Privacy Policy

Effective date: August 10, 2026
Last updated: August 10, 2026

This Privacy Policy explains how Gibon AI, Inc. ("Gibon," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our websites, applications, integrations, APIs, and hosted services (collectively, the "Services"). It applies to all of our products, including those offered under a separate brand or domain name.

Our Services are business tools. Most of the information we handle is submitted by an organization that has an account with us, on behalf of and under the direction of that organization.

The short version. We do not train AI models on your code or content, and we require our subprocessors not to either. We do not sell your personal information. We do use advertising and analytics cookies on our marketing websites, and you can opt out — see Section 8. Our advertising and analytics tools are never applied to the product itself or to anything you submit to it.


1. Scope: marketing websites vs. the product

This Policy covers two distinct environments, and the practices differ between them. The distinction matters, so we state it plainly:

Our marketing websites (including gibon.ai, demobot.dev, and related pages) use cookies, analytics, and advertising technologies as described in Section 8. These are ordinary commercial websites.

Our product — the authenticated application, APIs, integrations, and execution environments — does not carry third-party advertising or marketing analytics tags. Customer Content is never disclosed to advertising networks, analytics vendors, or data brokers, is never used for advertising or measurement, and is never used to build profiles about you or your users. Advertising identifiers collected on our marketing sites are not joined to product accounts or to Customer Content.


2. Controller and processor roles

We act as a controller for information about our website visitors, prospective customers, and the individuals who create and administer accounts — for example, account registration details, billing information, marketing analytics, and support correspondence.

We act as a processor for the content our customers submit to the Services or that the Services access on a customer's instruction — including source code, repositories, files, configuration, and generated artifacts (together, "Customer Content"). Our customer is the controller of that content and determines the purposes for which it is processed. If you are an end user or employee of an organization that uses our Services and you have questions about that organization's data, please contact them directly.

Where we act as a processor, we will enter into a data processing addendum with our customer on request, and that addendum governs and prevails over this Policy to the extent of any conflict. Contact [email protected].


3. Information we collect

3.1 Information you provide

3.2 Customer Content

When you connect a repository, system, or data source to the Services, or submit content directly, we process that content in order to perform the tasks you have requested. This can include source code and repository metadata, configuration and environment definitions, files and documents, prompts and instructions, and artifacts the Services generate — such as logs, summaries, diffs, test results, and screenshots or recordings of software the Services execute on your behalf.

Customer Content may contain personal data, including personal data about your own end users, if such data is present in the repositories, environments, or applications you connect. You control what you connect and what permission scopes you grant. We recommend limiting the Services' access to what is necessary and avoiding the introduction of production personal data into environments the Services execute.

3.3 Information collected automatically

3.4 Information from third parties

If you sign in through, or connect the Services to, a third-party platform, that platform may share information with us according to the permissions you grant — for example, your profile identifiers and the repositories or resources you authorize. We also receive limited information from our authentication, analytics, advertising, and payment providers, including aggregated campaign performance and conversion measurement.


4. How we use information

We use information to:

Where we rely on consent — including for non-essential cookies and advertising technologies — you may withdraw it at any time without affecting processing that already occurred.


5. Artificial intelligence, model training, and product improvement

This section describes commitments that we consider central to how we operate.

We do not use Customer Content to train, fine-tune, or otherwise improve machine learning models — ours or anyone else's. Your source code and the substantive content you submit are used only to perform the task you requested.

Our AI and data-processing subprocessors are contractually prohibited from training on your data. We use third-party providers to run inference and to support agent execution. We use commercial or enterprise arrangements with these providers under which data submitted through their APIs is not used for model training and is subject to limited retention for abuse monitoring, or to zero retention, according to the provider's terms and our configuration. Note that "not used for training" and "not retained" are different commitments; some providers retain data briefly for abuse monitoring even where they do not train on it.

We do use operational metadata to improve the Services. This is data *about* how the Services ran — durations, step and error counts, model selections, token and resource consumption, latency, tool call patterns, and completion outcomes. It does not include your source code or the substantive content of Customer Content. We use it to diagnose failures, tune model selection and workflow logic, manage cost and capacity, and measure quality.

Human review is limited. Our personnel do not routinely access Customer Content. Access occurs only where necessary to investigate a support request you have raised, to respond to a suspected security incident or abuse, or where required by law. Such access is limited to authorized personnel, logged, and subject to confidentiality obligations.

AI output. Output generated by the Services may be inaccurate or incomplete and should be reviewed before use. Identical inputs may produce different outputs.


6. Execution environments and isolation

Some of our Services execute code and run software on your behalf. This work is performed in ephemeral, isolated compute environments (microVMs) scoped to a single customer. Customer Content is present in those environments only for the purpose of performing the requested task and for the lifetime of that environment; environments are not shared between customers and are destroyed after use. Persistent storage of Customer Content outside those environments is limited to what is necessary to provide the Services — for example, run history, generated artifacts, and configuration you have chosen to save.


7. How we share information

We do not sell personal information for money. We do share certain identifiers and online activity from our marketing websites with advertising partners for cross-context behavioral advertising, as described in Section 8 — under some state privacy laws this is defined as "sharing," and in some cases as a "sale," even though no money changes hands. We never share Customer Content for these purposes. You can opt out as described in Sections 8 and 12.

Otherwise, we disclose information only as follows:


8. Cookies, analytics, and advertising

The cookie preferences interface in our website footer lists the specific technologies in use and lets you manage your choices. In summary:

8.1 Categories

8.2 Where these apply

Analytics and advertising technologies operate on our marketing websites only. They are not present in the authenticated product, in our APIs, or in execution environments, and they never process Customer Content.

8.3 Your controls

Opting out of advertising cookies does not stop you from seeing ads; it stops those ads from being targeted based on your activity on our websites.


9. Subprocessors and partners

This list is current as of the "last updated" date above. We will update it when subprocessors change. Customers may request advance notice of subprocessor changes by emailing [email protected].

9.1 Service subprocessors

These vendors process data in connection with delivering the product.

9.2 Marketing website analytics and advertising partners

On our marketing websites, we work with third-party analytics and advertising providers in the following categories. These operate on our marketing websites only, receive no Customer Content, and have no access to the product, its APIs, or its execution environments.

The specific providers in use at any time are identified in the cookie preferences interface in our website footer, which reflects the technologies currently deployed on our websites. You may also request the current list by emailing [email protected]. We update that list as providers change, without amending this Policy. Because the categories, the data types disclosed, and your opt-out rights stay the same regardless of which provider sits in a category, this Policy describes the categories and the preferences interface carries the current names.

What would change this Policy. If we begin disclosing personal information to a category of recipient not listed above, or begin disclosing categories of personal information beyond those described here — for example, uploading customer or prospect lists to an advertising platform for audience matching, using identity resolution or data enrichment services, or sharing offline conversion data — we will update this Policy before doing so.

We evaluate the security and privacy practices of each subprocessor before engagement and bind each by written agreement. Where required, we will give customers notice of new subprocessors and an opportunity to object, as set out in any data processing addendum executed with that customer. This notice commitment applies to the service subprocessors in Section 9.1; marketing website providers in Section 9.2 do not process Customer Content and are not subprocessors for that purpose.


10. Retention

We retain information for as long as necessary to provide the Services, to comply with our legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements.

Retention periods vary by data category and, in some cases, by your plan and configuration. As general principles:

You may request deletion of your data at any time as described in Section 12. On account termination, we delete or de-identify Customer Content in accordance with our Terms of Service, subject to backups that are cycled out on a routine schedule and to any legal hold.


11. Security

We maintain a security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle. These include encryption of data in transit and at rest, role-based access controls and least-privilege provisioning, tenant isolation for execution environments, centralized logging and monitoring, vulnerability management, secure development practices, and vendor security review.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for configuring the Services appropriately — including the scope of access you grant and the credentials or secrets present in any environment we access. If we become aware of a breach affecting your data, we will notify you without undue delay and in accordance with applicable law and any data processing addendum executed with you.

Report a suspected vulnerability or security issue to [email protected].


12. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information; to opt out of targeted advertising, sale, sharing, or profiling; to object to or restrict certain processing; to withdraw consent; and to appeal a denial of a request. You will not be discriminated against for exercising these rights.

If you are our direct customer or a website visitor, contact [email protected] to exercise these rights, or use the Your Privacy Choices link in our website footer for advertising opt-outs. We will verify your request and respond within the timeframe required by applicable law. If your data is part of Customer Content submitted by an organization, please direct your request to that organization; we will assist them in responding as their processor.

California residents. We do not sell personal information for monetary consideration. We do share personal information for cross-context behavioral advertising as described in Section 8 — specifically, identifiers (such as cookie and advertising IDs), internet and network activity (pages viewed, referral data), and inferred campaign interest, disclosed to the categories of analytics and advertising recipients described in Section 9.2. The specific providers currently in use are identified in our cookie preferences interface. You may opt out via the Your Privacy Choices link, by enabling Global Privacy Control, or by emailing [email protected]. We do not knowingly collect, sell, or share the personal information of anyone under 16. You may designate an authorized agent to submit a request on your behalf. The categories of personal information we collect, our purposes, and our disclosures are described in Sections 3, 4, 7, and 9. You may also appeal a denied request by replying to our decision or emailing [email protected].

Other U.S. states. Residents of states including Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others with comprehensive privacy laws have comparable rights, including the right to opt out of targeted advertising and to appeal a denied request. The same contacts and controls apply.

Outside the United States. The Services are offered to and intended for business customers in the United States. We do not target, market, or offer the Services to individuals or organizations in the European Economic Area, the United Kingdom, or Switzerland, and we do not currently maintain a representative under GDPR Article 27. If you are located outside the United States, please do not use the Services or submit information to us. If you have questions about information we may hold about you, contact [email protected] and we will respond.


13. International transfers

We are based in the United States, and the Services are operated from and intended for use in the United States. Information we collect is processed in the United States. Some of our subprocessors may process or store data in other countries in the course of providing their services to us; where that occurs, we require appropriate contractual protections.

If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law. Your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.


14. Children

The Services are business tools not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we have done so, we will delete it. Contact [email protected] if you believe a child has provided us information.


15. Changes to this Policy

We may update this Policy from time to time. If a change is material, we will notify account holders by email or by a prominent notice in the Services before it takes effect. The "last updated" date above indicates the most recent revision. Prior versions are available on request at [email protected].


16. Contact us

Gibon AI, Inc. 2261 Market Street STE 80461, San Francisco, CA 94114 Privacy: [email protected] · Security: [email protected] · Legal: [email protected]

The Services are intended for business customers in the United States.