Data ownership
Client and operational data belongs to the organization or person that provided it. InnerChispa should use it only for the stated business, service, security or support purpose.
AI & Data
Local processing is preferred for sensitive workloads. Cloud providers are used when capability, reliability or research value justify it. Memory, retention, deletion and third-party processing should be explicit.

Client and operational data belongs to the organization or person that provided it. InnerChispa should use it only for the stated business, service, security or support purpose.
Processing should be tied to a lawful basis or legitimate operational purpose, with clear notice when data is collected through contact forms, emails, meetings, documents, demos or service workflows.
The architecture supports local-first processing and governed cloud escalation. Sensitive or repetitive workloads should stay local when practical; advanced models or public hosting may use external providers.
Persistent memory must be purposeful, reviewable, limited to operational value and removable when legally or contractually appropriate.
External AI providers may process prompts, files or metadata depending on the service used. Customer environments should define what can be sent externally and what must remain local.
The public website must not expose private customer data, internal IPs, credentials, raw MongoDB records, private MCP tools or operational dashboards.
Collect only what is needed for contact, evaluation, service delivery, security, legal compliance, investor communication or product improvement.
Employment, security, access-control, financial and customer-facing decisions should preserve human review rather than relying on fully automated conclusions.