Privacy

What ARB Copilot collects, why, and how it's protected.

What we collect

  • Account data: email, display name, sign-in method (Google or email/password).
  • Workspace data: workspace name, plan, members, roles.
  • Architecture request content: the request fields you submit (title, description, NFRs, integrations, data sensitivity, etc.).
  • AI analysis output: the structured analysis the AI returns for each request.
  • Decision records and overrides: final decisions you record, rationale, override reasons.
  • Audit logs: who did what, when, with action metadata. No request content is duplicated into audit logs.
  • Rate-limit events: per user/workspace counters with a hash of the IP address (not the IP itself).

Tenant isolation

Every workspace is isolated server-side by row-level security. Members of one workspace cannot read or modify another workspace's requests, analyses, decisions, audit logs, or decision memory.

AI processing

Signed-in workspaces send request content to ARB Copilot's configured AI processing gateway and model provider. See the AI Data Notice for what to avoid sending. Public demo pages use static sample data only and do not call any AI provider.

Subprocessors

ARB Copilot relies on the following categories of infrastructure providers. This list reflects the providers actually used by the running application:

  • Authentication and database infrastructure: Supabase (Postgres, authentication, row-level security).
  • Hosting and content delivery: Cloudflare edge infrastructure.
  • AI gateway and model provider: a managed AI gateway routing to Google Gemini models.
  • Transactional email: Resend, for invitations, review notifications and clarification emails.

We will update this list when a provider changes. Current provider detail for a specific pilot is available on request.

Model training. ARB Copilot does not train, fine-tune or build any models of its own, and does not use tenant content for that purpose. Content sent for a live analysis is transmitted to the configured AI subprocessors for inference only. Retention and training behaviour at the provider layer is governed by the applicable provider terms and configuration; we do not claim zero retention. Regulated and sensitive data remains prohibited during the pilot, and AI output is advisory and human-reviewed.

Cookies, local storage and session technologies

  • Session storage: your authentication session is stored in browser local storage by the authentication client so you stay signed in.
  • Application preferences: small local-storage keys hold UI state such as dismissed banners, demo/walkthrough state, and the active workspace.
  • No advertising cookies and no third-party marketing or cross-site tracking are used.

International processing

The operator is based in India, and the infrastructure providers listed above operate globally. Your content may therefore be processed outside your own country.

Retention

Workspace data is retained until you or the workspace owner request deletion. Audit logs and rate-limit events are retained for operational and security purposes and are append-only, so a deletion request cannot remove immutable audit metadata.

Access, correction, export and deletion

Workspace owners can export decision memory and request metadata from within the product. For access, correction, full export, or workspace deletion, email hari@eabyea.com from the address associated with your account. We aim to acknowledge reasonable privacy requests within five business days and to complete them within 30 days, subject to the audit-retention limits above.

Compliance status

ARB Copilot is an early-access product. We make no claim of certification or formal compliance under any specific framework, and the pilot does not include a data processing agreement or support for regulated data.

Operator

ARB Copilot is operated by Hari Krishna Bodapati, based in India.

Contact

For privacy questions, email hari@eabyea.com.

Questions? Contact hari@eabyea.com. Last updated: June 2026.