Trust
Privacy
This notice explains the data used by the current Autonomy Applied test environment.
Last updated: August 22, 2026
Information we process
Autonomy Applied processes account details, authentication records, product activity, purchase and credit records, uploaded documents, imported HOA documents, extracted text, review decisions, generated reports, and support information needed to operate the service.
Documents and AI providers
Documents are stored in private, account-scoped storage. Relevant document content may be sent to configured AI and document-processing providers, including OpenAI and Google Document AI, to extract text, validate OCR, retrieve source material, and generate reports or answers. Human-approved corrections become the searchable version; rejected material is excluded from retrieval.
Tow Intake photo evidence
Tow Intake stores private, account-scoped JPEG copies of vehicle evidence photos. The upload is decoded, resized when needed, and re-encoded without source EXIF or GPS metadata. The temporary raw upload is removed during finalization; a private scheduled cleanup retries expired, rejected, abandoned, or incompletely cleaned raw uploads until the storage provider's signed-upload token can no longer recreate them. When you request photo analysis, the sanitized image is sent to the configured AI provider to suggest plate/state text, broad visible color, and vehicle-only identifying features. The system instructs the provider to ignore people and unrelated vehicles, but users must still avoid uploading images they are not authorized to use and must review every suggested observation. Approved evidence remains linked to the private incident record while needed for the service or applicable operational and legal obligations. A final production retention and deletion schedule must be approved before live launch.
One-time portal imports
When you authorize a credentialed HOA portal import, the username and password are used in memory only for that fetch. They are not saved in the database, storage, background queue, analytics, or AI prompts. Downloaded documents and sanitized source details may be retained in your private knowledge base.
Knowledge Base research
Large, complete-corpus research temporarily stores your research question, document-level progress, validated source references, and grounded result so the work can continue after you close the browser. These owner-scoped research runs are scheduled for deletion 24 hours after they complete fully or partially, fail, or are cancelled. Operational events contain counts and duration buckets, not questions, answers, filenames, document titles, extracted content, or support quotes.
Retention and deletion
Account documents, extracted content, approved semantic navigation records, reports, and purchase records remain available while needed to provide the service or meet operational and legal obligations. Short-lived durable Knowledge Base research is governed by the separate 24-hour completion retention above. Available deletion controls remove active objects only after reference checks; provider backups and security records may age out on their own schedules. A final production retention schedule must be approved before live launch.
Security and service providers
We use access controls, private storage, ownership checks, redacted operational logs, and restricted server credentials. Infrastructure, authentication, payments, document processing, and AI providers process only the information needed for their role. No system can guarantee absolute security.
Your choices
You can choose what to upload or import, review OCR results, reject extracted content, and delete eligible documents. Contact Autonomy Applied through the support channel shown in the application for access, correction, or deletion questions.