AI Code of Conduct & Responsible AI Practices
Version 1.3 — Last updated: June 24, 2026
This document sets out the responsible-AI commitments of Green Union Capital Inc. ("Geb AI", "we", "us") for the operation of the Geb AI conversational assistant, the Geb v7 language model family, and all associated tools and surfaces (collectively, the "Service"). It is published as a transparency artefact under the Government of Canada's Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (Innovation, Science and Economic Development Canada, September 2023), and is aligned with the Office of the Privacy Commissioner of Canada's Principles for Responsible, Trustworthy and Privacy-Protective Generative AI Technologies (December 2023). It complements, and does not replace, our Privacy Policy, Terms of Service, and Data Handling Policy.
1. Our Commitments
Geb AI is built and operated on a small number of bright-line commitments. They are not aspirational; they are the product's contract with its users.
- We do not train our language models on your data. The Geb v7 language model family — Green Union Capital's proprietary model, fine-tuned from an open-source foundation model — is fine-tuned only on (a) curated synthetic examples that teach it how to use tools — web search, prospecting, document generation, code execution, and similar — and (b) publicly licensed corpora. User conversations, uploads, KoL memory, and tool outputs are never used to train Geb v7 or any other Geb model. Instead of retraining models on user data, Geb uses the per-user Key of Life (KoL) memory layer described below (see Privacy Policy section 5A).
- Your Key of Life (KoL) memory is yours. KoL is a per-user memory layer you can read, edit, export, and delete at any time. It is never read by other users, never used to train models, and never sold or shared.
- We do not perform biometric identification of real persons. The Service is not designed for, and may not be used for, facial recognition, gait identification, voiceprint matching, or any other 1:N biometric identification.
- We do not generate non-consensual deepfakes of real people. Uploads of photos, voice samples, or video of identifiable real persons for the purpose of synthesizing their likeness, voice, or actions are prohibited and technically restricted in image and video generation tools.
- We are transparent about what Geb is. Every Geb AI surface is labelled as AI-generated. We disclose which third-party model providers we use and where data is processed.
- We do not sell, lease, or barter conversation data. Not to advertisers, governments, data brokers, affiliates, or anyone else — for any price, ever. This commitment expressly covers conversation content, KoL memory, uploads, and any data derived from them.
- No advertising. No advertising profiles. No engagement-maximisation. Geb AI does not display advertising to anyone, does not build advertising profiles from your activity, and does not optimise the Service for engagement-time, daily-active-use, or other metrics that incentivise unhealthy dependence.
- Your data is portable, free of charge, even after cancellation. You may export your conversations and KoL memory as machine-readable JSON at any time, with no fee and no paywall, including after your subscription ends.
2. Alignment with Canada's Federal Voluntary Code
Green Union Capital Inc. has formally adhered to the Government of Canada's Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems and has applied to be listed as a public signatory. The Code organises responsible AI around six principles. Below we map each principle to a concrete Geb practice.
- Accountability. A named Privacy Officer (the Founder of Green Union Capital Inc.) is accountable for our compliance with this Code, applicable privacy law, and our internal AI risk-management process. All material AI-policy changes are versioned and dated on this page.
- Safety. We operate a layered safety stack: refusal training on Geb v7 (built on a published harm taxonomy), output-side content filtering (especially in Child Mode), tool-access restrictions in Child Mode, real-person-likeness restrictions on image and video generation, abuse and rate-limit detection, and an 18+ age gate.
- Fairness and Equity. Geb v7 is fine-tuned with attention to Egyptian-Arabic and Canadian-English usage patterns and we test for performance disparities across dialect, gender, and register during pre-release evaluation. We document known limitations in section 8 below.
- Transparency. The Service is clearly labelled as AI. Sub-processors are listed publicly in our Privacy Policy. Geb v7's training-data summary, the list of supplementary model providers (Google), and the in-region processing footprint are all disclosed.
- Human Oversight and Monitoring. We monitor outputs for harm, plan pre-release red-team exercises beginning with Geb v7 (see section 4), and provide human review of any account-protective automated decision (see section 6). High-impact incidents trigger a written post-incident review.
- Validity and Robustness. Geb v7 releases are gated on a fixed evaluation suite covering refusal accuracy, factuality, dialect coverage, and adversarial robustness. We will publish a model card for each major Geb model release beginning with Geb v7.
3. Acceptable Use
The following uses of the Service are prohibited. Violations may result in immediate termination, deletion of generated content, and reporting to law enforcement where required by law. This list is illustrative and not exhaustive; conduct that is unlawful, deceptive, or that creates a foreseeable risk of serious harm is prohibited regardless of whether it is enumerated here. Real-person likeness restrictions and deepfake prohibitions are also incorporated into our Terms of Service §6D.
- Illegal activity. You may not use the Service to plan, facilitate, or commit conduct that is unlawful in your jurisdiction or in Canada.
- Compliance with local law. You are responsible for compliance with applicable local law, including Egyptian Cybercrime Law 175/2018 and Canadian Criminal Code ss. 318–320 (hate propaganda). We do not assist conduct that is unlawful in your jurisdiction; equally, we do not impose moderation beyond the legal minimum or arbitrary political viewpoint suppression.
- Real-person impersonation and deepfakes. You may not use the Service to generate, edit, or distribute images, video, or audio that synthesizes the likeness or voice of an identifiable real person without that person's informed, documented consent. This restriction is enforced in our image and video generation tools and is incorporated into our Terms of Service §6D.
- Child sexual abuse material (CSAM) and minor exploitation. Absolutely prohibited. Suspected CSAM is preserved as required by law and reported to the Canadian Centre for Child Protection (cybertip.ca) and to other competent authorities.
- Targeted harassment, hate speech, and incitement to violence. You may not use the Service to harass, threaten, intimidate, or dehumanize individuals or groups on the basis of race, ethnicity, national origin, religion, gender, gender identity, sexual orientation, disability, or other protected characteristic.
- Malware, cyberweapons, and unauthorized access tooling. You may not use the Service to write, refine, or distribute code intended to compromise systems, networks, or accounts you are not authorized to access. Legitimate cybersecurity research, defensive tooling, and Capture-the-Flag (CTF) participation are not prohibited where conducted on systems you own or have written authorization to test.
- Election manipulation and political deepfakes. You may not use the Service to generate synthetic media depicting candidates, elected officials, or election workers; to operate coordinated inauthentic behaviour networks; to generate personalised political ads at scale; to impersonate election officials, candidates, or election workers; or to operate disinformation networks targeting voters.
- Substitution for licensed professional advice. The Service may not be presented or relied upon as a substitute for licensed medical, legal, financial, tax, or psychological advice. Outputs in these domains are informational only.
- Mass surveillance and biometric identification. You may not use the Service to perform face, voice, or gait identification of real people, to operate watchlists, or to enrich biometric databases.
- High-stakes automated decisions. You may not use the Service as the sole decision-maker for employment, admissions, housing, credit, insurance, immigration, or benefits decisions. A qualified human must be the decision-maker. This restriction targets institutional deployments. Personal use of Geb to prepare an application, draft a cover letter, summarize a policy, or research your own options is fully permitted.
- Critical-infrastructure operation. You may not use the Service to control or directly drive the operation of critical infrastructure (electrical grid, water, nuclear, aviation, rail, hospital life-support, weapon systems).
- Weapons of mass destruction and dual-use uplift. You may not use the Service to obtain meaningful uplift toward chemical, biological, radiological, nuclear, or high-yield explosive (CBRNE) capabilities.
- Unauthorized scraping of personal data. You may not use the Service to scrape, compile, or enrich personal data sets without a lawful basis under PIPEDA, the GDPR, or other applicable law.
- Use in unlicensed jurisdictions. The Service is not currently offered to users in the European Economic Area (which includes the EU member states), the United Kingdom, or Switzerland. You may not access the Service from those jurisdictions, including by means of a VPN or other circumvention.
3A. High-risk use requirements
Even where assist-mode use is permitted, certain domains warrant additional safeguards. If you operate Geb in a context where its output materially informs decisions about health, legal status, finance, employment, housing, insurance, immigration, education, or journalism affecting third parties, you must (a) keep a qualified human reviewer in the loop before any decision is communicated to the affected person, and (b) disclose to that person that AI tooling was used to inform the decision. We may require attestation of these practices for institutional accounts in these domains.
4. Safety Practices
Safety is built in layers. No single layer is sufficient on its own; the combination is what makes the Service safe to use at scale.
- Refusal training on Geb v7. Geb v7's refusal training is built on a published harm taxonomy (Constitutional-AI-inspired), with red-team-discovered jailbreak patterns hardened against in successive checkpoints.
- Output-side content filtering. Generations are screened by a downstream classifier that flags violent, sexual, self-harm, hateful, and CSAM-adjacent content. Flags trigger redaction or refusal.
- Child Mode. An optional, parent-controlled mode that (a) tightens the output classifier thresholds, (b) disables image and video generation, (c) disables web research and outbound tool calls, (d) enforces age-appropriate refusal training, and (e) records access events to KoLc for parental review.
- Real-person-likeness restrictions. Image-to-image and video generation tools refuse uploads of identifiable real persons unless the user attests to consent. Voice cloning is disabled.
- Age gate. The Service requires accounts to attest to being 18 or older. Detected under-18 accounts are terminated and the personal information deleted (see Privacy Policy section 10).
- Rate limits and abuse detection. We rate-limit by account, IP, and behavioural signal, and we operate automated detection for credential stuffing, scraping, and prompt-injection campaigns.
- Engagement design. We do not optimise the Service for engagement-time, daily-active-use, or other metrics that incentivise unhealthy dependence; KoL memory is opt-in, user-readable, and user-deletable.
- Responsible disclosure. Security and safety researchers are invited to report vulnerabilities to [email protected]. We commit to acknowledging reports within 5 business days, providing a substantive response within 30 days, validating findings and confirming remediation, protecting researcher identity, attributing credit with the researcher's permission, and never restricting a researcher's ability to disclose their findings to other organizations or to CERT/CIRT bodies. We do not pursue legal action against good-faith researchers who comply with this policy.
- Pre-release red-teaming. Beginning with Geb v7 (target: Q3 2026), each major release will be subjected to internal red-teaming covering CBRNE uplift, CSAM, election interference, fraud uplift, and dialect-specific harms, with a written report retained. Earlier releases rely on staged rollout and post-deployment monitoring.
- Risk tiering. Geb v7 is, by design, a small fine-tuned model not in frontier-capability territory; the safeguards in this section are calibrated accordingly. We commit to revisiting this framework — including pre-deployment dangerous-capability evaluations along the lines of Anthropic's Responsible Scaling Policy or OpenAI's Preparedness Framework — if Geb ever develops or deploys a frontier-class model.
- Breach notification. Where a breach poses a real risk of significant harm, we notify affected users without unreasonable delay (target: within 72 hours of confirmation, mirroring GDPR Art. 33), the Office of the Privacy Commissioner of Canada (PIPEDA s.10.1), the Commission d'accès à l'information du Québec where Quebec residents are affected, the provincial Information and Privacy Commissioners of Alberta and British Columbia where applicable, the Egyptian Personal Data Protection Center where Egyptian residents are affected, and other regulators required by applicable law.
5. Transparency
- AI marker. Every conversational surface is marked "Powered by Geb AI" or equivalent. Generated images and videos carry provenance metadata where supported. We are evaluating C2PA content credentials and SynthID-style watermarking for Geb's own generative outputs; for any third-party fallback generation, provenance follows that provider's capabilities.
- Sub-processor disclosure. Geb's active sub-processors are Google LLC / Google Cloud Platform (including Google Cloud Compute Engine in europe-west4 / Netherlands and me-central1 / Doha, Qatar for the MENA-region SearXNG search egress), Google Firebase, Cloudflare Inc., Stripe Inc., Resend Inc., and ElevenLabs Inc. (text-to-speech voice synthesis). Current processing locations and the purpose of each sub-processor are listed in our Privacy Policy, section 5, and updated when sub-processors change.
- Geo-aware search egress. Geb routes search traffic to the nearest geographic egress to minimize latency and avoid US-IP rate-limit bans on third-party search providers. The Doha (Qatar) egress was added 2026-05-09 to serve MENA users with sub-100ms search latency; Toronto, South Carolina, and Netherlands egresses serve Canadian, US, and EU users respectively. No personally identifying information is sent to these egress proxies — only the user's search query and aggregated request metadata, retained for 90 days for abuse detection and operational debugging.
- Model attribution. The primary language model is Geb v7 (Green Union Capital's proprietary model, fine-tuned from an open-source foundation model). Image generation is handled by Geb's own Imaging Model and video generation by Geb's own video model, both self-hosted. Third-party providers include Google (complementary and fallback AI services) and ElevenLabs (text-to-speech voice). The currently active model for any conversation is shown in the chat UI.
- Training-data summary. Geb v7 is fine-tuned from an open-source foundation model on (a) synthetic tool-use examples generated by Geb, (b) publicly licensed Arabic and English corpora (a detailed corpus list, including filtering provenance for Common Crawl-derived subsets, will be published with the Geb v7 model card), and (c) human-rated preference pairs collected under a documented protocol. No user data, KoL memory, or upload content is used in Geb v7 training.
- Processing footprint. Primary inference and storage are concentrated in Google Cloud's europe-west4 region (Netherlands) and a Geb-operated DGX cluster in Edmonton, Alberta. The full sub-processor footprint, including Cloudflare's global edge, is in Privacy Policy section 5. Cross-border transfers are documented in the Privacy Policy.
- EU AI Act classification. Geb AI is a deployer and downstream fine-tuner of an open-source foundation model; we are not a GPAI model provider within the meaning of EU AI Act Art. 53.
- KoL visibility. Your KoL memory is visible to you in-product, can be edited or deleted item-by-item, and can be exported as JSON at no charge.
- Transparency report. We do not voluntarily implement content moderation beyond the legal minimum. We commit to publishing an annual transparency report listing the volume and nature of legal demands received and our responses to them. Target: first annual transparency report — Q1 2027.
6. Human Oversight
- Privacy Officer. The Founder of Green Union Capital Inc. is the named Privacy Officer and is accountable for this Code, our Privacy Policy, and our AI risk-management process. Contact: [email protected].
- Human review of automated decisions. Account-protective automated decisions (anti-abuse enforcement, fraud holds, rate-limit suspension) are reviewable by a human on request to [email protected], in line with Quebec Law 25 §12.1.
- Bug and safety reports. Reports submitted to [email protected] receive an acknowledgement within 5 business days and a substantive response within 30 days.
- Privacy-rights requests. Access, correction, deletion, and portability requests are handled within 30 days, in line with PIPEDA and Quebec Law 25.
- Internal concerns and non-retaliation. Any current or future employee, contractor, or sub-processor staff member may raise responsible-AI or privacy concerns directly to the Privacy Officer at [email protected]. We commit to non-retaliation for good-faith reports.
- Post-incident review. High-impact safety failures (content failures with reasonable likelihood of serious harm, data exposure, or material misuse) trigger a written post-incident review and, where appropriate, public disclosure.
7. User Rights
Subject to the limits of applicable law, you have the following rights, exercisable by contacting [email protected]:
- Right of access (PIPEDA Principle 9; GDPR Art. 15; Quebec Law 25 §27).
- Right of correction (PIPEDA Principle 9; GDPR Art. 16; Quebec Law 25 §28).
- Right of deletion (PIPEDA; Quebec Law 25 §28.1; GDPR Art. 17 where applicable).
- Right of portability via JSON export, at no charge, including after subscription cancellation (Quebec Law 25, right of portability provisions; GDPR Art. 20 where applicable).
- Right to object to automated decisions and request human review (Quebec Law 25 §12.1; GDPR Art. 22 where applicable).
- Right to withdraw consent at any time, including by deleting your account; withdrawal is prospective and does not affect lawful processing prior to withdrawal.
8. Validity, Robustness, and Limitations
Generative AI systems make mistakes. The categories below are the ones Geb is most prone to.
- Hallucination. Geb may generate confident-sounding statements that are factually wrong, particularly for niche, recent, or paywalled information. Always verify load-bearing facts.
- Bias. Geb v7 and the supplementary models we use are trained on corpora that reflect societal bias. Output may under-represent or stereotype particular groups, dialects, or viewpoints. We test for performance disparities across dialect, gender, and register during pre-release evaluation; documented findings will accompany the Geb v7 model card.
- Domain limits. The Service is not a substitute for licensed medical, legal, financial, tax, or psychological advice.
- Dialect coverage. Based on internal preliminary evaluation, Geb v7 performs strongest on Modern Standard Arabic, Egyptian Arabic, and Canadian English; performance on Levantine, Gulf, and Maghrebi dialects, French, and other languages is more limited and is being expanded. Quantitative results will be released with the Geb v7 model card.
- Tool-use brittleness. Tools (deep research, document, slide, image, video generation) can fail or produce partial results. Errors are reported in-product where possible.
- Continuous monitoring. We monitor output quality, user-reported issues, and incident telemetry, and we ship corrective updates on a regular cadence.
9. Children and Vulnerable Users
- 18+ accounts only. The Service is restricted to users 18 years of age or older.
- Child Mode for adult-supervised use. Adults may enable Child Mode on their account when they are present with a minor. Child Mode tightens content filtering, disables image and video generation, disables outbound tool calls, and writes a parent-visible audit trail to KoLc (the Child Mode memory layer).
- No targeted advertising. See section 1 — Geb AI does not display targeted advertising to anyone, full stop, and does not build advertising profiles.
- Vulnerable-user safeguards. Self-harm and crisis content trigger a referral message to local crisis resources and refusal of detailed methods. If you are in crisis, please reach out: 9-8-8 Suicide Crisis Helpline (Canada, call or text, EN/FR, 24/7), 16328 (Egypt Ministry of Health & Population, General Secretariat of Mental Health & Addiction Treatment, 24/7), or your local emergency number.
10. Updates and Versioning
This Code is a living document. We will notify users in advance of material changes to the bright-line commitments in section 1, and ordinarily provide at least 30 days' notice via in-app notification and email to all account holders before they take effect, except where a more rapid change is required by law or to address a serious safety issue. The version history is maintained at the bottom of this page. We commit to never weakening the bright-line commitments in section 1 without first giving notice and a clear opportunity to delete your account and export your data.
11. Contact
Green Union Capital Inc.
Privacy Officer (Founder) — [email protected]
Responsible disclosure (security and safety) — [email protected]
General support — [email protected]
12. Versioning
- Version 1.3 — May 18, 2026. Removed Google Vertex AI from supplementary model providers (decommissioned 2026-05-11; Geb v7 now serves from a Geb-operated DGX cluster with Google Gemini API as the language-model fallback). Disclosed ElevenLabs Inc. as a new sub-processor for text-to-speech voice synthesis (Geb's spoken voice). Mirrored in Privacy Policy §5 and Data Handling Policy §9.
- Version 1.2 — May 9, 2026. Disclosed the Google Cloud Compute Engine me-central1 (Doha, Qatar) sub-processor and added the geo-aware search egress paragraph in §5 covering the Toronto / South Carolina / Netherlands / Doha SearXNG egress topology. Removed Anthropic PBC, Fawry Plus, and Meta Platforms (WhatsApp Business) from the sub-processor list — none currently process user data: Anthropic was previously listed in connection with training-pipeline tooling that does not handle user data, and the Fawry and WhatsApp channels are not yet live. They will be re-disclosed before any of those channels actually carries user data. Also removed the corresponding "supplementary inference (Claude family)" sentence in §7. Mirrored in Privacy Policy §5 and Data Handling Policy §9.
- Version 1.1 — May 8, 2026. Corrected Egypt MoHP crisis hotline (16328) and updated Canadian hotline to 9-8-8. Softened ISED signatory wording pending public-list confirmation. Softened pre-release red-team claim to a Geb-v7-onward commitment. Added bright-line commitments on no advertising, no sale of conversation data, and free portability. Added high-risk-use requirements (§3A), engagement-design and risk-tiering bullets (§4), breach-notification, whistleblower bullet (§6), C2PA commitment, EU AI Act Art. 53 classification statement, and inline supplementary sub-processor footprint. Cross-references to Privacy Policy §5 and Terms of Service §6D.
- Version 1.0 — May 8, 2026. Initial publication. Aligned with ISED Voluntary Code of Conduct (September 2023) and OPC Principles for Responsible Generative AI (December 2023).