Trust & Security
Last updated 4 September 2026
Operators hand Gentoo their crew’s passports, medical certificates, contracts and conduct reports. This page says plainly where that data lives, who touches it, how long we keep it, and what we do not offer yet. Ask us for anything that is not here.
Where your data lives
Each operator has its own workspace. Every record carries the workspace it belongs to, and every read and write is scoped to it on the server. There is no query that crosses workspaces. Trial sandboxes are isolated the same way, one per person.
Crew records, schedules, contracts, reports and rest-hour logs are stored in our database provider’s cloud in the United States. Uploaded files (certificate scans, receipts, signed contracts) are stored in object storage and served through short-lived signed links, never public URLs.
All traffic is encrypted in transit with TLS. Data is encrypted at rest by our infrastructure providers.
Who processes it
These are the providers that touch operator data on our behalf. We will tell you by email before adding one.
| Provider | What it does | What it sees |
|---|---|---|
| Vercel | Hosts the web app | Requests to the dashboard |
| Convex | Database and backend | All workspace records |
| Clerk | Sign-in and sessions | Names, emails, sign-in events |
| Cloudflare R2 | File storage | Uploaded documents and photos |
| Resend | Transactional email | Recipient address and the notification text |
| Apple, Google | Push notifications | Device tokens and the notification text |
| Anthropic | Polaris answers and document reading | The question, the workspace snapshot needed to answer it, and certificate or receipt images sent for reading |
| Voyage AI | Search index for the guideline library | Text of guideline documents, not crew records |
AI providers are used to answer a question or read a date off a document, then the exchange ends. We do not use crew data to train models, and we send only what the answer needs.
Who can see what
- ·Crew see their own records: profile, documents, contract, travel, rest hours, expenses and the reports they filed.
- ·HR sees the workspace. Owners additionally manage billing, access and the settings that shape the product.
- ·Every change made from the dashboard is written to an append-only audit log with who, what and when.
- ·Filed reports cannot be edited after the fact. Triage changes their status and adds to the thread, never the original text.
Conduct reports and the EU Whistleblower Directive
Concerns is a reporting channel, not a compliance certificate. Directive (EU) 2019/1937 puts the obligations on the operator: a confidential channel, acknowledgement within seven days, feedback within three months, and protection from retaliation. Gentoo gives you the record to evidence them.
- ·A report can be filed anonymously. When it is, the reporter’s identity is never stored: they receive a one-time case code and use it to follow the thread.
- ·A report about HR can be routed to the owner only, so it is not read by the people it concerns.
- ·Each report records when it was filed and when it was acknowledged, and the thread keeps every reply in order.
- ·Reports are immutable. Nobody, including Gentoo, can rewrite one after it is filed.
How long we keep it
Workspace data is kept for the term of your contract. When it ends, we delete the workspace on request and confirm in writing; provider backups roll off on their own schedule after that. You can export your data at any time from the dashboard, and we will help you leave if you ask.
Trial sandboxes that have not been opened for six months are deleted.
Agreements
- ·A data processing agreement is available on request, with the current list of providers annexed.
- ·If we confirm a breach affecting your data, we tell you without undue delay and no later than 72 hours after confirming it, with what we know and what we are doing.
What we do not offer today
We would rather you hear this from us than find out in procurement.
- ·No SOC 2 report yet. A Type I audit is planned; ask us for the current timeline.
- ·No single sign-on or SCIM provisioning. Sign-in is email-based through Clerk.
- ·No EU-only data residency. Data is stored in the United States.
- ·No payroll. Gentoo produces the pay facts and the export; your payroll provider runs payroll.
Contact
Security questions, a suspected vulnerability, or a data request: hello@getgentoo.com. We reply within two working days.
This document is a plain-language summary provided for convenience and is not legal advice. For questions, email hello@getgentoo.com.