Genesis Gateway

LEGAL

Privacy Notice

Last updated 29 September 2026

1. Who we are

Genesis Gateway is operated by VICTOR BRZEZINSKI, based at Office 7761OX, 3 Fitzroy Place, Area 1/1, Sauchiehall Street, Glasgow City Centre, G3 7RH, Scotland, United Kingdom. For the personal data described in this notice, that operator is generally the controller unless we expressly agree otherwise with a business customer.

For privacy or support questions, contact [email protected].

2. What this notice covers

This notice explains how Genesis handles personal data when you create or use an account, authenticate, buy or use Genesis Credits, create or use API keys, connect an application to Genesis Gateway, contact support, or otherwise use the service.

If you send personal data about another person through Genesis, you are responsible for having an appropriate legal basis or permission to do so. Where Genesis processes personal data solely on the documented instructions of a business customer, separate data-processing terms may also apply.

3. Data we process

  • Account data: email address, display name, avatar, account status, plan, user identifiers and account settings.
  • Authentication data: OAuth provider and provider-account identifiers, session records, security tokens and records associated with login or session security. Genesis does not store your Google or Discord password.
  • Billing and tax data: purchase and top-up status, amounts, Genesis ledger entries, Stripe/customer/payment references, billing country or location information supplied during payment, refund or dispute information, and tax information where needed to process or account for a transaction. Full card details are handled by Stripe rather than stored by Genesis.
  • API and security data: API-key metadata and secure key verifiers, request and session identifiers, account/tenant identifiers, rate-limit events, abuse or fraud signals, security events and technical diagnostics.
  • Network and coarse location data: an IP address or network address may be processed transiently to establish and secure a connection. Genesis may derive coarse country, region, city or approximate geographic coordinates from that address for reliability, latency, security and capacity analysis. The observability system is designed not to persist the raw IP address as part of that coarse-location telemetry.
  • Usage and performance data: routing mode, provider/model or route identifiers, metering information such as tokens, characters, audio duration or similar usage measurements, timestamps, WebSocket/network round-trip measurements, latency-stage measurements, capacity utilisation, failures, error classes and billing/settlement status.
  • Service content: text, audio and generated content supplied during a request may be processed transiently so Genesis and the relevant AI/speech providers can perform functions such as speech recognition, language-model inference, routing and speech synthesis.
  • Support data: information you choose to provide when you contact us, including correspondence and information needed to investigate an account, technical or billing issue.

Genesis does not intentionally retain raw voice audio, speech-to-text transcripts, prompts or generated conversation content in its normal application logs or observability telemetry after the live processing needed to fulfil the request. Service content may still be processed transiently in memory and transmitted to the provider selected for the request. Third-party providers may apply their own limited retention or abuse-monitoring practices under their contracts and privacy terms.

4. Why we use personal data and our legal bases

  • Providing the service and performing our contract: creating and securing your account, authenticating you, processing requests, routing AI/speech workloads, maintaining Genesis Credits and the usage ledger, providing transaction history and responding to service requests.
  • Legitimate interests: preventing fraud and abuse, protecting accounts and infrastructure, diagnosing failures, measuring latency and reliability, monitoring provider capacity, improving routing, planning capacity, investigating incidents and maintaining the security and commercial operation of Genesis.
  • Legal obligations: keeping accounting, tax and transaction records; responding to lawful requests; and complying with legal or regulatory requirements that apply to us.
  • Consent: where the law requires consent for a specific activity, we will ask for it separately. We do not rely on this general Privacy Notice as consent where specific consent is required.

Where we rely on legitimate interests, those interests are to operate, secure, measure and improve Genesis without using more personal data than is reasonably necessary for those purposes.

5. Who receives data

Genesis uses third parties for hosting, databases, networking, authentication, payments, tax support and AI/speech processing. Depending on the feature and routing configuration, these may include providers such as Hetzner, Neon, Stripe, Google, Discord, OpenRouter, Cerebras, OpenAI, Inworld, Cartesia and other or replacement providers used for the same purposes.

Genesis may dynamically choose or change the provider, model, voice or route used for a request. Service content and the minimum metadata needed to perform a request may therefore be transmitted to one or more relevant processors. We do not sell your personal data to advertisers.

We may also disclose information where reasonably necessary to comply with law, protect rights or security, investigate fraud or abuse, or support a corporate transaction such as a reorganisation, financing or sale, subject to applicable legal requirements.

6. International transfers

Some providers may process personal data outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, Genesis will rely on an applicable lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard available under the relevant provider agreement.

7. Retention

  • Account/profile data: while your account is active and normally for up to 24 months after closure, unless a longer period is reasonably needed for legal, fraud, security or dispute purposes.
  • Payment, ledger, tax and accounting records: normally up to 6 years where needed for accounting, tax, refunds, chargebacks, disputes or legal claims.
  • Detailed operational, usage, latency and coarse-location telemetry: normally up to 90 days, except where a record is needed to support billing, investigate abuse, diagnose a serious incident or resolve a dispute.
  • Routine security records: normally up to 90 days. Records relating to a security incident, fraud investigation or dispute may be kept longer while that matter remains active or where required by law.
  • Terms and legal-acceptance records: normally up to 6 years after the relevant account relationship ends.
  • Support correspondence: normally for as long as reasonably needed to resolve the request and maintain an appropriate record of the outcome, with longer retention where the correspondence relates to billing, fraud, a dispute or a legal obligation.
  • Raw voice audio, transcripts, prompts and generated conversation content: not intentionally retained by Genesis after the live request-processing path as part of normal application logging or observability.

We may retain anonymised or aggregated statistics for longer where they no longer reasonably identify an individual.

8. Cookies and local browser storage

Genesis currently uses essential cookies and similar browser storage for login sessions, CSRF protection, security and core account functionality. These technologies are required for the service to work. If Genesis later adds non-essential analytics, advertising or similar technologies, we will update this notice and obtain consent where required.

9. Security

We use technical and organisational measures intended to protect personal data and account credentials. These include access controls, secure session handling, API-key protection, tenant separation, rate limiting and operational security controls. No internet-connected service can be guaranteed completely secure.

You should keep your account and API credentials secure and revoke a credential promptly if you believe it has been exposed.

10. Your data-protection rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct or erase your personal data; restrict certain processing; receive certain data in a portable format; and object to processing based on legitimate interests.

You have the right to object to processing based on our legitimate interests. If you object, we will consider your circumstances and stop the processing where the law requires us to do so.

To make a privacy request, email [email protected]. We may need to verify your identity before acting on a request.

You may also complain to the UK Information Commissioner's Office if you believe your personal data has been handled unlawfully.

11. Automated routing and decision-making

Genesis automatically selects infrastructure or AI/speech providers based on routing settings, availability, performance, cost, capacity and similar technical factors. This routing is used to deliver the service and is not intended to make decisions about you that produce legal or similarly significant effects.

12. Children

Genesis is not intended to be purchased or operated by children. Our Terms require individual customers purchasing Genesis Credits to be at least 18 years old. If you believe a child has provided personal data to Genesis in breach of those requirements, contact us so we can investigate and take appropriate action.

13. Changes to this notice

We may update this notice as Genesis, its providers, its data practices or legal requirements change. Material changes will be brought to users' attention where required, and we may require acknowledgement of a new Privacy Notice version before continued use. The current version is always available at /privacy.