TemenAI Data & Privacy Policy
Last updated: August 17, 2026
At TemenAI, we recognize that core banking customizations, InfoBasic (jBC) routines, Java extensions, and business logic represent mission-critical intellectual property. This Data & Privacy Policy outlines our transparent security model, data flow boundaries, and exact technical scopes of data handling.
NEVER Sent to TemenAI
- User Prompts & Chat Queries
- Proprietary InfoBasic (jBC) & Java Code
- T24 Applications, Records & Tables
- Workspace Files & Project Directories
- API Keys & Local Configuration Files
- Customer / Account / Banking Data
Data Handled by TemenAI
- License Management: Cryptographic validation records, licensee entity name, expiry date & tier.
- Update Server: Version check metadata (client identifier, plugin version, anonymous machine UUID).
- Commercial Contacts: Enterprise license sales & support email communications.
1. Zero Routing of User Prompts & Proprietary Source Code
TemenAI operates as a direct-to-engine client inside your local Eclipse IDE or Temenos Design Studio workspace. When you generate code, analyze routines, or chat with the AI assistant:
- No TemenAI Cloud Relay: AI requests are executed directly from your local IDE instance to your chosen LLM endpoint (e.g., self-hosted Ollama/vLLM on your local machine or bank intranet, or directly to your cloud LLM accounts via Anthropic Claude, OpenAI, or Google Gemini). TemenAI does not operate any intermediate proxy or traffic relay.
- No Code Indexing or Ingestion: Your codebase, InfoBasic files, Java classes, BP routines, and local files are never uploaded, indexed, mirrored, or analyzed by TemenAI infrastructure.
- No AI Training on Your Code or Prompts: Neither TemenAI nor any third party has access to your prompts or code for model training or reinforcement learning through our plugin.
- Offline Air-Gapped Compatibility: In air-gapped or restricted financial networks configured with local LLMs (e.g., TemenAI Local LLM or Ollama), the plugin operates 100% locally with zero external internet traffic required for AI assistance.
2. Data Processed and Retained by TemenAI
To maintain plugin authenticity and provide optional software updates, TemenAI infrastructure interacts solely with the following two operational components:
A. License Validation & Management Data
The TemenAI plugin utilizes cryptographic TrueLicense architecture for offline license verification. When you purchase or request a corporate license:
- License Subject: The authorized licensee name or organization name (e.g., bank or enterprise legal entity).
- Validity Period: License activation date, issuance timestamp, and expiration date.
- License Scope: Number of permitted seats, developer nodes, or organizational tier.
- Cryptographic Signature: Public/private key signature ensuring license integrity and tamper resistance.
-
Offline Operation: Verification of your
.licfile occurs locally on your machine. TemenAI does not require an active cloud connection to validate installed offline licenses during daily coding.
B. Update Server Version Checks
The plugin includes an optional update checker that queries our update server (https://update.temenai.com or a bank's internal configured update host) to inform developers of new releases and security patches.
The payload sent during update checks is entirely anonymous. Instead of transmitting sensitive internal hostnames, the plugin generates a randomized, anonymous UUID (Universal Unique Identifier) upon first launch. This ensures we can provide update notifications to active clients without exposing your internal network naming topology:
Update Server Data Handling Rules for Banking Environments:
- Air-Gapped Compatibility: The update checker can be entirely disabled via Eclipse preferences or redirected to an internal corporate artifact repository (e.g., Nexus, Artifactory) for strict air-gapped environments.
- Zero Payload Ingestion: Update check requests never include internal hostnames, user credentials, code snippets, project filenames, or proprietary network data. The
machineIdis a non-reversible random string that cannot be traced back to a specific developer or workstation. - Minimal Log Retention: Public update server access logs (IP addresses, timestamps) are retained exclusively for security rate-limiting and are automatically purged after 30 days (reduced from standard 90 days for financial compliance).
3. Data Handling Comparison Matrix
| Data Category | Destination | TemenAI Server Access | Retention by TemenAI |
|---|---|---|---|
| User Prompts & Queries | Direct to Configured LLM (Local / Intranet / Direct Cloud API) | Never Routed | None (0 seconds) |
| Proprietary Banking Code (jBC, Java) | Local Workspace & Direct LLM Inference | Never Routed | None (0 seconds) |
| Editor Context & Selections | Local Workstation Memory | Never Routed | None (0 seconds) |
| Cryptographic License Key (.lic) | Local Eclipse Installation & TemenAI Licensing Records | Local Validation Only | Kept in CRM for license term only |
| Update Check Telemetry | TemenAI Update Server (/v2/latest) |
Version Metadata & Anonymous Machine UUID (No Hostnames) | Standard server logs (max 30 days) |
4. Local Storage on Developer Workstations
The TemenAI plugin stores minimal local configuration data directly on your workstation inside the standard Eclipse workspace metadata and secure preference store:
- User Preferences: Selected model providers, local server URLs (e.g.,
http://localhost:11434), custom shortcut keybindings, and temperature settings. - API Credentials: Third-party provider API keys (e.g., Anthropic or OpenAI keys, if cloud LLMs are chosen) are stored securely in local Eclipse Secure Storage or user preferences and sent directly to those respective endpoints using TLS encryption.
- Chat History: Chat conversations are kept in your local Eclipse session cache for your workflow convenience and can be cleared at any time.
5. Third-Party LLM Providers and Cloud APIs
If your organization chooses to configure external cloud AI providers (such as Anthropic, OpenAI, or Google Gemini) instead of on-premise local models:
- The Eclipse plugin establishes a direct, encrypted HTTPS connection directly from your workstation to the third-party API endpoint using your organization's API credentials.
- No traffic is routed through, proxied by, or accessible to TemenAI.
- Data handling by external providers is governed strictly by your organization's direct enterprise service agreements with those providers (e.g., zero-data-retention BAA/DPA agreements).
- For maximum security, financial institutions are encouraged to deploy our TemenAI Local LLM or on-premise Ollama/vLLM instances, guaranteeing 100% offline air-gapped isolation.
6. Enterprise Compliance & Banking Regulatory Alignment
TemenAI's zero-routing architecture is built specifically to satisfy rigorous financial industry compliance frameworks:
- Bank Data Sovereignty: Source code, financial algorithms, and database structures remain entirely within the bank's security perimeter, adhering to strict data localization and sovereignty laws.
- DORA (Digital Operational Resilience Act): By eliminating external dependencies for core AI functioning and providing offline air-gapped capabilities, TemenAI significantly reduces third-party ICT risk and supply chain vulnerabilities as mandated by DORA.
- MAS TRM & Global Banking Standards: TemenAI's zero-retention model aligns with the Monetary Authority of Singapore (MAS) Technology Risk Management guidelines, APRA CPS 234, and EBA guidelines on outsourcing by ensuring critical IP never leaves the bank's controlled environment.
- GDPR, CCPA & Data Protection Compliance: No personal data, PII, PAN (Primary Account Number), customer banking records, or identifiable information is collected, routed, or processed by TemenAI.
- Information Security Alignment (ISO 27001 / SOC 2): Our localized architecture simplifies your compliance audits for ISO 27001, SOC 2 Type II, and PCI-DSS by permanently removing TemenAI as a sub-processor of your sensitive data.
- No Third-Party Trackers: The TemenAI website and plugin contain zero third-party tracking scripts, analytics cookies, or behavioral advertising pixels.
7. Policy Updates & Contact
We may update this Data & Privacy Policy periodically to reflect enhancements in our software or licensing systems. Any updates will be published on this page with an updated revision date.
For questions, audit inquiries, or enterprise security reviews regarding this Data Policy, please contact our team at: contact@temenai.com.