In one sentence
The assistant only sees what you could already see, only acts when you ask, and never changes anything outside Morada OS without your explicit approval.The four commitments
Your data does not train AI models
Your organization’s conversations, files, and documents are never used to train or improve third-party AI models. Model providers are accessed under corporate agreements that restrict usage to generating the answer.
You approve before it happens
Every action that leaves Morada OS (sending an email, updating the CRM, posting a message) is assembled, shown in full, and only executed after you click Aprovar (Approve).
The assistant inherits your permissions
When you connect a tool, the assistant sees what your account sees in that service. It never widens an access you don’t have.
Your conversations are yours
Being an administrator gives no access to anyone’s conversation: management sees usage numbers only, never what was discussed. Only you decide whether to share a copy of a conversation, and only the people you chose see it, colleague or administrator.
What the assistant sees
The files you send in the chat
The files you send in the chat
Spreadsheets, documents, presentations, PDFs, images, and audio you attach are available to that conversation. Analysis runs in an isolated, temporary environment designed so your files neither leave it nor mix with another customer’s.
The organization's knowledge base (Brain)
The organization's knowledge base (Brain)
Documents your company added to the Brain (price tables, policies, manuals) are available to whoever has permission in that collection. Answers show which document the information came from, so you can check it.
The tools you connected
The tools you connected
Nothing is accessed before you connect. Once connected, the assistant queries the service when your request calls for it, with your permissions, and you can disconnect at any time.
The web, when your request calls for it
The web, when your request calls for it
If the answer depends on public information (a competitor’s launch, a news story, a market figure), the assistant searches the web and shows the link for every source. You can also paste the address of a page or a public PDF and ask it to read it. In those cases the search provider receives only the search terms, composed from the conversation, and the address you asked it to read: your files, Brain documents, and connected tool content are not sent to it.
What it does NOT see
What it does NOT see
- Other people’s conversations, including your own team’s.
- Documents in someone else’s Espaço Pessoal (Personal space) in the Brain.
- Data belonging to another customer organization. Morada OS data lives in a dedicated database, strictly separated by organization and workspace.
- Tools you have not connected.
Who sees what
Frequently asked questions
Does Morada.ai read our conversations?
Does Morada.ai read our conversations?
Not as a routine. Morada.ai staff access is restricted to what is needed to operate and support the service, under the conditions set out in the contract. No content is used to train models.
What happens when someone leaves the company?
What happens when someone leaves the company?
Access ends together with the corporate login. That person’s history is preserved and becomes inaccessible: nobody inherits their conversations. Copies of conversations they had already shared with colleagues stay with those colleagues, like a message already sent.
Can the assistant send an email or change something on its own?
Can the assistant send an email or change something on its own?
No. Queries and reads run directly, because they change nothing. Anything that changes something outside Morada OS appears as an approval card with the full details and waits for your click. You can adjust or cancel. On a custom connector, even queries go through that card.
When the assistant searches the web, what leaves my company?
When the assistant searches the web, what leaves my company?
The search terms leave, and, when you paste a link, the address you asked it to read. Those terms are composed by the assistant from the conversation, so they can repeat words from your request. Your files, Brain documents, and the content of the tools you connected are not sent to the search provider. Every piece of information comes back with a link to its source, so you can check it before using it.
How do I remove a tool's access?
How do I remove a tool's access?
Under Conectores (Connectors), open the tool’s card and click Desvincular (Unlink). The stored authorization is deleted immediately. To end it on the provider’s side as well, see the page for IT teams.
What if I send a file with customer data?
What if I send a file with customer data?
Morada OS is built to work with that kind of material, and every upload is recorded in audit trails tied to the user. Even so, send only what your company authorizes: your organization decides what enters the platform.
Which laws does Morada OS follow?
Which laws does Morada OS follow?
Data processing follows Brazil’s LGPD (Law 13.709/2018), with the roles, legal bases, retention periods, and the Data Protection Officer channel described in the Privacy policy.
Official documents
Privacy policy
Roles, legal bases, retention, and DPO contact.
Terms of service
Usage conditions, responsibilities, and service levels.
For IT teams
What the administrator approves, why, and how to revoke on each provider.