AI Safety & Privacy

Privacy isn't a feature here. It's the architecture.

Consent-first capture. Personal details redacted at processing. Audio deleted on a clock. Data resident in India. Rep-side rights built in.

Consent

Consent, plainly

  • Notice signage at the counter and at store entry — kit included with every deployment.
  • Staff consent captured through employment terms, reviewed with reps at rollout.
  • Opt-outs honored — no coverage forced on any individual.
What we never do

Six things GainCraft will never be.

  • No video
  • No facial recognition
  • No customer identification
  • No voiceprints
  • No data resale
  • No individual customer profiles
Data lifecycle

From counter to insight, in five steps.

  1. Step 1
    Capture — consent-first
  2. Step 2
    Redact personal details
  3. Step 3
    Analyze against playbook
  4. Step 4
    Auto-delete audio (30–90d, configurable)
  5. Step 5
    Retain aggregate insights only
Compliance

Designed for India's DPDP Act.

  • Data residency in India.
  • Encrypted in transit and at rest.
  • Role-based access with full audit logs.
  • Deletion, retention, and access controls per brand.
Model governance

Trust, not just accuracy.

  • Human-review sampling of scored conversations.
  • Accuracy and fairness checks across Indian languages.
  • Every rep can dispute any score. Human review resolves.
Roadmap honesty

We publish status. Not badges we haven't earned.

ISO 27001 and SOC 2 are in progress. We will publish live status as we complete each. We do not render certification badges we don't hold.

FAQ

Direct answers.

Every deployment follows local counsel guidance.

Get the 2-page trust summary.

A single PDF you can forward to legal, compliance, or IT.