#Summary
- Ergo answers when you mention it. When it does, it reads that conversation thread and any files shared in it.
- Answering means sending your message to an AI model. Those models are contracted not to keep your conversation and not to train on it.
- We don’t train any model on your data. There’s one narrow exception, described below, and it is reviewed by a human first.
- We store your strategic context and summaries of your conversations on our own infrastructure, separated per client.
- Usage statistics are counts and categories. They do not include the content of conversations.
- When you stop using Ergo, you tell us whether you want your data returned or deleted, and we complete this within 90 days.
#What the Slack app can see
Ergo replies when you @mention it in a channel or message it directly. When that happens it reads:
- The conversation thread it was mentioned in. Not just the message that mentioned it — the thread around it, so it has the context of what you were discussing. It doesn’t read the rest of the channel, and it doesn’t read other channels.
- Files shared in that thread. PDFs and Word documents are read as text. Voice messages are read from the transcript Slack produces.
- Who’s talking. Slack user identifiers and display names, so it knows who it’s answering.
- Which workspace the message came from. This is how Ergo knows which client it’s talking to. It’s taken from the authenticated Slack session and never from the content of a message. If a workspace doesn’t match a registered client, the request fails rather than falling back to a default.
Two further points. Ergo has no ambient access to your email, your analytics, your CRM or meetings it wasn’t part of — it only knows what it’s been shown, unless you deliberately connect a tool (see below). And anyone you add to the Ergo channel can see everything in it, including what Ergo has learned about your business. Channel membership is controlled by you.
#Where your conversation goes
Answering a question requires sending your message to an AI model. We reach models through the Vercel AI Gateway, on terms that mean your conversation is used to generate the answer and is not kept afterwards, and is not used to train anything. A second, smaller model sorts each conversation into a category so we can see what clients use Ergo for — it reads the conversation and keeps only the category, never the words.
The models change as better ones are released, so this notice doesn’t name the current ones. They’re drawn from the models available in the Vercel AI Gateway, and reached on the terms described above whichever one is in use. The current selection is available on request.
When you ask Ergo to read a web page, one more company can be involved. Some sites only assemble their words once a browser has run the page, and Ergo can’t do that itself. When it encounters one, it sends that web address to a rendering service, which fetches the page and returns the text. What is sent is the address, not your conversation — and only for pages Ergo couldn’t read on its own. If you direct Ergo to a page that is not yet public, treat that as disclosure to an external supplier.
When Ergo researches something current, a search query derived from your question goes to a specialist search provider — the query, not your conversation. The search provider and the rendering service above are both named on the subprocessor page rather than here, so that either can change without requiring an update to this notice.
#What we store, and where
On our own infrastructure: your strategic context (positioning, ICP, strategy, key decisions, brand), summaries of your conversations, links back to the Slack thread where a piece of work happened, records of anything you escalated to a human, and the documents Ergo has published for you.
A search index over that stored context is held by a specialist provider, so that Ergo can find relevant history from earlier work. The index is separated per client, and the provider is named on the subprocessor page.
Every stored record carries your client identifier and every query is scoped to it. The database itself filters by that identifier as an independent backstop, so a query that failed to scope correctly returns nothing rather than someone else’s data. File storage is partitioned per client. Your context isn’t pooled with anyone else’s, and Ergo can’t reach another client’s information from your channel.
Data in transit is encrypted with TLS. Data at rest is encrypted by the underlying providers under their standard measures.
The full list of companies involved in running Ergo, what each one holds, and where, is published at thisisinference.com/legal/ergo-subprocessors.
#Access within Inference
Thom Cummings has access. He reads any question you escalate to him, reviews changes Ergo proposes to its record of your business, and can access your material where necessary, so that a named individual remains accountable for the decisions Ergo supports.
No one else at Inference has access. Everyone who works on Ergo is under confidentiality obligations to you.
#Model training
We don’t train or tune any model on your data, and the model providers we use are contracted on terms that don’t let them either.
There is one exception. When you escalate a question and a human at Inference answers it, that exchange can become a general example that shapes how Ergo answers similar questions for everyone. Before that happens a human reviews it and strips out anything that identifies you — your name, your people, your customers, your numbers. What remains is the structure of the problem and the reasoning applied to it, not information about your business. This is set out in the contract.
#Usage statistics
Counts and categories: how many conversations, which capabilities were used, whether something was escalated, what category a conversation fell into. They identify your company, not the individual people in the channel, and they do not include the content of conversations. This is processed in the EU.
#Connected tools
You can connect Ergo to systems you choose — analytics, CRM, email, documentation tools. This is always something you set up deliberately; nothing is connected by default.
If you connect a system, personal data in that system can reach Ergo. If you connect an inbox or a CRM, that includes personal data about your customers and correspondents. You choose what to connect and what permissions to grant. You should grant the narrowest permissions that meet your needs.
The access credentials for those connections are held by a connector service on our behalf, keyed to your client identifier and unreachable from another client’s session.
#Documents Ergo publishes
When Ergo produces a document for you, it’s served at a web address containing 128 bits of randomness, which makes the link unguessable in practice. Those pages are marked so search engines don’t index them, and links expire after 180 days by default and can be revoked sooner. Missing, revoked and expired documents all return the same response, so the address cannot be used to determine whether a document exists.
Limitation: these pages are not behind a login. Anyone holding the link can read the document.
#Restricted data
The following must not be submitted. For clients this is a contractual requirement rather than a preference: no health data, no biometric data, nothing about someone’s race, politics, religion, union membership or sex life; nothing about children; nothing under legal privilege; no card payment details.
Ergo is a business service. It is not intended for personal use and is not directed at children.
#Controller and processor roles
If your organisation is an Ergo client, your organisation decides what goes into Ergo and why — in data protection terms it’s the controller. We act on its instructions as its processor. Inference is the controller for a narrow set of its own records: account and billing details, and the content-free usage statistics described above.
If you are an individual user and want to know what is held about you, ask your own organisation first — it is their data and their decision. They have a contractual right to our assistance in responding, which we provide. You may also write to us directly at the address below and we will forward it.
The supervisory authority for UK data protection is the Information Commissioner’s Office.
#Retention and deletion
Your data is retained for as long as your organisation uses Ergo. When it stops, it tells us whether it wants the data returned or deleted, and we complete this within 90 days.
Two categories survive deletion, both set out in the contract: backup copies held by our providers until they age out on their normal rotation, and the anonymised examples described above — which by then contain nothing that identifies you.
Removing Ergo. Uninstalling the Ergo app from your Slack workspace stops it seeing anything new immediately. It does not by itself delete what is already stored. To request deletion, contact us; the 90-day period above applies.
#International transfers
Some of the services Ergo runs on are outside the UK, principally in the United States. Where personal data goes to one of them, the transfer relies on the standard contractual clauses and the UK addendum in our contract with that provider. Which providers sit outside the UK, and what each one holds, is on the subprocessor page.
#Security
The measures that exist are described above: separation between clients enforced in software and in the database, encryption in transit and at rest, administrative access held by one named person behind a login. Inference does not hold a security certification. Clients receive a fuller description in Annex II of the data processing agreement, which sets out both the controls and their limitations.
If you believe there has been an incident affecting your data, contact us at the address below.
#Changes to this notice
We will update this page when what Ergo does changes, and the date at the top will move. Clients are notified of changes to the companies involved in running Ergo through the subprocessor page, which is the mechanism the contract refers to.
#Contact
privacy@thisisinference.comTCHQ Ltd, 24 Hove Park Road, Hove, England, BN3 6LJ