Privacy Policy
Last updated: June 30, 2026
1. Introduction & scope
Genlobe is a product of Kleio Technology, based in West Palm Beach, Florida, USA. In this policy, "Genlobe", "we", "us", and "our" refer to Kleio Technology operating the Genlobe platform.
Genlobe is an all-in-one backend for software builders: authentication, a runtime database (our Custom Entitiesfeature), AI agents, file storage, and per-Organization payments. Developers ("Tenants") build products on Genlobe; each product surfaces as an Organization with its own end-users and its own Stripe account.
This policy explains how we handle personal data across three audiences: the people who administer a Tenant account through the Tenant Dashboard (genlobe.ai/dashboard), visitors to our public landing site, and the end-users of apps built on Genlobe. Because our role differs depending on whose data is involved, please read the next section carefully.
2. Our role: controller vs. processor
Genlobe operates in two distinct data-protection roles over two distinct sets of data:
- Controller — for the account data of Tenants and the people who administer them (TenantMembers). This is our direct commercial relationship with you. We decide the purposes and means of processing this data, and Section 4 (legal bases) applies to it.
- Processor — for the end-user data, custom records, files, and AI-agent conversations that a Tenant stores or generates on the platform. Here, the Tenant is the controllerand Genlobe processes that data only on the Tenant's documented instructions, under a data-processing agreement. We do not determine the purposes of this data.
If you are an end-user of an app built on Genlobe and you want to exercise your privacy rights over that data, the developer who operates the app is your primary point of contact; we will assist them as their processor.
3. Information we collect
Account data (we are the controller). When you create or administer a Tenant account, we collect:
- Identity and contact details — name and email address.
- Authentication credentials — a hashed password (we never store passwords in clear text), email-verification and password-reset tokens, and verification status.
- Account metadata — role, account status, invitation history, and last-login timestamp.
- Optional company details you provide, such as a company website or logo.
- Billing identifiers for platform billing (Stripe customer and subscription identifiers). No payment-card data ever touches our systems — card details are handled entirely by Stripe's hosted checkout.
- Security and operational logs — including the IP address recorded in our administrative audit logs, and transactional email logs (recipient, type, and delivery status).
We use the IP address of a sign-in request transiently for rate-limiting and abuse prevention; it is not persisted to a sign-in log in those flows.
End-user and product data (we are a processor). On behalf of each Tenant, the platform stores and processes the data their app uses — end-user accounts and profiles, records in Custom Entities (whose shape and content the Tenant defines), uploaded files, AI-agent inputs and outputs, conversation messages, knowledge-base content, and per-Organization usage and billing data. The categories of personal data here are determined by the Tenant, not by us.
4. Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies to the account data for which we are the controller, we rely on the following legal bases:
- Performance of a contract — to create and administer your account, authenticate you, provide the service, and bill you for platform usage.
- Legal obligation — to meet our accounting, tax, and record-keeping duties.
- Legitimate interests — to keep the platform secure (rate-limiting, administrative audit logging, abuse prevention), balanced against your rights and freedoms.
For end-user data we process on a Tenant's behalf, the Tenant (as controller) is responsible for establishing the appropriate legal basis toward its own end-users.
5. How we use information
- To create, secure, and operate your account and team.
- To authenticate you and protect access (email verification, password reset, role-based access control).
- To provide and maintain the platform's features.
- To bill you for platform usage and meet related accounting obligations.
- To send transactional emails (such as verification, password reset, and team invitations).
- To prevent abuse and keep the platform secure (rate-limiting and audit logging of administrative actions).
- To provide support, produce aggregate usage metrics, and comply with legal obligations.
We do not use your personal data for targeted advertising, and we do not operate third-party analytics or tracking on our site today.
6. Sub-processors & sharing
We engage a small set of third-party sub-processors to deliver the service, each bound by a data-processing agreement. They include:
- Amazon Web Services — hosting, transactional email (SES), and backups, in the us-east-1 (United States) region.
- Supabase — managed PostgreSQL database (United States).
- Stripe — payments, both for platform billing and for the per-Organization Stripe account each Organization brings and configures itself.
- OpenRouter — the gateway through which all AI requests are routed.
- Anthropic, OpenAI, and other model providers (reached via OpenRouter) — for model inference.
- Google — OAuth social login for end-users, only when a Tenant enables it.
The full, current list — with each provider's service, region, and transfer safeguard — is published at /subprocessors. We give notice before adding or replacing a sub-processor that processes personal data, and Tenants may object within a 30-day window.
Beyond these sub-processors, we may disclose personal data when required by law or legal process, or to protect the rights, safety, and security of Genlobe, our users, and the public. If we are ever involved in a merger, acquisition, or sale of assets, we will give notice before personal data becomes subject to a different privacy policy.
We do not sell or share personal information (including for cross-context behavioral advertising), as those terms are used under the CCPA/CPRA.
7. International transfers
Our infrastructure and sub-processors are located primarily in the United States. If you are in the European Economic Area, the United Kingdom, or another region with data-transfer rules, your personal data is transferred to the United States. We rely on appropriate safeguards for these transfers — principally the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework and its UK extension — back-to-back with each sub-processor. The safeguard applied to each provider is noted at /subprocessors.
8. Data retention
We keep account data for as long as your account is active and for a reasonable period afterward to meet legal, accounting, and security obligations, after which we delete or anonymize it. Some specific retention controls already exist in the platform: billing audit logs are pruned on a rolling 90-day window, and verification and password-reset tokens are cleared once they are used or expire.
We want to be honest about the current state: not every data category yet has an automated, scheduled purge, and some operational and audit logs are retained until the related account or resource is deleted. We are actively improving these controls. For end-user data we process on a Tenant's behalf, retention is governed by the Tenant's instructions under our data-processing agreement.
9. Your rights
Depending on where you live, you may have rights over your personal data — including the rights to access, correct, delete, and obtain a portable copy of your data, to restrict or object to certain processing, and to withdraw consent where we rely on it.
To exercise any of these rights, contact us at privacy@genlobe.ai. We honor verified requests to the extent technically available, and we are honest about that qualifier: full, self-service end-to-end data export and erasure are not yet available through the dashboard, so some requests are handled manually by our team. We will not discriminate against you for exercising your rights. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data-protection authority.
California privacy rights (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it; to request access to and deletion of your personal information; to correct inaccurate personal information; and to be free from discrimination for exercising these rights. The categories of personal information we collect, the purposes for which we use them, and the sub-processors with whom we share them are described in Sections 3, 5, and 6 above.
We do not sell or share personal information — in the CCPA/CPRA sense, including for cross-context behavioral advertising — and we do not engage in targeted advertising. We do not knowingly process the sensitive personal information of California residents for purposes beyond providing the service. To make a CCPA/CPRA request, email privacy@genlobe.ai; you may use an authorized agent, and we will verify your request before acting on it.
10. AI processing
AI requests on the platform — agent chat, tool execution, and retrieval-augmented generation — are routed through OpenRouterto upstream model providers such as Anthropic and OpenAI. Prompts and outputs may contain personal data if a Tenant or end-user includes it. Access by AI agents to a Tenant's Custom Entity data is default-deny and opt-in per entity, which limits what personal data can reach a model.
Genlobe does not use customer data to train its own models.Upstream model providers may retain API inputs and outputs for a limited period (commonly around 30 days) for trust-and-safety and abuse-monitoring purposes before deletion. How those providers handle that data — including whether it is used for their own model training — is governed by each provider's terms and the configuration of the routing account; we encourage you to review the providers listed at /subprocessors.
11. Security
We apply technical and organizational measures designed to protect personal data, including password hashing, encryption of configuration secrets at rest, encryption in transit (TLS), strict per-Organization isolation, role-based access control, rate-limiting, and audit logging of administrative actions. No method of transmission or storage is perfectly secure, but we work to protect your data and to improve our controls over time. Learn more on our Security page.
12. Children
Genlobe is a business platform intended for users 18 years of age or older. We do not knowingly collect personal data from anyone under 18, and the service is not directed to children. Where a Tenant builds an app that may reach children, the Tenant is the controller of its end-users and is responsible for complying with applicable children's-privacy laws. If you believe a minor has provided us personal data, contact privacy@genlobe.ai and we will take appropriate action.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the platform after an update means you accept the revised policy.
14. Contact
For privacy questions or to exercise your rights, email privacy@genlobe.ai. For general inquiries, email info@kleiotechnology.com.
Genlobe is a product of Kleio Technology, West Palm Beach, Florida, USA. This policy is governed by the laws of the State of Florida, USA.