# ETP Foundry — AI-use disclosure: the in-console assistant **Draft v0.1 — pending counsel review · 28 September 2026** The signed-in ETP Foundry console includes an assistant, **"Ask the desk"**, live since 27 September 2026. This page says what it is, what it can and cannot do, and what is stored. ## 1. Provider The assistant runs **Google Gemini on Vertex AI** (Google Cloud, location `global`). The desk calls it with its own Google Cloud service account; no third-party API key is involved. The software also supports one alternative provider (Anthropic). That provider is **not enabled**. If it is ever enabled, this page and the sub-processor list will change first. ## 2. Who can use it Only signed-in users of the desk. It is not part of the public site, the public API or the hosted MCP. ## 3. What it can do - **Read the desk as you.** It sees only what your role can already see: proposals, funds, holdings, committees, schedules, vaults, reports and settings. Its tools call the desk with your own credentials, so the desk's access rules apply to it exactly as they apply to you. - **Answer questions from published material** (the methodology, the rulebook and the other public documents), citing the page it used. - **Prepare changes for you to approve**: for example, a confirmation or refusal of a proposal, an API key, an EVM address registration, a report, or a new ETP. - **Open pages and propose values for a form.** You watch each field fill. ## 4. What it cannot do - **It cannot approve, sign, confirm, refuse or submit anything on its own.** Every write waits for your explicit **Approve**. An action you do not approve expires after 10 minutes. - **It never submits a form.** Filling a field is not submitting it. - It cannot act as another user, or see anything your role cannot see. - **No published value, fixing or attestation is produced by AI.** Fixings are proposed by the desk's deterministic code and attested only by committee seats. - **It does not give investment, legal or tax advice**, and it will not say whether to buy, sell, create or redeem. Its answers can be wrong. Check anything that matters against the published documents and the ledger record. ## 5. Limits Each person has a daily message and token budget, a cap on tool steps per message, and a time limit per message. You can stop a running turn at any time. ## 6. What is stored - **Your conversations** (what you typed, the replies, the steps taken, and your approvals and rejections) are stored with the desk in Google Cloud (`us-central1`), in a folder named by a hash of your user id. **They are deleted automatically 90 days after the last message in the conversation.** Before then you can delete any conversation yourself ("Delete this conversation" in the conversation history, inside the assistant panel), and we delete any conversation on request (hello@etpfoundry.com). Only you can delete your conversation: an operator viewing the desk as you cannot. Each deletion and each automatic purge is recorded in the audit log by conversation id, never by content. - **A daily usage count** per user, to enforce the budget. - **Google** processes your messages, and the desk data the assistant reads for you, in order to reply. Under Google Cloud's terms for Vertex AI, this data is not used to train Google's models. ## 7. Contact Questions: hello@etpfoundry.com. Security issues: security@etpfoundry.com. Lucilla, Inc., federal corporation no. 16699448, Toronto, trading as ETP Foundry.