How Seros Uses AI
Effective date: September 22, 2026
This is the short, plain version of how Seros uses AI. The binding terms are in Section 7 of the Terms of Service, the Privacy Policy and the DPA.
Two different things
How we use AI in our own work. We use AI models as a tool when we build software — drafting code, tests and documentation, and reviewing our own work. A person on our side reviews everything before it becomes a deliverable, and we are accountable for it either way. Where a deliverable was produced with material AI assistance, we say so.
AI features we build for you. Where an engagement includes AI functionality, we build it so a model proposes and a person decides: consequential actions require human confirmation, and the decision is recorded. The model provider, what data reaches it, and where the human review points sit are agreed in the Statement of Work and documented in the deliverable.
The paused in-house product
Our first build was an in-house Slack-to-tracker application. It used AI to classify commitments and draft tracker work, and never wrote to a tracker without a person confirming the draft. That application is paused and is not deployed, so it is not processing anyone's data today. It remains the clearest worked example of how we build AI with review.
The default AI transport is local Ollama/Qwen. A hosted HTTP transport is supported by configuration, but no hosted AI vendor is confirmed in the current subprocessor list. Do not publish a hosted provider's name or make provider-specific training or retention claims until that provider is selected and reviewed.
What data goes to model providers
Only the minimum portion of material needed for the requested generation is sent to a model provider. Before any client material reaches a hosted provider, that provider's identity, processing location, retention and training terms are agreed in the statement of work and added to Subprocessors. Where a model runs inside our own boundary, or inside infrastructure the client controls, no third-party provider receives the content.
We do not use customer content to train a general-purpose model. This statement does not replace provider-specific contractual review when a hosted transport is enabled.
Training
- We do not use your content to train our own general-purpose models.
- We do not permit our model providers to train their models on your content. Our aim is to use enterprise or API terms where training is off by default, and where prompts and outputs are retained only briefly for abuse monitoring, or not at all. The exact retention window per provider is determined by the provider selected for that engagement and recorded in the Statement of Work; no AI provider is currently engaged for client work and must be confirmed against each provider's current terms.
- We may use aggregated statistics that cannot identify you or any individual — for example generation counts or error rates — to run and improve our own tooling.
- If we ever want to use client material to improve our own models, we will ask for opt-in consent first, in writing, per client. Silence will not count as consent.
Human oversight
- Everything the model produces is a draft until a person accepts it.
- You must review output before acting on it, and you must not use a system we build to make decisions with legal or similarly significant effects about a person without meaningful human review. That is a rule in the Acceptable Use Policy, not a suggestion.
- Where we build AI features, the human review points are documented in the deliverable, and administrators on your side control which integrations are connected and what is in scope.
Limitations, stated plainly
- The models are probabilistic. They can be wrong, out of date, or confidently invent detail that is not in your data.
- They can reflect bias in their training data, including in suggestions about who should do what. Watch for that in assignment recommendations.
- The same input can produce different output on different runs.
- Output is not legal, tax, medical, financial or other professional advice.
- Similar inputs from different customers can produce similar output. Output is not unique to you.
- Model providers change their models. Behaviour can change without an announcement from us.
Your controls
- Decide, in the statement of work, whether an engagement uses AI at all, which provider is acceptable, and what categories of your data may reach it.
- Where we build a system for you, choose which sources it connects to and what is in scope. Do not connect a source whose content should not be processed.
- Ask us to run a model inside your own infrastructure where that matters to you; we will say plainly what it costs in quality and money.
- Delete generated content the same way you delete any other content in your systems.
Questions: team@seros.dev.