AI Policy
Version 1.0 · Effective: 3 August 2026
Purpose
This policy describes how Traceably's artificial intelligence features behave, what happens to customer content when they are used, and how a customer controls them. It exists because the Privacy Policy governs personal information and the SaaS Services Agreement governs rights and obligations, and neither is the right place to explain how the AI behaves — that it drafts rather than decides, that it can be wrong, who can turn it off, and what it is not for.
This policy is published for customers and prospective customers. It is read with the Privacy Policy and the SaaS Services Agreement. Where this policy and either of those documents differ, those documents prevail.
1. What our AI features do
Traceably includes an AI Assistant that works on the content in your workspace and on documents you upload. It can:
- summarise a journey, a stage, or a list
- build a draft journey map from a description you write
- import a journey from a document or image and rebuild it as a map
- extract the contents of a document into a list of cards
- answer questions about a document you have uploaded
The Assistant is currently provided as a beta feature.
2. It drafts; you decide
Everything the Assistant produces is a draft for you to review. It does not make decisions about people, and it does not take action on your behalf without you confirming it.
This is built into how the features work rather than left to good intentions:
- building a journey shows you a plan you can correct, then a preview, then asks you to confirm before anything is created
- extracting a list shows you the cards before you save them
- importing tells you what it found and waits for you to continue
- the Assistant cannot alter a journey once you have saved it
Nothing the Assistant generates enters your workspace until you choose to keep it.
3. It can be wrong
AI output is generated text. It can be inaccurate, incomplete, or confidently wrong, and the same question asked twice may produce different answers.
Two specific things worth knowing:
- Content built from a description is not evidence. It comes from your prompt and the model's general knowledge, not from your research. The product says so at the point of use.
- Content extracted from a document may not match the document exactly. The Assistant may categorise things differently from your headings, or add items it inferred. Review before saving.
Do not rely on AI output for decisions that require accuracy without checking it. You are responsible for what you keep.
4. What we do with your content
Full detail is in the Privacy Policy. In summary:
- your messages, the relevant workspace content, and any document you upload are sent to our AI model provider to generate a response
- uploaded files are stored in your workspace and listed under Files; their contents are indexed so the Assistant can search them
- uploads are visible to other members of that workspace, and are never shared between workspaces
4.1 Where your content is processed
All AI processing takes place within Amazon Web Services, in an Australian region. Your content does not leave Australia to be processed by our AI features.
We access AI models through a managed service rather than by sending your content to the model developers, so your content is not transmitted to them, and it is not used to train the underlying models.
The specific model providers and models we use are set out in our Artificial Intelligence Management System (AIMS) Plan, available through our Trust Centre at trust.traceably.io. A current list of our sub-processors is available on request by emailing support@traceably.io.
4.2 Training and feedback
We do not currently use your content to train AI models — not your workspace content, not the documents you upload, and not your messages to the Assistant. The managed service through which we access AI models does not use that content to train the underlying models.
Feedback is different. When you rate a response using the helpful or not-helpful controls, that feedback and the conversation it relates to are used to improve our Services and may be used to train AI models. They may be read by Traceably staff as well as processed automatically. This applies on every plan.
Feedback is voluntary. If you would rather a conversation was not reviewed, do not rate it.
5. You control who can use it
AI can be switched off at four levels, and a person needs all of them to be on:
| Level | Controlled by |
|---|---|
| An organisation | An Owner or Admin |
| A workspace | An Owner or Admin |
| A role, or an individual person | An Owner or Admin |
Organisations that do not want AI used at all can have it disabled entirely.
Usage is metered in AI Credits from an organisation-wide pool. Administrators can see how much each member has used and cap or uncap individuals. That per-member consumption is visible to your organisation's administrators.
6. What you must not use it for
You must not upload material you do not have the right to upload — in particular other people's personal information, or another organisation's confidential material — or use the AI features to produce unlawful, harmful or deceptive content. The full restrictions are in the SaaS Services Agreement, clause 3.
The Assistant cannot tell whether you had the right to upload something. That judgement is yours.
7. Beta features
Features identified as beta, including the AI Assistant, are provided as-is. They may change, behave inconsistently, or be withdrawn, and they are not covered by our service level commitments. This is set out in clause 2(c) of the SaaS Services Agreement.
8. Questions and concerns
If you believe the AI features have produced something harmful or incorrect in a way that matters, contact us at support@traceably.io. If you have a privacy concern, the routes in the Privacy Policy apply.
9. Changes
We will update this policy as the AI features change, and post the revised version here with a new effective date and a new row in the Revision History above.
Exemptions
Any exemptions to this policy require approval by the Policy Owner.