Privacy Policy
Effective date: August 10, 2026
Last updated: August 10, 2026
This Privacy Policy explains how Gibon AI, Inc. ("Gibon," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our websites, applications, integrations, APIs, and hosted services (collectively, the "Services"). It applies to all of our products, including those offered under a separate brand or domain name.
Our Services are business tools. Most of the information we handle is submitted by an organization that has an account with us, on behalf of and under the direction of that organization.
The short version. We do not train AI models on your code or content, and we require our subprocessors not to either. We do not sell your personal information. We do use advertising and analytics cookies on our marketing websites, and you can opt out — see Section 8. Our advertising and analytics tools are never applied to the product itself or to anything you submit to it.
1. Scope: marketing websites vs. the product
This Policy covers two distinct environments, and the practices differ between them. The distinction matters, so we state it plainly:
Our marketing websites (including gibon.ai, demobot.dev, and related pages) use cookies, analytics, and advertising technologies as described in Section 8. These are ordinary commercial websites.
Our product — the authenticated application, APIs, integrations, and execution environments — does not carry third-party advertising or marketing analytics tags. Customer Content is never disclosed to advertising networks, analytics vendors, or data brokers, is never used for advertising or measurement, and is never used to build profiles about you or your users. Advertising identifiers collected on our marketing sites are not joined to product accounts or to Customer Content.
2. Controller and processor roles
We act as a controller for information about our website visitors, prospective customers, and the individuals who create and administer accounts — for example, account registration details, billing information, marketing analytics, and support correspondence.
We act as a processor for the content our customers submit to the Services or that the Services access on a customer's instruction — including source code, repositories, files, configuration, and generated artifacts (together, "Customer Content"). Our customer is the controller of that content and determines the purposes for which it is processed. If you are an end user or employee of an organization that uses our Services and you have questions about that organization's data, please contact them directly.
Where we act as a processor, we will enter into a data processing addendum with our customer on request, and that addendum governs and prevails over this Policy to the extent of any conflict. Contact [email protected].
3. Information we collect
3.1 Information you provide
- Account information — name, work email address, password or authentication identifiers, organization name, and role.
- Billing information — billing contact, billing address, plan and subscription details, and transaction history. We do not collect or store full payment card numbers. Card data is collected and processed directly by our payment processor.
- Communications — messages you send to support, sales, or via forms on our websites, including any attachments.
- Configuration — the settings, workflows, connected integrations, and permission scopes you configure for your account.
3.2 Customer Content
When you connect a repository, system, or data source to the Services, or submit content directly, we process that content in order to perform the tasks you have requested. This can include source code and repository metadata, configuration and environment definitions, files and documents, prompts and instructions, and artifacts the Services generate — such as logs, summaries, diffs, test results, and screenshots or recordings of software the Services execute on your behalf.
Customer Content may contain personal data, including personal data about your own end users, if such data is present in the repositories, environments, or applications you connect. You control what you connect and what permission scopes you grant. We recommend limiting the Services' access to what is necessary and avoiding the introduction of production personal data into environments the Services execute.
3.3 Information collected automatically
- Operational and usage data — run and session identifiers, timestamps, duration, step and task counts, model and tool invocations, token consumption, resource usage, success and failure rates, and error codes.
- Log and device data — IP address, browser and device type, operating system, referring pages, and pages viewed.
- Marketing and advertising data (marketing websites only) — cookie and pixel identifiers, advertising IDs, campaign and referral parameters, pages viewed, and conversion events such as sign-ups. See Section 8.
3.4 Information from third parties
If you sign in through, or connect the Services to, a third-party platform, that platform may share information with us according to the permissions you grant — for example, your profile identifiers and the repositories or resources you authorize. We also receive limited information from our authentication, analytics, advertising, and payment providers, including aggregated campaign performance and conversion measurement.
4. How we use information
We use information to:
- provide, operate, and maintain the Services, and perform the tasks you request;
- authenticate users, manage accounts, and administer permissions;
- process payments, manage subscriptions, and send billing communications;
- monitor, debug, secure, and improve the performance and reliability of the Services;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
- provide customer support and respond to your requests;
- send service, security, and administrative notices — you cannot opt out of these while you have an account;
- send marketing communications, where permitted, from which you may opt out at any time;
- measure the performance of our marketing, understand how visitors find and use our websites, and deliver and measure advertising, including retargeting — see Section 8; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Where we rely on consent — including for non-essential cookies and advertising technologies — you may withdraw it at any time without affecting processing that already occurred.
5. Artificial intelligence, model training, and product improvement
This section describes commitments that we consider central to how we operate.
We do not use Customer Content to train, fine-tune, or otherwise improve machine learning models — ours or anyone else's. Your source code and the substantive content you submit are used only to perform the task you requested.
Our AI and data-processing subprocessors are contractually prohibited from training on your data. We use third-party providers to run inference and to support agent execution. We use commercial or enterprise arrangements with these providers under which data submitted through their APIs is not used for model training and is subject to limited retention for abuse monitoring, or to zero retention, according to the provider's terms and our configuration. Note that "not used for training" and "not retained" are different commitments; some providers retain data briefly for abuse monitoring even where they do not train on it.
We do use operational metadata to improve the Services. This is data *about* how the Services ran — durations, step and error counts, model selections, token and resource consumption, latency, tool call patterns, and completion outcomes. It does not include your source code or the substantive content of Customer Content. We use it to diagnose failures, tune model selection and workflow logic, manage cost and capacity, and measure quality.
Human review is limited. Our personnel do not routinely access Customer Content. Access occurs only where necessary to investigate a support request you have raised, to respond to a suspected security incident or abuse, or where required by law. Such access is limited to authorized personnel, logged, and subject to confidentiality obligations.
AI output. Output generated by the Services may be inaccurate or incomplete and should be reviewed before use. Identical inputs may produce different outputs.
6. Execution environments and isolation
Some of our Services execute code and run software on your behalf. This work is performed in ephemeral, isolated compute environments (microVMs) scoped to a single customer. Customer Content is present in those environments only for the purpose of performing the requested task and for the lifetime of that environment; environments are not shared between customers and are destroyed after use. Persistent storage of Customer Content outside those environments is limited to what is necessary to provide the Services — for example, run history, generated artifacts, and configuration you have chosen to save.
7. How we share information
We do not sell personal information for money. We do share certain identifiers and online activity from our marketing websites with advertising partners for cross-context behavioral advertising, as described in Section 8 — under some state privacy laws this is defined as "sharing," and in some cases as a "sale," even though no money changes hands. We never share Customer Content for these purposes. You can opt out as described in Sections 8 and 12.
Otherwise, we disclose information only as follows:
- Subprocessors and service providers — the vendors listed in Section 9, who process data on our behalf under written agreements that restrict their use of the data to providing services to us.
- At your direction — to Third-Party Services you connect, and to other users within your organization's account, according to the permissions you configure.
- Within your organization — account administrators may access account information, usage data, and Customer Content associated with your organization's account.
- Legal and safety — where we believe in good faith that disclosure is required by law, legal process, or a governmental request, or is necessary to protect the rights, property, or safety of our customers, the public, or us. Where legally permitted, we will notify the affected customer before disclosing their Customer Content.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply or to notice of any material change.
- Aggregated or de-identified data — which cannot reasonably be used to identify you or your organization, and which we do not attempt to re-identify.
8. Cookies, analytics, and advertising
The cookie preferences interface in our website footer lists the specific technologies in use and lets you manage your choices. In summary:
8.1 Categories
- Strictly necessary — authentication, session management, security, load balancing, and fraud prevention. These cannot be disabled and are used across both our marketing websites and the product.
- Analytics — how visitors find and move through our marketing websites, which pages perform, and where sign-up flows break down.
- Advertising and retargeting — cookies and pixels placed by advertising platforms that allow us to show ads to people who have visited our websites, to measure whether ads led to a sign-up or purchase (conversion tracking), and to build audiences of similar prospects.
8.2 Where these apply
Analytics and advertising technologies operate on our marketing websites only. They are not present in the authenticated product, in our APIs, or in execution environments, and they never process Customer Content.
8.3 Your controls
- Consent banner. Where prior consent is required, non-essential cookies are not set until you consent. You can change or withdraw your choices at any time through the cookie preferences link in our website footer.
- "Your Privacy Choices." Residents of U.S. states with applicable privacy laws can opt out of the sharing of personal information for targeted advertising via the Your Privacy Choices link in our website footer, or by emailing [email protected].
- Global Privacy Control. We honor the Global Privacy Control (GPC) and similar browser-based opt-out preference signals as a valid request to opt out of sharing for targeted advertising, on the browser where the signal is received.
- Platform controls. You can also opt out through advertising platform settings, your device's advertising ID controls, and industry tools such as the Digital Advertising Alliance and Network Advertising Initiative opt-out pages.
Opting out of advertising cookies does not stop you from seeing ads; it stops those ads from being targeted based on your activity on our websites.
9. Subprocessors and partners
This list is current as of the "last updated" date above. We will update it when subprocessors change. Customers may request advance notice of subprocessor changes by emailing [email protected].
9.1 Service subprocessors
These vendors process data in connection with delivering the product.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, compute, storage, execution environments | All categories, at rest and in processing |
| MongoDB (Atlas) | Primary application database | Account, configuration, run history, artifacts |
| Clerk | User authentication and identity management | Account and authentication data |
| Stripe | Payment processing and subscription billing | Billing contact and transaction data; card data collected directly by Stripe |
| Datadog | Observability, logging, application performance monitoring | Operational and log data |
| Anthropic | Large language model inference | Prompts and content submitted for a requested task |
| OpenAI | Large language model inference | Prompts and content submitted for a requested task |
| Fireworks AI | Large language model inference | Prompts and content submitted for a requested task |
| Tavily | Web search retrieval for agent tasks | Search queries generated during a task |
| Mem0 | Agent memory storage and retrieval | Task context and memory records |
9.2 Marketing website analytics and advertising partners
On our marketing websites, we work with third-party analytics and advertising providers in the following categories. These operate on our marketing websites only, receive no Customer Content, and have no access to the product, its APIs, or its execution environments.
| Category | Purpose | Data disclosed |
|---|---|---|
| Web and product analytics providers | Measure how visitors find, navigate, and convert on our websites | Cookie and device identifiers, IP address, pages viewed, referral and campaign parameters |
| Advertising and social media platforms | Deliver advertising, build and match audiences, and retarget visitors who have previously visited our websites | Cookie and advertising identifiers, pages viewed, campaign parameters |
| Conversion measurement and attribution providers | Determine which campaigns led to a sign-up, trial, or purchase | Cookie and advertising identifiers, conversion and event data |
| Marketing, email, and CRM platforms | Manage prospect and customer communications and campaign operations | Contact details you provide, communication and engagement history |
The specific providers in use at any time are identified in the cookie preferences interface in our website footer, which reflects the technologies currently deployed on our websites. You may also request the current list by emailing [email protected]. We update that list as providers change, without amending this Policy. Because the categories, the data types disclosed, and your opt-out rights stay the same regardless of which provider sits in a category, this Policy describes the categories and the preferences interface carries the current names.
What would change this Policy. If we begin disclosing personal information to a category of recipient not listed above, or begin disclosing categories of personal information beyond those described here — for example, uploading customer or prospect lists to an advertising platform for audience matching, using identity resolution or data enrichment services, or sharing offline conversion data — we will update this Policy before doing so.
We evaluate the security and privacy practices of each subprocessor before engagement and bind each by written agreement. Where required, we will give customers notice of new subprocessors and an opportunity to object, as set out in any data processing addendum executed with that customer. This notice commitment applies to the service subprocessors in Section 9.1; marketing website providers in Section 9.2 do not process Customer Content and are not subprocessors for that purpose.
10. Retention
We retain information for as long as necessary to provide the Services, to comply with our legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements.
Retention periods vary by data category and, in some cases, by your plan and configuration. As general principles:
- Account and billing records are retained for the life of the account and for the period required by applicable law after closure.
- Customer Content and generated artifacts are retained for the period necessary to provide the Services and to make run history available to you. Current retention periods for specific artifact types are documented in our product documentation, and are configurable for some plans.
- Content within ephemeral execution environments exists only for the duration of the run and is destroyed when the environment is torn down.
- Operational and log data is retained on a rolling basis for security, debugging, and capacity purposes.
- Marketing analytics and advertising data is retained according to the retention settings of the relevant platform and our own configured limits.
You may request deletion of your data at any time as described in Section 12. On account termination, we delete or de-identify Customer Content in accordance with our Terms of Service, subject to backups that are cycled out on a routine schedule and to any legal hold.
11. Security
We maintain a security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle. These include encryption of data in transit and at rest, role-based access controls and least-privilege provisioning, tenant isolation for execution environments, centralized logging and monitoring, vulnerability management, secure development practices, and vendor security review.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for configuring the Services appropriately — including the scope of access you grant and the credentials or secrets present in any environment we access. If we become aware of a breach affecting your data, we will notify you without undue delay and in accordance with applicable law and any data processing addendum executed with you.
Report a suspected vulnerability or security issue to [email protected].
12. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information; to opt out of targeted advertising, sale, sharing, or profiling; to object to or restrict certain processing; to withdraw consent; and to appeal a denial of a request. You will not be discriminated against for exercising these rights.
If you are our direct customer or a website visitor, contact [email protected] to exercise these rights, or use the Your Privacy Choices link in our website footer for advertising opt-outs. We will verify your request and respond within the timeframe required by applicable law. If your data is part of Customer Content submitted by an organization, please direct your request to that organization; we will assist them in responding as their processor.
California residents. We do not sell personal information for monetary consideration. We do share personal information for cross-context behavioral advertising as described in Section 8 — specifically, identifiers (such as cookie and advertising IDs), internet and network activity (pages viewed, referral data), and inferred campaign interest, disclosed to the categories of analytics and advertising recipients described in Section 9.2. The specific providers currently in use are identified in our cookie preferences interface. You may opt out via the Your Privacy Choices link, by enabling Global Privacy Control, or by emailing [email protected]. We do not knowingly collect, sell, or share the personal information of anyone under 16. You may designate an authorized agent to submit a request on your behalf. The categories of personal information we collect, our purposes, and our disclosures are described in Sections 3, 4, 7, and 9. You may also appeal a denied request by replying to our decision or emailing [email protected].
Other U.S. states. Residents of states including Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others with comprehensive privacy laws have comparable rights, including the right to opt out of targeted advertising and to appeal a denied request. The same contacts and controls apply.
Outside the United States. The Services are offered to and intended for business customers in the United States. We do not target, market, or offer the Services to individuals or organizations in the European Economic Area, the United Kingdom, or Switzerland, and we do not currently maintain a representative under GDPR Article 27. If you are located outside the United States, please do not use the Services or submit information to us. If you have questions about information we may hold about you, contact [email protected] and we will respond.
13. International transfers
We are based in the United States, and the Services are operated from and intended for use in the United States. Information we collect is processed in the United States. Some of our subprocessors may process or store data in other countries in the course of providing their services to us; where that occurs, we require appropriate contractual protections.
If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law. Your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
14. Children
The Services are business tools not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn that we have done so, we will delete it. Contact [email protected] if you believe a child has provided us information.
15. Changes to this Policy
We may update this Policy from time to time. If a change is material, we will notify account holders by email or by a prominent notice in the Services before it takes effect. The "last updated" date above indicates the most recent revision. Prior versions are available on request at [email protected].
16. Contact us
Gibon AI, Inc. 2261 Market Street STE 80461, San Francisco, CA 94114 Privacy: [email protected] · Security: [email protected] · Legal: [email protected]
The Services are intended for business customers in the United States.