1. Scope
This policy covers genxis.com, gavel.genxis.com, the Gavel dashboard, API, CLI interactions with the Gavel API, builder waitlist forms, and strategic partner forms.
2. Measurement without cookies
Public marketing pages set no marketing analytics cookies. Our bridge records aggregate, anonymous measurement so we can understand how the site is used: page path, referrer category, viewport size, dark-mode preference, page performance, scroll depth, and outbound link hostnames. Session identifiers live in your browser's session storage and end with the tab. We do not create a persistent visitor identifier for public marketing analytics, and Global Privacy Control is honored. Form field values are never part of measurement.
The Gavel dashboard, account flows, payment flows, and API tools may use session storage, authentication tokens, API keys, payment-provider storage, or equivalent security state needed to sign in, protect accounts, operate checkout, prevent abuse, and keep the service working.
3. Network information
Any web request exposes information such as IP address, user agent, and request metadata to the servers involved. GenXis and its infrastructure providers process this only for content delivery, security, abuse prevention, and troubleshooting.
4. What you send through our forms
The builder waitlist and strategic partner forms are validated in your browser and sent over our bridge to the GenXis team. We use what you send to reply to you and to understand who is interested in working with us. Submissions pass through automated spam controls (hidden fields, timing, and rate limits) and are retained as long as reasonably needed for that purpose.
5. Providers and disclosure
We rely on hosting, security, payment, and email delivery providers to run the site and Gavel service, process checkout, deliver account messages, and protect the service. Current named providers are listed on the GenXis subprocessor page. We do not sell what you send us. We may disclose information when required by law, to protect rights or safety, or in connection with a corporate transaction.
6. Gavel product artifacts
When you use GenXis Gavel, remote verification receives the artifact content and metadata you explicitly submit, such as artifact name, stage, idempotency key, account identity, check result, receipt root, verifier policy metadata, operational logs, and billing metadata. The public API does not crawl your repository.
Artifacts and receipts are retained to operate the verification service, support replay, prevent duplicate billing, investigate abuse, and satisfy legal obligations. Unless a separate agreement says otherwise, product artifacts are retained while the account is active and for up to 90 days after account closure or a verified deletion request, except that receipts, ledgers, security records, billing records, dispute records, and legal-hold material may be retained longer where integrity, fraud prevention, tax, accounting, dispute, or legal requirements require it.
Gavel uses HTTPS in transit and provider controls for stored service data. Submitted source or artifacts are not used to train foundation models unless a separate written agreement says otherwise.
7. Accounts, payments, and logs
Account records may include email address, authentication events, API key metadata, key labels, credit balances, purchase history, and administrative actions. Payment processing may include checkout session identifiers, transaction metadata, tax information, and receipts handled by our payment provider. Operational logs may include IP address, user agent, request metadata, rate-limit state, error records, webhook delivery state, and security events. Operational logs are normally kept up to 12 months unless needed longer for security, abuse, disputes, accounting, or legal obligations.
8. Your choices
You can enable Global Privacy Control, close the tab to clear public-page session storage, or choose not to submit a form or artifact. To ask about access, correction, or deletion of anything you sent us, email privacy@genxis.com or use the form on the homepage and say what you need; we may ask for information to verify the request.
9. Security and location
We use reasonable safeguards, but no system is completely secure. Providers may process information outside your jurisdiction, subject to applicable legal safeguards.
10. Children
This site is for business audiences and is not directed to children under 13.
11. Changes
We may update this policy as the site changes. The date above identifies the current version.
