Privacy Policy
GovernKit is a governance tool, so we hold ourselves to the standard we help you apply to every other vendor. This policy describes exactly what we collect, why, and what we deliberately never touch.
Last updated: July 7, 2026
1. Who we are
GovernKit is a product of Zyref, LLC (“Zyref”, “we”, “us”). This policy covers our marketing website at governkit.ai and the GovernKit application at app.governkit.ai. For anything in this policy, you can reach us at hello@governkit.ai.
When your employer or team uses GovernKit, the team decides what governance records to keep and we process them on the team's behalf. Our Data Processing Addendum describes that relationship in detail.
2. What we collect
Account information
When you create an account we collect your name and email address, and a password that is stored only as a salted hash. We never see or store it in plain text. If you enable two-factor authentication, we store your TOTP secret and hashed single-use backup codes. We also store your email notification preferences and whether your email address has been verified.
Governance records
These records are the product itself. On behalf of your team, we store:
- Team names, departments, member roles, and invitations.
- AI tool requests: the tool name, vendor, category, a description of the intended use, and the categories of data the requester says will touch the tool.
- Review decisions, decision notes, and approval conditions.
- AI usage policies, their versions, and who acknowledged which version, when.
- An audit log of governance events, including requests, approvals, rejections, policy publications, acknowledgements, role changes, and billing events.
Billing information
Payments are processed by Stripe. We store your team's plan, subscription status, and Stripe customer and subscription identifiers. Your card details go directly to Stripe and never touch our servers.
AI feature usage
Plans include a monthly allowance of AI credits. To meter this fairly, we record each AI call: which team member ran it, which feature and model were used, and the token counts involved. These are the same numbers we display back to you on your usage page. We do not store the prompts or responses of these calls beyond the drafts and assessments saved into your workspace.
Technical data
The application sets only essential cookies: a session cookie to keep you signed in and a CSRF cookie to protect forms. Our web server keeps standard access logs (IP address, user agent, requested URL) for security and debugging. We may use error monitoring that captures technical context when something breaks, such as stack traces. This is not surveillance.
When you contact us
If you write to hello@governkit.ai or use the contact form on our website, we receive what you submit: your name, email address, message, and, from the form, the topic and company size you selected. We use it only to reply. Contact form submissions are delivered to us as email through Brevo, the same provider that handles our transactional email. They do not subscribe you to anything.
When you sign up for launch updates
If you ask to be notified about upcoming integrations or product updates on our website, we store your email address in Brevo together with a tag for where you signed up (a specific integration's waitlist, or the general product-updates form in the footer), and we use it for exactly one thing: telling you when the things we're building launch. It does not subscribe you to a newsletter or any other mailing, and you can unsubscribe from any of these emails or ask us to remove your address at any time at hello@governkit.ai.
3. What we deliberately don't collect
The safest data is data we never hold. GovernKit does not collect, and has no mechanism to collect:
- Prompts or AI conversation content. We govern which tools are approved. We never see what anyone types into them.
- Your files or confidential documents. The request form asks employees to describe their use case, never to paste the sensitive content itself.
- Browsing activity, traffic, or screen data. There are no browser extensions, agents, or network monitoring of any kind.
Our marketing website at governkit.ai is a static site: it sets no cookies and runs no third-party analytics or advertising trackers.
4. How we use information
- To run the service: authenticate you, route requests to the right reviewers, publish policies, and keep the audit trail your team relies on.
- To send transactional email: decisions on your requests, new requests for reviewers, overdue-request and policy-acknowledgement reminders, role changes, vendor policy-change alerts, billing updates, invitations, and account security notices (email verification, sign-in links, password and email changes). Each notification type can be switched off individually in your settings; security notices about your own account and payment-failure alerts are always sent. We send no marketing or newsletter email at all, except for launch updates you explicitly request on our website (section 2), which you can unsubscribe from at any time.
- To power AI features you invoke: see section 6.
- To bill your team: through Stripe, based on your plan and the AI credit usage described above.
- To keep the service secure and working: server logs and error reports.
We do not sell personal information, use it for advertising, or share it with data brokers. There is no third-party analytics on either site.
Legal bases (GDPR)
Where GDPR applies, we rely on:
| Legal basis | What it covers |
|---|---|
| Contract performance | Running the service you signed up for, including accounts, workflows, and the audit trail. |
| Legitimate interests | Security (server logs, error reports) and essential service email you can't opt out of. |
| Consent | The optional notification types you can toggle in settings. |
| Legal obligation | Billing and tax records. |
5. Vendor documents we read
GovernKit's vendor vetting fetches public documents published by AI vendors, including their privacy policies and terms of service, and analyzes them so your reviewers don't have to. These are public web pages about companies, not personal data about you. We keep recent snapshots so we can show you exactly what changed; snapshots older than 180 days are automatically deleted unless a finding still cites them.
6. Service providers we share data with
We share data only with the providers needed to run GovernKit, and only what each one needs:
- Stripe: payment processing and invoices. Receives your email and billing details you enter into Stripe's own forms.
- Brevo: delivers our transactional email. Receives recipient addresses and message content.
- OpenAI: powers the AI features, including drafting your AI usage policy from your questionnaire answers, drafting tool documentation, and analyzing vendors' public documents. Receives only the text needed for the specific task: your team name, questionnaire answers, tool names and descriptions, or a vendor's public policy text. It never receives your members' names or email addresses. This guarantee is enforced by an automated regression test in our codebase. Under OpenAI's API terms, this data is not used to train their models. (Risk suggestions on requests are computed by our own rules from the declared data types. No AI involved.)
- Amazon Web Services: hosts the application and its database, encrypted in transit and at rest.
- Cloudflare: serves the marketing website and provides front-end performance and security (CDN, DDoS protection). Cloudflare sees standard connection metadata but has no access to application or database data.
- Sentry: collects crash and error reports (stack traces and request metadata) so we can fix problems quickly.
Beyond these providers, we disclose information only if required by law, or as part of a merger or acquisition. In that case, this policy continues to apply to your data.
7. Retention and deletion
You can delete your account yourself, immediately.In account settings, choose “Delete account”, confirm with your account email and current password, and the deletion happens right away. There is no waiting period and no support ticket. Your credentials, two-factor secrets, backup codes, memberships, acknowledgements, and pending invitations to your email are deleted. Governance records that belong to your team's audit trail (for example, a decision you made as a reviewer) are retained by the team but re-attributed to “Deleted user”, with your name and email scrubbed from the audit text because they document the team's governance, not you. You'll receive a confirmation email.
One guard rail: if you own a team that other people still use, deletion is blocked (with an explanation) until you transfer ownership or the team winds down. Teams where you are the only member are deleted with your account. If you can't sign in to delete your account, email hello@governkit.ai from your account address and we'll take care of it.
Beyond deletion, data ages out on fixed schedules:
- Invitations: accepted, revoked, or expired invitations are purged 90 days after settling; overdue pending invites expire automatically.
- Login sessions: expired sessions are purged daily.
- AI usage records: deleted after 24 months (Stripe retains the financial record).
- Vendor document snapshots: pruned after 180 days, except those cited by an active finding.
- Governance records: requests, decisions, policies, acknowledgements, and the audit log are kept for the life of the team, because a defensible audit trail is the point of the product. Team owners control these records.
- Server logs and error reports: kept for a short operational window and then rotated out.
8. Your rights
The two most common data rights are self-serve. No email is required:
- Access and portability: download everything we hold about you as JSON from account settings (“Your data”): profile, memberships, requests, messages, acknowledgements, audit activity, and AI usage.
- Erasure: delete your account from account settings, immediately, as described in section 7.
- Correction: edit your name, email, password, two-factor settings, and notification preferences directly in settings.
For anything else, including restriction, objection, or questions about portability, email hello@governkit.ai and we'll respond within 30 days. For governance records processed on behalf of your team, we may redirect your request to your team's administrators, who control that data. If you're in the EU or UK, you also have the right to lodge a complaint with your local supervisory authority.
9. Security
Passwords are stored as salted hashes, two-factor authentication is available to every user, access is role-based, teams are fully isolated from each other, all traffic is encrypted in transit with TLS, and the database and its backups are encrypted at rest. Our security overview covers this in more depth. If we ever learn of a breach affecting your personal data, we will notify affected customers without undue delay.
10. International transfers
Zyref, LLC is a United States company, and our service providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses. Our Data Processing Addendum has the details.
11. Children
GovernKit is a workplace tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.
12. Changes to this policy
If we make material changes, we'll update the date at the top and notify account holders by email before the changes take effect. Continued use of GovernKit after that means you accept the updated policy.
13. Contact
Zyref, LLC · hello@governkit.ai