Draft, attorney review pending. This notice describes our current practices accurately to the best of our knowledge and will be replaced with attorney-reviewed language before general commercial release.

Privacy Policy

Last updated: September 3, 2026

Genstrata, Inc. ("Genstrata," "we," "us"), a Delaware corporation, operates Apograph at apograph.ai (the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights available to you. Capitalized terms not defined here have the meaning given in the Terms of Service at /terms.

1. Our role

For account, usage, technical, and contact-form data, Genstrata is the controller (the business responsible for the data).

For personal data that a Customer submits or directs us to collect about recipients and prospects, the Customer is the controller and Genstrata is a processor (service provider) acting on the Customer's instructions under our Data Processing Addendum at /dpa. If you are a recipient of a message drafted with Apograph and have a question about your data, see Section 8.

2. Information we collect

From account holders and Authorized Users:

  • Account information: name and email address when you sign in through Google or by email. Access is invite-only.
  • Work product: prospects, dossiers, drafts, voice samples, review decisions, and related files you upload or generate in the desk.
  • Voice samples: stored as text (your writing and transcripts of your speech) used to build and score a voice profile for your tenant. Live dictation may send microphone audio to a transcription service to produce that text. We do not keep a biometric voiceprint in the Apograph database.
  • Usage data: timestamps, feature use, gate outcomes, error logs, and similar operational metadata.
  • Technical data: IP address, browser user-agent, and request headers needed to operate and secure the Service.

About recipients and prospects (submitted by Customers or gathered at their direction):

  • Professional identity: name, title, employer, and public professional profile information.
  • Contact details: business email address and other contact information the Customer supplies, including from tenant-uploaded lists and the Customer's own LinkedIn connection exports.
  • Public professional activity: publications, filings, public statements, and similar information gathered from public sources at the Customer's direction.
  • Interaction history: whether a draft to the recipient was Held, Cleared, sent, or declined by the Customer.

We do not collect or intentionally process sensitive categories of personal data (such as health, biometric identifiers, or precise geolocation) about recipients, and Customers are prohibited from submitting it.

From visitors to the public site: contact form name, email address, optional organization, and message.

3. How we use information

  • Provide the Service: draft in your voice, research recipients you designate, run voice and claim gates, and present work for your review.
  • Verify material claims in drafts through GauntletScore, Genstrata's verification component.
  • Build and score a voice profile scoped to your tenant. We do not use your content to train models that serve other customers.
  • Authenticate invite-only access and prevent unauthorized use.
  • Communicate with you about the Service, including replies to contact-form mail and notices required by these policies.
  • Secure the Service, prevent abuse, debug, and comply with law.

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.

Automated processing. The Service uses automated tools to research recipients, draft messages, and score drafts. Every draft is presented to a human for review before it can be sent. The Service does not make decisions that produce legal or similarly significant effects about any person without human involvement.

4. AI providers and verification

Drafting, research, and voice scoring send relevant text (which may include a recipient's name and professional details) to third-party large-language-model providers. Claim verification is performed by GauntletScore, a Genstrata-operated component, which sends extracted claims and, where the check requires it, surrounding draft text to the AI and research providers listed on the GauntletScore subprocessors page. GauntletScore's in-memory anonymization for submitted documents does not apply to Apograph drafting, because a draft names the recipient.

Each AI provider we use processes data under commercial API terms that restrict use of submitted data for model training. Providers may retain API data for a limited period for abuse monitoring under their terms. The current list is on the Subprocessors page at /subprocessors.

5. How we share information

  • with the subprocessors listed on /subprocessors, to provide the Service;
  • within your tenant: a Customer's administrators can see the work product of the tenant's Authorized Users;
  • with recipients, when you choose to send a draft (sending is always your action);
  • when required by law, subpoena, or governmental request, or to protect the rights, safety, or property of Genstrata, our users, or others;
  • in connection with a merger, acquisition, financing, or sale of assets, in which case this policy continues to apply to your data until you are told otherwise.

6. Security

We use encryption in transit (TLS) and at rest, tenant-scoped access controls enforced at the database layer (row-level security), least-privilege access for Genstrata personnel, and logging of administrative access. No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected Customers without undue delay and within 72 hours where required by law, and will support Customers in meeting their own notification obligations.

7. Retention

DataRetainedThen
Account data and work productWhile your tenant is active (dossiers, drafts, and voice profile are the product)Export window of 30 days after termination, then deleted from live systems
Deleted tenant dataPurged from live systems within 30 days of terminationBackups age out within 90 days
Operational and security logs90 daysDeleted or aggregated
Contact-form correspondence24 months from last contactDeleted
Recipient dataPer the Customer's instructions and for as long as the Customer's tenant retains itDeleted with the tenant

You may request earlier deletion at any time (Section 8). We may retain information longer where required by law or to resolve disputes.

8. Your rights and choices

Depending on where you live you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights email privacy@genstrata.com.

  • We respond within 30 days (45 days where California law applies), and will tell you if we need longer.
  • We verify identity before acting on a request, using the email associated with your account or other reasonable means.
  • You may designate an authorized agent to make a request on your behalf; we may ask the agent for proof of authorization.
  • We will not discriminate against you for exercising your rights.
  • You can unsubscribe from non-essential email using the link in the message. Service notices cannot be opted out of while your account is active.

If you are a recipient or prospect: where a Customer is the controller of your data, we will refer your request to that Customer and help them respond. Genstrata does not currently operate a cross-tenant suppression list; a do-not-contact request is handled by the Customer that holds your record.

Appeals. If we decline a request you may appeal by replying to our response. Residents of some U.S. states may also contact their state attorney general.

9. Cookies

See our Cookie Policy at /cookies. We use only strictly necessary and functional cookies and similar storage. We do not use advertising or analytics cookies.

10. Children

Apograph is not intended for, and may not be used by, anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us personal data, contact privacy@genstrata.com and we will delete it.

11. International transfers

Genstrata is based in the United States. Our infrastructure providers process data in the United States. Some AI providers may process data in other regions under their terms. The Service is currently offered without a dedicated EU or UK data-residency option. If you access the Service from outside the United States, your data will be transferred to and processed in the United States.

12. Changes

We may update this policy. The last-updated date at the top will change, and for material changes we will notify account holders by email before the change takes effect.

13. Contact

Privacy requests: privacy@genstrata.com. General questions: info@genstrata.com.

Genstrata, Inc., a Delaware corporation.

Legal: legal@genstrata.com. Privacy: privacy@genstrata.com. Security: security@genstrata.com. General: info@genstrata.com.

Postal address for service of process: write legal@genstrata.com for the current Delaware registered-agent street address on file with the Division of Corporations.

Back to Apograph