Legal

Data handling

What the brain reads, what it writes, and how your data is protected along the way.

Last updated 28 September 2026

Read-only by default

Every connection starts read-only. The brain reads from the systems you connect; nothing is written back until you switch on a specific agent that needs to, such as one that publishes to your CMS.

Write access is requested per agent, scoped to what that agent does, and can be revoked at any time from the connected system.

What we connect to

  • Search and site behaviour: Google Search Console, Google Analytics 4.
  • Pipeline: HubSpot, Salesforce or Pipedrive.
  • Commerce: Shopify, if you sell online.
  • Publishing: Webflow or WordPress, only if you want agents to publish.

You choose which of these to connect. We only request the permissions each connection needs.

Every change is reversible

Agents never delete. Each change they make is recorded as a revision you can review and roll back in one click.

Your data stays yours

Your records build your brain only. They are never pooled with other customers’ data, shared with other customers, or used to train models for anyone else.

Security

  • Data is encrypted in transit and at rest.
  • Access tokens for connected systems are stored encrypted and used only by the service.
  • Access by our team is limited to what is needed to support your account.

Retention and deletion

You can disconnect any system at any time. When you close your account, we delete data from your connected systems within 30 days. To request deletion sooner, write to hello@gtmind.in.

Questions

For security questions or to report a vulnerability, write to hello@gtmind.in.