Privacy Policy
What we keep, what we don't, where it lives, who processes it, and your rights — in plain English.
Last updated: August 7, 2026
Who we are
OPS GNETICS is operated by Technologies GNETICS Inc. ("GNETICS", "we"), based in the province of Québec, Canada. We process personal information in accordance with Québec's Law 25 (Act respecting the protection of personal information in the private sector) and applicable Canadian law. This policy explains what we collect through ops.gnetics.ca and its products, and how we handle it.
What we collect
- Email address — provided at signup for account recovery and account-level notifications (billing, key rotation).
- Agent contributions (OPS Memory) — patterns and notes your agent writes via
POST /api/v1/contribute. Stored inside your tenant only. - Business profile & catalog (OPS Profile) — the company information you enter (sector, website, socials, brand voice, ICP) and your product/offer catalog.
- Security scans (OPS Security) — the domain(s) you verify as yours and the passive scan results (headers, TLS, DNS, exposure). We read only publicly served responses of your own site.
- Build sandbox content (OPS Build) — the files and secrets you place in your isolated environment (secrets are encrypted at rest).
- Media content (OPS Media) — prompts and generated assets, handled through the connected content platform under your account.
- Billing data — handled by Stripe; we store a customer/subscription reference, never full card numbers.
- Basic request logs — timestamp, route, status, tenant id, for operations and abuse detection. Request bodies are not persisted in operational logs.
What we don't do
- No third-party analytics, tracking pixels, advertising cookies, or session-replay tools.
- We do not sell or rent your data, and we do not use your contributions or content to train third-party models.
- We do not republish your data outside your tenant.
Subprocessors
We rely on a minimal set of providers, each strictly necessary to run the Services and bound to appropriate protection:
- Hostinger — hosting of the Canadian server where tenant data lives.
- Stripe, Inc. — PCI-DSS-compliant payment processing.
- OpenRouter and the AI model providers it routes to — used to generate content (OPS Media) and power the assistant chatbot. Prompts you send to these features may be processed on infrastructure outside Canada. Do not put sensitive personal data in generation prompts.
- Email delivery — for transactional messages (access kits, notifications).
Where your data lives
Tenant data is stored on a Canadian server hosted by Hostinger. Data does not leave the host except for the specific subprocessor calls listed above (payment tokens to Stripe; generation prompts to AI providers). There is no offsite analytics shipper and no cross-border database replica.
Cross-tenant isolation
Every row carries a tenant_id; every read and write — agent search, contribute, dashboard, security scans, profile, catalog — is scoped by the tenant_id derived from your credentials. A tenant cannot, under any supported API, read or enumerate another tenant's data. This invariant is verified by an automated isolation test suite on every change; if it breaks, the build does not ship.
Operator access — least-privilege and traced
As operator we hold the database, so a privileged read path technically exists. We use it only for abuse investigation, billing disputes, or a binding legal request from a Canadian court of competent jurisdiction. Such access is least-privilege and traced. We never use it to satisfy curiosity, to mine tenants in bulk, or for marketing.
Your rights (Law 25)
You have the right to access, rectify and withdraw your personal information, and to data portability where applicable. You can export your patterns from Settings → Export, edit your profile/catalog directly, and delete everything yourself (below). For any other request, or to reach our person in charge of personal information protection, write to contact.gnetics@gmail.com. If a breach of confidentiality presenting a risk of serious injury occurs, we will notify affected users and the Commission d'accès à l'information as required by Law 25.
Retention and deletion
We retain your data while your account is active. You can delete your tenant and all attached data from Settings → Danger zone — an irreversible, single-transaction deletion covering patterns, contributions, profile, catalog, scans and audit rows. We keep no shadow copies. Minimal billing records may be retained where required by law.
Security
We apply appropriate technical and organizational measures: database-level tenant isolation, encrypted secrets vault for OPS Build, HTTPS in transit, credentials stored hashed, and controlled network egress. No system is perfectly secure, but we treat your data as our own.
Cookies
We use only what is necessary to keep you signed in (a session token in your browser's storage). No advertising or tracking cookies.
Changes & contact
If we materially change what we collect, where it lives, or who can access it, we will update the Last updated date and post a note before the change takes effect. Questions, access or deletion requests: contact.gnetics@gmail.com. See also our Terms of Service and Sales Terms.