Privacy: who can see what
Who can see your conversations, your profile, your Twin, your documents, and what an admin can and cannot see.
This page answers the question every security review asks first: who can see what. The rules are the same everywhere WethosAI runs, including the mobile apps, Slack and Microsoft Teams. If a term below is unfamiliar, Words we use defines it.
Your conversations with XO
XO is the AI assistant inside WethosAI. You can talk to it in several places, and each has its own rule.
| Where | Default | Who can see it |
|---|---|---|
| The main XO chat | Private | Only you |
| Your own profile page | Private | Only you |
| Another person's profile page | Private | Only you |
| Your calendar | Private | Only you |
| Inside a group | Private, and you can make it public | Only you, unless you make it public for the group |
| A shared conversation in a group | Shared | The members of that group |
Each conversation is separate. XO only knows what was said in the conversation you are in, and it does not carry information from one conversation into another.
If you talk to XO about another person, on their profile page or through their Twin, that conversation is yours. The other person cannot see it, and neither can anyone else. Its purpose is to help you prepare for a conversation with them.
Shared conversations
A shared conversation is one that every member of a group can see. Only the person who started it can rename it, edit it or delete it. A private conversation inside a group stays private even though it happens in the group's space. Only you can make it public, and once you have, it cannot be made private again.
Your profile
Your profile is what WethosAI knows about how you work. The members of your organization can see it: your name, title and location, your picture, the About Me section you write, and the summary of how you work across the four dimensions. You can change your About Me at any time. Your profile can be downloaded as a PDF from your profile page.
Your Twin
A Twin is an AI model of you that you build yourself. It exists only with your permission. You choose what it learns from, and you decide whether it stays active. You can see what it has learned from, and you can withdraw it at any time. Who can talk to it is governed by your organization's settings. The conversations other people have with your Twin are private to them; your Twin does not report them to you.
Nothing your Twin learns is used to train AI models shared with other customers.
Virtual Members
A Virtual Member is an AI model of someone who is not on the platform. It is built from that person's public professional record and from information your organization already holds and is allowed to use. Nothing about them is gathered from anywhere else. The person cannot see their Virtual Member, because they are not on the platform. When they join, their own profile replaces it. Anyone in the Brainstorm can see and edit a Virtual Member's card.
Your documents
Documents only reach the platform when you upload them, or when you connect a folder or file as a Sync Point. Connecting Google Drive or Microsoft 365 does not copy everything in your account.
Permissions travel with a document. A file shared in a group is visible to the people who can already see it in Drive or Microsoft 365. Someone without access to it there cannot see it here. Disconnecting an integration stops future updates. It does not delete documents that have already been uploaded.
What an admin can and cannot see
An admin is a person who manages your organization's WethosAI account.
An admin can see: who belongs to the organization, each person's account status and license, which groups exist and who is in them, and how much the platform is used across the organization, such as the number of active users, time spent in the platform, and which features are in use.
An admin cannot see: your private conversations with XO, your conversations with anyone's Twin, or the conversations of a group they are not a member of. Usage is reported for the organization as a whole. It is not a record of what any one person asked.
The rule behind all of this
WethosAI describes how people tend to work so that decisions can be prepared with those people in mind. It is not built to judge people, rank them, or limit what they can do, and it must not be used to make decisions about anyone's employment. Profiles, Twins and Virtual Members exist for preparation and practice, not for evaluation.
Enterprise controls
WethosAI is SOC 2 Type II certified. It supports single sign-on and role-based access controls. It does not use customer data to train AI models shared with other customers, and it deletes your data within 30 days of a request. Trust and Security lists every control, and the Trust Center holds the audit reports and live status.