IER-0
Home
Legal

Privacy

How Tier0 is designed to handle workspace data, customer support content, provider credentials, and AI processing boundaries.

Data
Scoped

Workspace and project boundaries guide access.

AI
Bounded

Models receive controlled context, not provider secrets.

Review
Audited

Important support actions keep evidence.

1.0

Information we process

Tier0 is built for support operations. Workspaces may contain member profiles, customer email addresses, inbound and outbound support messages, thread metadata, project settings, approval decisions, policies, knowledge sources, provider connection status, billing state, and operational telemetry.

  • Workspace members and roles
  • Customer support threads and metadata
  • Project configuration and policy records
2.0

We do not sell personal data

We do not sell customer data, workspace data, support thread content, uploaded knowledge sources, provider configuration, or billing records. We do not use support content to build advertising profiles. Providers and subprocessors are used to operate the service, secure it, deliver email, authenticate users, store data, process payments, run voice infrastructure, and route model calls.

  • No sale of personal data
  • No advertising profile building
  • Subprocessors exist to run the service
3.0

Core providers and subprocessors

The current production stack is designed around Vercel for hosting and serverless infrastructure, Neon for Postgres and Auth, Resend for email transport and inbound events, Stripe for billing, LiveKit for hosted voice, and directly configured AI model providers. Each provider has its own legal, privacy, subprocessor, and data-processing terms; official references are linked below for review.

  • Vercel hosting, Blob, and Workflow
  • Neon Postgres and Neon Auth
  • Resend email, Stripe billing, LiveKit voice, and AI model providers
4.0

How AI context is handled

AI features receive scoped, delimited support context for classification, summaries, drafts, citations, risk checks, and action proposals. Provider secrets, payment credentials, signing secrets, and unrelated workspace data are not intended to be part of model context. Model outputs remain assistive, schema-validated where possible, and subject to project policy plus human approval before customer-facing action.

  • Schema-validated outputs
  • Prompt-injection checks
  • Bounded model context
5.0

Retention and deletion

Workspace retention settings should control how long original inbound payloads, normalized thread records, attachments, knowledge sources, customer memory, analytics data, and audit records remain available. Some audit evidence may need to be retained longer than ordinary message content to preserve account security, billing, abuse-prevention, and compliance records.

  • Retention settings
  • Knowledge source retirement
  • Security and audit preservation
6.0

Security posture

The product is designed around tenant isolation, authenticated app routes, verified public events, server-side secrets, and deterministic executor gates.

  • Tenant isolation
  • Signature verification
  • Server-side credentials
7.0

Customer choices and contact

Workspace owners can manage retention, knowledge sources, project policy, integrations, customer memory, and account access from the product surfaces that apply to their plan. Privacy, export, deletion, correction, abuse, or legal requests can be sent to support@driftrail.com. We may need to verify workspace authority before discussing account-specific data or making administrative changes.

  • Retention and source controls
  • Verified workspace requests
  • Contact support@driftrail.com
8.0

AI Generation & Project Operations Disclosure

YOU ARE HEREBY NOTIFIED AND EXPLICITLY AGREE THAT THIS ENTIRE PROJECT, WEBSITE, APPLICATION, SOURCE CODE, AND UNDERLYING CO-ENGINEERED ENVIRONMENT MAY BE WHOLLY OR PARTIALLY CREATED, GENERATED, WRITTEN, DEPLOYED, OR MAINTAINED BY ARTIFICIAL INTELLIGENCE AGENTS (SELF-HEALING AI DEVELOPERS). OPERATIONAL FAULT RESOLUTIONS ARE EXECUTED AUTONOMOUSLY WITHOUT DIRECT HUMAN AUTHORSHIP IN FLIGHT. BY UTILIZING THE SERVICES, YOU WAIVE ANY CLAIMS RELATED TO THE AUTONOMOUS PRODUCTION OF CODEBASES AND RELATIVE ASSETS.

  • AI-generated codebase elements
  • Autonomous diagnostic hotfix operations
  • Absolute release of claims regarding AI authorship
9.0

Third-Party AI & Google Gemini Processing

While the platform operators do not directly monetize or utilize your personal data for secondary commercial purposes, all support content, logs, and query details are processed by third-party artificial intelligence systems to perform generation features. In particular, data processed by the models is subject to the [Google Gemini Terms of Service](https://ai.google.dev/gemini-api/terms) and [Google Privacy Policy](https://policies.google.com/privacy). We make no representations regarding third-party data processing safety.

  • Google Gemini data-processing subprocessor
  • Adherence to Google Privacy guidelines
  • Users must review Google Gemini legal references
10.0

Absolute Disclaimer of Warranties & Zero Liability Covenants

TO THE FULLEST EXTENT PERMISSIBLE BY LAW, THE SERVICE IS PROVIDED 'AS IS' AND 'AS AVAILABLE' WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL THE OPERATORS, PARTNERS, DEVELOPERS, OR MACHINE AGENTS BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, OR SPECIAL DAMAGES (INCLUDING LOSS OF PROFITS, SECURITY LEAKS, OR DATA LOSS) ARISING UNDER ANY THEORY OF LIABILITY, REGARDLESS OF FORESEEABILITY.

  • AS-IS disclaimers
  • Exclusion of all direct and indirect damages
  • Statute of limitations waiver for claims
Operations

What this means in production.

These pages describe the product contract behind the UI, not a decorative brochure. Each surface should connect back to the same governed support loop.

Control boundary

Support content is not sold.

Operator workflow

Support moves through secure ingest, AI preparation, human approval, outbound execution, and audit evidence.

Configuration impact

Provider setup, project policies, knowledge trust, retention, and billing limits decide how this behaves for a real workspace.

Proof points

Designed for governed support, not hidden autonomy.

Support content is not sold.
Privacy controls should be reviewed before production use.
Provider terms and subprocessors may also apply.
Next

Keep exploring the operating model.