Privacy Policy

Your information deserves clear protection.

This policy explains how Gulfstream Intelligence collects, uses, discloses, and protects personal information and customer content when you use our website, platform, and related services.

Effective date: July 29, 2026

Privacy at a glance

  • We do not sell customer content or personal information.
  • We do not use customer content to train, fine-tune, evaluate, or improve AI models.
  • Gulfstream personnel do not review customer content in ordinary operations.
  • We process content only to provide the functionality you request.
  • You can contact us to exercise applicable privacy rights.
01

Scope and our role

This policy applies to Gulfstream Intelligence's public website, platform, applications, support, sales, and related services (collectively, the "Services"). It does not apply to third-party products or websites that have their own privacy policies.

If your employer or another organization provides your account, that organization generally controls the customer content and account data submitted through its workspace. In that context, Gulfstream generally acts as a service provider or processor on the organization's instructions. Please direct requests about organization-controlled content to your organization first.

Gulfstream acts as a controller or business for information collected directly through our website, sales process, account administration, billing, security, and our own service operations.

02

Information we collect

We collect information you provide, information created through your use of the Services, and limited technical information collected automatically.

Account and organization information

Name, work email, password hash, organization name and email, account role, preferences, verification status, and team invitations.

Customer content

Projects, product and indication details, submission plans, documents, prompts, chats, assessments, simulations, reports, outputs, and other material you upload or create.

Usage and technical information

IP address, browser and device information, log and audit events, timestamps, feature activity, model selection, token usage, referral data, and diagnostic information.

Billing and commercial information

Plan, billing cycle and status, subscription identifiers, transaction status, and related business records. Payment card details are collected by Stripe, not Gulfstream.

Communications

Sales inquiries, support requests, feedback, company information, and messages you send to us.

Integration information

If you enable an integration such as SharePoint, we process the account details, encrypted authorization tokens, selected files, and sync activity needed to provide it.

We may also receive information from your organization's administrators, authorized integrations, payment providers, referral sources, and publicly available sources you ask the Services to use.

03

How we use information

  • Provide, operate, maintain, and personalize the Services.
  • Authenticate users, manage organizations and permissions, and keep accounts secure.
  • Process prompts, documents, projects, assessments, simulations, and submission-planning workflows.
  • Provide customer support, service notices, verification messages, and responses to sales inquiries.
  • Administer trials, subscriptions, billing, invoices, and related records.
  • Monitor reliability, prevent abuse, investigate incidents, enforce agreements, and maintain audit trails.
  • Analyze and improve service performance, features, and user experience using aggregate, de-identified, or technical telemetry rather than customer content.
  • Comply with law and protect the rights, safety, and integrity of Gulfstream, our customers, and others.

Where applicable law requires a legal basis, we rely on performance of our contract, our legitimate interests in operating and securing the Services, your consent, and compliance with legal obligations, as appropriate to the activity.

04

AI processing and customer content

The Services use AI models provided by OpenAI and Anthropic. To generate a response, Gulfstream may send the selected provider the prompt, relevant project context, retrieved document excerpts, instructions, and other content needed for the requested feature. The provider used may depend on your selection and the workflow.

Program Mode is designed to ground responses in approved project content and designated regulatory sources. General Mode supports broader research and drafting. In both modes, only submit information you are authorized to process.

Customer content is not training data

Gulfstream does not use customer content to train, fine-tune, evaluate, benchmark, or improve any Gulfstream or third-party AI model. We do not add customer content to development, testing, demonstration, or model-evaluation datasets, and we do not opt customer content into voluntary provider data-sharing or model-improvement programs.

We use approved commercial API services whose applicable business terms and settings provide that API inputs and outputs are not used for model training by default. These providers process only the content needed to deliver the feature you request. Provider retention for limited service, security, or abuse-prevention purposes is separate from model training and is governed by the applicable provider terms, settings, and contractual commitments. Contact us for current subprocessor or contractual information relevant to your organization.

Unless a written agreement with Gulfstream expressly permits it, the standard Services are not intended to process protected health information or directly identifying patient information and are not offered as a validated electronic records or electronic-signature system under 21 CFR Part 11. Do not submit data subject to heightened legal requirements or rely on the Services as the sole authoritative repository for regulated records. Customers are responsible for appropriate authorization, minimization, and de-identification before submission.

05

How we disclose information

We disclose information only as needed to provide the Services, follow your instructions, operate our business, protect the Services, or comply with law. Our material provider categories include:

Google Cloud

Cloud hosting, databases, file storage, networking, security, and service operations.

OpenAI and Anthropic

AI inference, analysis, generation, and related model functionality selected within the platform.

Stripe

Checkout, payment processing, subscriptions, invoices, and fraud prevention.

Google email services

Account verification, password reset, transactional messages, and support communications.

Microsoft

SharePoint and Microsoft Graph functionality, only when an authorized user enables the integration.

We may also disclose information to professional advisers, auditors, insurers, authorities when legally required, and parties to a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate safeguards. Organization administrators may access information associated with their workspace. We do not sell customer content or personal information, disclose customer content to advertisers or data brokers, or share one customer's content with another customer.

06

Cookies and similar technologies

Essential service storage

We use cookies and browser storage for sign-in, session continuity, email verification, security, preferences, and theme settings. Authentication cookies generally expire after one day for access and 30 days for refresh, unless cleared earlier.

When enabled, Google's advertising and measurement tag may collect campaign, device, cookie, and interaction information to measure website conversions. Third-party checkout and integration pages may also use their own cookies. You can control non-essential cookies through browser settings and, where presented, consent tools, though blocking essential storage may prevent the Services from working.

We do not use customer content for advertising and do not knowingly sell or share personal information for cross-context behavioral advertising.

07

Retention and deletion

We retain information for as long as needed to provide the Services, maintain your account or organization, meet contractual commitments, resolve disputes, protect security, and comply with legal, regulatory, tax, accounting, and audit obligations. Retention depends on the information's nature and the customer's configuration. Retained customer content is not used for AI training or model improvement.

Removing a project or account from the active interface may not immediately erase every copy. Certain project records, chat or simulation history, audit events, transaction records, and backups may be retained where required for traceability, security, fraud prevention, legal claims, contractual commitments, or system recovery. When retention is no longer necessary, we delete, aggregate, or de-identify the information according to our operational processes.

A routine project removal is a retirement or soft-delete action so project history remains traceable. A verified privacy deletion request is handled separately: information is removed from active application systems where technically and legally permitted, while only narrowly required audit, transaction, legal, or backup records are retained.

08

Security

Founder-controlled access with no routine content review

As of this policy's effective date, Gulfstream Intelligence is developed and operated by its founder and CEO as sole developer. Within Gulfstream, the founder is the only human authorized to access the application source code and production administration. There is no employee engineering or support team, and no contractor has standing access to customer content.

Privileged administrative access is not permission to inspect customer content. Gulfstream does not read or review customer documents, prompts, chats, reports, or outputs as part of ordinary operations, analytics, product development, quality assurance, demonstrations, or AI evaluation.

Exceptional human access to customer content would occur only when a customer explicitly requests and authorizes support that requires it, when access is reasonably necessary to investigate a security or reliability incident affecting the Services, or when required by law. Any such access is limited to the minimum information and time necessary, used only for that purpose, and logged where technically feasible. Gulfstream does not disclose customer content except at the customer's direction, to the service providers identified in this policy as necessary to operate the Services, or when legally required.

Gulfstream's founder maintains ongoing training in cybersecurity, privacy, and life-sciences regulatory practice and applies that training to the design, development, and operation of the Services.

We use administrative, technical, and organizational measures designed to protect information, including encryption in transit and at rest, access controls, credential and secret management, tenant-aware permissions, logging, backups, and security monitoring. The Services are hosted on Google Cloud, and private or isolated deployment options may be available by agreement.

No method of transmission or storage is completely secure. Customers must protect account credentials, configure organization access appropriately, and notify us promptly of suspected unauthorized access.

09

International transfers

Gulfstream and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws that differ from those in your jurisdiction. Where required, we use contractual and other safeguards intended to support lawful international transfers.

10

Your privacy rights

Depending on your location and our relationship with you, you may have rights to access, correct, delete, or obtain a copy of personal information; restrict or object to processing; withdraw consent; opt out of certain disclosures; or appeal a denied request. We will not discriminate against you for exercising applicable rights.

Send requests to contact@gulfstreamlifescience.com. We may verify your identity and authority before responding. If your account is managed by an organization, contact its administrator for requests concerning organization-controlled customer content.

You may also unsubscribe from optional marketing messages using the link in the message. Service, security, billing, and account communications may continue while your account remains active.

11

Changes to this policy

We may update this policy to reflect changes in our Services, providers, or legal obligations. We will post the updated policy with a revised effective date and, where required, provide additional notice through the Services or by email.

12

Contact us

Questions, concerns, or privacy requests can be sent to Gulfstream Intelligence at:

Gulfstream Intelligence

contact@gulfstreamlifescience.com

Please include "Privacy Request" in the subject line and identify the account or organization connected with your request.

This policy describes Gulfstream's current privacy practices and is not a substitute for customer-specific contractual terms, data processing agreements, or legally required notices.

Learn how Gulfstream governs AI use

Review our intended-use, oversight, and controlled-source principles.

AI Governance