Skip to content
Nautilus Services by GoodVenturesAI + software implementation
NAUTILUSSERVICES / BY GOODVENTURES

PUBLIC WEBSITE / CURRENT RELEASE

Privacy notice.

How the public Nautilus Services website handles AI chat, booking details, transactional messages, calendar integrations, and technical service data.

This notice describes the public marketing website at nautilus.services, including its public AI chat and booking form. It does not describe a future client engagement, a private system delivered to a client, or the separate privacy terms of an external service.

What the site collects

If you use the public AI chat, the site processes the messages you submit and the answer returned to your browser. Nautilus does not intentionally write raw chat transcripts to its application database. The current chat can still be processed in your browser, through the site’s request path, by OpenRouter, and by the selected model provider to produce the answer.

Before a chat request is sent for AI inference, the site attempts to redact email addresses and phone numbers it detects. This is a limited, automated safeguard and may not identify every contact detail or other personal information. The chat also rejects certain recognizable credential patterns. You must not submit passwords, API keys, private keys, tokens, regulated data, confidential customer content, source code, or security findings.

If you use the booking form, Nautilus collects the name, email address, optional company, project context, selected time, visitor and team time zones, booking status, notification and calendar state, booking identifier, and operational timestamps needed to reserve and manage the appointment. Booking records are stored inside a dedicated Google Cloud data boundary used for this public engagement service.

AI processing

The public chat sends a redacted version of visitor messages, approved Nautilus reference material, and service instructions to OpenRouter. OpenRouter routes the request to a selected model provider. The site requests Zero Data Retention and denies provider data collection on each request, and it disables the OpenRouter prompt cache header.

These controls are intended to prevent prompt retention and training by the eligible inference endpoint. They do not mean that no processing occurs. OpenRouter may retain request metadata such as model, token counts, timestamps, and latency, and provider-specific operational, security, abuse-prevention, legal, or technical exceptions may apply under the relevant provider terms. Do not use public chat for sensitive or confidential material.

Public chat is not a secure intake channel

Redaction and credential detection reduce some accidental exposure; they do not guarantee removal. A suitable authorized transfer method can be established after scope, identity, and an engagement boundary are confirmed.

Booking messages and calendar services

Nautilus uses Resend to send transactional booking messages to the visitor and the Nautilus team. Resend processes the sender and recipient addresses, message content, delivery metadata, and, when used, the standards-based ICS calendar invitation. An email provider accepting a message does not guarantee inbox placement, reading, or calendar acceptance.

Google Calendar is optional and is used only after a separate authorization has been configured. When enabled, the service may read availability and send the booking time, organizer and attendee details, booking reference, and event data to Google to create and update a calendar event and conferencing details. Without that authorization, Nautilus uses its booking record as the reservation authority and sends an email and ICS invitation instead.

Infrastructure and security data

Hosting, database, network, content-delivery, email, and security layers may process technical information needed to operate and defend the service. This can include IP address, timestamp, requested path, response status, browser or user-agent information, rate-limit identifiers, error and delivery state, and security signals. Access and retention depend on operational need, provider configuration, and applicable obligations.

No behavioral advertising or analytics

The current release does not embed an advertising pixel or behavioral analytics script and does not use public chat or booking activity to build advertising audiences. Network and security providers may use technical mechanisms required to deliver, rate-limit, or protect the service. External links and providers control their own collection and terms.

Retention, deletion, and questions

Booking records and their reserved-slot records are configured to expire 180 days after the scheduled appointment. Associated booking event and notification-state records are configured to expire 180 days after each event. Booking-management sessions expire after 30 days, and application rate-limit records expire after their short abuse-prevention windows. Google Cloud TTL deletion is asynchronous, and records may persist for a limited time in backups, security systems, provider systems, or where a legal, security, or dispute-preservation obligation applies.

To ask a privacy question or request access, correction, or deletion, email team@goodventures.ca and identify the request as relating to nautilus.services. Nautilus may need to verify identity and may retain information where required for security, legal, dispute, or recordkeeping purposes. Do not include sensitive evidence until an appropriate transfer channel is confirmed.

Email the privacy contact