Platform

The loop

Our goal is to learn from permissioned usage without sacrificing existing capabilities. Customer-data retraining and demonstrated improvement remain future work.

How it works

The planned champion–challenger loop would select consented business-side examples, train a candidate, and compare it with the current model on new learning and retained capabilities. A nightly run would be an opportunity to improve, not a guaranteed upgrade. Candidates that fail quality or regression checks would not be promoted. De-identification does not replace consent.

Contribution is opt-in and reversible. By default nothing is collected for training. When you turn it on, an append-only consent event is recorded and ingestion is gated on it in real time. Flip ghost mode any time and the pipe goes dark immediately — new usage stops flowing. Self-hosting is unaffected: running the open weights sends nothing, regardless of this setting.

Heads up.Training contribution is gated behind a Data Processing Agreement. Until that agreement is in place for your organization, the consent path stays closed and no usage is collected — the system fails closed, not open.

Private vs shared models

The planned default is to use consented data for a model that is yours alone — never pooled with anyone else. A shared, niche-wide model only turns on once enough businesses contribute that no single one is identifiable, and only with separate, explicit consent. For liability-bearing or privileged verticals, a private single-tenant model under a DPA keeps your data fully isolated.

Deletion & erasure

You can withdraw consent or request erasure at any time. Erased data is excluded from future training within our committed SLA, and affected model versions are queued for retrain and deprecation. One honest limit: already-shipped open weights can’t be retroactively scrubbed — which is exactly why old versions age out as new ones ship. The full terms live on the consent page and in the DPA.