Decision record · CDR-0024
We do not learn from your business.
Ratified 26 August 2026. The wording below is the ratified wording, not a paraphrase of it.
Most privacy pages describe what a company is permitted to do with your data. This one describes something we have removed the ability to do, and shows you the decision that removed it.
CDR-0024 Ratified 26 August 2026. A decision record is written down before the thing is built, and published afterwards. No exception clause Not for research, not for a pooled model, not with consent.
We never use your business content — your conversations, documents or records — to improve our products or train any model. Not pooled, not anonymised, not even with your permission.
Why there is no opt-in. An opt-in setting sounds like the moderate position. In practice it builds a second code path that has to keep track of whose data it is allowed to touch, and a condition like that is one you get wrong once and are then wrong about silently. A rule with no exception has nothing to get wrong.
It also removes a conversation we would rather not have with you. There is no setting to find, no default to check on a Tuesday, and no version of this where the answer depends on which plan you are on.
The line is content versus operation.
We can know that you opened the website builder eleven times without knowing a word of what you wrote in it. That distinction is the whole policy, so here is which side of it everything falls on.
What we never touch.
Your conversations. Your documents and uploads. Your Hub — what you sell, who you sell to, your prices, your plans. Anything an Mi Agent drafted for you and anything you edited. None of it trains anything, ours or anybody else's.
What we do keep, and name.
Your account and login records. Your billing records. Support correspondence, because you sent it to us. And product usage telemetry — which screen was opened, how often — which is how we find out that a feature is confusing without reading what you did inside it.
operation, not content
If you leave.
Your content and records are removed and cannot be retrieved. We keep invoices and acceptance records, because we are required to keep them, and we will tell you exactly which ones rather than describing them as “certain records”.
What cannot be erased, including by us.
A permanent, tamper-evident record that your account existed and was deleted. It is in the signed audit chain, so what we did and did not do can always be proved — including against us. A deletion log a company can quietly rewrite is not a deletion log.
SEC-016 · signed append-only ledger
Why you should believe this one.
A promise on a marketing page is worth what the mechanism behind it is worth. There are three here, and none of them is us remembering to be careful.
CDR-0024 is a ratified record in the same series as the decision that made Australian business the customer we build for. Changing it means writing a new record that supersedes it, dated, saying what changed and why. That is a slower and more visible thing to do than editing a paragraph on a website.
The failure mode for a policy like this is almost never a decision to break it — it is a pipeline somebody built for a good reason that quietly includes the wrong bucket. A rule with no exception means there is no permitted-source check to get wrong, because there is no permitted source.
Your Hub is scoped by the session that resolved you rather than by a filter the interface applies. A filter is something an interface can forget; the boundary here sits underneath it. That control is SEC-006 on the register, with its real state.
The rest of what we can and cannot prove.
This is one decision. The Trust page carries all twenty-four security controls with their real states, including the four that are pending and the ones we will not claim.