Data Handling Policy
Last updated: June 24, 2026
This Data Handling Policy explains where and how Geb AI (operated by Green Union Capital Inc.) stores and processes your data, complementing our Privacy Policy.
1. Infrastructure
- Hosting: Google Cloud Platform, primary region
europe-west4(Netherlands). - Application runtime: Google Cloud Run (stateless containers, auto-scaled).
- Database: Google Cloud SQL for PostgreSQL, private connectivity only.
- AI models: Geb v7 (Green Union Capital's proprietary model) as primary for chat and Gemini for complementary capabilities.
- File uploads (Pro plan and above): Google Cloud Storage with lifecycle-based auto-expiry.
- Authentication: Google Firebase Authentication.
- Payments: Stripe (PCI-DSS Level 1 certified).
2. Data flow
- Your browser sends a request to
api.gebai.ca(Cloud Run backend). - The backend verifies your Firebase ID token.
- The backend persists your message to PostgreSQL and forwards it to the AI model.
- The AI model returns a response, which is persisted to PostgreSQL and returned to your browser.
- Usage telemetry is recorded for billing and operational purposes.
Message content is transmitted over TLS 1.2+ and stored encrypted at rest.
3. Retention
- Chat messages and folders: retained until you delete them.
- Chat attachments: files attached to a conversation for one-off analysis are automatically purged 30 days after last access unless saved to a chat.
- Key of Life documents: files you upload to your private memory are retained until you delete them, or — if you delete your account — purged within 30 days of account deletion. They are not auto-purged.
- Usage telemetry: retained up to 24 months for analytics, fraud detection, and service improvement.
- Account records: retained while active and for a limited period after closure to comply with tax and legal obligations.
4. Training data
Geb AI does not train its language models on your conversations, attachments, or personal data. Our proprietary model, Geb v7, is fine-tuned from an open-source foundation model only on (a) curated synthetic examples that teach it how to use tools — web search, prospecting, document generation, code execution, and similar — and (b) publicly licensed corpora. Your chats stay yours.
Instead of retraining models on user data, Geb uses a private memory layer called Key of Life (KoL). KoL stores facts, preferences, and prior context that you explicitly share with Geb during conversations, encrypted at rest in our Canadian data centre (Edmonton, Alberta). You can view, edit, or wipe your KoL memory at any time from the in-app memory panel. KoL is per-account and never shared with other users or used to improve Geb's models for anyone but you. See Privacy Policy section 5A for details.
Separately, the Tier 2 deep-research feature can — only after you opt in — use your browser as a transient fetch egress to load public web pages on your behalf (Terms section 6B, Privacy section 5B). The fetched HTML is sent to the backend for parsing; cookies, autofill, and content from other tabs are not accessed.
5. Access controls
- Production database access is restricted to authorized personnel for operational purposes only.
- All production access is logged and audited.
- Secrets (API keys, database credentials) are stored in Google Secret Manager with least-privilege IAM policies.
- Two-factor authentication is required for all operator accounts.
6. Data breach notification
In the unlikely event of a breach of security safeguards that compromises personal information, we will assess the risk of significant harm and notify the relevant supervisory authorities and affected individuals as required by law:
- The Office of the Privacy Commissioner of Canada (OPC) under PIPEDA, where there is a real risk of significant harm.
- The Office of the Information and Privacy Commissioner of Alberta (OIPC-AB) under PIPA, where Alberta residents are affected.
- The Office of the Information and Privacy Commissioner for British Columbia (OIPC-BC) under PIPA-BC, where British Columbia residents are affected.
- The Commission d'accès à l'information du Québec (CAI) under Quebec Law 25, where Quebec residents are affected.
- The relevant EU and UK supervisory authorities within 72 hours where the EU GDPR or UK GDPR applies.
- The Egyptian Personal Data Protection Center where Egypt PDP Law 151/2020 applies.
Affected individuals are notified without undue delay where there is a real risk of significant harm. We retain records of all breaches for a minimum of 24 months as required by PIPEDA section 10.1, and longer where other applicable laws so require.
7. Data export and deletion
You can export your chat history and delete individual conversations through the Service. For full account deletion or complete data export, email [email protected]. We respond within 30 days.
8. Enterprise data sovereignty
Customers with specific regulatory requirements (MENA data residency, sector-specific compliance) can discuss dedicated deployment options. Contact [email protected].
9. Sub-processors
Current third-party sub-processors:
| Sub-processor | Location | Purpose |
|---|---|---|
| Google LLC / Google Cloud Platform | United States, European Union (europe-west4 / Netherlands) | Hosting, storage, and complementary / fallback AI inference |
| ElevenLabs, Inc. | United States | Text-to-speech voice synthesis (Geb's voice); data shared: text content sent to Geb for spoken responses |
| Google Cloud Compute Engine — me-central1 (Doha, Qatar) | Qatar (Doha) | Anonymized web-search egress proxy (SearXNG) for MENA-region users; user search queries (no PII), aggregated request logs (90-day retention) |
| Google Firebase | United States, European Union | Authentication and analytics |
| Cloudflare, Inc. | Global edge | CDN, DDoS protection, Cloudflare Access service-token auth, cloudflared tunneling for backend egress |
| Stripe, Inc. | United States | Card processing and subscription management |
| Resend, Inc. | United States | Transactional and security emails |
We update this list when sub-processors change and notify affected users where legally required. Personal information stored in the Netherlands, the United States, Egypt, Qatar, or other jurisdictions may be subject to lawful access requests by foreign governments under applicable local law.
10. Contact
Green Union Capital Inc.
[email protected]