PRIVACY, ACCESS, ACCOUNTABILITY
Privacy policy

Trust requires clear boundaries.

This policy explains how Delphi Knows handles information when an authorised user accesses the service directly or through a named Custom GPT.

Effective 4 August 2026

01

Scope

This policy applies to the Delphi Knows service, its application programming interface, and Custom GPTs configured to retrieve authorised company knowledge from that service. It does not replace the privacy policies or retention rules of the original systems from which company information was obtained.

02

Information processed

When you use Delphi, the service may process:

  • the question, search terms, filters, and document identifiers submitted in your request;
  • your named access profile and its approved retrieval policy;
  • authorised excerpts and metadata retrieved from approved company sources;
  • the answer returned to you, including citations and evidence references; and
  • technical and audit information about the request and its outcome.

The service is designed for company knowledge, not for passwords, authentication secrets, payment information, or other credentials. Do not place such information in a question.

03

Named access and credentials

Access is associated with an individual profile. A profile determines whether the user is active and which source categories may be searched. The access credential is used only to authenticate requests. Delphi stores a cryptographic digest for credential verification rather than the reusable plaintext credential in its profile record.

Do not share your GPT link outside the authorised audience and do not disclose, copy, or request the credential embedded in its Action configuration. Access may be suspended or rotated if a link or credential is believed to be compromised.

04

Source and privacy boundaries

Delphi applies a retrieval policy for each named profile. Company-reader profiles are configured to exclude private Slack messages and direct messages, email, and Plaud recording content. They can retrieve only the explicitly approved company source categories configured for that profile. Unknown or newly introduced source categories are denied until reviewed and approved.

Access controls reduce exposure but do not change the confidentiality of the underlying company information. Users must handle returned material according to their employer's policies and their existing duty of confidentiality.

05

How information is used

Information is processed to:

  • authenticate and authorise the request;
  • search approved sources and retrieve relevant evidence;
  • generate an answer with citations, uncertainty, or refusal where appropriate;
  • maintain security, investigate misuse, and demonstrate who accessed what; and
  • diagnose and improve the reliability of the service.

Delphi does not sell company information or use it for advertising. It does not autonomously send messages to people, publish content, or change source systems.

06

Custom GPT and OpenAI processing

When Delphi is used through a Custom GPT, the user's conversation is processed by OpenAI under the terms and privacy settings applicable to that user's ChatGPT account. The GPT may send the question and necessary request parameters to the Delphi API and receive retrieved company information in response. Users should review the privacy controls and data settings of their ChatGPT account before use.

Delphi's operator does not control OpenAI's independent handling of ChatGPT conversations. OpenAI's current privacy information is available from OpenAI's own websites and should be reviewed separately.

07

Audit trail

Delphi records access events for security and accountability. An event can include the named profile, time, requested operation, bounded request detail, response status, and outcome. The audit design excludes credential-shaped fields and does not intentionally write reusable authentication secrets to the audit trail.

Audit access is restricted. An authorised user may inspect their own events where that capability is provided; designated owners or administrators may inspect the wider audit trail for governance and incident response.

08

Retention and deletion

Source information remains subject to the retention rules of its original company system. The current pilot does not promise a fixed automatic deletion period for access-audit records. They are retained for security and accountability until an authorised administrator applies a documented retention or deletion decision.

Suspending or deleting a Delphi profile does not automatically delete information from the original source systems. Security records may need to be preserved where required to investigate access or meet company obligations.

09

Accuracy, corrections, and human review

Delphi can return incomplete, stale, or incorrect information. Citations and evidence references are provided so material findings can be checked. A user may suggest a correction, but a suggestion does not silently alter the reviewed knowledge graph or become canonical company truth. Material changes require the relevant controlled review process.

10

Your choices and requests

You may stop using the GPT at any time. You may ask the Delphi administrator who issued your access to suspend your profile, rotate your credential, explain your retrieval policy, provide available access-history information, or assess a correction or deletion request.

Requests concerning information in an original company system must also follow that system's owner, policy, and retention process.

11

Security and incidents

Delphi uses named profiles, source allowlists and denylists, restricted database permissions, credential digests, and audit records to reduce risk. No system can guarantee absolute security. If you believe access has been misused or information has been exposed, stop using the GPT and notify the Delphi administrator immediately.

12

Changes and contact

This policy may be updated as Delphi's access model, integrations, or legal obligations change. The effective date above identifies the current version.

For privacy, access, correction, or security questions, contact the Delphi administrator or company representative who supplied your named access.