Privacy & Data Use
Privacy & Data Use
Overview
Pithy Notes supports preliminary governance review and early-stage risk evaluation for AI systems, including agent-based workflows.
It supports clearer early decisions from user-provided inputs. It is not a full assessment, audit, or certification.
Data Collection
When you use Pithy Notes, we may collect:
- • vendor name and product name
- • high-level use case descriptions
- • general data categories
- • AI usage indicators, if known
- • your email and optional contact information
Safe Usage
Pithy Notes is intentionally designed to work with high-level, non-sensitive inputs.
Please do not include:
- • confidential internal system details
- • proprietary data or datasets
- • contract terms or legal documents
- • security configurations
- • personally identifiable information beyond general categories
Data Usage
We use submitted information to:
- • generate your preliminary governance review output
- • improve the quality and consistency of the product
- • identify aggregated and anonymized governance trends
Aggregated Insights
We may analyze patterns across submissions to understand common AI use cases, recurring risk indicators, governance control gaps, and evolving practitioner needs.
These insights are aggregated, anonymized, and non-identifiable.
We do not share individual vendor assessments or user-specific data.
For hosted environments, supporting providers that process data on our behalf are listed on the Subprocessors page.
Data Minimization Principle
Pithy Notes follows a data minimization approach. We collect only what is necessary for preliminary review and prefer structured inputs over detailed free text.
The tool is designed to function without sensitive information.
Limitations
All outputs are preliminary, based on user-provided inputs, and intended for decision-support only.
They do not verify vendor practices, replace formal due diligence, or constitute legal or compliance advice.
Related Disclosures
For additional information about platform boundaries and hosted service providers, review the Terms of Use, Trust & Governance page, and Subprocessors page.
