ABAIOS Build™ Terms of Service
Legal · Plain-language privacy

Privacy Policy

Last updated: 2026-07-07 · Operated by PeopleStar Software · Contact: mcallpl@gmail.com

The short version

We collect what's needed to run the service: your account details, the requests you submit, and basic security data like IP addresses. Request text is processed by an AI provider (Google Gemini) to classify intent. We don't sell your data, we don't run ad trackers, and we don't use your content to train AI models. Email us to see or delete your data.

01Who we are

AIOS Build at aiosbuild.peoplestar.com (the "Service") is operated by PeopleStar Software ("we," "us"). This policy explains what we collect when you use the Service, why, who else processes it, and the choices you have.

02What we collect

DataWhenWhy
Username, email address, password (stored only as a one-way bcrypt hash — we cannot read it)When you create an accountTo create and secure your account
Request text, project names, Constitution rules, and the Command Packs and risk decisions generated from themWhen you use the governance consoleThis is the product: your request history, approvals, and audit trail
Approval decisions (approver name, role, note, timestamp)When a human approves or rejects a requestThe accountability record the Service exists to keep
Workspace membership and invitations (who invited whom, when accepted)When you create or join a workspaceTo control who sees a workspace's data
IP addressOn signup, login, and free-generator useRate limiting and abuse prevention; login security events
A session cookie (AIOS_SESSION)When you sign inTo keep you signed in. This is the only cookie we set — no advertising or analytics trackers

The free generator at /try stores nothing about you or your request — it is processed and returned, with only a temporary IP-based rate-limit counter kept (deleted within roughly an hour).

03What we do NOT do

04Who processes data for us

ProviderWhat they processWhy
Google (Gemini API)The text of a submitted requestAI classification of the request's intent, as part of the governance pipeline
DigitalOceanAll Service data (servers and database are hosted there, in the United States)Hosting

These providers act on our instructions to run the Service. Don't include secrets — passwords, API keys, customer personal data — in request text; the Service's own guidance tells you the same thing.

05How long we keep data

Account data and your governance records (requests, decisions, approvals, audit entries) are kept while your account exists — a durable audit trail is the point of the product. If you delete your account, we delete or de-identify your personal data within a reasonable period, except records we must keep for security or legal reasons. Rate-limit counters expire within about an hour. Login security events are retained for abuse investigation.

06Security

Traffic is encrypted with TLS. Passwords are stored only as bcrypt hashes. Sessions use HttpOnly, Secure, SameSite cookies. Workspace isolation means users only see data in workspaces they belong to. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you as the law requires.

07Your choices and rights

California residents: we do not sell or "share" personal information as the CCPA defines those terms, and we honor access, deletion, and correction requests as described above. If you are in a jurisdiction with similar rights (such as the EU/UK), we honor equivalent requests. Requests go to mcallpl@gmail.com.

08Children

The Service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.

09Changes to this policy

If we change this policy materially, we will post the new version here with a new "Last updated" date and take reasonable steps to notify account holders. Continuing to use the Service after a change takes effect means you accept it.

10Contact

Privacy questions or requests: mcallpl@gmail.com.