Privacy Policy
Last updated: 4th October 2026
1. Who we are
Arib (“we”, “us”) operates the Arib service at arib.io. We are the data controller for the personal data described in this policy.
Contact: contact@arib.io
2. The service in brief
Arib lets you build AI agents using your own model provider account. You connect your own provider API key — OpenAI, Anthropic, Google, OpenRouter, or others.
We do not resell access to model providers and do not bill you for model usage. When an agent runs, your prompts and messages are transmitted to the provider you selected, authenticated with your key, under your agreement with them.
3. What we collect
Account information. Email address, first and last name, and a hashed password. If you connect a third-party account such as Google or GitHub, we store the provider’s user identifier, encrypted access and refresh tokens, and the permissions you granted.
Your Content, defined in section 4.
Credentials. Model provider API keys, stored encrypted. API keys you generate for Arib itself.
Usage data. Per-request token counts, cost, model, latency, and completion reason, associated with the API key used. We use this to show you how your agents perform and where your usage goes.
Technical data. IP address, user agent, and request logs.
4. Your Content
“Your Content” means anything you put into Arib and anything Arib produces for you:
- Prompts and system prompts
- Messages you send and your agents’ replies
- Documents, files, and folders in your knowledge bases, including the vector representations generated from them
- Agent configurations and variables
- Apps and integrations you build
- Webhook configuration and the data delivered to it
5. How we use Your Content
- To operate the service — authenticate you, execute agents, search documents, persist your work, and deliver webhook notifications.
- To share with the model provider you selected — see section 6.
- For operational observability — see section 8.
- For security — detecting abuse, enforcing rate limits, and investigating misuse.
- To send service email — see section 10.
We do not use Your Content to train or fine-tune any model, ours or anyone else’s.
We do not sell Your Content.
6. Model providers
When an agent runs, Your Content — including system prompts, your messages, and excerpts retrieved from your knowledge bases — is transmitted to the model provider configured for that agent, using your API key.
That provider processes Your Content under its own privacy policy and your agreement with it, not this policy. We do not control how they retain, use, or improve their services. If a provider uses your data to train its models, that is governed by your relationship with them. Review your provider’s terms before connecting sensitive material.
The specific provider for each agent is shown in its configuration.
7. Analytics
Registered users. We use PostHog to understand how the product is used. At sign-up we transmit your name and email address to PostHog as account properties, and your feature usage — including which features you use and which models you select — is associated with your account.
Visitors without an account. We collect anonymous usage analytics from visitors who have not created an account. This is used to understand how the service is used and where it fails. Anonymous analytics are not linked to an account, and we do not use them to identify you.
We do not send your prompts, messages, or documents for analytics purposes.
8. Observability and error monitoring
To diagnose errors, measure reliability, and improve performance, we record technical traces of requests and agent runs using PostHog and OpenTelemetry.
Agent-run traces may contain Your Content, including your prompts, your agents’ outputs, the tool definitions available to the agent, and the inputs and results of tool calls — which may include the contents of files read from your knowledge bases and the content of web pages retrieved on your behalf.
These traces are retained for 30 days.
Error monitoring. When an unexpected error occurs, we record diagnostic information — a stack trace, request path, and technical context — to diagnose and fix defects. These reports are not linked to your account and do not include your name or email. Error monitoring is enabled in production and disabled in local development.
9. Cookies
We use a small number of cookies. We do not use advertising or cross-site tracking cookies.
Strictly necessary. A session cookie keeps you signed in. It cannot be disabled and is required for the service to function.
Analytics. Anonymous visitor analytics, described in section 7, set an identifier so that activity from the same browser is counted together rather than as many separate visits.
You can prevent analytics cookies by blocking cookies or enabling your browser’s tracking protection. Doing so will not affect your ability to use Arib.
10. Email
We use Brevo to deliver service email, including verification, password reset, security notices, and product updates. We do not use it for third-party advertising. Email addresses you provide are processed by Brevo as our processor.
11. Legal bases
Where the GDPR or equivalent applies:
- Contract — operating the service for you
- Legitimate interests — security, reliability, analytics, observability, and service email
- Consent — optional connected accounts
12. Service providers
We share personal data only with providers who process it on our behalf under contract, or with the model provider you select.
| Provider | Role |
|---|---|
| Cloudflare | Domain registration, DNS, static frontend hosting, and delivery |
| Hetzner | PostgreSQL database and API servers |
| Brevo | Transactional email delivery |
| PostHog | Product analytics, observability, and error monitoring |
| Your selected model provider | Model inference, using your API key |
Cloudflare and Hetzner may process IP addresses and request metadata as part of hosting and security.
13. International transfers
Some providers process data outside your country. Hetzner and Brevo are established in the European Economic Area. Cloudflare and PostHog are established in the United States. Where required, we use transfer mechanisms such as Standard Contractual Clauses, and we maintain appropriate agreements with each provider.
14. Retention
| Data | Retention |
|---|---|
| Your account and Your Content | While your account is active |
| Observability traces (may contain Your Content) | 30 days |
| Product analytics events | We do not currently delete these while we operate the service |
| Anonymous visitor analytics | We do not currently delete these while we operate the service |
| Error reports | We do not currently delete these while we operate the service |
| Server security logs | We do not currently delete these while we operate the service |
Deleting an agent, app, prompt, or knowledge base deletes it and its associated embeddings. Deleting your account deletes your chats, agents, apps, knowledge bases, prompts, credentials, and API keys from our production systems.
Analytics and diagnostic records are retained independently of your account and are not deleted when you delete your account.
15. Security
Data is transmitted over HTTPS. Model provider credentials and connected-account tokens are encrypted at rest. Access to production data is limited to personnel who require it and is bound by confidentiality obligations.
No system is perfectly secure, and we cannot guarantee absolute security.
16. Your rights
Depending on your location, you may have the right to:
- Access and obtain a copy of your personal data
- Correct inaccurate data
- Delete your data
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time
- Object to or opt out of analytics
- Complain to your supervisory authority
You can access, export, and delete most data directly in the product. For anything else, contact contact@arib.io. We will respond within the period required by applicable law.
You may disconnect a third-party account at any time, which deletes the stored tokens for that provider.
17. Children’s privacy
Arib is not directed to children under 13, or the equivalent minimum age where you live. We do not knowingly collect personal data from children below that age.
18. Automated decision-making
We do not use Your Content to make decisions with legal or similarly significant effects.
19. Changes
We will notify you of material changes through the product or by email before they take effect. Previous versions are available on request.
20. Contact
Arib — contact@arib.io