GNI AI Solutions operates an AI-native trading intelligence system ("ISSIE").
This policy describes what data passes through our public gateway
(api.gni-ai-solutions.com) and how it is handled.
What we process
For ordinary authenticated PWA chat, the current message and a bounded attention-state projection are sent to OpenAI through the ChatGPT Codex subscription to generate a reply. Prior chat turns are not forwarded.
Jev first classifies each non-command chat turn using only the current message, a small attention-state projection, and a static context-pack catalog. Jev runs through OpenRouter's TypeSafe SystemOne service; it does not receive file or memory contents. Exact attention commands and link-only messages are handled locally and skip Jev.
When Jev selects a relevant context pack, the gateway retrieves at most two allowlisted packs from local PWA/attention documents, the existing non-persisting GNI context compiler, read-only Engram episodic memory, or the local wiki/second-brain allowlist (up to 4,200 excerpt characters total) and sends those excerpts, with source references and SHA-256 hashes, to GPT-6. Engram material is episodic and unverified, not canonical truth. No full-disk scan is performed and chat turns are not written into compiler history.
Authentication tokens (Bearer tokens / session cookies) used to secure the gateway.
Basic request metadata (timestamps, IP addresses, and route status) for security and rate limiting. Provider request bodies and Jev classifications are not written to application logs.
If you use a PWA response-feedback button, the selected label and attention-judgment hash are appended to a local calibration file. No message text is stored, and labels do not automatically train models or change authority policy.
Team operational state served to authorized clients.
Provider processing
OpenAI and OpenRouter process the data sent to their services under their respective terms and privacy policies. GNI does not control provider-side retention. The Jev key remains server-side and is never sent to the browser. Jev only returns typed classifications; it cannot execute actions.
What GNI does not do
GNI does not sell personal data or use message content for advertising or profiling.
The PWA does not forward prior chat turns, invoke arbitrary tools, or execute external actions.
GNI does not retain PWA chat transcripts on the gateway; session cookies are HttpOnly, Secure, SameSite, and expire after 1 hour.
Data retention
Pending queue messages: 72 hours maximum.
Response records: 72 hours maximum.
Ledger entries: 30 days.
Replay-protection acknowledgements: 5 minutes.
Security
All gateway traffic is served over TLS via Cloudflare Tunnel. Authentication is
enforced with Bearer tokens; the founder session uses a rotating CSRF token.
Rate limiting is applied to login attempts.
Contact
For privacy inquiries, contact the GNI operations team via the gateway
health endpoint (/api/health) or the team state endpoint.