Privacy Policy
A Legal Disclaimer
The explanations and information provided on this page are only general and high-level explanations and information on how to write your own document of a Privacy Policy. You should not rely on this article as legal advice or as recommendations regarding what you should actually do, because we cannot know in advance what are the specific privacy policies you wish to establish between your business and your customers and visitors. We recommend that you seek legal advice to help you understand and to assist you in the creation of your own Privacy Policy.
Privacy Policy - The Basics
Having said that, a privacy policy is a statement that discloses some or all of the ways a website collects, uses, discloses, processes, and manages the data of its visitors and customers. It usually also includes a statement regarding the website’s commitment to protecting its visitors’ or customers’ privacy, and an explanation about the different mechanisms the website is implementing in order to protect privacy.
Different jurisdictions have different legal obligations of what must be included in a Privacy Policy. You are responsible to make sure you are following the relevant legislation to your activities and location.
What to Include in the Privacy Policy
Generally speaking, a Privacy Policy often addresses these types of issues: the types of information the website is collecting and the manner in which it collects the data; an explanation about why is the website collecting these types of information; what are the website’s practices on sharing the information with third parties; ways in which your visitors an customers can exercise their rights according to the relevant privacy legislation; the specific practices regarding minors’ data collection; and much much more.
​
To learn more about this, check out our article “Creating a Privacy Policy”.
Privacy Policy & Terms of Service
Effective Date: September 1, 2026
​
This document contains two separate policies:
​
-
Part A — Website Policy (www.leverageworks.ai)
-
Part B — Private AI Product & Services Policy
PART A: WEBSITE POLICY
leverageworks.ai (Wix-Hosted Website)
This policy applies solely to visitors of www.leverageworks.ai. This website does not require user registration, login, or account creation.
​
1. Introduction
Welcome to www.leverageworks.ai ("the Website"), operated by Leverage Works AI ("Leverage," "we," "us," or "our"). This Website is hosted on the Wix platform and serves as an informational presence only. We are committed to protecting your privacy and being transparent about the limited data we collect.
2. Information We Collect
Because this Website does not offer user accounts or login functionality, we collect only the following:
a. Information You Voluntarily Provide
-
Contact form submissions (name, email address, message content)
-
Email addresses submitted for newsletters or inquiries
b. Automatically Collected Information (via Wix)
As a Wix-hosted website, Wix may automatically collect:
-
IP address and approximate geographic location
-
Browser type and version
-
Device type and operating system
-
Pages visited and time spent on pages
-
Referring URLs
-
Cookies and similar tracking technologies
This data is collected and processed by Wix in accordance with the Wix Privacy Policy and Wix Cookie Policy. We encourage you to review Wix's policies directly.
​
3. How We Use Information
We use the information collected to:
-
Respond to your inquiries and contact form submissions
-
Improve the Website's content and user experience
-
Analyze aggregate traffic patterns (via Wix Analytics)
-
Comply with legal obligations
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Cookies
This Website uses cookies as managed by the Wix platform. Cookies may be used for:
-
Essential website functionality
-
Analytics and performance measurement
-
Remembering your preferences
You may control cookie settings through your browser. Note that disabling certain cookies may affect Website functionality. Per Wix's guidance, a cookie consent banner is displayed to visitors where required by applicable law (e.g., GDPR, ePrivacy Directive).
5. Third-Party Services
This Website is built and hosted on Wix.com. Wix acts as a data processor on our behalf. We may also use:
-
Wix Analytics for traffic analysis
-
Google Analytics (if enabled) for visitor behavior insights
-
Email service providers to respond to inquiries
Each third party operates under its own privacy policy.
​
6. Data Retention
Contact form submissions and inquiry emails are retained for as long as necessary to respond to your request and for a reasonable period thereafter for record-keeping, not to exceed 24 months unless required by law.
​
7. Your Rights
Depending on your jurisdiction, you may have the right to:
-
Access the personal data we hold about you
-
Request correction or deletion of your data
-
Object to or restrict processing
-
Lodge a complaint with a supervisory authority (EU/UK residents)
-
Opt out of sale of personal information (California residents under CCPA)
To exercise any of these rights, contact us at: privacy@leverageworks.ai
​
8. Children's Privacy
This Website is not directed to children under the age of 13. We do not knowingly collect personal information from children.
​
9. Changes to This Policy
We may update this Website Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the Website after changes constitutes acceptance of the revised policy.
​
10. Contact Us
Leverage Works AI
www.leverageworks.ai
support@leverageworks.ai
​
​
PART B: PRIVATE AI PRODUCT & SERVICES POLICY
Leverage Private AI — Deployed in Your Cloud
This policy applies to Leverage's Private AI product and services, which are deployed separately for each customer within their own cloud environment. This policy governs data handling, privacy, security, and terms of use for all Leverage Private AI deployments.
​
1. Introduction
Leverage Private AI ("the Product") is an enterprise AI assistant platform deployed exclusively within your organization's own cloud environment (AWS, Azure, Google Cloud, or other cloud of your choice). Unlike conventional AI services, Leverage Private AI is architected from the ground up on a zero-data-egress principle: your data stays in your cloud, under your control, at all times.
This policy describes how data is handled, what protections are in place, and the terms governing use of the Product.
​
2. Core Data Privacy Principle: Your Cloud, Your Data
Your data, queries, documents, and AI-generated insights never leave your cloud environment and are never transmitted to Leverage, any AI model provider, or any third party.*
This is not merely a policy commitment — it is enforced by the technical architecture of the Product. Leverage Private AI is deployed entirely within your cloud tenancy. There are no outbound data pipelines, no telemetry callbacks to Leverage servers, and no shared infrastructure between customers.
​
* Exception — Optional Web Search Feature
When the web search feature is enabled by your organization, Leverage Private AI incorporates a third-party search engine (Google Search) to retrieve supplemental, publicly available web data to enrich AI responses.
The following safeguards apply:
-
Search queries are automatically redacted before transmission — any private, sensitive, or proprietary data identified in the query is removed prior to the search request being sent.
-
Only the search results (publicly available web content) are returned to your environment.
-
The combined AI response and any derived insights are never shared with Google, Leverage, or any other third party — they remain entirely within your cloud environment.
-
Web search is an opt-in feature and can be disabled by your organization's administrator at any time.
No other feature of Leverage Private AI transmits data outside your cloud environment.
​
3. Data We Do Not Collect
Leverage explicitly does not collect or store and of your company’s data or insights:
-
Your employees' queries or prompts
-
Documents, files, or data sources connected to the Product
-
AI-generated responses or insights produced within your environment
-
Metadata about your usage patterns, search history, or connected integrations
-
Any output, summary, or derivative of your organizational data
This data is stored and processed in your company’s private cloud, and Leverage has no technical access to your deployment environment unless explicitly granted by your organization for a specific, time-limited support purpose.
​
4. We Do Not Train AI Models on Your Data
Leverage Private AI does not train, fine-tune, or update any AI model using your organization's data — ever.
We go further: we believe that the standard AI service policy of "no model training on customer data" falls short of true enterprise security. Comprehensive data protection requires complete architectural isolation—ensuring zero data egress, zero third-party access, and zero external storage or processing.
Our Position on Model Training and Data Security
We believe that responsible corporate security policy should always include:
-
Never sharing sensitive organizational data with third parties, including AI service providers and model developers, regardless of the stated purpose.
-
Treating AI query data as sensitive by default. The questions your employees ask an AI system — and the documents they reference — often contain your most sensitive strategic, financial, legal, and operational information. This data should be treated with the same rigor as any other confidential asset.
-
Demanding architectural guarantees, not just contractual promises. A policy that says "we won't train on your data" is only as strong as the architecture that enforces it. Leverage Private AI enforces this through deployment design: the AI model runs within your cloud, and no data pathway to external model providers exists.
-
Recognizing that model training creates permanent data exposure risk. When your data is used to train a model, it may influence that model's outputs for all users — including competitors — in ways that are difficult to detect, audit, or reverse.
Leverage's commitment: The AI models used within Leverage Private AI are pre-trained, commercially licensed models deployed within your environment. Your data is used solely to generate responses for your authorized users in real time. It is never used to update, retrain, or improve any model. And your data is shared with no 3rd party company, including Leverageworks.ai.
​
5. Deployment Architecture & Security
Customer-Isolated Deployment
Each customer receives a fully isolated deployment within their own cloud account or tenancy. There is no shared compute, storage, or networking between customers.
No Leverage Back-Channel
Leverage does not maintain persistent access to your deployment. Software updates are delivered as versioned packages that your team applies on your schedule (with optional automation).
Data Source Integrations
When you connect data sources (e.g., Gmail, Outlook, Google Drive, OneDrive, Slack, Google Chat, Jira, Confluence, HubSpot, SharePoint, GitHub, Bitbucket, Salesforce, and others), all data retrieved from those sources is processed and stored exclusively within your cloud environment. Credentials and access tokens are stored in your cloud's secret management service and are never transmitted to Leverage.
Encryption
All data is encrypted at rest and in transit using industry-standard protocols (AES-256 at rest; TLS 1.2+ in transit) within your cloud environment, consistent with your cloud provider's security standards.
Access Controls
Access to the Product is governed entirely by your organization's identity and access management (IAM) policies. Leverage does not manage, provision, or have visibility into user accounts within your deployment.
​
6. Compliance & Regulatory Considerations
Because your data never leaves your cloud environment, Leverage Private AI is designed to support compliance with:
-
GDPR (General Data Protection Regulation)
-
HIPAA (Health Insurance Portability and Accountability Act) — when deployed in a HIPAA-eligible cloud configuration
-
SOC 2 — your deployment inherits your cloud provider's SOC 2 controls
-
CCPA (California Consumer Privacy Act)
-
Industry-specific regulations (financial services, legal, healthcare, government) — consult your compliance team regarding your specific obligations
Note: Compliance is a shared responsibility. Leverage provides the architecture; your organization is responsible for configuring and operating the deployment in accordance with applicable regulations.
​
7. Incident Response & Breach Notification
In the event of a security incident affecting your deployment:
-
Your organization's security team has full visibility and control, as the deployment resides in your cloud.
-
Leverage will provide technical assistance upon request.
-
Because Leverage does not hold your data, Leverage itself cannot be the source of a data breach involving your organizational data.
​
8. Terms of Use
Authorized Use
The Product is licensed for use by your organization's authorized employees and contractors in accordance with your subscription agreement. Unauthorized access or sharing of access credentials is prohibited.
Acceptable Use
Users may not use the Product to:
-
Generate content that is illegal, harmful, or violates applicable law
-
Attempt to circumvent security controls or access data beyond their authorization
-
Reverse-engineer or extract the underlying AI models
-
Use the Product in any manner that violates your organization's acceptable use policies
Intellectual Property
AI-generated outputs produced within your deployment are owned by your organization, subject to the terms of the underlying AI model license. Leverage retains ownership of the Product software and platform.
Availability
Leverage targets high availability but does not guarantee uninterrupted service. Specific uptime commitments are defined in your Service Level Agreement (SLA).
​
9. Changes to This Policy
Leverage may update this policy to reflect changes in the Product, applicable law, or industry best practices. Material changes will be communicated to your organization's designated administrator with reasonable advance notice.
​
​
10. Contact
For privacy, security, or compliance inquiries related to Leverage Private AI:
Leverage Works AI
www.leverageworks.ai
info@leverageworks.ai