All legal documents are available on this single page for easy review and policy acceptance.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
AbabilX ("AbabilX," "we," "us," or "our") provides an AI-powered platform that helps software developers and teams automate pull-request summaries, standups, commit workflows, repository analytics, digests, and team collaboration (collectively, the "Service"). The Service is available through our website, web application, desktop application, mobile applications, REST API, and any future clients such as a command-line interface or browser extension.
This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we keep it, and the rights and choices available to you. It is written to be read; where we must use a technical or legal term, we define it in Section 2.
Your security and privacy come first. AbabilX is built with a user-first approach to data protection. We encrypt data across its full journey through our platform — protected in transit between your devices and our servers (TLS/HTTPS) and encrypted at rest in storage. We share Personal Data only for the limited purposes described in this Policy, never sell it, and give you controls to disconnect integrations and delete your account at any time.
No tracking. No third-party telemetry. We do not embed advertising trackers, analytics pixels, or behavioral-profiling SDKs in our website, apps, or clients. We do not track you across other websites, build marketing profiles, or sell your activity to data brokers. Operational server logs exist only for security, abuse prevention, and keeping the Service running — not for surveillance or ads.
By creating an account or using the Service, you acknowledge this Privacy Policy. Where local law requires consent for specific processing (for example, certain cookies or marketing communications), we ask for it separately.
Note: This Policy describes our practices. Contractual commitments to business customers regarding the processing of Personal Data are set out in our Data Processing Addendum.
This Policy applies to Personal Data processed when you:
This Policy does not apply to:
The Service is intended for users aged 18 or older. We do not knowingly collect Personal Data from anyone under 18. If we learn that we have collected Personal Data from a person under 18, we will delete that data and terminate the associated Account. If you believe a minor has provided us Personal Data, contact info@ababilx.cloud.
We collect information in three ways: information you provide, information collected automatically, and information received from third parties.
When you register, we collect your name, username, email address, and profile picture, typically supplied by the OAuth provider you sign in with. You may additionally provide a cover image, language preference (English or Bangla), theme preference, and notification preferences.
When you connect a third-party account, we receive and store the credentials required to act on your behalf:
We store OAuth tokens server-side and never expose them to other users. See Section 15 for how tokens are protected.
We store the settings you create in the Service, including standup rules (channels, schedules, timezones, target repositories), auto-commit job configurations (repository, cadence, limits), weekly digest configurations, team settings, kanban board structures, webhook configurations, and attendance settings.
We store content you author in the Service: wall posts and comments, kanban tasks, notes and attachments, chat messages, work-log entries, standup message overrides, and prompts you send to AI features.
If you purchase a Premium plan, we collect subscription records: plan type, billing cycle, start and expiry dates, and invoice history. Payment card details are collected and processed by our payment providers; we do not store full card numbers. See our Billing & Refund Policy.
If you contact support or respond to our communications, we keep the correspondence and any information you include in it.
When you enable features that read from GitHub, we access and may cache: your repository list, repository metadata, commit metadata (messages, authors, timestamps, diffs where required for summaries), branch information, pull requests (titles, descriptions, files changed, reviews, comments, check statuses), and organization membership relevant to repository access.
We collect standard technical data when you use the Service: IP address, browser type and version, operating system, device type, client version (for desktop and mobile apps), pages and features accessed, timestamps, and referring URLs. This data comes from first-party server logs only — not from third-party tracking or analytics services.
Note: We do not use covert device fingerprinting, third-party analytics SDKs, or advertising trackers. Technical attributes (such as user-agent and IP address) are processed solely for security, abuse prevention, and essential diagnostics as described in Sections 7 and 8 — never for marketing or cross-site profiling.
We use a small set of strictly necessary cookies and browser storage entries to keep you signed in, protect your session, and remember preferences (such as theme and language). Details, names, and lifetimes are documented in our Cookie Policy. We do not use third-party advertising cookies, analytics cookies, or tracking pixels.
We maintain:
Logs are retained on the schedule in Section 12 and access to them is restricted under Section 15.
If you enable push notifications on iOS or Android, we store the Firebase Cloud Messaging (FCM) registration token for your device so we can deliver notifications. Deregistering the device or disabling notifications removes the token.
We do not purchase Personal Data from data brokers.
We use the information described in Section 6 to:
We do not use your information for third-party advertising, behavioral tracking, or building marketing profiles. AbabilX is designed for pure privacy: no ad networks, no cross-site trackers, no telemetry SDKs sold to third parties.
Where the EU/UK General Data Protection Regulation ("GDPR") or similar laws apply, we rely on the following legal bases:
Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights and freedoms; you may object as described in Section 13. Further GDPR detail is in our GDPR Compliance Statement.
AI features are a core part of the Service. We treat the data flowing through them with specific safeguards, described fully in our AI Policy and summarized here:
AbabilX does not sell your Personal Data. We share information only when it is necessary to provide the Service you choose to use, when you direct us to, when the law requires it, or with your explicit consent. Every sharing category below is intentional, limited, and documented — we do not pass your data to third parties for their own unrelated purposes.
We share Personal Data only in the following circumstances:
We use vetted third parties for hosting, storage, content delivery, push notifications, email delivery, payments, and AI processing. Each is bound by contract to process Personal Data only on our instructions and to protect it. The current list, including purpose and location, is maintained in our Subprocessor List.
When you use a feature that acts on a third-party platform — committing to GitHub, posting to Slack — we transmit the necessary data to that platform. That transmission is visible to the platform and governed by its terms.
If your Account belongs to a team, content you create in team features (wall, board, chat, attendance, digests) is visible to team members according to the team's roles and settings, and team owners/administrators can manage members and content.
We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or enforceable governmental request. Where lawful and practicable, we will notify you before disclosing your data so you can seek protective measures. We object to requests we believe are overbroad.
If AbabilX is involved in a merger, acquisition, financing, reorganization, or sale of assets, Personal Data may be transferred as part of that transaction. We will notify you of any such transfer and of any resulting change in this Policy, and the successor remains bound by commitments at least as protective as this Policy.
We may share aggregated or de-identified information that cannot reasonably be used to identify you (for example, overall usage statistics).
We share Personal Data for any other purpose only with your consent.
We operate from Bangladesh and use infrastructure and Subprocessors located in multiple countries. Your information may therefore be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws.
Where we transfer Personal Data from jurisdictions that restrict international transfers (including the EEA, the United Kingdom, and Switzerland), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with our Subprocessors, together with supplementary technical measures (encryption in transit, access controls). Details are in our GDPR Compliance Statement and Data Processing Addendum.
We retain Personal Data only as long as needed for the purposes described in this Policy, then delete or de-identify it. Representative schedules:
Where deletion is not immediately possible (for example, data in backups), we isolate the data from further processing until deletion completes.
Depending on your jurisdiction, you may have the right to:
info@ababilx.cloud.Self-service controls available in the Service include: editing profile data, disconnecting GitHub/Slack integrations, revoking sessions by signing out, disabling email/desktop/push notifications, changing language and privacy mode, and deleting your Account.
To exercise a right that lacks a self-service control, email info@ababilx.cloud. We verify requests using your account email and respond within 30 days (or the shorter period local law requires). We do not discriminate against you for exercising your rights.
California-specific rights are described in our CCPA/CPRA Compliance Statement; EEA/UK-specific detail is in our GDPR Compliance Statement.
You may delete your Account at any time from within the Service or by emailing info@ababilx.cloud from your account email. On deletion:
Warning: If you own a team, deleting your Account deletes the team and its content for all members. Transfer team ownership first if the team should continue.
Deletion is irreversible. Revoking AbabilX's access from within GitHub, Google, or Slack disables the integration but does not by itself delete your AbabilX Account.
Protecting your data is central to how we build AbabilX. We apply defense-in-depth security — encryption across connections and storage, strict access controls, session hardening, and continuous review — so your information stays protected throughout its lifecycle on our platform.
We protect Personal Data using administrative, technical, and physical safeguards appropriate to its sensitivity, described in detail in our Security Policy. Key measures include:
HttpOnly, Secure, SameSite cookies inaccessible to client-side scripts. Sign-in and account-linking flows use one-time exchange codes and tickets so credentials never appear in URLs, logs, or referrer headers.No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we continuously review and improve these measures.
We maintain an incident-response process covering detection, containment, investigation, remediation, and post-incident review (see our Security Policy). If a breach of security leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Personal Data, we will:
Security researchers who identify vulnerabilities should follow our Vulnerability Disclosure Policy.
The GDPR/UK GDPR rights and legal bases in Sections 8 and 13 apply. Transfer safeguards are described in Section 11. Full detail: GDPR Compliance Statement.
California residents have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information under the CCPA/CPRA. We do not sell or share personal information as those terms are defined. Full detail: CCPA/CPRA Compliance Statement.
If the Lei Geral de Proteção de Dados applies to you, you have rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing, exercisable via info@ababilx.cloud. Our legal bases parallel those in Section 8.
We collect, use, and disclose Personal Data with consent or under recognized exceptions, for reasonable purposes we have notified. You may withdraw consent and request access or correction via info@ababilx.cloud.
Where the Digital Personal Data Protection Act, 2023 applies, we process personal data for the lawful purposes described here with your consent or for legitimate uses recognized by the Act, and you may exercise rights of access, correction, erasure, and grievance redressal via info@ababilx.cloud.
AbabilX is operated from Bangladesh. We handle Personal Data consistent with applicable Bangladeshi law, including obligations relating to data security and lawful disclosure, and we apply the protections in this Policy to all users regardless of location.
We may update this Policy to reflect changes in the Service, our practices, or legal requirements. Every change is versioned (Section 20). For material changes — those affecting your rights or how we handle your data — we will notify you through the Service or by email, update the version and dates above, and, where the change is significant, require your acceptance before continued use. Continued use after the effective date of non-material changes constitutes acceptance.
info@ababilx.cloudPostal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
We aim to acknowledge privacy inquiries within 7 days and resolve them within 30 days.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
These Terms of Service (the "Terms") are a binding agreement between you and AbabilX ("AbabilX," "we," "us," "our") governing your access to and use of the AbabilX platform, websites, web application, desktop application, mobile applications, REST API, and any future clients such as a command-line interface or browser extension (collectively, the "Service").
By creating an Account, clicking to accept, or using the Service, you agree to these Terms, our Privacy Policy, our Acceptable Use Policy, and the other policies referenced in these Terms, each of which is incorporated by reference. If you do not agree, do not use the Service.
If you use the Service on behalf of an organization, you represent that you have authority to bind that organization, and "you" includes both you and the organization.
Capitalized terms have the meanings given here or where first defined:
To use the Service you must:
You register by authenticating through a supported identity provider (GitHub or Google). You must provide accurate information and keep it current. One person may not maintain multiple Accounts to evade Plan limits or enforcement actions.
You are responsible for all activity under your Account. You must:
info@ababilx.cloud promptly of any unauthorized use or suspected compromise.We are not liable for loss caused by unauthorized use of your Account arising from your failure to protect your credentials.
A Team owner controls Team membership, roles, settings, and content, and may remove members or delete the Team. Content you contribute to a Team is accessible to that Team according to its roles and settings, and may remain with the Team after you leave. If you join a Team, the Team owner's instructions govern Team content to the extent they conflict with your individual preferences.
The Service is offered on a Free plan and a paid Premium plan. Feature limits (for example, auto-commit duration, daily commit caps, digest frequency, AI usage allowances) are published in the Service and may differ by Plan. We may change Plan features prospectively; material reductions to a paid Plan take effect no earlier than your next renewal.
Paid subscriptions are billed in advance for the selected billing cycle and renew automatically until cancelled. By purchasing, you authorize us and our payment providers to charge your payment method for the subscription fee and applicable taxes. Detailed billing terms, upgrade/downgrade mechanics, and refund rules are in our Billing & Refund Policy, which forms part of these Terms.
Fees are exclusive of taxes unless stated otherwise. You are responsible for applicable taxes, duties, and levies, excluding taxes on our income.
You may cancel at any time; cancellation stops future renewals and your Premium features remain active until the end of the paid period. When a Premium plan expires, scheduled features that exceed Free limits (standup rules, auto-commit jobs, digest schedules) are paused rather than deleted, and resume if you re-subscribe.
If we offer a trial or promotional pricing, the specific terms presented at signup control. Unless stated otherwise, trials convert to paid subscriptions at the end of the trial period if a payment method is on file, and we will notify you before charging.
Subject to these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Service and Documentation for your internal business or personal purposes during the term of your Account.
You may not, except as expressly permitted by these Terms or by law that cannot be excluded:
You retain all rights in your Customer Content. These Terms do not transfer ownership of your repositories, code, messages, posts, or configurations to us.
You grant AbabilX a worldwide, non-exclusive, royalty-free license to host, store, reproduce, process, transmit, display, and modify Customer Content solely as necessary to (a) provide and secure the Service, (b) perform the operations you request (for example, generating a PR summary or posting a standup to Slack), and (c) comply with law. This license ends when the Customer Content is deleted from the Service, subject to the retention periods in the Privacy Policy, Section 12.
You represent and warrant that you have all rights necessary to submit your Customer Content and to grant the license above, and that your Customer Content and your use of the Service do not violate law or third-party rights. You — not AbabilX — are responsible for the content of commits, messages, and posts made through the Service at your direction.
Output is generated by machine-learning systems and may be inaccurate, incomplete, or unsuitable for your purpose. You must review Output before relying on it or distributing it. Output describing code (summaries, digests, standup drafts) is informational and is not a code review, security audit, or professional advice.
As between you and AbabilX, and to the extent permitted by law, you own the Output generated from your Customer Content. Because AI systems can produce similar output for similar inputs, we cannot guarantee Output is unique to you, and you receive no rights in output generated for other customers.
You are responsible for how you use Output, including verifying it before committing it to repositories, posting it to third-party platforms, or sharing it with others. Additional AI-specific terms, including prompt handling and provider restrictions, are in our AI Policy, which forms part of these Terms.
The Service interoperates with third-party platforms including GitHub, Google, and Slack. Your use of those platforms is governed by their own terms and policies, and you must comply with them when using AbabilX features that act on those platforms. We are not responsible for third-party platforms, their availability, or changes to their APIs that affect Service functionality. Actions the Service performs on a connected platform at your direction (commits, branch creation, message posting) are attributed to your authorization.
If you access the Service programmatically through our REST API or future developer tools, the Developer & API Policy applies in addition to these Terms. In summary: keep credentials confidential, respect rate limits, do not misrepresent your application, and do not use the API to reconstruct or resell the Service.
You must comply with our Acceptable Use Policy ("AUP"), which is incorporated into these Terms and prohibits, among other things: unlawful content and activity, malware, phishing, spam, harassment, unauthorized access attempts, rate-limit and quota evasion, cryptocurrency abuse, and misuse of AI features. Violations may result in suspension or termination under Section 19.
Warning: Automation features (auto-commit, scheduled messages) act under your identity on external platforms. Using them to violate another platform's terms — for example, to fabricate activity in a way GitHub prohibits — is your responsibility and grounds for enforcement under the AUP.
The Service, including its software, design, text, graphics, logos, and Documentation, is owned by AbabilX or its licensors and is protected by intellectual-property laws. Except for the license in Section 6, no rights are granted to you by implication or otherwise.
"AbabilX" and our logos are trademarks of AbabilX. You may not use them without prior written permission, except for truthful, nominative references to the Service.
The Service incorporates open-source components licensed under their own terms. Nothing in these Terms limits your rights under, or grants you rights that supersede, the applicable open-source licenses. Attribution notices are available in the Service or Documentation where required.
If you send us suggestions, ideas, or other feedback about the Service, you grant us a perpetual, irrevocable, worldwide, royalty-free license to use it for any purpose without obligation or compensation to you. Do not send feedback you consider confidential.
We may offer features identified as beta, preview, experimental, or "coming soon." Such features: (a) may change or be withdrawn at any time without notice; (b) may be subject to additional terms or usage caps; (c) are provided as-is without the service commitments applicable to generally available features; and (d) should not be relied upon for production-critical workflows. Feedback on beta features is governed by Section 13.
We work to keep the Service available and performant, but the Service is provided without an uptime guarantee. Access may be interrupted by maintenance, updates, infrastructure failures, third-party platform outages, or events beyond our control.
We may perform scheduled or emergency maintenance. Where practicable, we announce scheduled maintenance in advance through the Service.
We may modify the Service, including adding, changing, or removing features. If a change materially reduces core functionality of a paid Plan, we will notify affected subscribers, who may cancel and receive a pro-rated refund of prepaid, unused fees for the affected period as their exclusive remedy.
Our collection and use of Personal Data is described in the Privacy Policy. Our security practices are described in the Security Policy. Business customers requiring contractual data-processing terms may execute our Data Processing Addendum.
We respond to notices of alleged copyright infringement under our Copyright & DMCA Policy. Repeat infringers' Accounts will be terminated in appropriate circumstances.
You may not use the Service in violation of export-control or sanctions laws applicable to you or to us, including regulations administered by the U.S. Office of Foreign Assets Control and equivalent authorities. You represent that you are not located in, organized under the laws of, or ordinarily resident in a comprehensively sanctioned jurisdiction, and that you are not a sanctioned or restricted party or acting on behalf of one.
You may stop using the Service and delete your Account at any time (see Privacy Policy, Section 14). Fees already paid are handled per the Billing & Refund Policy.
We may suspend or terminate your access, with or without notice, if:
Where the cause is curable and does not pose immediate risk, we will make reasonable efforts to notify you and give you an opportunity to cure before termination.
Upon termination: your license ends; scheduled jobs stop; and your data is handled per the retention and deletion terms of the Privacy Policy. Sections that by their nature should survive — including 7.2 (for stored data during wind-down), 12, 13, 20, 21, 22, 23, and 24 — survive termination.
THE SERVICE, DOCUMENTATION, AND OUTPUT ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, ABABILX AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT DEFECTS WILL BE CORRECTED, OR THAT OUTPUT WILL BE ACCURATE OR RELIABLE.
SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES; TO THAT EXTENT, THE ABOVE EXCLUSIONS APPLY TO THE MAXIMUM EXTENT PERMITTED AND YOUR STATUTORY RIGHTS ARE UNAFFECTED.
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
THESE LIMITATIONS DO NOT APPLY TO: (i) LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW; (ii) A PARTY'S FRAUD OR WILLFUL MISCONDUCT; OR (iii) YOUR PAYMENT OBLIGATIONS. THE LIMITATIONS IN THIS SECTION APPLY REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
You will defend, indemnify, and hold harmless AbabilX and its officers, directors, employees, and agents from and against claims, damages, liabilities, costs, and expenses (including reasonable legal fees) arising from: (a) your Customer Content; (b) your use of the Service in violation of these Terms, the AUP, or applicable law; (c) actions the Service performs on third-party platforms at your direction; or (d) your violation of third-party rights. We will promptly notify you of any such claim and may participate in its defense with counsel of our choosing at our expense. You may not settle a claim in a way that imposes obligations on us without our written consent.
These Terms are governed by the laws of Bangladesh, without regard to conflict-of-laws rules. If you are a consumer in a jurisdiction whose mandatory consumer-protection laws grant you additional rights, those rights are unaffected.
Before starting formal proceedings, you agree to contact info@ababilx.cloud describing the dispute; both parties will attempt in good faith to resolve it within 30 days.
Any dispute not resolved informally shall be finally settled by binding arbitration seated in Dhaka, Bangladesh, under the Arbitration Act, 2001 (Bangladesh), by a sole arbitrator, conducted in English. Judgment on the award may be entered in any court of competent jurisdiction. Either party may instead seek: (a) relief in small-claims court for qualifying disputes; or (b) injunctive relief in any competent court for infringement or misuse of intellectual property or confidential information.
To the extent permitted by law, disputes must be brought on an individual basis; class, collective, and representative proceedings are waived. If this waiver is found unenforceable for a particular claim, that claim shall proceed in court, not arbitration.
info@ababilx.cloud and by post to AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.info@ababilx.cloudinfo@ababilx.cloudinfo@ababilx.cloudPostal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Acceptable Use Policy ("AUP") defines conduct that is prohibited on the AbabilX Service. It applies to every user, Account, Team, and client (web, desktop, mobile, API, and any future CLI or browser extension), and to all content transmitted through or stored on the Service. It forms part of our Terms of Service.
Terms defined in the Terms of Service and Privacy Policy have the same meanings here. "Content" includes Customer Content, Output you distribute, and anything you cause the Service to post on a third-party platform.
Use the Service lawfully, honestly, and without harming the Service, other users, third-party platforms, or third parties. Where a specific behavior is not listed below but is of the same character as a listed prohibition, it is equally prohibited. If you are unsure whether a use is acceptable, ask info@ababilx.cloud before proceeding.
You may not use the Service to:
You may not:
You may not:
You may not use AbabilX's automation to violate a connected platform's terms or harm its users, including:
You may not:
You may not:
You may not post, store, or transmit content that:
Team-space behavioral norms are further described in our Community Guidelines.
You may not use AI Features to:
You may not:
You may not:
You may not:
You may not:
Example — automation misuse (prohibited, items 39, 53): configuring auto-commit to generate daily filler commits on an employer-monitored repository so contribution graphs misrepresent work performed.
Example — permitted automation: using auto-commit on your own experimental repository to keep a scheduled changelog file updated, with no one being deceived.
Example — rate-limit evasion (prohibited, items 25–26): after receiving HTTP 429 responses, rotating through several accounts or IP addresses to continue hammering the sign-in endpoint.
Example — permitted retry: honoring
Retry-Afterand backing off exponentially.
Example — AI misuse (prohibited, item 72): editing a standup rule so the AI reports completed work on tickets no one touched, to mislead a client.
Example — permitted use: letting the AI draft your standup from real commit activity, then reviewing and correcting it before it posts.
Example — security research: testing whether our WebSocket handshake leaks tokens is in scope for good-faith research under the Vulnerability Disclosure Policy; testing it by hijacking another user's live session is not (item 11).
Report suspected violations to info@ababilx.cloud (or info@ababilx.cloud for security matters) with the relevant account, content, or URL and a description. We review reports promptly and keep reporter identities confidential except where disclosure is legally required.
We may, at our discretion and proportionate to the violation:
For minor, curable violations we will ordinarily warn first. Violations involving illegality, security attacks, minors, or imminent harm result in immediate action without notice.
If you believe an enforcement action was mistaken, reply to the enforcement notice or write to info@ababilx.cloud within 30 days with the facts you believe we got wrong. A person not involved in the original decision will review the appeal and respond.
We may revise this AUP as new abuse patterns emerge, recording changes in Section 11. The version in force at the time of the conduct governs enforcement.
Abuse reports: info@ababilx.cloud · Security: info@ababilx.cloud · Legal: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Security Policy describes the technical and organizational measures AbabilX uses to protect the Service and the data entrusted to it. It covers our web, desktop, mobile, and API surfaces and the infrastructure behind them. It is a statement of practice, not a contract; contractual security commitments for business customers are made in the Data Processing Addendum.
Our commitment: We treat user security and privacy as foundational requirements, not optional features. Every layer of the Service — authentication, transport, storage, access control, and monitoring — is designed to keep your data confidential, intact, and available only to you and those you authorize.
We protect data across its full path through AbabilX — from your device to our servers and while stored on our systems:
The Service's authentication design keeps credentials out of URLs, logs, and client-side script reach:
HttpOnly; Secure; SameSite cookie, path-restricted to the authentication endpoints and unreadable by JavaScript — neutralizing token theft via cross-site scripting.SameSite cookie scoping plus bearer-token authorization, so cross-site form posts cannot authenticate.Layered throttles protect the platform:
Rejected requests receive HTTP 429 with retry guidance. Deliberate evasion of these limits violates the Acceptable Use Policy.
Our incident-response process covers:
We welcome good-faith security research. If you believe you have found a vulnerability, report it to info@ababilx.cloud following our Vulnerability Disclosure Policy, which defines scope, safe-harbor commitments, and reporting expectations. Do not access other users' data, disrupt the Service, or publicly disclose an issue before we have had a reasonable opportunity to remediate.
Security is shared. You are responsible for:
We update this Policy as our practices evolve, recording changes in Section 19. We will not weaken a stated commitment without prominent notice.
Security reports: info@ababilx.cloud · General: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This AI Policy explains how AbabilX's AI-powered features work, what data they process, which third parties are involved, and the limits you should understand before relying on machine-generated content. It applies to every AI feature of the Service across all clients and forms part of our Terms of Service. Data-protection terms in our Privacy Policy apply to all processing described here.
New AI Features will be governed by this Policy from launch; if a feature materially departs from these terms, we will say so where the feature is offered.
For each request, the Service assembles the minimum context the feature needs, typically drawn from:
Personal identifiers (names, emails) appear in Prompts only insofar as they already appear in the underlying content — for example, a commit author name inside commit metadata.
We do not transmit to AI Providers:
Output is currently generated by DeepSeek, called via API as a Subprocessor (see our Subprocessor List). Our provider agreements require that Prompts and Output:
If we add or replace an AI Provider, we update the Subprocessor List before the change takes effect and, for business customers under our Data Processing Addendum, provide the notice and objection rights described there.
We do not use your Customer Content, Prompts, or Output to train machine-learning models. We will not begin doing so without explicit prior notice to you and, where required by law, your consent. Aggregated, de-identified telemetry (for example, feature usage counts and error rates) may be used to improve the Service, but never in a form that reproduces your content.
Warning: AI Output can be wrong — confidently wrong.
We operate controls around AI Features, including:
Content processed by AI Features may include text written by others (commit messages, PR comments, task descriptions). Such text can contain prompt-injection attempts — instructions embedded in content intended to manipulate the model.
Our mitigations include separating system instructions from user content, constraining what actions the assistant can take (state-changing actions require your explicit confirmation in the interface), and scoping every request to your existing permissions: the model cannot read or act on anything your account could not already access. No mitigation is perfect; treat Output derived from untrusted content with corresponding skepticism, and report suspected injection issues to info@ababilx.cloud under our Vulnerability Disclosure Policy.
AI Features are subject to plan-based allowances and rolling usage windows shown in the Service. Attempting to evade limits — through multiple accounts, automated retry storms, or manipulation of usage accounting — violates the Acceptable Use Policy. Limits may change prospectively; material reductions for paid plans follow the notice rules in the Terms of Service, Section 5.1.
You agree to:
We will update this Policy as AI Features and providers evolve, recording changes in Section 17. Changes that reduce your protections — for example, any change to Section 8 — are material and will be notified prominently in advance.
AI questions: info@ababilx.cloud · Privacy: info@ababilx.cloud · Security: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Billing & Refund Policy governs payments for the AbabilX Service and forms part of our Terms of Service. Terms defined there apply here.
The Service offers a Free plan and a paid Premium plan. Current prices, features, and limits are displayed in the Service at the point of purchase; the price shown at checkout is the price you pay for that Billing Cycle. Feature limits (auto-commit duration and daily caps, digest and rule allowances, AI usage windows) are enforced automatically per Plan.
Payments are processed by third-party payment providers. We do not store full card numbers or bank credentials; the provider transmits to us only confirmation of payment status and the records needed to manage your subscription (see Privacy Policy, Section 6.1.5). You must have authority to use the payment method you provide, and you must keep it current.
Fees exclude taxes unless expressly stated. You are responsible for value-added, sales, goods-and-services, withholding, and similar taxes applicable to your purchase, excluding taxes on AbabilX's income. Where we are required to collect tax, it is added at checkout.
You may cancel at any time in the Service or by writing to info@ababilx.cloud from your account email. Cancellation:
When Premium ends (by cancellation lapse or non-payment):
Except as stated in this Section or required by law, Fees are non-refundable, and unused time in a Billing Cycle is not refunded on cancellation.
We will refund, pro-rated where applicable:
We do not refund: partial-cycle cancellations outside Section 10.2; dissatisfaction with AI Output quality (see AI Policy, Section 9); suspension or termination for violation of the Acceptable Use Policy or Terms of Service; or failure to cancel before a Renewal Date, except as goodwill at our discretion.
Email info@ababilx.cloud from your account email with the charge date and reason. We respond within 7 business days; approved refunds are issued to the original payment method and may take 5–10 business days to appear, depending on the provider.
If a renewal charge fails, we will retry and notify you. If payment is not completed within a reasonable grace period, the subscription lapses to Free and Section 9 applies. We do not charge late fees.
Contact us before disputing a charge with your payment provider — most issues are resolved faster under Section 10.4. Chargebacks filed for services legitimately received violate the Acceptable Use Policy (item 102) and may result in suspension pending resolution. We will promptly reverse any charge shown to be erroneous.
We may change prices prospectively. Price changes to an active subscription take effect no earlier than your next Renewal Date, and we will notify you at least 14 days before a renewal at a higher price. If you do not accept the new price, cancel before the Renewal Date; you will retain service through the period already paid.
Subscription records and invoices are available in the Service or on request to info@ababilx.cloud. We retain billing records for the period required by tax and accounting law (Privacy Policy, Section 12).
Updates are versioned in Section 17. Changes reducing your refund rights apply only to purchases made after the change's effective date.
Billing questions and refund requests: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Policy governs programmatic access to the AbabilX Service — the REST API, WebSocket endpoints, webhooks, and any future developer surfaces (CLI, browser extension, SDKs). It supplements the Terms of Service and Acceptable Use Policy; where they conflict, the Terms of Service control.
You must:
info@ababilx.cloud immediately.You must not share Credentials between users, embed a user's Credentials in a multi-tenant service, or solicit users' Credentials outside AbabilX's authentication flows.
Retry-After and implement exponential backoff with jitter.info@ababilx.cloud before engineering around them.If your Integration receives data from the API:
You are responsible for:
In addition to the Acceptable Use Policy, you may not use the API to:
When AbabilX ships a command-line interface or browser extension:
We may throttle, suspend, or revoke API access — per token, per Integration, or per Account — for violations of this Policy, security risk, or harm to the Service, following the enforcement approach in the Acceptable Use Policy, Section 7. Where practical we will contact you first.
Changes are versioned in Section 15; material changes are announced through the Service's changelog with reasonable notice.
Developer questions: info@ababilx.cloud · Security: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
AbabilX respects intellectual-property rights and expects users to do the same. This Policy explains how rights holders can report allegedly infringing content hosted on the Service, how affected users can respond, and how we handle repeat infringement. Our process follows the framework of the U.S. Digital Millennium Copyright Act ("DMCA") notice-and-takedown model, applied globally as our operational standard, alongside applicable Bangladeshi copyright law.
Content hosted on AbabilX that may be subject to a Notice includes: wall posts and comments, kanban tasks, notes and attachments, chat attachments, uploaded profile and cover images, and stored digests or summaries. Content residing on GitHub, Slack, or Google platforms is not hosted by us — see Section 10.
Send Notices to info@ababilx.cloud (or by post to the address in Section 12) including all of the following:
Incomplete Notices may be rejected with an explanation of what is missing.
Note: Consider whether the use may be a fair use, fair dealing, or otherwise licensed before filing. Section 8 describes liability for misrepresentation.
On receiving a complete Notice, we will:
We may decline to act on Notices that are incomplete, plainly meritless, or abusive, and will tell the complainant why.
If your content was removed and you believe the removal was mistaken or the material was misidentified, send a Counter-Notice to info@ababilx.cloud including:
We will forward the Counter-Notice to the complainant. Unless the complainant informs us within 10–14 business days that they have filed a court action seeking to restrain the alleged infringement, we may restore the material.
We maintain a record of substantiated Notices per Account. Accounts that accumulate repeated substantiated Notices — ordinarily three within any 12-month period, or fewer for egregious cases — will be terminated in accordance with the Terms of Service, Section 19. Counter-noticed removals that are resolved in the user's favor do not count.
Knowingly materially misrepresenting that content is infringing, or that it was removed by mistake, can make you liable for resulting damages (including costs and legal fees) under the DMCA §512(f) and equivalent laws. Filing false Notices or Counter-Notices also violates our Acceptable Use Policy (item 97) and may result in account action and refusal of future submissions.
Trademark concerns (impersonation, misleading use of a mark in usernames, teams, or content) should be sent to info@ababilx.cloud with: the mark, registration details or basis of rights, the offending content's location, and the requested action. We review trademark complaints case-by-case under the Acceptable Use Policy, Sections 4.5 and 4.7.
The Service reads from and writes to GitHub, Slack, and Google platforms at users' direction. Content stored on those platforms — repository code, Slack message history in a workspace, Google account data — must be reported to the respective platform under its own copyright process (for example, GitHub's DMCA process). Where a user employs AbabilX automation to place infringing content on a third-party platform, you may additionally report the conduct to us under the Acceptable Use Policy, and we may act on the user's AbabilX Account.
Changes are versioned in Section 13. The process in force when a Notice is received governs that Notice.
Designated Agent — Copyright:
Email: info@ababilx.cloud
Post: AbabilX — Copyright Agent, Sector 4, Uttara, Dhaka, Bangladesh
Other legal matters: info@ababilx.cloud
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
AbabilX's collaboration features — team walls, kanban boards, chat, daily updates, attendance, and digests — are shared workspaces. These Guidelines set the behavioral standard inside them. They apply to every member of every Team and complement the Acceptable Use Policy ("AUP"), which lists platform-wide prohibitions. Where these Guidelines and the AUP overlap, the stricter rule applies.
Terms defined in the Terms of Service apply. "Team Space" means any collaboration surface scoped to a Team.
Do not post in any Team Space content that:
AI features draft standups, digests, summaries, and task descriptions. When that content enters a Team Space under your name:
Attendance, work logs, and activity graphs exist to coordinate work, not to surveil people.
info@ababilx.cloud with the team, content, and what happened — especially when the problem involves the team's leadership, or is severe (threats, hate speech, doxxing, CSAM — the last is reported to authorities without exception).Violations are handled under the AUP's enforcement framework (AUP, Section 7): content removal, feature restrictions, suspension, or termination, proportionate to severity and history. Team-level moderation by owners is independent of, and does not limit, platform-level enforcement. Appeals follow AUP Section 8.
Changes are versioned in Section 13 and announced in the Service when material.
Conduct reports: info@ababilx.cloud · Urgent safety issues: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Data Processing Addendum ("DPA") forms part of the agreement between AbabilX and the customer accepting it ("Customer") under the Terms of Service (together, the "Agreement"), and applies where AbabilX processes Personal Data subject to Data Protection Law on Customer's behalf. In case of conflict regarding the processing of Personal Data, this DPA prevails over the Agreement; executed Standard Contractual Clauses prevail over this DPA.
This DPA is accepted by using the Service as a business or organization, or by countersignature where a signed copy is requested (info@ababilx.cloud).
The subject matter, duration, nature, purposes, data categories, and Data Subject categories of Processing are set out in Annex I (Section 16).
AbabilX shall:
Customer shall:
info@ababilx.cloud.AbabilX maintains the measures described in Annex II and the Security Policy, and may update them provided the protection level is not materially reduced.
AbabilX shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing (as information becomes available): the nature of the breach, categories and approximate volumes affected, likely consequences, and measures taken or proposed. AbabilX will cooperate with Customer's reasonable investigation and its regulatory and Data Subject notification obligations. Notification is not an admission of fault.
Upon termination of the Agreement, or upon Customer's deletion of specific data through the Service, AbabilX deletes Customer Personal Data as described in the Privacy Policy, Sections 12 and 14 (including rotation out of encrypted backups), except where retention is required by law. On written request made before account deletion, AbabilX will provide an export of Customer Personal Data in a machine-readable format.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, Section 21, except where Data Protection Law does not permit such limitation (including a Data Subject's rights under the SCCs).
This DPA takes effect upon acceptance and remains in force as long as AbabilX processes Customer Personal Data under the Agreement.
As detailed in the Security Policy:
HttpOnly; Secure; SameSite refresh cookies; one-time exchange codes and tickets keeping credentials out of URLs and logs.DPA execution and questions: info@ababilx.cloud · Privacy: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Statement explains how AbabilX meets its obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR for users and customers in the European Economic Area, the United Kingdom, and Switzerland (whose FADP is addressed by analogy). It supplements — and should be read with — our Privacy Policy and, for business customers, our Data Processing Addendum ("DPA").
GDPR terms — "Controller," "Processor," "Personal Data," "Processing," "Data Subject" — carry their statutory meanings.
Individual users acting purely for themselves interact with us as Controller throughout.
Our lawful bases per purpose are tabulated in the Privacy Policy, Section 8: contract for operating the Service and generating requested Output; legitimate interests for security, abuse prevention, and service analytics (assessed against Data Subjects' rights, with minimization safeguards); consent for non-essential communications and any non-essential storage; legal obligation for tax, accounting, and lawful requests. Where we rely on legitimate interests, you may object (Section 5).
Under Articles 15–22 GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time (Article 7(3)).
Self-service (immediate):
By request to `info@ababilx.cloud`:
We verify requests against your account email, respond within one month (extendable by two months for complex requests, with notice), and act free of charge except where requests are manifestly unfounded or excessive (Article 12(5)).
If we process your data as Processor for a team or business, we will redirect your request to that customer, who is the Controller responsible for responding (see DPA, Section 11).
AbabilX operates from Bangladesh — a country without an EU adequacy decision — and uses Subprocessors in several countries. Transfers of EEA/UK/Swiss Personal Data are protected by:
Article 25 obligations are reflected in the platform's construction:
me endpoints expose only the fields each screen needs; AI requests carry the minimum context per feature (AI Policy, Section 4);We maintain records of processing activities appropriate to our size and processing (Article 30), assess new features with privacy-affecting scope before launch, and conduct data-protection impact assessments where processing is likely to result in high risk (Article 35). Subprocessors are engaged under written contracts imposing GDPR-equivalent obligations (Article 28(4)); the current list is the Subprocessor List.
We have not appointed a mandatory Data Protection Officer under Article 37, as our core activities do not involve large-scale systematic monitoring or large-scale special-category processing; privacy responsibility rests with engineering leadership, reachable at info@ababilx.cloud. We will appoint a DPO and an EU/UK representative (Article 27) if and when our processing triggers those obligations, and will update this Statement accordingly.
Where a Personal Data Breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of awareness (Article 33) and affected Data Subjects without undue delay where the risk is high (Article 34). For Customer Personal Data processed under the DPA, we notify the customer within 72 hours so it can meet its own obligations (DPA, Section 10).
The Service does not make decisions producing legal or similarly significant effects on you based solely on automated processing (Article 22). AI features generate drafts and summaries for human review; plan-limit and rate-limit enforcement are contractual usage controls, and enforcement decisions affecting your account involve human review (see Acceptable Use Policy, Sections 7–8).
You may lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of an alleged infringement (Article 77) — for example, your national Data Protection Authority in the EEA, or the ICO in the UK. We would welcome the opportunity to resolve your concern first at info@ababilx.cloud.
Changes are versioned in Section 14; material changes are announced through the Service.
Privacy and GDPR requests: info@ababilx.cloud · Legal: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This Statement provides the disclosures required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA") for California residents who use AbabilX. It supplements our Privacy Policy, which describes our practices in full.
"Personal information," "sell," "share," "sensitive personal information," "service provider," and "business purpose" carry their CCPA statutory meanings. "You" means a California resident.
We collect the categories of personal information listed in Section 4, for the purposes listed in Section 5, retained per Section 8. We do not sell or share personal information (Section 6).
Mapped to the CCPA's statutory categories (Cal. Civ. Code §1798.140(v)):
Content you or your integrations submit (repository metadata, messages, posts) may incidentally contain identifiers of you or others; it is handled as Customer Content under the Privacy Policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. We have no actual knowledge of selling or sharing personal information of consumers under 16. Because we do not sell or share, we do not offer an opt-out mechanism, and browser opt-out signals (such as Global Privacy Control) require no change to our processing — your data is already treated as opted out.
The only sensitive personal information we process is account authentication material (tokens and codes), used solely to authenticate you and secure the Service — a use permitted under §7027(m) without a right-to-limit obligation. We do not use sensitive personal information to infer characteristics.
Retention periods per category follow the schedule in our Privacy Policy, Section 12: account data for the life of the account; logs on rolling 30–180-day windows; billing records as required by tax law; all subject to deletion on account closure.
California residents have the right to:
info@ababilx.cloud with "California Privacy Request" in the subject. We verify your identity via your account email (and reasonable follow-up where needed), confirm receipt within 10 business days, and respond within 45 days (extendable once by 45 days with notice).We will not deny you the Service, charge different prices, or degrade quality because you exercised CCPA rights. Plan-based feature differences apply equally to everyone and are unrelated to privacy requests.
Entities in our Subprocessor List act as service providers under written contracts that prohibit retaining, using, or disclosing personal information for any purpose other than performing their services, and prohibit selling or sharing it — consistent with §1798.140(ag) and our Data Processing Addendum, Section 5.
Changes are versioned in Section 15. This Statement is reviewed at least annually.
California privacy requests: info@ababilx.cloud (subject: "California Privacy Request")
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
This document is the single authoritative list of third parties that process Personal Data on AbabilX's behalf ("Subprocessors"). It supports the commitments in our Privacy Policy (Section 10.1) and Data Processing Addendum (Section 7). Other policies link here rather than duplicating the list.
"Subprocessor" — a third party engaged by AbabilX to process Personal Data in the course of providing the Service. Terms defined in the Privacy Policy apply.
Before engaging a Subprocessor we assess its security posture and data-protection practices, and we bind it by written contract to: process Personal Data only on our instructions; apply appropriate security measures; not use the data for its own purposes (including model training, for AI providers); and support deletion and breach-notification obligations. International transfers to Subprocessors rely on Standard Contractual Clauses where required (GDPR Compliance Statement, Section 6).
Note: Where a row names a function rather than a single vendor, the engaged vendor for your account is available on request to
info@ababilx.cloud; the contractual protections in Section 3 apply identically.
The following process your data because you connect them and direct the Service to interact with them. They act under their own terms as independent controllers, not as our Subprocessors:
Disconnecting an integration in AbabilX stops our access but does not delete data those platforms hold — manage that with the platform directly.
We update this list at least 14 days before adding or replacing a Subprocessor. Business customers under the DPA may subscribe to change notices and object as described in DPA Section 7 by emailing info@ababilx.cloud with the subject "Subprocessor notifications." Every change is recorded in Section 8.
Questions and notification subscriptions: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Version: 1.0.0
Security research conducted in good faith makes AbabilX safer for everyone. We welcome reports of vulnerabilities in our Service, will work with you to understand and remediate them, and will not pursue action against research that follows this Policy.
In scope:
Out of scope:
You must:
Email `info@ababilx.cloud` with:
Report in English or Bangla. Encrypted reports: request our key at the same address.
For good-faith research conducted in accordance with this Policy:
This safe harbor does not extend to research that materially violates Section 4, harms users, or breaks laws we cannot waive. If you are unsure whether planned testing is covered, ask info@ababilx.cloud before testing.
We support coordinated disclosure. Please give us 90 days from acknowledgment (or a mutually agreed timeline) before publishing details. We may request a short extension for complex fixes; we will not use the process to indefinitely suppress publication. Where a fix ships sooner and users are protected, earlier coordinated publication is fine — talk to us.
The following are ordinarily not accepted as Vulnerabilities (unless you demonstrate concrete exploitability):
info@ababilx.cloud — still appreciated).We do not currently operate a paid bug bounty. With your consent, we credit meaningful findings in our changelog or an acknowledgments page. If a bounty program launches, this Policy will be updated with its terms.
Changes are versioned in Section 13. The Policy version in effect when you begin testing governs that research.
Security reports: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.