Privacy & trust
People have to trust it,
or they will not use it.
Gaite is used in the hardest weeks of people's lives, often through their employer. Everything below follows from one rule: the person owns what they share, and nobody else gets to see it.
The boundary
Who sees what.
Your employer never sees what you talk about
Company administrators have no path to an individual's conversations, plan, or life event. That boundary is enforced in the data layer, not by policy.
Sponsors see their name, not your life
A sponsor's logo and contacts appear inside Gaite for the people they cover. What those people share stays with them.
Family members do not see each other's conversations
Each family member has a private Gaite of their own. Sharing is explicit: you choose a plan, document, or checklist and who to send it to.
What you control
Your information is yours, in the plain sense.
Gaite does not sell, rent, share, or monetize personal data. Its business is plans for people and contracts with the organizations that support them.
- ✓See everything Gaite has remembered about you, listed plainly under My Information
- ✓Edit or delete any remembered fact, one at a time or all at once
- ✓Export your data, or delete your account and everything in it, yourself
- ✓Turn on Private Chat for a conversation that is never remembered or saved
- ✓Decide what is shared, with whom, and when
How it is built
Where the information lives and how it is kept apart.
Encrypted in transit and at rest
All data moves over TLS and is stored encrypted on Google Cloud Platform.
Isolated per organization
Each organization's people, documents, and benefits information are isolated by rule. Anything not explicitly allowed is denied.
A dedicated environment per organization
Each organization's documents are read in an environment dedicated to that organization. Nothing is shared across customers.
Sign-in by Firebase
Sign-in is handled by Google's identity platform. Gaite does not store passwords. Sponsored accounts are verified by work email through a signed invite link.
Administrative audit log
Actions taken by an organization's administrators are logged and kept for 24 months for compliance review.
Credentials scrubbed from documents
When benefits documents are brought in, anything that looks like a credential is removed before the text is stored.
Gaite runs on Google Cloud Platform, Firebase, and Vercel, which hold their own independent certifications. Gaite does not yet hold its own SOC 2 or HIPAA certification. If either is a requirement for your organization, tell us and we will be straight with you about timing.
Safety
Two commitments that do not bend.
If someone shares that they are struggling, Gaite always connects them to real help, including the 988 lifeline. This safety floor is fixed and does not depend on how the conversation goes.
No decision is made for anyone. Gaite organizes, cites, and points to professionals. It does not give medical, legal, or financial advice.
Ask us anything about this.
Security reviews, data processing agreements, or a walkthrough of what an administrator can and cannot see. Privacy policy · Terms of service