Data Handling Policy
Last updated: September 23, 2026 · Effective: October 23, 2026
This Data Handling Policy explains where and how Geb AI (operated by Green Union Capital Inc.) stores and processes your data, complementing our Privacy Policy.
1. Infrastructure
- Hosting: Google Cloud Platform, primary region
europe-west4(Netherlands). - Application runtime: Google Cloud Run (stateless containers, auto-scaled).
- Database: Google Cloud SQL for PostgreSQL, private connectivity only.
- AI models: Geb (Green Union Capital's proprietary model) as primary for chat. Image generation uses Google's Gemini image model; video generation uses Google's Veo (chat) and Lightricks' LTX (Geb Studio); Google also provides fallback AI inference.
- File uploads (all plans): Google Cloud Storage.
- Authentication: Google Firebase Authentication.
- Payments: Stripe (PCI-DSS Level 1 certified).
2. Data flow
- Your browser sends a request to
api.gebai.ca(Cloud Run backend). - The backend verifies your Firebase ID token.
- The backend persists your message to PostgreSQL and forwards it to the AI model.
- The AI model returns a response, which is persisted to PostgreSQL and returned to your browser.
- Usage telemetry is recorded for billing and operational purposes.
Message content is transmitted over TLS 1.2+ and stored encrypted at rest.
3. Retention
- Chat messages and folders: retained until you delete them.
- Chat attachments: retained until you delete the conversation or your account.
- Key of Life documents: files you upload to your private memory are retained until you delete them, or — if you delete your account — purged within 30 days of account deletion. They are not auto-purged.
- Usage telemetry: retained for 12 months for operational debugging, abuse detection, and billing reconciliation.
- Security and audit logs: retained for 24 months.
- Account records: deleted when you delete your account. Billing records are kept for 7 years for tax purposes, and records under a legal hold are kept for as long as the law requires.
- Learning records: live-repair copies of message text up to 24 hours; learning records up to 365 days; reference-set examples (identifiers removed) while your account exists. All are deleted with your account (see section 4).
4. How Geb learns from your conversations
Geb learns from conversations on the Service to fix its mistakes and improve for everyone: message text, Geb's responses, and information about how each turn was handled are used for live repair of your own conversation (kept up to 24 hours) and to improve Geb for everyone, including training Geb's own models (kept up to 365 days). This analysis is done by Geb's own models on servers we operate. Learning is on by default on every plan, and you can turn it off at any time in your profile settings under Privacy and data → "Help improve Geb". The full description is in Terms of Service section 6A and Privacy Policy section 5A.
Geb uses a private memory layer called Key of Life (KoL). KoL stores facts, preferences, and prior context that you explicitly share with Geb during conversations, encrypted at rest in our Canadian data centre (Edmonton, Alberta). You can view, edit, or wipe your KoL memory at any time from the in-app memory panel. KoL is per-account and never shared with other users.
Separately, the Tier 2 deep-research feature can — only after you opt in — use your browser as a transient fetch egress to load public web pages on your behalf (Terms section 6B, Privacy section 5B). The fetched HTML is sent to the backend for parsing; cookies, autofill, and content from other tabs are not accessed.
5. Access controls
- Production database access is restricted to authorized personnel for operational purposes only.
- All production access is logged and audited.
- Secrets (API keys, database credentials) are stored in Google Secret Manager with least-privilege IAM policies.
- Two-factor authentication is required for all operator accounts.
6. Data breach notification
In the unlikely event of a breach of security safeguards that compromises personal information, we will assess the risk of significant harm and notify the relevant supervisory authorities and affected individuals as required by law:
- The Office of the Privacy Commissioner of Canada (OPC) under PIPEDA, where there is a real risk of significant harm.
- The Office of the Information and Privacy Commissioner of Alberta (OIPC-AB) under PIPA, where Alberta residents are affected.
- The Office of the Information and Privacy Commissioner for British Columbia (OIPC-BC) under PIPA-BC, where British Columbia residents are affected.
- The Commission d'accès à l'information du Québec (CAI) under Quebec Law 25, where Quebec residents are affected.
- The relevant EU and UK supervisory authorities within 72 hours where the EU GDPR or UK GDPR applies.
- The Egyptian Personal Data Protection Center where Egypt PDP Law 151/2020 applies.
Affected individuals are notified without undue delay where there is a real risk of significant harm. We retain records of all breaches for a minimum of 24 months as required by PIPEDA section 10.1, and longer where other applicable laws so require.
7. Data export and deletion
You can export your data and delete individual conversations through the Service. Delete your account instantly from Profile → Danger zone, or email [email protected]and we will complete it within 7 business days. For a complete data export, use "Download my data" in your profile, or email us and we will respond within 30 days.
8. Enterprise data sovereignty
Customers with specific regulatory requirements (MENA data residency, sector-specific compliance) can discuss dedicated deployment options. Contact [email protected].
9. Sub-processors
Current third-party sub-processors:
| Sub-processor | Location | Purpose |
|---|---|---|
| Google LLC / Google Cloud Platform | United States, European Union (europe-west4 / Netherlands) | Hosting and storage; image generation (Gemini) and chat video generation (Veo); fallback AI inference |
| ElevenLabs, Inc. | United States | Text-to-speech voice synthesis (Geb's voice) and real-time speech-to-text for voice conversations; data shared: text sent for spoken responses and the audio of what you say in a voice conversation |
| Lightricks Ltd. (LTX) | Israel, United States | Geb Studio video generation; data shared: your scene prompts and reference images |
| Google Cloud Compute Engine — me-central1 (Doha, Qatar) | Qatar (Doha) | Anonymized web-search egress proxy (SearXNG) for MENA-region users; user search queries (no PII), aggregated request logs (90-day retention) |
| Google Firebase | United States, European Union | Authentication and analytics |
| Cloudflare, Inc. | Global edge | CDN, DDoS protection, Cloudflare Access service-token auth, cloudflared tunneling for backend egress |
| Stripe, Inc. | United States | Card processing and subscription management |
| Resend, Inc. | United States | Transactional and security emails |
We update this list when sub-processors change and notify affected users where legally required. Personal information stored in the Netherlands, the United States, Egypt, Qatar, or other jurisdictions may be subject to lawful access requests by foreign governments under applicable local law.
10. Contact
Green Union Capital Inc.
[email protected]