Privacy Policy

Last updated: 4th October 2026

1. Who we are

Arib (“we”, “us”) operates the Arib service at arib.io. We are the data controller for the personal data described in this policy.

Contact: contact@arib.io

2. The service in brief

Arib lets you build AI agents using your own model provider account. You connect your own provider API key — OpenAI, Anthropic, Google, OpenRouter, or others.

We do not resell access to model providers and do not bill you for model usage. When an agent runs, your prompts and messages are transmitted to the provider you selected, authenticated with your key, under your agreement with them.

3. What we collect

Account information. Email address, first and last name, and a hashed password. If you connect a third-party account such as Google or GitHub, we store the provider’s user identifier, encrypted access and refresh tokens, and the permissions you granted.

Your Content, defined in section 4.

Credentials. Model provider API keys, stored encrypted. API keys you generate for Arib itself.

Usage data. Per-request token counts, cost, model, latency, and completion reason, associated with the API key used. We use this to show you how your agents perform and where your usage goes.

Technical data. IP address, user agent, and request logs.

4. Your Content

“Your Content” means anything you put into Arib and anything Arib produces for you:

5. How we use Your Content

We do not use Your Content to train or fine-tune any model, ours or anyone else’s.

We do not sell Your Content.

6. Model providers

When an agent runs, Your Content — including system prompts, your messages, and excerpts retrieved from your knowledge bases — is transmitted to the model provider configured for that agent, using your API key.

That provider processes Your Content under its own privacy policy and your agreement with it, not this policy. We do not control how they retain, use, or improve their services. If a provider uses your data to train its models, that is governed by your relationship with them. Review your provider’s terms before connecting sensitive material.

The specific provider for each agent is shown in its configuration.

7. Analytics

Registered users. We use PostHog to understand how the product is used. At sign-up we transmit your name and email address to PostHog as account properties, and your feature usage — including which features you use and which models you select — is associated with your account.

Visitors without an account. We collect anonymous usage analytics from visitors who have not created an account. This is used to understand how the service is used and where it fails. Anonymous analytics are not linked to an account, and we do not use them to identify you.

We do not send your prompts, messages, or documents for analytics purposes.

8. Observability and error monitoring

To diagnose errors, measure reliability, and improve performance, we record technical traces of requests and agent runs using PostHog and OpenTelemetry.

Agent-run traces may contain Your Content, including your prompts, your agents’ outputs, the tool definitions available to the agent, and the inputs and results of tool calls — which may include the contents of files read from your knowledge bases and the content of web pages retrieved on your behalf.

These traces are retained for 30 days.

Error monitoring. When an unexpected error occurs, we record diagnostic information — a stack trace, request path, and technical context — to diagnose and fix defects. These reports are not linked to your account and do not include your name or email. Error monitoring is enabled in production and disabled in local development.

9. Cookies

We use a small number of cookies. We do not use advertising or cross-site tracking cookies.

Strictly necessary. A session cookie keeps you signed in. It cannot be disabled and is required for the service to function.

Analytics. Anonymous visitor analytics, described in section 7, set an identifier so that activity from the same browser is counted together rather than as many separate visits.

You can prevent analytics cookies by blocking cookies or enabling your browser’s tracking protection. Doing so will not affect your ability to use Arib.

10. Email

We use Brevo to deliver service email, including verification, password reset, security notices, and product updates. We do not use it for third-party advertising. Email addresses you provide are processed by Brevo as our processor.

Where the GDPR or equivalent applies:

12. Service providers

We share personal data only with providers who process it on our behalf under contract, or with the model provider you select.

ProviderRole
CloudflareDomain registration, DNS, static frontend hosting, and delivery
HetznerPostgreSQL database and API servers
BrevoTransactional email delivery
PostHogProduct analytics, observability, and error monitoring
Your selected model providerModel inference, using your API key

Cloudflare and Hetzner may process IP addresses and request metadata as part of hosting and security.

13. International transfers

Some providers process data outside your country. Hetzner and Brevo are established in the European Economic Area. Cloudflare and PostHog are established in the United States. Where required, we use transfer mechanisms such as Standard Contractual Clauses, and we maintain appropriate agreements with each provider.

14. Retention

DataRetention
Your account and Your ContentWhile your account is active
Observability traces (may contain Your Content)30 days
Product analytics eventsWe do not currently delete these while we operate the service
Anonymous visitor analyticsWe do not currently delete these while we operate the service
Error reportsWe do not currently delete these while we operate the service
Server security logsWe do not currently delete these while we operate the service

Deleting an agent, app, prompt, or knowledge base deletes it and its associated embeddings. Deleting your account deletes your chats, agents, apps, knowledge bases, prompts, credentials, and API keys from our production systems.

Analytics and diagnostic records are retained independently of your account and are not deleted when you delete your account.

15. Security

Data is transmitted over HTTPS. Model provider credentials and connected-account tokens are encrypted at rest. Access to production data is limited to personnel who require it and is bound by confidentiality obligations.

No system is perfectly secure, and we cannot guarantee absolute security.

16. Your rights

Depending on your location, you may have the right to:

You can access, export, and delete most data directly in the product. For anything else, contact contact@arib.io. We will respond within the period required by applicable law.

You may disconnect a third-party account at any time, which deletes the stored tokens for that provider.

17. Children’s privacy

Arib is not directed to children under 13, or the equivalent minimum age where you live. We do not knowingly collect personal data from children below that age.

18. Automated decision-making

We do not use Your Content to make decisions with legal or similarly significant effects.

19. Changes

We will notify you of material changes through the product or by email before they take effect. Previous versions are available on request.

20. Contact

Arib — contact@arib.io