Privacy Policy
Effective July 15, 2026
What Apex is
Apex is a managed workspace for licensed loan officers to manage workflow across their tech stack. Apex helps operators review business context, draft communications, and use approved connector tools in a seamless, cohesive fashion. Apex never takes borrower-facing or external account action without explicit approval by the licensed operator.
Information we collect
Apex may collect operator account information, workspace routing information, app-session records, connector status, audit logs, messages or records an operator asks Apex to review, and artifacts produced by Apex during normal use.
Apex uses this information to provide the managed workspace, route the operator to the correct Apex cell, maintain connector state, display work back to the operator, support auditability, debug issues, and improve product reliability.
Teach Apex browser recordings
The Teach Apex Chrome extension records only after the operator explicitly begins a demonstration. During an active recording it may collect the visible page content, page URL, origin and title, clicks, scrolling, selections, semantic values the operator enters, and bounded screenshots needed to reproduce the demonstrated workflow. The operator can stop or cancel the recording at any time.
Password and verification-code fields are redacted. Teach Apex does not include saved credentials, cookies, browser storage, session tokens, one-time verification codes, or a raw keystroke stream in the recording package. Operators are instructed not to demonstrate passwords, verification codes, Social Security numbers, or financial account information.
The sanitized recording package is sent over HTTPS to the operator's assigned Apex cell, stored with private customer- and operator-scoped permissions, and used only to create, test, audit, and improve the reusable skill requested by that operator. Apex may process the sanitized package through its configured AI provider only to provide that requested Teach Apex functionality. Teach Apex recording data is not sold, used for advertising, or used to train generalized AI or machine-learning models.
Teach Apex's use and transfer of information received from Chrome adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Teach Apex uses recording data only to create, test, secure, audit, and support the reusable workflow skill explicitly requested by the operator. It does not use recording data for advertising, creditworthiness determinations, lending decisions, or generalized AI training.
Recording data is shared only with the operator's assigned Apex infrastructure and service providers necessary to deliver Teach Apex, including the configured AI model provider. Authorized personnel do not read recording content unless the operator explicitly requests support for that specific recording, or access is necessary for security or legal compliance.
Google user data
When an operator signs in with Google, Apex requests basic profile information only to authenticate the operator and route them to the correct managed workspace. Google sign-in does not give Apex access to Gmail.
When an operator separately connects Gmail, Apex requests Gmail read and send scopes so the operator can ask Apex to review relevant mailbox context, prepare draft communications, and send email only after the operator explicitly approves the exact action. Apex does not autonomously send Gmail messages, delete Gmail messages, archive Gmail messages, move Gmail messages, or mark Gmail messages without operator approval.
Apex stores only the tokens and operational records needed to keep the operator's Gmail connector working, show connector status, provide the requested workspace functionality, and maintain auditability. Apex may process Gmail message content only when needed to provide operator-requested workflow assistance, such as reading relevant mailbox context, finding likely mortgage leads, preparing draft communications, or executing an operator-approved send.
Apex does not use Google user data for advertising, does not sell Google user data, does not use Google user data to train generalized AI or machine-learning models, and does not transfer Google user data except as needed to provide and operate Apex, comply with law, or act with the operator's direction.
Apex's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How information is protected
Apex is built around managed cells, approval gates, audit records, and restricted connector custody. Access to operational data is limited to authorized operators and maintainers who need it to provide, support, secure, and improve the product.
Retention and deletion
Apex keeps operational records only as needed to provide the product, support auditability, debug issues, and improve reliability. Operators may request access, correction, disconnection of Google access, or deletion by contacting support.
Contact
For privacy questions or data requests, contact george@always-invert.com.