Privacy Policy
Last updated: July 26, 2026
1. Introduction
At Giya ("Giya", "we", "our", or "us"), we respect your privacy and are committed to protecting the personal data and intellectual property generated within your innovation workspace. This Privacy Policy explains how we collect, use, isolate, and safeguard your information when you use our multi-panel ideation platform.
2. Data We Collect
- Account & Authentication Credentials: Email address and encrypted authentication tokens managed through Supabase Auth.
- Workspace & Project Content: Project goals, target audience notes, version trees, canvas node graphs, and Input-Process-Output (IPO) tables created in your workspace.
- Insight Bank References: URLs, scraped social media preview metadata, image links, and text excerpts added to your workspace.
- AI Dialogue & Prompts: Inputs provided to AI thinking tools (First Principles, Six Thinking Hats, HATERADE, Force Semantics).
3. How We Use Your Data
We process your data strictly to deliver and improve the Giya workspace experience, including:
- Constructing and compiling visual node graphs and W3C JSON-LD / OWL 2 ontologies.
- Scraping preview metadata (thumbnails, titles, descriptions) for URLs you add to your Insight Bank.
- Maintaining immutable version snapshots when publishing releases.
- Generating App Specifications and Markdown exports.
4. AI Data Privacy & Security
🔒 Strict Guarantee: Your workspace content, notes, canvas connections, and AI prompt inputs are never used to train public or foundational third-party AI models.
AI requests are routed through OpenRouter with guardrail screening and Zero Data Retention required per request. Under this route, OpenRouter and the serving inference provider do not retain prompt or response content. OpenRouter may retain non-content operational metadata such as token counts, latency, and request status.
5. Data Storage & Isolation
Saved confidential workspace payloads are encrypted in server-only application code with AES-256-GCM and an independent random data-encryption key for each account. Every query is scoped to the authenticated user, and ownership is checked before confidential content is decrypted.
This is application-level client-confidential encryption, not zero-knowledge encryption. Authorized Giya operations decrypt the minimum necessary content in memory, and content intentionally submitted to an approved AI provider is processed outside the encrypted-at-rest boundary.
6. Cookies & Session Storage
Giya uses essential HTTP-only cookies solely to maintain authenticated sessions and early access authorization. We do not use third-party tracking cookies or advertising pixels.
7. Your Rights & Data Export
You maintain full ownership of your data. You may export your workspace specifications, JSON-LD ontologies, and App Specifications at any time, or request complete account and project deletion by contacting privacy@giya.app.
