AI & Data

The system should know where data belongs.

Local processing is preferred for sensitive workloads. Cloud providers are used when capability, reliability or research value justify it. Memory, retention, deletion and third-party processing should be explicit.

The system should know where data belongs.
Generated and reused visual assets are composed as editorial website imagery; diagrams remain readable HTML.

Data ownership

Client and operational data belongs to the organization or person that provided it. InnerChispa should use it only for the stated business, service, security or support purpose.

Lawful and transparent processing

Processing should be tied to a lawful basis or legitimate operational purpose, with clear notice when data is collected through contact forms, emails, meetings, documents, demos or service workflows.

Local vs cloud

The architecture supports local-first processing and governed cloud escalation. Sensitive or repetitive workloads should stay local when practical; advanced models or public hosting may use external providers.

AI memory

Persistent memory must be purposeful, reviewable, limited to operational value and removable when legally or contractually appropriate.

Model provider boundaries

External AI providers may process prompts, files or metadata depending on the service used. Customer environments should define what can be sent externally and what must remain local.

No sensitive public exposure

The public website must not expose private customer data, internal IPs, credentials, raw MongoDB records, private MCP tools or operational dashboards.

Data minimization

Collect only what is needed for contact, evaluation, service delivery, security, legal compliance, investor communication or product improvement.

Review before automation

Employment, security, access-control, financial and customer-facing decisions should preserve human review rather than relying on fully automated conclusions.