Legal · Pre-launch draft

Draft Privacy Notice

A non-executed description of the data handled by the current account, workspace, Guard and optional Composer code. It does not describe preview billing, marketplace or Memory-indexing features as live.

Draft pending legal review

Pre-launch draft only. This is not an executed privacy policy and has not been approved by counsel. Public signup and billing are closed; no real AI provider is connected by default.

Effective date: not yet effective — draft updated 27 August 2026

1.Draft status and operator

This page is a pre-launch technical privacy draft. It has not been approved by counsel, is not the executed privacy policy for a paid service, and does not make a representation that the current deployment satisfies a particular privacy framework.

GenCMS is developed and operated by iGears Technology Limited in Hong Kong. Privacy questions about this draft can be sent to [email protected].

  • Address: Unit 23B, Block 4, Golden Dragon Industrial Centre, 182–190 Tai Lin Pai Road, Kwai Chung, New Territories, Hong Kong.
  • Telephone: +852-2117-8811.
  • Public signup and account billing are closed in the current launch posture; administrators create and assign member accounts.

This description is limited to behavior implemented in the repository. Hosting, reverse-proxy and infrastructure logging or retention must be reviewed separately before an operative notice is issued.

2.Records the application stores

RecordCurrent fields and purpose
AccountName, email, role, language preference, active/disabled status, timestamps and a scrypt password hash for account access.
SessionSession and account identifiers, creation/expiry times, optional user-agent text and authentication method. Approved-IP administrator sessions also carry the bound IP.
Approved-IP administrator auditWhen that optional path is enabled and attempted: timestamp, outcome, trusted client IP and, for a successful event, the administrator identifier. The application rotates the current audit file after it exceeds 1 MB and retains one previous file.
TenantTenant name, slug, active/suspended status, member assignment and an optional Hong Kong or Canada AI gateway assignment.
WorkspaceSkill-install records, Memory collections and sources, Agent/Workflow/App drafts, policy settings and activity metadata, all stored under an admin or tenant scope.
Workspace API keyName, scopes, hash, prefix/last four characters, creator, expiry, revocation and last-use timestamps. The plaintext secret is returned once and is not stored.
Tenant AI keyKey alias, assigned gateway, enabled abilities, budget and rate limits, lifecycle/synchronization state, spend summaries and a hash used to verify the derived gateway secret. The one-time plaintext key is not returned again.

The current application uses JSON files in its configured server data directory for these low-volume records. This draft does not promise a database, replication or backup service.

3.Sessions and scoped API keys

Password sign-in sets the gc_session HTTP-only cookie. The cookie is signed, backed by a revocable server-side session, and marked Secure in production. Users can list active session metadata and revoke another session.

Workspace API keys can carry workspace:read, workspace:write, guard:scan and composer:run scopes. The application stores a SHA-256 hash rather than the plaintext secret and checks expiry, revocation, scope and active workspace status when a key is used.

API-key creation, listing and revocation require a signed-in browser session. Account and administration routes do not accept a workspace API key.

The optional approved-IP administrator path uses the trusted proxy IP, configured administrator and strict public origin. It is disabled unless the operator supplies every required setting. Successful, rate-limited and configuration-failure attempts are recorded in the rotating approved-IP audit described above; session tokens and secrets are not included.

4.Workspace records are not an AI Memory service

A Memory source record can contain a title, supplied text, URL, MIME type, byte-size value, metadata and status. The current Memory APIs store and return those fields; they do not fetch the URL, upload a referenced file, extract text, create chunks or embeddings, retrieve context, generate citations or export a collection.

Skill installations and Agent, Workflow and App entries are stored records or drafts. The current backend does not download or execute marketplace packages and does not run those drafts.

Record-level APIs can update or delete a source, collection, install or draft. Deleting a collection also deletes its source records from the current workspace JSON store. This is not a promise about backups, infrastructure logs or a general account-erasure workflow.

5.Composer gateway transmission

If a tenant has a ready region-locked AI key with chat enabled, an authorized Composer request sends the submitted prompt and optional system instruction to AIHK in Hong Kong or AICA in Canada, according to that tenant assignment. The response is returned to the caller.

The current code does not accept a caller-selected provider and does not auto-route a prompt to the other region or an outside provider.

When Composer activity saving is enabled, activity may contain gateway and model identifiers, latency, token counts, upstream status and a short failure reason. The activity helper deliberately excludes prompts, system instructions and model output.

A platform administrator can enter a short-lived, visibly labelled, read-only Shadow tenant support view. It changes the workspace scope used for reads and rejects mutations; it does not sign the administrator in as a tenant member.

6.Guard request and activity data

Guard accepts an exact public github.com repository target or content supplied directly in the request. Public GitHub collection is performed by the GenCMS server. Arbitrary URL and MCP fetching, private-repository traversal, redirect following and ZIP upload are disabled.

For direct paste, the scanner analyses the request content without making a network fetch. The current application code does not add anonymous scans to workspace activity.

For a signed-in or API-key scan, optional workspace activity can contain target type, score, risk label, files and bytes scanned, finding count or a short failure reason. It deliberately excludes the repository URL, pasted content and full report.

The in-process rate limiter can use a trusted client IP for anonymous requests. It is not the product analytics or billing system described in earlier previews.

7.Activity settings and limits

A workspace policy can turn Composer or Guard activity saving on or off and carries an activity-retention-days value from 1 to 730. The default code value is 90 days. Activity is filtered by that value when listed and old scoped entries are pruned when new activity is appended, subject to fixed record-count ceilings.

That application setting is not a general retention schedule for accounts, Memory sources, sessions, provider records, server logs or backups. The current build has no complete account-deletion, bulk-export or backup-rotation workflow.

8.Payments, cookies and analytics

The current site has no connected subscription, checkout, payment-method, invoice, credit-metering, marketplace-purchase or publisher-payout system, so the application does not collect payment details for those features.

The repository sets the gc_session cookie for authentication. It does not include an advertising-cookie, cross-site tracking or product-analytics integration. Deployment-level access or security logs are outside this application description.

Project services are fixed-price and documented in a separate quotation. Any personal data needed for a quotation or project must be described in the applicable engagement documents rather than inferred from this draft platform notice.

9.What this draft does not promise

This draft does not state fixed deletion or response deadlines, a backup schedule, encryption for every stored field, a hosting region, international-transfer mechanism, provider or subprocessor list, analytics arrangement, security certification, incident-notification period or data-portability guarantee.

Before broader account access or real provider processing is enabled, counsel and the operator should review the deployed hosting, logging, support and customer arrangements and publish an operative notice that matches them.

Questions or requests can be sent to [email protected]. This draft does not promise a response timetable beyond obligations that may apply under law or an accepted project agreement.