Legal
Privacy notice — pilot draft
Last updated August 3, 2026
Status and scope
This notice describes the current ObiAnswers pilot design. It is a product draft and has not been approved by counsel. An organization must ensure it has authority to provide employee and company information and must not upload data prohibited by its agreement or applicable law.
Information the service processes
- Account data
- Name, email address, authentication identifiers, verification state, and session/security metadata.
- Organization data
- Organization profile, membership, role, status, and assigned location or department identifiers.
- Approved documents
- Uploaded files, file metadata, access rules, extracted page or section text, processing status, and source mappings.
- Questions and answers
- Employee questions, generated answers, customer-facing replies, citations, confidence/status, feedback, and manager-review records.
- Usage and audit data
- Question counts, limits, request IDs, operational activity, processing stages, safe error categories, and timing measurements.
How information is used
Information is used to authenticate users, enforce organization and audience access, ingest approved documents, retrieve source-backed evidence, generate and save answers, support manager review, apply limits, troubleshoot failures, protect the service, and produce organization analytics and authorized exports. ObiAnswers is not designed to sell personal information or serve behavioral advertising.
Service providers and AI processing
The application uses Google Firebase services for authentication, database, file storage, and optional App Check, and uses OpenAI for document files/vector search and answer generation. Hosting and operational vendors may also process limited data as configured by the operator. Questions and relevant approved source text are sent to OpenAI to provide the requested answer. Final subprocessor, training, retention, location, and transfer disclosures must be verified against signed provider and customer terms before launch.
Access and sharing
Organization members see data according to their current role and document audience. Managers can see broader question, document, team, insight, and review data. Administrators and service providers may access information when necessary to operate, secure, support, comply with law, or complete an authorized deletion. The service does not intentionally publish permanent document URLs; authorized source links are short lived.
Retention, deletion, and exports
The pilot stores records while the organization account and operational need remain active. Exact retention periods, backup expiry, deletion verification, legal holds, account termination handling, and response deadlines have not yet been approved. Authorized managers can export limited CSV data and delete individual documents; organization-level access, correction, export, or deletion requests must be sent to the contact below and will be handled under the final contract and law.
Security and limitations
ObiAnswers uses server-side authorization, encrypted provider connections, restricted credentials, private Storage/database rules, short-lived source links, and audit/usage controls. No system is completely secure. This repository does not claim compliance certification, guaranteed availability, or suitability for regulated healthcare, child/minor, emergency, legal, or financial data.
Contact and changes
For pilot privacy, correction, access, or deletion questions, contact support@deskhero.local. This notice may change as the service, contracts, providers, and legal decisions are finalized. Material production changes require an updated date and appropriate notice.