement with the AI provider governs its handling of that conversation.
  • Salesforce record data is not persistently stored. When a tool you invoke needs record data, it transits our infrastructure only to perform that operation and may appear briefly in short-lived operational logs or caches; it is not stored in a database.
  • What we retain is limited: the Salesforce metadata you choose to stage or index (code, flows, objects, fields — not record data), encrypted OAuth tokens for your connected org, account details, and high-level tool-usage logs that do not include record content.
  • We never use your data to train AI models, and we contractually prohibit our sub-processors from doing so.

1. Scope of This Policy

This Privacy Policy governs personal information collected through the Platform, including the website, web application, APIs, and any related services. By accessing or using the Platform, you acknowledge that you have read and understood this policy. If you do not agree, you should not use the Platform.

This policy may be amended from time to time. Updates are effective upon posting. Continued use of the Platform after updates constitutes acceptance of the revised policy. We will notify users of material changes at least 30 days in advance via email or in-app notification.

2. Types of Information Collected

2.1 Account Information

When you create an account, we collect:

  • Email address (for authentication and communications)
  • Display name (if provided via Google OAuth)
  • Organization name and project names you create
  • Subscription and billing information (processed by Stripe; we do not store full payment card numbers)

2.2 Information from Salesforce and Other Integrations

When you connect a Salesforce organization, we access and process:

  • Salesforce metadata: Apex classes, triggers, Flows, custom objects, fields, Lightning Web Components, Visualforce pages, permission sets, profiles, validation rules, and related configuration data
  • Salesforce record data: Only when you explicitly use data query features (e.g., SOQL queries). Query results appear in chat responses and are subject to the same retention policy as all chat messages, which are deleted on request. You control which records you query.
  • Object schemas and field definitions

What We Do NOT Permanently Store

  • Salesforce record data is not persistently stored. It transits our infrastructure only to perform a requested operation and is returned to your AI client
  • Salesforce login credentials (authentication uses OAuth 2.0 tokens only)
  • Full payment card numbers (processed by Stripe)

When you connect other integrations (e.g., Jira, Confluence), we access data as authorized by the OAuth scope you approve during connection.

2.3 Chat and Conversation Data

  • Queries, prompts, and messages you send through the Platform
  • AI-generated responses and tool outputs
  • Uploaded documentation files (.md format)

2.4 Usage and Technical Information

  • Query counts and feature usage statistics
  • Error logs and performance metrics
  • Browser type, IP address, and device information (collected automatically)
  • Pages accessed and time spent on the Platform

3. How We Collect Information

We collect information through the following methods:

  • Directly from you: When you create an account, connect integrations, send messages, upload files, or contact support
  • From Salesforce and integrations: When you authorize OAuth access, we retrieve metadata and configuration data from your connected organizations
  • Automatically: Through authentication cookies. We do not use third-party tracking cookies, analytics pixels, or advertising trackers
  • From payment processors: Stripe provides us with subscription status and billing information (not full card numbers)

3.1 Cookies

The Platform uses only essential authentication cookies. We do not use marketing cookies, analytics cookies, or third-party tracking cookies. No cookie consent banner is required because we only use strictly necessary cookies.

4. How We Use Your Information

We use collected information to:

  • Provide, operate, and improve the Platform and Services
  • Create and manage your account and workspace
  • Process Salesforce metadata for AI-powered analysis, search, and recommendations
  • Generate AI responses to your queries using third-party LLM providers
  • Facilitate code generation, documentation, and deployment assistance
  • Process payments and manage subscriptions
  • Provide technical support and respond to inquiries
  • Monitor for security incidents, fraud, and abuse
  • Maintain audit logs for compliance purposes
  • Communicate product updates and policy changes
  • Comply with legal obligations and enforce our Terms of Service

AI Model Training

We do NOT use your queries, Salesforce data, or conversation history to train AI models. Anonymized, aggregated usage patterns (e.g., feature popularity, error rates) may be used for service improvement, but individual data is never used for training.

5. AI Providers and Data Processing

5.1 Which AI Providers We Use

The Platform uses the following large language model (LLM) providers via their enterprise API endpoints:

5.2 How Data Flows to AI Providers

When you use the Services through an AI client (ChatGPT, Claude, Cursor, etc.), your prompts and the model's responses are exchanged directly between your AI client and the AI provider — they do not pass through ApexGenius. ApexGenius exposes the tools the model calls to read and act on your Salesforce org, and returns the results of those tool calls to your AI client. Your agreement with the AI provider governs its handling of your prompts and responses. (We may separately use an AI provider for server-side functions such as generating search embeddings over your metadata; those providers act as our sub-processors and do not receive your AI conversation.)

Zero-Retention API Usage

All AI providers listed above operate under API terms that prohibit using customer data for model training. Prompts and responses are processed and discarded by the AI providers — they are not stored, logged, or used to improve their models. This is a contractual commitment from each provider under their enterprise/API data processing terms.

5.3 Bring Your Own Key (BYOK)

Enterprise customers may provide their own LLM API keys. When BYOK is enabled, your data is sent directly to the AI provider under your own account and API agreement. Your keys are stored using enterprise-grade encryption and are never stored in plaintext or shared.

6. Sensitive Data and Data Minimization

The Platform is designed to operate on Salesforce metadata (code, flows, objects, fields, and configuration) rather than on record-level data. Salesforce record data is only processed when you explicitly run a data query, and you control which records are returned.

We follow data-minimization principles, and you control which records you query. ApexGenius maintains HIPAA-compliant safeguards; Protected Health Information (PHI) is processed only under a signed Business Associate Agreement (BAA). If your use case involves PHI, contact us at support@apexgenius.ai to put a BAA in place.

Salesforce record data returned by a query transits our infrastructure only to fulfill your request and is not persistently stored. It is returned to your AI client, where your agreement with the AI provider governs its handling.

7. Information Sharing and Disclosure

We do not sell your personal information. We share information only in the following circumstances:

7.1 Third-Party Service Providers (Sub-Processors)

We use the following service providers to operate the Platform. Each provider accesses only the data necessary to perform their function:

ProviderPurposeData Accessed
Supabase (AWS)Database, authentication, vault encryptionAll application data (encrypted at rest)
AnthropicAI language model (Claude)Prompts containing metadata context + user queries
OpenAIAI language modelPrompts containing metadata context + user queries
GoogleAI language model (Gemini)Prompts containing metadata context + user queries
xAIAI language model (Grok)Prompts containing metadata context + user queries
GroqAI inference accelerationPrompts containing metadata context + user queries
StripePayment processingBilling information, subscription status
VercelFrontend hosting and CDNStatic assets, IP addresses (standard web serving)
DigitalOceanBackend application hostingApplication runtime (all data encrypted in transit)
UpstashRedis caching and rate limitingRate limit counters, metadata cache (no sensitive data)

7.2 Legal Requirements

We may disclose information to courts, law enforcement, regulatory authorities, or government agencies to comply with legal obligations, subpoenas, court orders, or lawful requests; to enforce our Terms of Service; or to protect the rights, safety, or property of GAT Solutions LLC, our users, or the public.

7.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or asset sale, your information may be transferred to the successor entity. We will notify you of any such transfer and any changes to this Privacy Policy.

7.4 With Your Consent

We may share information when you direct us to, including through integrations you authorize (e.g., connecting Jira, exporting data).

8. How We Secure Your Information

We implement the following technical and organizational security measures:

ProtectionImplementation
Encryption at restIndustry-standard encryption for credentials and stored metadata; OAuth tokens held as encrypted vault references
Encryption in transitTLS encryption on all connections; HSTS enforced
Credential storageOAuth tokens and API keys stored as encrypted vault references (never plaintext)
Multi-tenant isolationRow-Level Security (RLS) on all database tables; per-user, per-organization, per-project scoping
Access controlJWT authentication, role-based access control (RBAC), per-user Salesforce authentication
Rate limitingPer-user and per-API-key rate limits to prevent abuse
Audit loggingRPC call logs, RBAC change logs, error logs with retention policies
Credential handlingOAuth tokens and API keys stored as encrypted vault references; not written to application logs in plaintext
Security headersIndustry-standard security headers on all responses
Incident responseFormal Incident Response Policy with severity-based SLAs (Critical: 24-72hrs, High: 7-14 days)

While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents per our Incident Response Policy.

9. Data Retention and Deletion

We don't persistently store your Salesforce record data or your AI conversation.

Record data transits only to fulfill a request; your AI conversation stays between you and your AI provider. You can request deletion of the limited data we do retain at any time.

9.1 Retention Periods

Data TypeRetention Period
AI prompts and responsesExchanged directly between your AI client and the AI provider; not stored or logged by ApexGenius
Salesforce record dataTransits only to perform a requested operation; not persistently stored
Salesforce metadataDuration of active project connection; deleted upon disconnection or account termination
Account informationDuration of account; deleted within 30 days of account termination
Audit logs (RBAC)90 days
Error logs30 days (critical errors retained longer)

9.2 Immediate Deletion

You may request immediate deletion of your data at any time by contacting support@apexgenius.ai. We will process deletion requests within 30 days, except where retention is required by legal, regulatory, or compliance obligations.

10. HIPAA Compliance

ApexGenius maintains HIPAA-compliant safeguards for the Platform. HIPAA does not provide an official certification. These safeguards include:

  • No record-data storage: Salesforce record data transits only to perform your request and is not persistently stored; connection credentials are encrypted at rest (AES-256-GCM)
  • Audit logging: Access events and permission changes are logged
  • Per-user Salesforce auth: Each team member authenticates with their own Salesforce credentials, respecting existing permission models

A signed Business Associate Agreement (BAA) is required before the Platform may be used to process Protected Health Information (PHI). If you connect the Platform to a third-party AI service such as ChatGPT, you are also responsible for using a HIPAA-eligible service and maintaining any separate BAA required with that provider. An ApexGenius BAA covers ApexGenius services only. Contact us at support@apexgenius.ai before any PHI use.

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of all personal information we hold about you
  • Correction: Request correction of inaccurate personal information
  • Deletion: Request deletion of your personal information and account data
  • Data portability: Request an export of your data in a machine-readable format
  • Withdraw consent: Revoke Salesforce access, disconnect integrations, or close your account at any time
  • Opt-out of communications: Unsubscribe from marketing emails (transactional emails about your account will continue)

11.1 California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at support@apexgenius.ai.

11.2 Exercising Your Rights

To exercise any of these rights, contact us at support@apexgenius.ai. We will respond within 30 days. We may verify your identity before processing requests. Rights may be restricted where retention is required by legal obligations.

12. Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information. If you believe a child has provided us with personal information, please contact us at support@apexgenius.ai.

13. Third-Party Links

The Platform may contain links to third-party websites or services (e.g., Salesforce, Jira). We are not responsible for the privacy practices or content of these third-party services. We recommend reviewing their privacy policies before providing them with your information.

14. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the State of Florida, United States, without regard to its conflict of law principles. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of the State of Florida.

15. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Material changes will be communicated at least 30 days in advance via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after changes become effective constitutes acceptance of the revised policy.

16. Contact Us

If you have any questions about this Privacy Policy or how we handle your data:

  • Email: support@apexgenius.ai
  • Company: GAT Solutions LLC, Florida, United States
  • We typically respond within 24-48 hours

© 2026 GAT Solutions LLC. All rights reserved.