AbabilX Legal Policies

All legal documents are available on this single page for easy review and policy acceptance.

Quick Navigation

AbabilX Privacy Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Introduction

AbabilX ("AbabilX," "we," "us," or "our") provides an AI-powered platform that helps software developers and teams automate pull-request summaries, standups, commit workflows, repository analytics, digests, and team collaboration (collectively, the "Service"). The Service is available through our website, web application, desktop application, mobile applications, REST API, and any future clients such as a command-line interface or browser extension.

This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we keep it, and the rights and choices available to you. It is written to be read; where we must use a technical or legal term, we define it in Section 2.

Your security and privacy come first. AbabilX is built with a user-first approach to data protection. We encrypt data across its full journey through our platform — protected in transit between your devices and our servers (TLS/HTTPS) and encrypted at rest in storage. We share Personal Data only for the limited purposes described in this Policy, never sell it, and give you controls to disconnect integrations and delete your account at any time.

No tracking. No third-party telemetry. We do not embed advertising trackers, analytics pixels, or behavioral-profiling SDKs in our website, apps, or clients. We do not track you across other websites, build marketing profiles, or sell your activity to data brokers. Operational server logs exist only for security, abuse prevention, and keeping the Service running — not for surveillance or ads.

By creating an account or using the Service, you acknowledge this Privacy Policy. Where local law requires consent for specific processing (for example, certain cookies or marketing communications), we ask for it separately.

Note: This Policy describes our practices. Contractual commitments to business customers regarding the processing of Personal Data are set out in our Data Processing Addendum.

2. Definitions

  • "Account" means the AbabilX account you register, whether individual or associated with an organization or team.
  • "Customer Content" means content you submit to the Service or authorize us to access on your behalf, including repository data retrieved through your connected GitHub account, messages posted to Slack through the Service, wall posts, kanban tasks, chat messages, attendance records, and AI prompts you enter.
  • "Output" means content generated by AI features of the Service in response to your Customer Content or prompts, such as PR summaries, standup drafts, and digest text.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
  • "Service" means all AbabilX websites, applications, APIs, and clients described in Section 1.
  • "Subprocessor" means a third party we engage to process Personal Data on our behalf, listed in our Subprocessor List.
  • "You" means the individual using the Service, and where applicable, the organization on whose behalf that individual acts.

3. Our Privacy Principles

  1. Minimum necessary access. We request only the OAuth scopes and data the Service needs to perform the functions you enable.
  2. Purpose limitation. We use data for the purposes described in this Policy and not for unrelated purposes without telling you.
  3. No sale of Personal Data. We do not sell Personal Data and have not sold it in the preceding 12 months.
  4. No AI training on your content without notice. We do not use Customer Content to train machine-learning models, and we contractually restrict our AI Subprocessors from doing so. See Section 9 and our AI Policy.
  5. Security by design. Token handling, session management, and transport security follow the practices described in Section 15 and our Security Policy.
  6. Transparency. Material changes to this Policy are versioned, announced, and — where the change is significant — require your re-acceptance before continued use.
  7. End-to-end protection. Personal Data and authentication credentials are encrypted in transit (TLS) and protected at rest. We apply layered controls from sign-in through storage, processing, and deletion.
  8. Controlled data sharing. We share Personal Data only with the categories of recipients in Section 10, for defined purposes, under contract where applicable, and never for advertising resale.
  9. No tracking or profiling. We do not use third-party analytics, advertising telemetry, cross-site tracking, or behavioral profiling. Your use of AbabilX is not monitored for marketing purposes.

4. Scope of This Policy

4.1 What This Policy Covers

This Policy applies to Personal Data processed when you:

  • visit our websites or landing pages;
  • register for or use the Service through any client (web, desktop, mobile, API, CLI, or browser extension);
  • connect third-party accounts (GitHub, Google, Slack) to the Service;
  • communicate with us, including support requests;
  • receive notifications from the Service.

4.2 What This Policy Does Not Cover

This Policy does not apply to:

  • Third-party platforms. GitHub, Google, Slack, and other connected platforms process your data under their own privacy policies. Disconnecting an integration in AbabilX does not delete data held by those platforms.
  • Your organization's practices. If you use AbabilX through a team or organization, your team owner or administrators may access content you create within that team (for example, wall posts, kanban activity, attendance records). Their handling of that information is governed by their own policies.
  • Content you make public. Content you choose to publish or share beyond the Service is outside our control once shared.

5. Eligibility and Children

The Service is intended for users aged 18 or older. We do not knowingly collect Personal Data from anyone under 18. If we learn that we have collected Personal Data from a person under 18, we will delete that data and terminate the associated Account. If you believe a minor has provided us Personal Data, contact info@ababilx.cloud.

6. Information We Collect

We collect information in three ways: information you provide, information collected automatically, and information received from third parties.

6.1 Information You Provide

6.1.1 Account Data

When you register, we collect your name, username, email address, and profile picture, typically supplied by the OAuth provider you sign in with. You may additionally provide a cover image, language preference (English or Bangla), theme preference, and notification preferences.

6.1.2 OAuth Authorizations

When you connect a third-party account, we receive and store the credentials required to act on your behalf:

  • GitHub: an access token scoped to the permissions you grant, your GitHub username and user ID.
  • Google: your Google account identifier and identity token, used for sign-in (including mobile sign-in).
  • Slack: workspace and bot tokens, workspace ID, team name, and (if you authorize it) a user token for posting as you.

We store OAuth tokens server-side and never expose them to other users. See Section 15 for how tokens are protected.

6.1.3 Configuration Data

We store the settings you create in the Service, including standup rules (channels, schedules, timezones, target repositories), auto-commit job configurations (repository, cadence, limits), weekly digest configurations, team settings, kanban board structures, webhook configurations, and attendance settings.

6.1.4 Content You Create

We store content you author in the Service: wall posts and comments, kanban tasks, notes and attachments, chat messages, work-log entries, standup message overrides, and prompts you send to AI features.

6.1.5 Billing Information

If you purchase a Premium plan, we collect subscription records: plan type, billing cycle, start and expiry dates, and invoice history. Payment card details are collected and processed by our payment providers; we do not store full card numbers. See our Billing & Refund Policy.

6.1.6 Communications

If you contact support or respond to our communications, we keep the correspondence and any information you include in it.

6.2 Information Collected Automatically

6.2.1 Repository and Development Metadata

When you enable features that read from GitHub, we access and may cache: your repository list, repository metadata, commit metadata (messages, authors, timestamps, diffs where required for summaries), branch information, pull requests (titles, descriptions, files changed, reviews, comments, check statuses), and organization membership relevant to repository access.

6.2.2 Usage and Device Data

We collect standard technical data when you use the Service: IP address, browser type and version, operating system, device type, client version (for desktop and mobile apps), pages and features accessed, timestamps, and referring URLs. This data comes from first-party server logs only — not from third-party tracking or analytics services.

Note: We do not use covert device fingerprinting, third-party analytics SDKs, or advertising trackers. Technical attributes (such as user-agent and IP address) are processed solely for security, abuse prevention, and essential diagnostics as described in Sections 7 and 8 — never for marketing or cross-site profiling.

6.2.3 Cookies, Local Storage, and Session Storage

We use a small set of strictly necessary cookies and browser storage entries to keep you signed in, protect your session, and remember preferences (such as theme and language). Details, names, and lifetimes are documented in our Cookie Policy. We do not use third-party advertising cookies, analytics cookies, or tracking pixels.

6.2.4 Logs and Diagnostics

We maintain:

  • API logs — request method, path, status code, latency, and the authenticated account identifier;
  • Server logs — infrastructure-level events needed to operate the platform;
  • Security logs — authentication events, token refresh and revocation events, rate-limit rejections, and administrative actions;
  • Crash logs and performance metrics — error traces and timing data from our applications, used to diagnose defects.

Logs are retained on the schedule in Section 12 and access to them is restricted under Section 15.

6.2.5 Mobile Push Tokens

If you enable push notifications on iOS or Android, we store the Firebase Cloud Messaging (FCM) registration token for your device so we can deliver notifications. Deregistering the device or disabling notifications removes the token.

6.3 Information from Third Parties

  • GitHub API: repository, commit, pull request, branch, and profile data as authorized by your token.
  • Slack API: channel lists, workspace metadata, and message delivery status.
  • Google: identity assertions confirming your sign-in.
  • Payment providers: confirmation of payment status and subscription events.

We do not purchase Personal Data from data brokers.

7. How We Use Information

We use the information described in Section 6 to:

  1. Provide the Service — authenticate you; execute standup rules, auto-commit jobs, and digest schedules; render dashboards and analytics; deliver team collaboration features; send notifications you have enabled.
  2. Operate integrations on your behalf — read repository data from GitHub, create commits and branches you request, and post messages to Slack channels you authorize.
  3. Generate AI Output — send the minimum relevant context (see Section 9) to our AI provider to produce PR summaries, standup drafts, commit summaries, and digest text.
  4. Maintain security and prevent abuse — detect and block brute-force attempts, credential abuse, rate-limit violations, fraud, and violations of our Acceptable Use Policy.
  5. Bill and manage subscriptions — enforce plan limits, process upgrades and expirations, and maintain required financial records.
  6. Keep the Service reliable — use aggregated, de-identified operational metrics and first-party error diagnostics to fix bugs and maintain performance. We do not use third-party analytics platforms or behavioral tracking for this purpose.
  7. Communicate with you — send transactional messages (security alerts, policy updates, plan notices) and, with your consent where required, product announcements. You can opt out of non-essential communications at any time.
  8. Comply with law — meet legal obligations, respond to lawful requests, and establish or defend legal claims.

We do not use your information for third-party advertising, behavioral tracking, or building marketing profiles. AbabilX is designed for pure privacy: no ad networks, no cross-site trackers, no telemetry SDKs sold to third parties.

Where the EU/UK General Data Protection Regulation ("GDPR") or similar laws apply, we rely on the following legal bases:

  • Creating and operating your Account; executing features you configure: Contract (Art. 6(1)(b))
  • Sending data to AI providers to generate Output you request: Contract (Art. 6(1)(b))
  • Security logging, rate limiting, fraud and abuse prevention: Legitimate interest (Art. 6(1)(f)) — protecting the Service and its users
  • Service analytics and improvement: Legitimate interest (Art. 6(1)(f)) — with data minimization safeguards
  • Non-essential cookies; marketing communications: Consent (Art. 6(1)(a)) — withdrawable at any time
  • Tax, accounting, and lawful-request compliance: Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights and freedoms; you may object as described in Section 13. Further GDPR detail is in our GDPR Compliance Statement.

9. AI Features and Your Data

AI features are a core part of the Service. We treat the data flowing through them with specific safeguards, described fully in our AI Policy and summarized here:

  1. What is sent. To generate Output, we transmit only the context required for the specific feature — for example, commit messages, diffs, and PR metadata for a PR summary. We do not send your OAuth tokens, password-equivalent secrets, or billing data to AI providers.
  2. Who processes it. AI Output is generated by our contracted AI provider (currently DeepSeek), acting as a Subprocessor under data-protection terms.
  3. No training. We do not use your Customer Content or prompts to train models, and our agreements restrict our AI providers from using them to train their models.
  4. Retention. Prompts and Output handled by the AI provider are retained only as long as needed to return the response and meet the provider's short-term abuse-monitoring window; Output we store for you (for example, a saved digest) is retained under Section 12.
  5. Accuracy. Output is machine-generated and may be inaccurate. Review Output before relying on it; see the disclaimer in our AI Policy.

10. How We Share Information

AbabilX does not sell your Personal Data. We share information only when it is necessary to provide the Service you choose to use, when you direct us to, when the law requires it, or with your explicit consent. Every sharing category below is intentional, limited, and documented — we do not pass your data to third parties for their own unrelated purposes.

We share Personal Data only in the following circumstances:

10.1 Subprocessors and Service Providers

We use vetted third parties for hosting, storage, content delivery, push notifications, email delivery, payments, and AI processing. Each is bound by contract to process Personal Data only on our instructions and to protect it. The current list, including purpose and location, is maintained in our Subprocessor List.

10.2 Connected Platforms at Your Direction

When you use a feature that acts on a third-party platform — committing to GitHub, posting to Slack — we transmit the necessary data to that platform. That transmission is visible to the platform and governed by its terms.

10.3 Your Team or Organization

If your Account belongs to a team, content you create in team features (wall, board, chat, attendance, digests) is visible to team members according to the team's roles and settings, and team owners/administrators can manage members and content.

We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or enforceable governmental request. Where lawful and practicable, we will notify you before disclosing your data so you can seek protective measures. We object to requests we believe are overbroad.

10.5 Business Transfers

If AbabilX is involved in a merger, acquisition, financing, reorganization, or sale of assets, Personal Data may be transferred as part of that transaction. We will notify you of any such transfer and of any resulting change in this Policy, and the successor remains bound by commitments at least as protective as this Policy.

10.6 Aggregated or De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you (for example, overall usage statistics).

We share Personal Data for any other purpose only with your consent.

11. International Data Transfers

We operate from Bangladesh and use infrastructure and Subprocessors located in multiple countries. Your information may therefore be transferred to, stored in, and processed in countries other than your own, which may have different data-protection laws.

Where we transfer Personal Data from jurisdictions that restrict international transfers (including the EEA, the United Kingdom, and Switzerland), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses with our Subprocessors, together with supplementary technical measures (encryption in transit, access controls). Details are in our GDPR Compliance Statement and Data Processing Addendum.

12. Data Retention

We retain Personal Data only as long as needed for the purposes described in this Policy, then delete or de-identify it. Representative schedules:

  • Account Data: Life of the Account; deleted on account deletion (Section 14)
  • OAuth tokens: Until you disconnect the integration, the token expires or is revoked, or the Account is deleted
  • Customer Content (posts, tasks, messages, configurations): Life of the Account or until you delete the item; team content may persist for the team per its settings
  • AI prompts and Output stored in your Account: Life of the Account or until you delete the item
  • Slack messages sent via the Service (history/replay): Until you delete the rule/message or the Account
  • Billing and subscription records: Duration required by tax and accounting law
  • API, server, and security logs: Rolling window, typically 30–180 days depending on log type; security-incident logs may be preserved for the duration of an investigation
  • Crash and performance diagnostics: Rolling window, typically 90 days
  • Backups: Encrypted backups age out on a rolling schedule; deleted data leaves backups as they rotate

Where deletion is not immediately possible (for example, data in backups), we isolate the data from further processing until deletion completes.

13. Your Rights and Choices

Depending on your jurisdiction, you may have the right to:

  1. Access — obtain confirmation of whether we process your Personal Data and receive a copy.
  2. Correction — have inaccurate or incomplete data corrected. Most profile fields are directly editable in Settings.
  3. Deletion — have your Personal Data deleted (see Section 14).
  4. Portability — receive your data in a structured, commonly used, machine-readable format.
  5. Objection — object to processing based on legitimate interests.
  6. Restriction — restrict processing in the circumstances defined by applicable law.
  7. Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
  8. Complain — lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first at info@ababilx.cloud.

Self-service controls available in the Service include: editing profile data, disconnecting GitHub/Slack integrations, revoking sessions by signing out, disabling email/desktop/push notifications, changing language and privacy mode, and deleting your Account.

To exercise a right that lacks a self-service control, email info@ababilx.cloud. We verify requests using your account email and respond within 30 days (or the shorter period local law requires). We do not discriminate against you for exercising your rights.

California-specific rights are described in our CCPA/CPRA Compliance Statement; EEA/UK-specific detail is in our GDPR Compliance Statement.

14. Account Closure and Deletion

You may delete your Account at any time from within the Service or by emailing info@ababilx.cloud from your account email. On deletion:

  • your profile, configurations, content, tokens, and stored Output are permanently deleted from production systems;
  • active sessions and refresh credentials are revoked;
  • data shared into team spaces you do not own may persist for the team, attributed to a deactivated account, where the team owner controls it;
  • billing records are retained as required by law (Section 12);
  • residual copies in encrypted backups are removed as backups rotate.

Warning: If you own a team, deleting your Account deletes the team and its content for all members. Transfer team ownership first if the team should continue.

Deletion is irreversible. Revoking AbabilX's access from within GitHub, Google, or Slack disables the integration but does not by itself delete your AbabilX Account.

15. Security

Protecting your data is central to how we build AbabilX. We apply defense-in-depth security — encryption across connections and storage, strict access controls, session hardening, and continuous review — so your information stays protected throughout its lifecycle on our platform.

We protect Personal Data using administrative, technical, and physical safeguards appropriate to its sensitivity, described in detail in our Security Policy. Key measures include:

  • Encryption end to end across our platform. Data traveling between your browser, desktop or mobile apps, and our APIs is encrypted with HTTPS/TLS. Data at rest in our databases, backups, and object storage uses provider-managed encryption. Together, these layers protect your information from your device through our systems.
  • Token and session protection. API authentication uses short-lived JSON Web Tokens. Long-lived web session refresh uses rotating tokens delivered in HttpOnly, Secure, SameSite cookies inaccessible to client-side scripts. Sign-in and account-linking flows use one-time exchange codes and tickets so credentials never appear in URLs, logs, or referrer headers.
  • Access control. Every API request is authorized against the requesting account; administrative functions are restricted to a small set of authorized personnel under least-privilege principles.
  • Rate limiting. Authentication endpoints and APIs are rate-limited per client and per account to resist brute-force and abuse.
  • Secrets management. OAuth tokens and credentials are stored server-side with restricted access and are never shared between users.
  • Session revocation. Signing out invalidates the session's refresh credentials server-side.

No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we continuously review and improve these measures.

16. Incident Response and Breach Notification

We maintain an incident-response process covering detection, containment, investigation, remediation, and post-incident review (see our Security Policy). If a breach of security leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Personal Data, we will:

  1. notify affected users and, where applicable, business customers without undue delay after becoming aware, consistent with legal requirements (including the GDPR's 72-hour supervisory notification standard where it applies);
  2. describe the nature of the breach, the data affected, the likely consequences, and the measures taken;
  3. cooperate with regulators and provide reasonable assistance to affected customers.

Security researchers who identify vulnerabilities should follow our Vulnerability Disclosure Policy.

17. Regional Disclosures

17.1 European Economic Area, United Kingdom, and Switzerland

The GDPR/UK GDPR rights and legal bases in Sections 8 and 13 apply. Transfer safeguards are described in Section 11. Full detail: GDPR Compliance Statement.

17.2 California (United States)

California residents have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information under the CCPA/CPRA. We do not sell or share personal information as those terms are defined. Full detail: CCPA/CPRA Compliance Statement.

17.3 Brazil (LGPD)

If the Lei Geral de Proteção de Dados applies to you, you have rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing, exercisable via info@ababilx.cloud. Our legal bases parallel those in Section 8.

17.4 Singapore (PDPA)

We collect, use, and disclose Personal Data with consent or under recognized exceptions, for reasonable purposes we have notified. You may withdraw consent and request access or correction via info@ababilx.cloud.

17.5 India (DPDP Act)

Where the Digital Personal Data Protection Act, 2023 applies, we process personal data for the lawful purposes described here with your consent or for legitimate uses recognized by the Act, and you may exercise rights of access, correction, erasure, and grievance redressal via info@ababilx.cloud.

17.6 Bangladesh

AbabilX is operated from Bangladesh. We handle Personal Data consistent with applicable Bangladeshi law, including obligations relating to data security and lawful disclosure, and we apply the protections in this Policy to all users regardless of location.

18. Changes to This Policy

We may update this Policy to reflect changes in the Service, our practices, or legal requirements. Every change is versioned (Section 20). For material changes — those affecting your rights or how we handle your data — we will notify you through the Service or by email, update the version and dates above, and, where the change is significant, require your acceptance before continued use. Continued use after the effective date of non-material changes constitutes acceptance.

19. Contact

  • All inquiries (privacy, support, security, legal): info@ababilx.cloud

Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

We aim to acknowledge privacy inquiries within 7 days and resolve them within 30 days.

20. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication of the restructured Privacy Policy, replacing the May 28, 2026 policy page. Added AI data handling (Section 9), token/session security detail (Section 15), breach notification (Section 16), and regional disclosures (Section 17).

AbabilX Terms of Service

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Acceptance of These Terms

These Terms of Service (the "Terms") are a binding agreement between you and AbabilX ("AbabilX," "we," "us," "our") governing your access to and use of the AbabilX platform, websites, web application, desktop application, mobile applications, REST API, and any future clients such as a command-line interface or browser extension (collectively, the "Service").

By creating an Account, clicking to accept, or using the Service, you agree to these Terms, our Privacy Policy, our Acceptable Use Policy, and the other policies referenced in these Terms, each of which is incorporated by reference. If you do not agree, do not use the Service.

If you use the Service on behalf of an organization, you represent that you have authority to bind that organization, and "you" includes both you and the organization.

2. Definitions

Capitalized terms have the meanings given here or where first defined:

  • "Account" — your registered AbabilX account.
  • "Customer Content" — content you submit to the Service or authorize the Service to access on your behalf, as defined in the Privacy Policy, Section 2.
  • "Documentation" — the usage guides and reference materials we publish for the Service.
  • "Output" — content generated by the Service's AI features in response to Customer Content or prompts.
  • "Order" — a purchase of a paid plan, whether through the Service's checkout or a signed agreement.
  • "Plan" — a tier of the Service (currently Free or Premium) with the features and limits published at the time of purchase or use.
  • "Team" — an organization or collaboration space within the Service that groups multiple Accounts.

3. Eligibility

To use the Service you must:

  1. be at least 18 years old;
  2. have the legal capacity to enter a binding contract;
  3. not be barred from using the Service under the laws of any applicable jurisdiction, including export-control and sanctions laws (Section 18);
  4. not have been previously suspended or removed from the Service for cause.

4. Accounts

4.1 Registration

You register by authenticating through a supported identity provider (GitHub or Google). You must provide accurate information and keep it current. One person may not maintain multiple Accounts to evade Plan limits or enforcement actions.

4.2 Account Security

You are responsible for all activity under your Account. You must:

  • safeguard the devices and identity-provider accounts used to access AbabilX;
  • keep pairing codes (such as desktop login codes) confidential;
  • notify info@ababilx.cloud promptly of any unauthorized use or suspected compromise.

We are not liable for loss caused by unauthorized use of your Account arising from your failure to protect your credentials.

4.3 Teams

A Team owner controls Team membership, roles, settings, and content, and may remove members or delete the Team. Content you contribute to a Team is accessible to that Team according to its roles and settings, and may remain with the Team after you leave. If you join a Team, the Team owner's instructions govern Team content to the extent they conflict with your individual preferences.

5. Plans, Subscriptions, and Billing

5.1 Plans

The Service is offered on a Free plan and a paid Premium plan. Feature limits (for example, auto-commit duration, daily commit caps, digest frequency, AI usage allowances) are published in the Service and may differ by Plan. We may change Plan features prospectively; material reductions to a paid Plan take effect no earlier than your next renewal.

5.2 Billing and Renewal

Paid subscriptions are billed in advance for the selected billing cycle and renew automatically until cancelled. By purchasing, you authorize us and our payment providers to charge your payment method for the subscription fee and applicable taxes. Detailed billing terms, upgrade/downgrade mechanics, and refund rules are in our Billing & Refund Policy, which forms part of these Terms.

5.3 Taxes

Fees are exclusive of taxes unless stated otherwise. You are responsible for applicable taxes, duties, and levies, excluding taxes on our income.

5.4 Cancellation and Expiry

You may cancel at any time; cancellation stops future renewals and your Premium features remain active until the end of the paid period. When a Premium plan expires, scheduled features that exceed Free limits (standup rules, auto-commit jobs, digest schedules) are paused rather than deleted, and resume if you re-subscribe.

5.5 Trials and Promotions

If we offer a trial or promotional pricing, the specific terms presented at signup control. Unless stated otherwise, trials convert to paid subscriptions at the end of the trial period if a payment method is on file, and we will notify you before charging.

6. License and Access

Subject to these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Service and Documentation for your internal business or personal purposes during the term of your Account.

You may not, except as expressly permitted by these Terms or by law that cannot be excluded:

  1. copy, modify, translate, or create derivative works of the Service;
  2. reverse engineer, decompile, or disassemble the Service, or attempt to derive its source code, except to the extent such restriction is prohibited by applicable law;
  3. rent, lease, sell, sublicense, or otherwise commercially exploit access to the Service;
  4. remove or obscure proprietary notices;
  5. use the Service to build a competing product by systematically extracting its features or content;
  6. circumvent Plan limits, rate limits, or security controls.

7. Customer Content

7.1 Your Ownership

You retain all rights in your Customer Content. These Terms do not transfer ownership of your repositories, code, messages, posts, or configurations to us.

7.2 License to Us

You grant AbabilX a worldwide, non-exclusive, royalty-free license to host, store, reproduce, process, transmit, display, and modify Customer Content solely as necessary to (a) provide and secure the Service, (b) perform the operations you request (for example, generating a PR summary or posting a standup to Slack), and (c) comply with law. This license ends when the Customer Content is deleted from the Service, subject to the retention periods in the Privacy Policy, Section 12.

7.3 Your Responsibilities

You represent and warrant that you have all rights necessary to submit your Customer Content and to grant the license above, and that your Customer Content and your use of the Service do not violate law or third-party rights. You — not AbabilX — are responsible for the content of commits, messages, and posts made through the Service at your direction.

8. AI Features and Output

8.1 Nature of Output

Output is generated by machine-learning systems and may be inaccurate, incomplete, or unsuitable for your purpose. You must review Output before relying on it or distributing it. Output describing code (summaries, digests, standup drafts) is informational and is not a code review, security audit, or professional advice.

8.2 Ownership of Output

As between you and AbabilX, and to the extent permitted by law, you own the Output generated from your Customer Content. Because AI systems can produce similar output for similar inputs, we cannot guarantee Output is unique to you, and you receive no rights in output generated for other customers.

8.3 Your Use of Output

You are responsible for how you use Output, including verifying it before committing it to repositories, posting it to third-party platforms, or sharing it with others. Additional AI-specific terms, including prompt handling and provider restrictions, are in our AI Policy, which forms part of these Terms.

9. Third-Party Integrations

The Service interoperates with third-party platforms including GitHub, Google, and Slack. Your use of those platforms is governed by their own terms and policies, and you must comply with them when using AbabilX features that act on those platforms. We are not responsible for third-party platforms, their availability, or changes to their APIs that affect Service functionality. Actions the Service performs on a connected platform at your direction (commits, branch creation, message posting) are attributed to your authorization.

10. API and Developer Terms

If you access the Service programmatically through our REST API or future developer tools, the Developer & API Policy applies in addition to these Terms. In summary: keep credentials confidential, respect rate limits, do not misrepresent your application, and do not use the API to reconstruct or resell the Service.

11. Acceptable Use

You must comply with our Acceptable Use Policy ("AUP"), which is incorporated into these Terms and prohibits, among other things: unlawful content and activity, malware, phishing, spam, harassment, unauthorized access attempts, rate-limit and quota evasion, cryptocurrency abuse, and misuse of AI features. Violations may result in suspension or termination under Section 19.

Warning: Automation features (auto-commit, scheduled messages) act under your identity on external platforms. Using them to violate another platform's terms — for example, to fabricate activity in a way GitHub prohibits — is your responsibility and grounds for enforcement under the AUP.

12. Intellectual Property

12.1 Our Property

The Service, including its software, design, text, graphics, logos, and Documentation, is owned by AbabilX or its licensors and is protected by intellectual-property laws. Except for the license in Section 6, no rights are granted to you by implication or otherwise.

12.2 Trademarks

"AbabilX" and our logos are trademarks of AbabilX. You may not use them without prior written permission, except for truthful, nominative references to the Service.

12.3 Open Source

The Service incorporates open-source components licensed under their own terms. Nothing in these Terms limits your rights under, or grants you rights that supersede, the applicable open-source licenses. Attribution notices are available in the Service or Documentation where required.

13. Feedback

If you send us suggestions, ideas, or other feedback about the Service, you grant us a perpetual, irrevocable, worldwide, royalty-free license to use it for any purpose without obligation or compensation to you. Do not send feedback you consider confidential.

14. Beta and Experimental Features

We may offer features identified as beta, preview, experimental, or "coming soon." Such features: (a) may change or be withdrawn at any time without notice; (b) may be subject to additional terms or usage caps; (c) are provided as-is without the service commitments applicable to generally available features; and (d) should not be relied upon for production-critical workflows. Feedback on beta features is governed by Section 13.

15. Service Availability and Modifications

15.1 Availability

We work to keep the Service available and performant, but the Service is provided without an uptime guarantee. Access may be interrupted by maintenance, updates, infrastructure failures, third-party platform outages, or events beyond our control.

15.2 Maintenance

We may perform scheduled or emergency maintenance. Where practicable, we announce scheduled maintenance in advance through the Service.

15.3 Modifications

We may modify the Service, including adding, changing, or removing features. If a change materially reduces core functionality of a paid Plan, we will notify affected subscribers, who may cancel and receive a pro-rated refund of prepaid, unused fees for the affected period as their exclusive remedy.

16. Privacy and Security

Our collection and use of Personal Data is described in the Privacy Policy. Our security practices are described in the Security Policy. Business customers requiring contractual data-processing terms may execute our Data Processing Addendum.

We respond to notices of alleged copyright infringement under our Copyright & DMCA Policy. Repeat infringers' Accounts will be terminated in appropriate circumstances.

18. Export Control and Sanctions

You may not use the Service in violation of export-control or sanctions laws applicable to you or to us, including regulations administered by the U.S. Office of Foreign Assets Control and equivalent authorities. You represent that you are not located in, organized under the laws of, or ordinarily resident in a comprehensively sanctioned jurisdiction, and that you are not a sanctioned or restricted party or acting on behalf of one.

19. Suspension and Termination

19.1 By You

You may stop using the Service and delete your Account at any time (see Privacy Policy, Section 14). Fees already paid are handled per the Billing & Refund Policy.

19.2 By Us

We may suspend or terminate your access, with or without notice, if:

  1. you materially breach these Terms or the AUP;
  2. your use creates security, legal, or operational risk to the Service or others;
  3. payment for a paid Plan fails and is not cured;
  4. we are required to do so by law;
  5. we discontinue the Service (in which case we will give reasonable advance notice and a refund of prepaid, unused fees).

Where the cause is curable and does not pose immediate risk, we will make reasonable efforts to notify you and give you an opportunity to cure before termination.

19.3 Effect of Termination

Upon termination: your license ends; scheduled jobs stop; and your data is handled per the retention and deletion terms of the Privacy Policy. Sections that by their nature should survive — including 7.2 (for stored data during wind-down), 12, 13, 20, 21, 22, 23, and 24 — survive termination.

20. Warranty Disclaimer

THE SERVICE, DOCUMENTATION, AND OUTPUT ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, ABABILX AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT DEFECTS WILL BE CORRECTED, OR THAT OUTPUT WILL BE ACCURATE OR RELIABLE.

SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES; TO THAT EXTENT, THE ABOVE EXCLUSIONS APPLY TO THE MAXIMUM EXTENT PERMITTED AND YOUR STATUTORY RIGHTS ARE UNAFFECTED.

21. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

  1. NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR DATA, EVEN IF ADVISED OF THE POSSIBILITY;
  2. ABABILX'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS IS LIMITED TO THE GREATER OF (A) THE AMOUNTS YOU PAID US FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY, OR (B) FIFTY U.S. DOLLARS (USD $50).

THESE LIMITATIONS DO NOT APPLY TO: (i) LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW; (ii) A PARTY'S FRAUD OR WILLFUL MISCONDUCT; OR (iii) YOUR PAYMENT OBLIGATIONS. THE LIMITATIONS IN THIS SECTION APPLY REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

22. Indemnification

You will defend, indemnify, and hold harmless AbabilX and its officers, directors, employees, and agents from and against claims, damages, liabilities, costs, and expenses (including reasonable legal fees) arising from: (a) your Customer Content; (b) your use of the Service in violation of these Terms, the AUP, or applicable law; (c) actions the Service performs on third-party platforms at your direction; or (d) your violation of third-party rights. We will promptly notify you of any such claim and may participate in its defense with counsel of our choosing at our expense. You may not settle a claim in a way that imposes obligations on us without our written consent.

23. Governing Law and Dispute Resolution

23.1 Governing Law

These Terms are governed by the laws of Bangladesh, without regard to conflict-of-laws rules. If you are a consumer in a jurisdiction whose mandatory consumer-protection laws grant you additional rights, those rights are unaffected.

23.2 Informal Resolution First

Before starting formal proceedings, you agree to contact info@ababilx.cloud describing the dispute; both parties will attempt in good faith to resolve it within 30 days.

23.3 Arbitration

Any dispute not resolved informally shall be finally settled by binding arbitration seated in Dhaka, Bangladesh, under the Arbitration Act, 2001 (Bangladesh), by a sole arbitrator, conducted in English. Judgment on the award may be entered in any court of competent jurisdiction. Either party may instead seek: (a) relief in small-claims court for qualifying disputes; or (b) injunctive relief in any competent court for infringement or misuse of intellectual property or confidential information.

23.4 No Class Actions

To the extent permitted by law, disputes must be brought on an individual basis; class, collective, and representative proceedings are waived. If this waiver is found unenforceable for a particular claim, that claim shall proceed in court, not arbitration.

24. General Provisions

  1. Entire Agreement. These Terms, together with the policies incorporated by reference and any Order, are the entire agreement between you and AbabilX regarding the Service and supersede all prior agreements on that subject.
  2. Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary, and the remainder stays in effect.
  3. No Waiver. Failure to enforce a provision is not a waiver of the right to enforce it later.
  4. Assignment. You may not assign these Terms without our prior written consent. We may assign them in connection with a merger, acquisition, or sale of assets, with notice to you.
  5. Force Majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disasters, war, terrorism, labor disputes, governmental action, internet or utility failures, and third-party platform outages. Payment obligations are excluded.
  6. Notices. We may notify you through the Service or at your account email. Legal notices to us go to info@ababilx.cloud and by post to AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.
  7. Independent Contractors. The parties are independent contractors; these Terms create no partnership, joint venture, or agency.
  8. Headings and Interpretation. Headings are for convenience. "Including" means "including without limitation."
  9. Changes to These Terms. We may update these Terms. Material changes will be notified through the Service or by email at least 14 days before taking effect; continued use after the effective date constitutes acceptance. If you do not agree, stop using the Service before the effective date and, for paid Plans, request a pro-rated refund of prepaid, unused fees for the remaining period.
  10. Survival. Provisions identified in Section 19.3 survive termination or expiration.

25. Contact

  • Legal notices and disputes: info@ababilx.cloud
  • General support: info@ababilx.cloud
  • Billing: info@ababilx.cloud

Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

26. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Acceptable Use Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose and Scope

This Acceptable Use Policy ("AUP") defines conduct that is prohibited on the AbabilX Service. It applies to every user, Account, Team, and client (web, desktop, mobile, API, and any future CLI or browser extension), and to all content transmitted through or stored on the Service. It forms part of our Terms of Service.

2. Definitions

Terms defined in the Terms of Service and Privacy Policy have the same meanings here. "Content" includes Customer Content, Output you distribute, and anything you cause the Service to post on a third-party platform.

3. General Standard

Use the Service lawfully, honestly, and without harming the Service, other users, third-party platforms, or third parties. Where a specific behavior is not listed below but is of the same character as a listed prohibition, it is equally prohibited. If you are unsure whether a use is acceptable, ask info@ababilx.cloud before proceeding.

4. Prohibited Conduct

4.1 Illegal Activity

You may not use the Service to:

  1. violate any applicable law or regulation;
  2. store, transmit, or distribute content that is illegal in your jurisdiction or ours;
  3. facilitate, promote, or provide instructions for criminal activity;
  4. launder money or move proceeds of crime;
  5. evade sanctions or export-control restrictions (see Terms of Service, Section 18);
  6. infringe another party's copyright, trademark, patent, trade secret, or other rights;
  7. violate another person's privacy or data-protection rights, including collecting Personal Data without a lawful basis;
  8. distribute child sexual abuse material or any content sexualizing minors (reported to authorities without exception);
  9. traffic in stolen data, credentials, or financial instruments;
  10. sell or promote illegal goods or services.

4.2 Security Violations

You may not:

  1. access or attempt to access another user's Account, data, tokens, or sessions;
  2. probe, scan, or test the vulnerability of the Service outside the Vulnerability Disclosure Policy;
  3. breach or circumvent authentication, authorization, or policy-gate controls;
  4. forge, replay, tamper with, or fabricate tokens, exchange codes, connect tickets, cookies, or webhook signatures;
  5. brute-force pairing codes, exchange codes, webhook tokens, or any credential;
  6. intercept or monitor traffic between other users and the Service;
  7. introduce malware, ransomware, spyware, keyloggers, cryptominers, logic bombs, or any malicious code;
  8. use the Service to develop, host, distribute, or command-and-control malware;
  9. conduct denial-of-service or resource-exhaustion attacks against the Service or any third party;
  10. exploit a vulnerability for any purpose other than good-faith reporting under our disclosure policy;
  11. steal, harvest, or attempt to extract credentials, API keys, or OAuth tokens of any party;
  12. exfiltrate data through AI features, crafted prompts, or injection techniques;
  13. attempt to extract system prompts, model configurations, or other users' AI context;
  14. disable, overload, or impair any part of the Service's infrastructure.

4.3 Abuse of Platform Mechanics

You may not:

  1. circumvent, or attempt to circumvent, rate limits, quotas, or plan limits;
  2. create multiple Accounts to evade limits, bans, billing, or enforcement;
  3. share one Account among multiple people to evade per-user limits;
  4. automate account creation;
  5. resell, sublicense, or provide third parties access to the Service without authorization;
  6. use the free plan programmatically at scale to substitute for a paid plan;
  7. manipulate AI usage accounting or abuse retry mechanisms to exceed allowances;
  8. scrape the Service, or bulk-download content you do not own, outside documented API access;
  9. use the API in violation of the Developer & API Policy;
  10. cache or store other users' data beyond what a permitted integration requires;
  11. interfere with the Service's operation, updates, or security mechanisms;
  12. remove, obscure, or falsify attribution or provenance information the Service attaches to content;
  13. abuse webhook endpoints with junk, oversized, or malicious payloads;
  14. register misleading webhook integrations to capture data not intended for you.

4.4 Misuse of Third-Party Integrations

You may not use AbabilX's automation to violate a connected platform's terms or harm its users, including:

  1. using auto-commit or scheduled automation to fabricate development activity in a deceptive manner (for example, to defraud an employer, client, or metric-based program);
  2. committing to repositories you lack rights to modify;
  3. posting to Slack channels or workspaces without authorization;
  4. sending messages through the Service that violate Slack's or GitHub's policies;
  5. using the Service to evade a suspension or ban imposed by GitHub, Google, or Slack;
  6. exceeding or laundering third-party API quotas through our infrastructure;
  7. connecting accounts you do not own or lack authority to connect;
  8. using integration tokens obtained through AbabilX outside the Service.

4.5 Spam and Deceptive Practices

You may not:

  1. send spam, bulk unsolicited messages, or chain content through any Service feature (chat, wall, standups, digests, webhooks);
  2. use scheduled messages to flood channels or recipients;
  3. engage in phishing, or create content that impersonates login pages, security notices, or other trusted communications;
  4. impersonate any person, organization, or AbabilX itself;
  5. misrepresent your affiliation or the origin of content;
  6. distribute deceptive AI-generated content presented as human-authored where that presentation is materially misleading;
  7. manipulate reactions, activity graphs, attendance records, or analytics to deceive a team or third party;
  8. operate pyramid schemes, advance-fee fraud, fake giveaways, or other fraudulent schemes;
  9. engage in payment fraud, including using stolen payment instruments or initiating illegitimate chargebacks;
  10. abuse trials, promotions, or referral mechanics through fabricated identities.

4.6 Cryptocurrency and Resource Abuse

You may not:

  1. mine cryptocurrency using Service infrastructure;
  2. use automation features to farm airdrops, testnet rewards, or activity-based token distributions deceptively;
  3. operate wallet-draining, rug-pull, or other crypto-fraud schemes through the Service;
  4. use the Service as infrastructure for unregistered securities offerings or scam token promotion.

4.7 Harassment and Harmful Content

You may not post, store, or transmit content that:

  1. harasses, bullies, threatens, or intimidates any person;
  2. incites or glorifies violence against people or groups;
  3. is hate speech — attacking people based on race, ethnicity, national origin, religion, caste, sexual orientation, gender identity, disability, or serious disease;
  4. sexualizes anyone without consent, or constitutes non-consensual intimate imagery;
  5. doxxes — publishing another's private information (home address, government ID, private contact details) without consent;
  6. stalks or enables stalking or surveillance of another person;
  7. encourages self-harm or suicide;
  8. constitutes terrorist or violent-extremist content or recruitment;
  9. defames another person with reckless or knowing falsehood;
  10. exploits or endangers minors in any way.

Team-space behavioral norms are further described in our Community Guidelines.

4.8 Misuse of AI Features

You may not use AI Features to:

  1. generate content prohibited elsewhere in this AUP;
  2. produce deliberately false summaries or reports intended to deceive a team, employer, or client;
  3. attempt prompt injection against the Service or other users;
  4. probe, jailbreak, or manipulate models to bypass safety controls;
  5. generate malware, exploits, or attack tooling for unauthorized use;
  6. mass-produce misleading or spam content;
  7. represent Output as an audit, certification, or professional opinion;
  8. process content you have no right to process (see AI Policy, Section 14).

4.9 Reverse Engineering and Competitive Misuse

You may not:

  1. reverse engineer, decompile, or disassemble the Service except where law grants an unwaivable right;
  2. bypass technical protections on the desktop, mobile, or web clients;
  3. systematically extract Service features, prompts, or data to build or train a competing product;
  4. benchmark and publish results in a misleading manner that misrepresents the Service;
  5. access the Service to monitor its availability or functions on behalf of a competitor without our consent.

4.10 Infrastructure and Network Abuse

You may not:

  1. use the Service as an open proxy, relay, or anonymization layer for attacks;
  2. spoof network identifiers or headers to disguise abusive traffic;
  3. distribute or coordinate botnets;
  4. conduct port scanning or network reconnaissance of our systems or third parties from the Service;
  5. abuse presigned upload URLs to host unrelated files, pirated content, or malware;
  6. use storage features as a general-purpose CDN or file-sharing service for content unrelated to the Service's purpose;
  7. embed the Service in a frame or wrapper that misleads users about what they are interacting with.

4.11 Data Misuse

You may not:

  1. collect or harvest other users' Personal Data from the Service;
  2. use team features to surveil members beyond the feature's disclosed purpose;
  3. re-identify or attempt to re-identify de-identified data;
  4. retain data from a Team after your authorized access ends, beyond copies you lawfully own;
  5. sell or broker data obtained through the Service;
  6. use attendance, activity, or analytics data to violate employment or privacy law.

You may not:

  1. submit false DMCA notices or counter-notices (see Copyright & DMCA Policy);
  2. submit fraudulent privacy or data-subject requests targeting another person's data;
  3. abuse support channels through threats, deception, or vexatious volume;
  4. misrepresent your identity or authority in any legal, billing, or verification process;
  5. evade payment through technical manipulation of plan enforcement;
  6. file chargebacks for services legitimately received, in lieu of the refund process in the Billing & Refund Policy.

5. Examples

Example — automation misuse (prohibited, items 39, 53): configuring auto-commit to generate daily filler commits on an employer-monitored repository so contribution graphs misrepresent work performed.

Example — permitted automation: using auto-commit on your own experimental repository to keep a scheduled changelog file updated, with no one being deceived.

Example — rate-limit evasion (prohibited, items 25–26): after receiving HTTP 429 responses, rotating through several accounts or IP addresses to continue hammering the sign-in endpoint.

Example — permitted retry: honoring Retry-After and backing off exponentially.

Example — AI misuse (prohibited, item 72): editing a standup rule so the AI reports completed work on tickets no one touched, to mislead a client.

Example — permitted use: letting the AI draft your standup from real commit activity, then reviewing and correcting it before it posts.

Example — security research: testing whether our WebSocket handshake leaks tokens is in scope for good-faith research under the Vulnerability Disclosure Policy; testing it by hijacking another user's live session is not (item 11).

6. Reporting Violations

Report suspected violations to info@ababilx.cloud (or info@ababilx.cloud for security matters) with the relevant account, content, or URL and a description. We review reports promptly and keep reporter identities confidential except where disclosure is legally required.

7. Enforcement

We may, at our discretion and proportionate to the violation:

  1. remove or disable content;
  2. pause or delete offending automations (rules, jobs, webhooks);
  3. throttle, suspend, or restrict features of an Account or Team;
  4. suspend or terminate Accounts (see Terms of Service, Section 19);
  5. revoke API or integration access;
  6. notify affected third-party platforms;
  7. report to law enforcement where we believe conduct is criminal, and preserve related records.

For minor, curable violations we will ordinarily warn first. Violations involving illegality, security attacks, minors, or imminent harm result in immediate action without notice.

8. Appeals

If you believe an enforcement action was mistaken, reply to the enforcement notice or write to info@ababilx.cloud within 30 days with the facts you believe we got wrong. A person not involved in the original decision will review the appeal and respond.

9. Changes to This Policy

We may revise this AUP as new abuse patterns emerge, recording changes in Section 11. The version in force at the time of the conduct governs enforcement.

10. Contact

Abuse reports: info@ababilx.cloud · Security: info@ababilx.cloud · Legal: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

11. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Security Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose and Scope

This Security Policy describes the technical and organizational measures AbabilX uses to protect the Service and the data entrusted to it. It covers our web, desktop, mobile, and API surfaces and the infrastructure behind them. It is a statement of practice, not a contract; contractual security commitments for business customers are made in the Data Processing Addendum.

Our commitment: We treat user security and privacy as foundational requirements, not optional features. Every layer of the Service — authentication, transport, storage, access control, and monitoring — is designed to keep your data confidential, intact, and available only to you and those you authorize.

2. Definitions

  • "Access token" — a short-lived JSON Web Token (JWT) authorizing API requests.
  • "Refresh token" — a longer-lived, rotating credential used to obtain new access tokens.
  • "Least privilege" — granting each system and person only the access required for their function.
  • "Subprocessor" — see the Subprocessor List.

3. Security Governance

  • Security requirements are owned by the engineering leadership and reviewed as the platform evolves.
  • Our practices are aligned with recognized frameworks — including the spirit of SOC 2's trust principles (security, availability, confidentiality) and OWASP application-security guidance. We do not currently hold a third-party certification and do not claim one.
  • Personnel access to production systems is limited to a small set of authorized individuals under least privilege (Section 7).
  • Subprocessors are assessed for their security posture before engagement and bound by data-protection terms.

4. Infrastructure Security

  • The Service runs on hardened server infrastructure with network-level access restrictions; administrative access requires authenticated, encrypted channels.
  • Production data stores (PostgreSQL for durable data, Redis for caching and ephemeral state) are not exposed to the public internet.
  • File and media storage uses dedicated object storage with scoped, time-limited upload credentials (presigned URLs), so clients never hold storage-account keys.
  • Environments are separated: development and testing do not use production credentials.

5. Encryption

We protect data across its full path through AbabilX — from your device to our servers and while stored on our systems:

  • In transit (end-to-end connections): all client–server and server–server traffic uses HTTPS/TLS (TLS 1.2+). WebSocket connections upgrade over TLS. We do not operate unencrypted production endpoints. Your session tokens and API requests never travel over plain HTTP.
  • At rest: production databases and backups reside on encrypted storage volumes; object storage applies provider-managed at-rest encryption (AES-256 class).
  • Credential hashing and signing: session integrity relies on signed JWTs (HMAC-SHA-256); one-time codes and tickets are generated with a cryptographically secure random source and are single-use with short expiry.

6. Authentication and Session Security

The Service's authentication design keeps credentials out of URLs, logs, and client-side script reach:

  1. OAuth sign-in. Users authenticate via GitHub or Google OAuth; AbabilX never sees or stores user passwords.
  2. One-time exchange codes. OAuth callbacks deliver a single-use, short-lived code that the client exchanges server-side for tokens, so tokens never transit the browser URL, history, or referrer headers.
  3. Short-lived access tokens. API requests carry a JWT with a one-hour lifetime, limiting the exposure window of any leaked token.
  4. Rotating HttpOnly refresh cookies. Web session refresh uses a rotating refresh token stored in an HttpOnly; Secure; SameSite cookie, path-restricted to the authentication endpoints and unreadable by JavaScript — neutralizing token theft via cross-site scripting.
  5. Connect tickets. Account-linking flows (Slack, GitHub) use single-use tickets minted from an authenticated session instead of passing bearer tokens in redirect URLs.
  6. WebSocket authentication. Real-time notification sockets authenticate through the connection handshake rather than URL query parameters.
  7. Revocation. Signing out retires the refresh token server-side and clears its cookie; refresh tokens are rotated on every use, so a replayed old token fails.
  8. Device pairing. Desktop sign-in uses short pairing codes with server-side brute-force rate limiting (Section 10); codes can be regenerated by the user at any time.

7. Authorization and Access Control

  • Every API request is authenticated and then authorized against the requesting account: users can access only their own resources and the team resources their role permits.
  • Team features enforce role-based permissions (owner, manager, member) evaluated server-side on each request — never trusted from the client.
  • Administrative endpoints are gated behind a separate super-administrator check in middleware; administrative capability is limited to designated personnel.
  • Privacy-affecting platform gates (for example, policy acceptance) are enforced in server middleware, not only in the interface.

8. Secrets and Token Management

  • Third-party OAuth tokens (GitHub, Slack, Google) are stored server-side, are never returned to other users, and are excluded from API responses and serialization by default (deny-by-default field marshaling).
  • Application secrets (signing keys, provider credentials) are supplied through environment configuration, not source code, and access to them is restricted.
  • Webhook endpoints authenticate callers: GitHub App webhooks are signature-verified; internal server-to-server sinks require a shared internal secret; inbound board webhooks embed per-hook random tokens that can be regenerated or revoked.

9. Application Security

  • Input handling: database access uses parameterized queries throughout, preventing SQL injection; request bodies are schema-validated before use.
  • Cross-origin controls: the API enforces a strict CORS allow-list — production trusts only the configured frontend origin; permissive localhost origins are impossible in release mode.
  • Output encoding: the web client uses a framework rendering model (React) that escapes content by default.
  • Cross-site request protection: state-changing browser flows rely on SameSite cookie scoping plus bearer-token authorization, so cross-site form posts cannot authenticate.
  • Dependency hygiene: dependencies are version-pinned and updated on a regular cadence; builds fail on compilation and vet errors.
  • AI-specific controls: see the AI Policy, Sections 10–11 (authorization-scoped context, prompt-injection mitigations, kill switch).

10. Rate Limiting and Abuse Resistance

Layered throttles protect the platform:

  • a global per-IP limit on all API traffic;
  • a tight shared limiter on credential endpoints (sign-in, token refresh, code exchange, device pairing) so brute-force attempts cannot be spread across routes;
  • per-user limits on high-frequency endpoints;
  • plan-based usage allowances on resource-intensive features (AI, automation jobs).

Rejected requests receive HTTP 429 with retry guidance. Deliberate evasion of these limits violates the Acceptable Use Policy.

11. Logging and Monitoring

  • API, authentication, and administrative events are logged with account identifiers, timestamps, and outcomes; security-relevant events (failed logins, token refresh anomalies, rate-limit rejections) are reviewable for investigation.
  • Logs exclude credential material: tokens are not written to logs, and the URL-free credential design in Section 6 keeps them out of standard access logs.
  • Log access is restricted to authorized personnel; retention follows the Privacy Policy, Section 12.
  • Crash and performance telemetry is monitored to detect service degradation.

12. Backups, Disaster Recovery, and Business Continuity

  • Production databases are backed up on a regular schedule to encrypted storage, with backups retained on a rolling window.
  • Restores are tested as part of operational practice; recovery procedures are documented so the platform can be rebuilt from configuration plus backups.
  • Scheduled workloads (standups, digests, auto-commit jobs) are idempotently designed so missed windows during an outage do not duplicate actions once service resumes.
  • Dependence on any single third party is documented in the Subprocessor List; provider outages degrade specific features rather than the whole platform where feasible.

13. Vulnerability Management and Testing

  • Code changes are reviewed before release; security-sensitive areas (authentication, authorization, payment, webhooks) receive heightened scrutiny.
  • We perform internal security reviews of the platform's attack surface and remediate findings by severity: critical issues are addressed immediately, high within days, others on a prioritized schedule.
  • Dependency vulnerabilities are tracked against advisories and patched.
  • We engage in penetration-testing exercises as the platform matures, and we treat external researcher reports (Section 15) as a first-class input to this process.

14. Incident Response

Our incident-response process covers:

  1. Detection and triage — anomaly identification from monitoring, logs, user reports, or researcher disclosure; severity classification.
  2. Containment — revoking affected credentials (all refresh tokens for an account or globally, provider tokens, webhook secrets), disabling affected features (including the AI kill switch), and isolating affected systems.
  3. Eradication and recovery — root-cause remediation, patched deployment, restoration from backups where needed.
  4. Notification — informing affected users and customers without undue delay, consistent with the breach-notification commitments in the Privacy Policy, Section 16, and applicable law.
  5. Post-incident review — documented lessons and corrective actions.

15. Responsible Disclosure

We welcome good-faith security research. If you believe you have found a vulnerability, report it to info@ababilx.cloud following our Vulnerability Disclosure Policy, which defines scope, safe-harbor commitments, and reporting expectations. Do not access other users' data, disrupt the Service, or publicly disclose an issue before we have had a reasonable opportunity to remediate.

16. Shared Responsibility

Security is shared. You are responsible for:

  • protecting the GitHub/Google/Slack accounts you use to sign in (enable multi-factor authentication on them — the strength of your identity-provider account is the strength of your AbabilX sign-in);
  • keeping desktop pairing codes and webhook URLs confidential, and regenerating them if exposed;
  • scoping the OAuth permissions you grant to what you actually use;
  • controlling membership and roles in Teams you own;
  • keeping your devices and browsers patched.

17. Changes to This Policy

We update this Policy as our practices evolve, recording changes in Section 19. We will not weaken a stated commitment without prominent notice.

18. Contact

Security reports: info@ababilx.cloud · General: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

19. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication. Documents the 2026 authentication hardening: one-time exchange codes, rotating HttpOnly refresh cookies, connect tickets, handshake-authenticated WebSockets, and layered rate limiting.

AbabilX AI Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose and Scope

This AI Policy explains how AbabilX's AI-powered features work, what data they process, which third parties are involved, and the limits you should understand before relying on machine-generated content. It applies to every AI feature of the Service across all clients and forms part of our Terms of Service. Data-protection terms in our Privacy Policy apply to all processing described here.

2. Definitions

  • "AI Feature" — any Service capability that produces content using a machine-learning model, listed in Section 3.
  • "Prompt" — the input transmitted to an AI model, whether typed by you (assistant chat) or assembled by the Service from your Customer Content (for example, commit metadata for a summary).
  • "Output" — the content the model returns, as presented to you by the Service.
  • "AI Provider" — a third party whose models we call to generate Output (see Section 6).

3. AI Features in the Service

  • PR Summaries:** Summarizes a pull request's changes, discussion, and status.
  • AI Standups:** Drafts standup messages from recent commit and PR activity for your configured rules.
  • Commit Summaries:** Condenses commit activity into readable summaries.
  • Weekly Digest:** Produces periodic digests of individual or team repository activity.
  • Task Description Generation:** Drafts kanban task descriptions on request.
  • Ababil AI Assistant:** Conversational assistant that answers questions using your account and team context.

New AI Features will be governed by this Policy from launch; if a feature materially departs from these terms, we will say so where the feature is offered.

4. What Data Is Sent to AI Systems

For each request, the Service assembles the minimum context the feature needs, typically drawn from:

  • commit metadata (messages, authors, timestamps) and diffs where the feature summarizes code changes;
  • pull-request titles, descriptions, review comments, and file lists;
  • repository and branch names;
  • your configured preferences relevant to the Output (language, format);
  • for the assistant: your message and the account/team context needed to answer it.

Personal identifiers (names, emails) appear in Prompts only insofar as they already appear in the underlying content — for example, a commit author name inside commit metadata.

5. What Data Is Never Sent

We do not transmit to AI Providers:

  • OAuth tokens, refresh tokens, API keys, or any authentication credentials;
  • passwords or pairing codes;
  • billing or payment information;
  • your notification device tokens;
  • data from accounts or teams other than those the requesting user is authorized to access.

6. Third-Party AI Providers

Output is currently generated by DeepSeek, called via API as a Subprocessor (see our Subprocessor List). Our provider agreements require that Prompts and Output:

  1. are used only to provide the API response to us;
  2. are not used to train or improve the provider's models;
  3. are retained only transiently, subject to the provider's short-term abuse-monitoring window;
  4. are protected with security measures consistent with our Security Policy.

If we add or replace an AI Provider, we update the Subprocessor List before the change takes effect and, for business customers under our Data Processing Addendum, provide the notice and objection rights described there.

7. Storage and Retention of Prompts and Output

  • Transient processing. Prompts exist at the AI Provider only for the duration needed to generate the response, plus any short abuse-monitoring window the provider operates.
  • Stored Output. Output the Service saves for you — generated digests, PR summaries attached to history, assistant conversation history — is stored in your Account and retained under the Privacy Policy, Section 12. You can delete stored items, and account deletion removes them.
  • Logs. Our API logs record that an AI request occurred (route, status, account, latency); they do not duplicate full Prompt content beyond what diagnostics require.

8. No Model Training on Your Content

We do not use your Customer Content, Prompts, or Output to train machine-learning models. We will not begin doing so without explicit prior notice to you and, where required by law, your consent. Aggregated, de-identified telemetry (for example, feature usage counts and error rates) may be used to improve the Service, but never in a form that reproduces your content.

9. Accuracy, Hallucinations, and Human Review

Warning: AI Output can be wrong — confidently wrong.

  1. Hallucination. Models may generate statements that are plausible but false: misdescribing a code change, inventing a rationale, or mislabeling activity. Output summarizing your repositories is a convenience, not a source of truth; the repository itself is.
  2. Human review required. You must review Output before committing it, posting it (for example, to a Slack channel your team reads), or making decisions based on it. Standup and digest automations post on schedules you configure — configure them only where machine-drafted content is acceptable, and use the override/edit controls the Service provides.
  3. Not professional advice. Output is not legal, security, financial, or engineering advice, and it is not a code review or audit.
  4. No warranty. Warranty disclaimers and liability limits for Output are in the Terms of Service, Sections 20–21.

10. Safety Systems and Abuse Detection

We operate controls around AI Features, including:

  • authorization checks — every AI request is validated against your account and team permissions before context is assembled;
  • usage accounting — per-account usage windows and plan-based allowances (Section 12);
  • rate limiting — request throttles that resist automated abuse;
  • kill switch — AI Features can be disabled platform-wide if a safety, security, or provider issue arises;
  • abuse review — we may review usage patterns (and, where necessary to investigate a specific violation, the associated content) when we have reason to believe the Acceptable Use Policy is being violated.

11. Prompt Injection and Security

Content processed by AI Features may include text written by others (commit messages, PR comments, task descriptions). Such text can contain prompt-injection attempts — instructions embedded in content intended to manipulate the model.

Our mitigations include separating system instructions from user content, constraining what actions the assistant can take (state-changing actions require your explicit confirmation in the interface), and scoping every request to your existing permissions: the model cannot read or act on anything your account could not already access. No mitigation is perfect; treat Output derived from untrusted content with corresponding skepticism, and report suspected injection issues to info@ababilx.cloud under our Vulnerability Disclosure Policy.

12. Usage Limits and Fair Use

AI Features are subject to plan-based allowances and rolling usage windows shown in the Service. Attempting to evade limits — through multiple accounts, automated retry storms, or manipulation of usage accounting — violates the Acceptable Use Policy. Limits may change prospectively; material reductions for paid plans follow the notice rules in the Terms of Service, Section 5.1.

13. Responsible AI Commitments

  1. Transparency. AI-generated content is presented in contexts that make its machine origin clear.
  2. Minimization. We send the least content necessary per request (Section 4).
  3. Provider accountability. AI Providers are bound by contract to the restrictions in Section 6.
  4. User control. You choose which AI Features run, on which repositories and channels, and on what schedule; automations can be paused or deleted at any time.
  5. Continuous review. We monitor feature behavior and provider practices, and will suspend a feature that we determine causes harm we cannot mitigate.

14. Your Responsibilities

You agree to:

  • review Output before relying on or distributing it (Section 9);
  • not use AI Features to generate unlawful, infringing, or deceptive content, or content that violates the Acceptable Use Policy;
  • not attempt to extract other users' data, system prompts, or provider credentials through crafted inputs;
  • ensure that content you route into AI Features (for example, a repository you connect) is content you are authorized to process.

15. Changes to This Policy

We will update this Policy as AI Features and providers evolve, recording changes in Section 17. Changes that reduce your protections — for example, any change to Section 8 — are material and will be notified prominently in advance.

16. Contact

AI questions: info@ababilx.cloud · Privacy: info@ababilx.cloud · Security: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

17. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Billing & Refund Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Scope

This Billing & Refund Policy governs payments for the AbabilX Service and forms part of our Terms of Service. Terms defined there apply here.

2. Definitions

  • "Billing Cycle" — the recurring period you select at purchase (for example, monthly or annual).
  • "Fees" — the subscription charges for a paid Plan, exclusive of taxes.
  • "Renewal Date" — the first day of each new Billing Cycle.

3. Plans and Pricing

The Service offers a Free plan and a paid Premium plan. Current prices, features, and limits are displayed in the Service at the point of purchase; the price shown at checkout is the price you pay for that Billing Cycle. Feature limits (auto-commit duration and daily caps, digest and rule allowances, AI usage windows) are enforced automatically per Plan.

4. Billing and Renewal

  1. Paid subscriptions are billed in advance for each Billing Cycle.
  2. Subscriptions renew automatically on the Renewal Date at the then-current price for your Plan (subject to Section 13), until cancelled.
  3. By subscribing you authorize us and our payment providers to charge your payment method for Fees and applicable taxes each cycle.
  4. The Billing Cycle runs from activation; time is not paused for periods you choose not to use the Service.

5. Payment Methods and Providers

Payments are processed by third-party payment providers. We do not store full card numbers or bank credentials; the provider transmits to us only confirmation of payment status and the records needed to manage your subscription (see Privacy Policy, Section 6.1.5). You must have authority to use the payment method you provide, and you must keep it current.

6. Taxes

Fees exclude taxes unless expressly stated. You are responsible for value-added, sales, goods-and-services, withholding, and similar taxes applicable to your purchase, excluding taxes on AbabilX's income. Where we are required to collect tax, it is added at checkout.

7. Upgrades and Downgrades

  • Upgrade (Free → Premium): takes effect immediately upon successful payment; the Billing Cycle starts that day.
  • Renewal-length change or downgrade: takes effect at the next Renewal Date. Your current cycle's features continue until then.
  • Downgrade effects: configurations exceeding Free-plan limits are paused, not deleted (Section 9).

8. Cancellation

You may cancel at any time in the Service or by writing to info@ababilx.cloud from your account email. Cancellation:

  1. stops future renewals — you are not charged again;
  2. does not shorten the current cycle: Premium features remain active until the end of the period already paid;
  3. does not by itself delete your Account or data (see Privacy Policy, Section 14 for deletion).

9. Plan Expiry Behavior

When Premium ends (by cancellation lapse or non-payment):

  • standup rules, auto-commit jobs, and digest schedules that exceed Free limits are paused, and their configurations retained;
  • the Service notifies you in-app (and by email if enabled);
  • re-subscribing reactivates paused configurations;
  • content you created is unaffected.

10. Refunds

10.1 General Rule

Except as stated in this Section or required by law, Fees are non-refundable, and unused time in a Billing Cycle is not refunded on cancellation.

10.2 When We Do Refund

We will refund, pro-rated where applicable:

  1. Billing errors — duplicate charges, charges after a completed cancellation, or charges in the wrong amount: full correction.
  2. Extended service failure — if a platform-wide outage attributable to us makes the paid Service substantially unusable for more than 72 consecutive hours in a cycle, a pro-rated refund or service credit for the affected period, on request.
  3. Material feature reduction — as provided in the Terms of Service, Section 15.3.
  4. Service discontinuation or termination without cause by us — refund of prepaid, unused Fees.
  5. First-purchase goodwill — if you request within 14 days of your first Premium purchase and have made no more than incidental use of Premium features, we will refund that purchase. This applies once per customer.
  6. Statutory rights — nothing here limits non-waivable refund rights under your local consumer law.

10.3 When We Do Not Refund

We do not refund: partial-cycle cancellations outside Section 10.2; dissatisfaction with AI Output quality (see AI Policy, Section 9); suspension or termination for violation of the Acceptable Use Policy or Terms of Service; or failure to cancel before a Renewal Date, except as goodwill at our discretion.

10.4 How to Request

Email info@ababilx.cloud from your account email with the charge date and reason. We respond within 7 business days; approved refunds are issued to the original payment method and may take 5–10 business days to appear, depending on the provider.

11. Failed Payments

If a renewal charge fails, we will retry and notify you. If payment is not completed within a reasonable grace period, the subscription lapses to Free and Section 9 applies. We do not charge late fees.

12. Chargebacks

Contact us before disputing a charge with your payment provider — most issues are resolved faster under Section 10.4. Chargebacks filed for services legitimately received violate the Acceptable Use Policy (item 102) and may result in suspension pending resolution. We will promptly reverse any charge shown to be erroneous.

13. Price Changes

We may change prices prospectively. Price changes to an active subscription take effect no earlier than your next Renewal Date, and we will notify you at least 14 days before a renewal at a higher price. If you do not accept the new price, cancel before the Renewal Date; you will retain service through the period already paid.

14. Invoices and Records

Subscription records and invoices are available in the Service or on request to info@ababilx.cloud. We retain billing records for the period required by tax and accounting law (Privacy Policy, Section 12).

15. Changes to This Policy

Updates are versioned in Section 17. Changes reducing your refund rights apply only to purchases made after the change's effective date.

16. Contact

Billing questions and refund requests: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

17. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Developer & API Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Scope

This Policy governs programmatic access to the AbabilX Service — the REST API, WebSocket endpoints, webhooks, and any future developer surfaces (CLI, browser extension, SDKs). It supplements the Terms of Service and Acceptable Use Policy; where they conflict, the Terms of Service control.

2. Definitions

  • "API" — AbabilX's application programming interfaces, including REST endpoints and real-time (WebSocket) streams.
  • "Credentials" — access tokens, refresh tokens, pairing codes, exchange codes, connect tickets, and webhook tokens issued by the Service.
  • "Integration" — software you build or operate that calls the API or receives webhooks.

3. API Access and Authentication

  1. API access is authorized per Account. Requests are authenticated with a short-lived bearer access token obtained through the Service's supported authentication flows (OAuth sign-in with token exchange, token refresh, or desktop pairing).
  2. Real-time streams authenticate through the connection handshake; do not place Credentials in URLs.
  3. An Integration acts as the user who authorized it and receives only the access that user has. Do not attempt to broaden access beyond the authenticated account's permissions.
  4. Access requires acceptance of our current policies; requests from accounts gated by policy acceptance or plan enforcement will receive corresponding error responses (for example, HTTP 403), which your Integration must handle rather than retry blindly.

4. Credential Handling

You must:

  1. store Credentials securely (platform keychains, encrypted storage, or server-side secrets management — never in client-side source, public repositories, or logs);
  2. treat refresh tokens, pairing codes, and webhook URLs as secrets;
  3. transmit Credentials only over TLS and only to AbabilX endpoints;
  4. use the token-refresh flow rather than persisting long-lived access tokens;
  5. revoke Credentials you no longer need (sign out, regenerate pairing codes, delete webhooks);
  6. report suspected Credential compromise to info@ababilx.cloud immediately.

You must not share Credentials between users, embed a user's Credentials in a multi-tenant service, or solicit users' Credentials outside AbabilX's authentication flows.

5. Rate Limits and Quotas

  1. The API enforces layered rate limits: global per-client limits, strict limits on authentication endpoints, and per-account limits on high-frequency routes (see Security Policy, Section 10).
  2. Exceeding a limit returns HTTP 429 with retry guidance. Integrations must honor Retry-After and implement exponential backoff with jitter.
  3. Deliberate evasion — rotating accounts, IP addresses, or request signatures to exceed limits — violates the Acceptable Use Policy (items 25–26) and this Policy.
  4. Plan-based quotas (AI usage, automation limits) apply equally to API-originated usage.
  5. If your legitimate use case requires higher limits, contact info@ababilx.cloud before engineering around them.

6. Data Use and Storage by Integrations

If your Integration receives data from the API:

  1. use it only to provide functionality to the user who authorized the access;
  2. store no more than the Integration requires, for no longer than it requires;
  3. protect stored data with measures appropriate to its sensitivity;
  4. delete a user's data promptly when they disconnect your Integration or ask you to;
  5. do not sell it, use it for advertising, or disclose it except as the user directs or law requires;
  6. comply with applicable data-protection law as an independent controller of what you store.

7. Webhooks

  1. Inbound board webhooks embed a per-hook secret token in the URL. Keep webhook URLs confidential; anyone holding the URL can post to the hook. Regenerate the token if exposed.
  2. Send well-formed payloads within documented size limits; junk, oversized, or malicious payloads may be dropped and the hook revoked.
  3. Outbound events you receive from AbabilX (where offered) must be verified using the provided signature or secret before processing.
  4. Webhook traffic counts against rate limits.

8. Developer Responsibilities

You are responsible for:

  1. accurately representing your Integration to its users — its identity, functionality, and data practices;
  2. providing your own privacy policy to your users where you process their data;
  3. keeping your Integration's dependencies patched and its infrastructure secure;
  4. handling API errors gracefully — including 401 (refresh then re-authenticate), 403 (do not retry without resolving the cause), and 429 (back off);
  5. not degrading the experience of the users who authorized your Integration;
  6. maintaining a way for us to contact you about your Integration's behavior.

9. Prohibited API Uses

In addition to the Acceptable Use Policy, you may not use the API to:

  1. reconstruct, mirror, or resell the Service or a substantial part of it;
  2. build a dataset of AbabilX users or their content;
  3. train machine-learning models on data obtained from the API without the explicit consent of the data's owner and our written permission;
  4. poll endpoints at frequencies with no functional justification;
  5. bypass the Service's user interface controls for gated features (policy acceptance, plan limits, role permissions);
  6. operate an Integration after we have revoked its access;
  7. misattribute your Integration's actions to AbabilX.

10. Versioning and Deprecation

  1. We may evolve the API. Backwards-incompatible changes to documented behavior will be announced with a reasonable migration period — ordinarily at least 90 days, shortened only where security requires.
  2. Undocumented endpoints and response fields may change without notice; do not depend on them.
  3. Deprecation notices are published in the Service's changelog. Continuing to call a removed endpoint yields standard error responses.

11. Future Clients: CLI and Browser Extension

When AbabilX ships a command-line interface or browser extension:

  1. they will authenticate through the same short-lived-token flows described in Section 3 — this Policy applies to them from release;
  2. third-party tools must not impersonate official AbabilX clients (user-agents, branding, or update channels);
  3. browser-extension builds by third parties that inject into or wrap the Service require our written permission.

12. Enforcement

We may throttle, suspend, or revoke API access — per token, per Integration, or per Account — for violations of this Policy, security risk, or harm to the Service, following the enforcement approach in the Acceptable Use Policy, Section 7. Where practical we will contact you first.

13. Changes to This Policy

Changes are versioned in Section 15; material changes are announced through the Service's changelog with reasonable notice.

14. Contact

Developer questions: info@ababilx.cloud · Security: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

15. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Community Guidelines

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose and Scope

AbabilX's collaboration features — team walls, kanban boards, chat, daily updates, attendance, and digests — are shared workspaces. These Guidelines set the behavioral standard inside them. They apply to every member of every Team and complement the Acceptable Use Policy ("AUP"), which lists platform-wide prohibitions. Where these Guidelines and the AUP overlap, the stricter rule applies.

2. Definitions

Terms defined in the Terms of Service apply. "Team Space" means any collaboration surface scoped to a Team.

3. Core Expectations

  1. Be professional. Team Spaces are working environments. Disagree with ideas, not people.
  2. Be honest. Do not fabricate work records, misattribute contributions, or misrepresent activity — including through automation (AUP items 39, 53, 72).
  3. Respect boundaries. Colleagues' personal information, schedules, and off-hours are not yours to broadcast.
  4. Respect access. Use only the Team data your role grants; leaving a Team ends your right to its content (AUP item 94).
  5. Assume good faith first, report real problems fast. Most friction is misunderstanding; genuine misconduct should be reported, not endured (Section 9).

4. Team Spaces

  • Wall: for posts relevant to the team — announcements, discussion, appreciation. Keep categories on-topic; category requests are reviewed by team moderators.
  • Board (kanban): task titles, descriptions, and comments should describe work accurately. Do not delete or move others' tasks to obscure history or shift blame.
  • Chat: direct messages and channels carry the same conduct standards as public spaces. Harassment is harassment regardless of visibility.
  • Daily updates and digests: these are read by your team and may be posted to Slack. Review AI-drafted content before it represents you (see Section 6).

5. Content Standards

Do not post in any Team Space content that:

  1. harasses, demeans, threatens, or discriminates (AUP Section 4.7);
  2. is sexually explicit or gratuitously violent;
  3. discloses another person's private information without consent — including screenshots of private conversations shared to shame;
  4. is deliberately false and presented as fact about a person or their work;
  5. is spam, chain content, or off-platform promotion unrelated to the team's work;
  6. infringes intellectual-property rights (see Copyright & DMCA Policy);
  7. contains credentials, tokens, or secrets — including your own. Post secrets nowhere; rotate any secret posted by accident and tell your team owner.

6. AI-Assisted Content

AI features draft standups, digests, summaries, and task descriptions. When that content enters a Team Space under your name:

  1. you own it — review and correct drafts before they post (see AI Policy, Section 9);
  2. do not configure automations to report work that did not happen;
  3. do not present AI-generated assessments of a colleague's work as your considered judgment without actually considering it.

7. Roles and Moderation Within Teams

  1. Team owners and managers moderate their own Team Spaces first: they can manage categories, remove content, adjust roles, and remove members.
  2. Moderation power carries obligations — apply rules consistently, don't use role permissions to bully, silence good-faith dissent, or snoop beyond your legitimate function.
  3. AbabilX intervenes at the platform level when conduct violates the AUP or these Guidelines and the Team cannot or will not address it, or when the violator controls the Team.

8. Attendance and Activity Data

Attendance, work logs, and activity graphs exist to coordinate work, not to surveil people.

  1. Record your own attendance and work logs truthfully; do not check in for others or manipulate heartbeat/extension mechanics.
  2. Team owners must use attendance and analytics data lawfully and proportionately, consistent with employment and privacy law in their jurisdiction (AUP item 96).
  3. Off-day and OTP mechanisms are integrity controls — circumventing them violates the AUP.

9. Reporting

  • Inside your Team: raise it with your team owner or a manager, who has the tools to act.
  • To AbabilX: email info@ababilx.cloud with the team, content, and what happened — especially when the problem involves the team's leadership, or is severe (threats, hate speech, doxxing, CSAM — the last is reported to authorities without exception).
  • Reports are handled confidentially; retaliation against a good-faith reporter is itself a violation.

10. Enforcement

Violations are handled under the AUP's enforcement framework (AUP, Section 7): content removal, feature restrictions, suspension, or termination, proportionate to severity and history. Team-level moderation by owners is independent of, and does not limit, platform-level enforcement. Appeals follow AUP Section 8.

11. Changes to These Guidelines

Changes are versioned in Section 13 and announced in the Service when material.

12. Contact

Conduct reports: info@ababilx.cloud · Urgent safety issues: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

13. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Data Processing Addendum (DPA)

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Introduction and Order of Precedence

This Data Processing Addendum ("DPA") forms part of the agreement between AbabilX and the customer accepting it ("Customer") under the Terms of Service (together, the "Agreement"), and applies where AbabilX processes Personal Data subject to Data Protection Law on Customer's behalf. In case of conflict regarding the processing of Personal Data, this DPA prevails over the Agreement; executed Standard Contractual Clauses prevail over this DPA.

This DPA is accepted by using the Service as a business or organization, or by countersignature where a signed copy is requested (info@ababilx.cloud).

2. Definitions

  • "Data Protection Law" — all laws applicable to the processing of Personal Data under the Agreement, including the EU/UK GDPR, the CCPA/CPRA, and analogous laws.
  • "Customer Personal Data" — Personal Data contained in Customer Content that AbabilX processes on Customer's behalf.
  • "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach" — as defined in the GDPR; for the CCPA, "Controller" reads as "Business" and "Processor" as "Service Provider."
  • "SCCs" — the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller→processor) or Module Three (processor→processor) as applicable, and the UK Addendum where UK GDPR applies.

3. Roles of the Parties

  1. For Customer Personal Data, Customer is the Controller (or a Processor acting for another Controller) and AbabilX is the Processor.
  2. AbabilX acts as an independent Controller for: account registration data of its users, billing records, security and service logs, and service telemetry — as described in the Privacy Policy. Those are outside this DPA.

4. Details of Processing

The subject matter, duration, nature, purposes, data categories, and Data Subject categories of Processing are set out in Annex I (Section 16).

5. Processor Obligations

AbabilX shall:

  1. process Customer Personal Data only on Customer's documented instructions — the Agreement, this DPA, and Customer's configuration and use of the Service constitute those instructions — unless required otherwise by law, in which case AbabilX informs Customer unless legally prohibited;
  2. immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law;
  3. ensure persons authorized to process Customer Personal Data are bound by confidentiality obligations;
  4. implement the technical and organizational measures in Annex II;
  5. not sell, share (for cross-context behavioral advertising), or retain, use, or disclose Customer Personal Data other than to provide the Service (CCPA §7051 obligations), and certify that it understands these restrictions;
  6. not use Customer Personal Data to train machine-learning models (see AI Policy, Section 8);
  7. assist Customer as described in Sections 10–11.

6. Customer Obligations

Customer shall:

  1. have a lawful basis for the Personal Data it submits or connects to the Service (including repository content and workspace messages);
  2. provide required notices to, and obtain required consents from, its Data Subjects (including team members whose attendance and activity data it processes);
  3. configure the Service (roles, integrations, retention-relevant deletions) consistently with its obligations;
  4. not submit special-category data or data of minors except as strictly incidental to development content and lawful.

7. Subprocessing

  1. Customer grants general written authorization for the Subprocessors listed in the Subprocessor List.
  2. AbabilX will update the list at least 14 days before adding or replacing a Subprocessor. Customer may subscribe to updates by emailing info@ababilx.cloud.
  3. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected services and receive a pro-rated refund of prepaid, unused fees.
  4. AbabilX imposes data-protection obligations on each Subprocessor materially equivalent to this DPA and remains liable for its Subprocessors' performance.

8. International Transfers

  1. Customer authorizes Processing in the locations identified in the Subprocessor List and in Bangladesh, where AbabilX operates.
  2. Where Processing involves a transfer of Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties enter into the SCCs, which are incorporated by reference: Module Two (or Three), with AbabilX as data importer and Customer as data exporter; Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 14 days); Clause 17 governing law of Ireland; Clause 18 courts of Ireland; Annexes I–II completed by Sections 16–17 of this DPA. For UK transfers, the UK IDTA Addendum applies with equivalent selections; for Switzerland, references adapt to the FADP.
  3. AbabilX applies the supplementary measures in Annex II to all transfers.

9. Security

AbabilX maintains the measures described in Annex II and the Security Policy, and may update them provided the protection level is not materially reduced.

10. Personal Data Breach

AbabilX shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing (as information becomes available): the nature of the breach, categories and approximate volumes affected, likely consequences, and measures taken or proposed. AbabilX will cooperate with Customer's reasonable investigation and its regulatory and Data Subject notification obligations. Notification is not an admission of fault.

11. Assistance and Data Subject Requests

  1. Taking into account the nature of Processing, AbabilX shall assist Customer with appropriate technical and organizational measures to fulfil Data Subject requests (access, rectification, erasure, restriction, portability, objection). The Service's self-service controls (content editing/deletion, integration disconnection, export on request) are the primary mechanism.
  2. If AbabilX receives a request directly from Customer's Data Subject, it will (where lawful) redirect the Data Subject to Customer and not respond substantively except on Customer's instruction.
  3. AbabilX shall provide reasonable assistance with Customer's data-protection impact assessments and prior consultations, to the extent the required information is available to AbabilX.

12. Audits

  1. On written request no more than once per 12 months (absent a Personal Data Breach or regulator requirement), AbabilX will make available the information reasonably necessary to demonstrate compliance with this DPA — including its current security documentation and Subprocessor list — and will respond to a reasonable written security questionnaire.
  2. Where that information is insufficient under Data Protection Law, Customer may conduct (directly or via an independent auditor bound to confidentiality) an audit limited in scope, duration, and access so as not to compromise the security of other customers, at Customer's expense, on at least 30 days' notice.

13. Return and Deletion

Upon termination of the Agreement, or upon Customer's deletion of specific data through the Service, AbabilX deletes Customer Personal Data as described in the Privacy Policy, Sections 12 and 14 (including rotation out of encrypted backups), except where retention is required by law. On written request made before account deletion, AbabilX will provide an export of Customer Personal Data in a machine-readable format.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, Section 21, except where Data Protection Law does not permit such limitation (including a Data Subject's rights under the SCCs).

15. Term and Termination

This DPA takes effect upon acceptance and remains in force as long as AbabilX processes Customer Personal Data under the Agreement.

16. Annex I — Processing Description

  • Data exporter:** Customer — the organization or individual using the Service for its team or business.
  • Data importer:** AbabilX, Sector 4, Uttara, Dhaka, Bangladesh — provider of the Service.
  • Subject matter:** Provision of the AbabilX developer-automation and team-collaboration platform.
  • Duration:** The term of the Agreement plus the deletion periods in Section 13.
  • Nature and purpose:** Hosting, retrieval, transmission, display, AI-assisted summarization, scheduling, and notification of development and collaboration data, as configured by Customer.
  • Categories of Data Subjects:** Customer's team members and administrators; individuals appearing in connected repository and workspace content (e.g., commit authors, PR reviewers, message authors).
  • Categories of Personal Data:** Names, usernames, email addresses, avatars; repository/commit/PR metadata containing author identities; messages and posts; task and work-log content; attendance and schedule records; configuration data; technical identifiers (IP address, device tokens).
  • Special categories:** None intended; incidental presence only if contained in Customer Content.
  • Frequency:** Continuous, as driven by Customer's use and configured automations.
  • Retention:** Per the Privacy Policy, Section 12.

17. Annex II — Technical and Organizational Measures

As detailed in the Security Policy:

  1. TLS encryption in transit for all traffic; encrypted storage for databases, objects, and backups.
  2. OAuth-based authentication; short-lived signed access tokens; rotating HttpOnly; Secure; SameSite refresh cookies; one-time exchange codes and tickets keeping credentials out of URLs and logs.
  3. Server-side, per-request authorization; role-based team permissions; segregated super-administrator access; least-privilege personnel access.
  4. Server-side secrets management; deny-by-default serialization of stored third-party tokens; signature-verified webhooks.
  5. Layered rate limiting (global per-IP, strict credential-endpoint, per-user) against brute force and abuse.
  6. Security logging of authentication and administrative events, with credential material excluded from logs.
  7. Scheduled encrypted backups with rolling retention; documented recovery procedures.
  8. Incident-response process with detection, containment (credential revocation, feature kill switches), remediation, notification, and post-incident review.
  9. Vendor assessment and contractual flow-down of data-protection obligations to Subprocessors, including no-training restrictions on AI providers.

18. Contact

DPA execution and questions: info@ababilx.cloud · Privacy: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

19. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX GDPR Compliance Statement

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose

This Statement explains how AbabilX meets its obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR for users and customers in the European Economic Area, the United Kingdom, and Switzerland (whose FADP is addressed by analogy). It supplements — and should be read with — our Privacy Policy and, for business customers, our Data Processing Addendum ("DPA").

2. Definitions

GDPR terms — "Controller," "Processor," "Personal Data," "Processing," "Data Subject" — carry their statutory meanings.

3. Our Roles Under the GDPR

  • Data: Your account registration data, billing records, security and service logs, telemetry | Our role: Controller | Governing document: Privacy Policy
  • Data: Personal Data inside Customer Content processed for a team or business (repository content, workspace messages, team members' collaboration data) | Our role: Processor on the customer's behalf | Governing document: DPA

Individual users acting purely for themselves interact with us as Controller throughout.

4. Lawful Bases

Our lawful bases per purpose are tabulated in the Privacy Policy, Section 8: contract for operating the Service and generating requested Output; legitimate interests for security, abuse prevention, and service analytics (assessed against Data Subjects' rights, with minimization safeguards); consent for non-essential communications and any non-essential storage; legal obligation for tax, accounting, and lawful requests. Where we rely on legitimate interests, you may object (Section 5).

5. Data Subject Rights and How to Exercise Them

Under Articles 15–22 GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time (Article 7(3)).

Self-service (immediate):

  • edit profile data in Settings (rectification);
  • disconnect GitHub/Slack integrations, disable notification channels, sign out of sessions (restriction/objection in effect);
  • delete individual content items;
  • delete your account entirely (erasure — see Privacy Policy, Section 14).

By request to `info@ababilx.cloud`:

  • a copy of your Personal Data (access) and a machine-readable export (portability, Article 20);
  • objection to legitimate-interest processing (Article 21) — we will stop unless we demonstrate compelling legitimate grounds;
  • restriction while a dispute is assessed (Article 18).

We verify requests against your account email, respond within one month (extendable by two months for complex requests, with notice), and act free of charge except where requests are manifestly unfounded or excessive (Article 12(5)).

If we process your data as Processor for a team or business, we will redirect your request to that customer, who is the Controller responsible for responding (see DPA, Section 11).

6. International Transfers

AbabilX operates from Bangladesh — a country without an EU adequacy decision — and uses Subprocessors in several countries. Transfers of EEA/UK/Swiss Personal Data are protected by:

  1. Standard Contractual Clauses (Decision 2021/914) with our Subprocessors, and — for business customers — the SCCs incorporated into our DPA, Section 8 (with the UK Addendum for UK transfers);
  2. Supplementary measures: TLS for all transfers, encrypted storage, credential-free URLs and logs, least-privilege access, and Subprocessor contractual restrictions (including no AI training on your content);
  3. Transfer impact assessment: we evaluate destination-country law and Subprocessor safeguards before engagement and on material change, and we commit to challenging disproportionate government access requests where lawful (Privacy Policy, Section 10.4).

7. Data Protection by Design and by Default

Article 25 obligations are reflected in the platform's construction:

  • minimization: split me endpoints expose only the fields each screen needs; AI requests carry the minimum context per feature (AI Policy, Section 4);
  • default protection: third-party tokens are excluded from serialization by default; team content is scoped to team roles server-side;
  • security by design: short-lived tokens, rotating HttpOnly refresh cookies, one-time codes and tickets, handshake-authenticated WebSockets (Security Policy, Section 6);
  • transparency and control: versioned policies requiring re-acceptance on material change; granular notification and privacy toggles; self-service deletion.

8. Records, DPIAs, and Accountability

We maintain records of processing activities appropriate to our size and processing (Article 30), assess new features with privacy-affecting scope before launch, and conduct data-protection impact assessments where processing is likely to result in high risk (Article 35). Subprocessors are engaged under written contracts imposing GDPR-equivalent obligations (Article 28(4)); the current list is the Subprocessor List.

We have not appointed a mandatory Data Protection Officer under Article 37, as our core activities do not involve large-scale systematic monitoring or large-scale special-category processing; privacy responsibility rests with engineering leadership, reachable at info@ababilx.cloud. We will appoint a DPO and an EU/UK representative (Article 27) if and when our processing triggers those obligations, and will update this Statement accordingly.

9. Breach Notification

Where a Personal Data Breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of awareness (Article 33) and affected Data Subjects without undue delay where the risk is high (Article 34). For Customer Personal Data processed under the DPA, we notify the customer within 72 hours so it can meet its own obligations (DPA, Section 10).

10. Automated Decision-Making

The Service does not make decisions producing legal or similarly significant effects on you based solely on automated processing (Article 22). AI features generate drafts and summaries for human review; plan-limit and rate-limit enforcement are contractual usage controls, and enforcement decisions affecting your account involve human review (see Acceptable Use Policy, Sections 7–8).

11. Supervisory Authorities and Complaints

You may lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of an alleged infringement (Article 77) — for example, your national Data Protection Authority in the EEA, or the ICO in the UK. We would welcome the opportunity to resolve your concern first at info@ababilx.cloud.

12. Changes to This Statement

Changes are versioned in Section 14; material changes are announced through the Service.

13. Contact

Privacy and GDPR requests: info@ababilx.cloud · Legal: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

14. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX CCPA/CPRA Compliance Statement

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose and Scope

This Statement provides the disclosures required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA") for California residents who use AbabilX. It supplements our Privacy Policy, which describes our practices in full.

2. Definitions

"Personal information," "sell," "share," "sensitive personal information," "service provider," and "business purpose" carry their CCPA statutory meanings. "You" means a California resident.

3. Notice at Collection

We collect the categories of personal information listed in Section 4, for the purposes listed in Section 5, retained per Section 8. We do not sell or share personal information (Section 6).

4. Categories of Personal Information

Mapped to the CCPA's statutory categories (Cal. Civ. Code §1798.140(v)):

  • CCPA Category: A. Identifiers | Collected?: Yes | Examples in Our Context: Name, username, email, avatar, IP address, OAuth account identifiers
  • CCPA Category: B. Customer records (§1798.80(e)) | Collected?: Yes | Examples in Our Context: Account and subscription records
  • CCPA Category: C. Protected classifications | Collected?: No | Examples in Our Context: —
  • CCPA Category: D. Commercial information | Collected?: Yes | Examples in Our Context: Plan purchases, billing history
  • CCPA Category: E. Biometric information | Collected?: No | Examples in Our Context: —
  • CCPA Category: F. Internet/network activity | Collected?: Yes | Examples in Our Context: Feature usage, API logs, device/browser data
  • CCPA Category: G. Geolocation data | Collected?: Limited | Examples in Our Context: Coarse location inferable from IP address only; no precise geolocation
  • CCPA Category: H. Sensory data | Collected?: No | Examples in Our Context: —
  • CCPA Category: I. Professional/employment information | Collected?: Limited | Examples in Our Context: Team roles, work logs, and attendance records created by you or your team
  • CCPA Category: J. Education information | Collected?: No | Examples in Our Context: —
  • CCPA Category: K. Inferences | Collected?: No | Examples in Our Context: We do not build behavioral profiles
  • CCPA Category: L. Sensitive personal information | Collected?: Limited | Examples in Our Context: Account log-in credentials in the form of authentication tokens (see Section 7)

Content you or your integrations submit (repository metadata, messages, posts) may incidentally contain identifiers of you or others; it is handled as Customer Content under the Privacy Policy.

5. Sources, Purposes, and Disclosures

  • Sources: you directly; your devices and browsers automatically; connected platforms (GitHub, Google, Slack) at your direction; payment providers (Privacy Policy, Section 6).
  • Business purposes: providing and securing the Service; executing configured automations; generating AI Output; billing; debugging; auditing interactions; complying with law (Privacy Policy, Section 7).
  • Disclosures for business purposes: to the service providers in our Subprocessor List (hosting, storage, notifications, email, payments, AI processing); to connected platforms at your direction; to authorities where legally required (Privacy Policy, Section 10). Each category in Section 4 marked "Yes" may be disclosed to the service providers whose function requires it.

6. No Sale or Sharing

We do not sell personal information, and we do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. We have no actual knowledge of selling or sharing personal information of consumers under 16. Because we do not sell or share, we do not offer an opt-out mechanism, and browser opt-out signals (such as Global Privacy Control) require no change to our processing — your data is already treated as opted out.

7. Sensitive Personal Information

The only sensitive personal information we process is account authentication material (tokens and codes), used solely to authenticate you and secure the Service — a use permitted under §7027(m) without a right-to-limit obligation. We do not use sensitive personal information to infer characteristics.

8. Retention

Retention periods per category follow the schedule in our Privacy Policy, Section 12: account data for the life of the account; logs on rolling 30–180-day windows; billing records as required by tax law; all subject to deletion on account closure.

9. Your Rights

California residents have the right to:

  1. Know/Access — the categories and specific pieces of personal information we have collected, the sources, purposes, and disclosure recipients;
  2. Delete — subject to statutory exceptions (security, legal compliance, completing a transaction you requested);
  3. Correct — inaccurate personal information;
  4. Opt out of sale/sharing — not applicable, as we do neither (Section 6);
  5. Limit sensitive personal information — not applicable to our permitted-purpose use (Section 7);
  6. Non-discrimination — see Section 11.

10. How to Exercise Your Rights

  • Self-service: edit profile data in Settings (correct); delete content items or your entire account in the Service (delete).
  • By request: email info@ababilx.cloud with "California Privacy Request" in the subject. We verify your identity via your account email (and reasonable follow-up where needed), confirm receipt within 10 business days, and respond within 45 days (extendable once by 45 days with notice).
  • Authorized agents may submit requests with proof of written authorization; we may still require you to verify identity directly.
  • We do not charge for requests unless they are manifestly unfounded or excessive.

11. Non-Discrimination

We will not deny you the Service, charge different prices, or degrade quality because you exercised CCPA rights. Plan-based feature differences apply equally to everyone and are unrelated to privacy requests.

12. Service-Provider Relationships

Entities in our Subprocessor List act as service providers under written contracts that prohibit retaining, using, or disclosing personal information for any purpose other than performing their services, and prohibit selling or sharing it — consistent with §1798.140(ag) and our Data Processing Addendum, Section 5.

13. Changes to This Statement

Changes are versioned in Section 15. This Statement is reviewed at least annually.

14. Contact

California privacy requests: info@ababilx.cloud (subject: "California Privacy Request")
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

15. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Subprocessor List

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Purpose

This document is the single authoritative list of third parties that process Personal Data on AbabilX's behalf ("Subprocessors"). It supports the commitments in our Privacy Policy (Section 10.1) and Data Processing Addendum (Section 7). Other policies link here rather than duplicating the list.

2. Definitions

"Subprocessor" — a third party engaged by AbabilX to process Personal Data in the course of providing the Service. Terms defined in the Privacy Policy apply.

3. How We Engage Subprocessors

Before engaging a Subprocessor we assess its security posture and data-protection practices, and we bind it by written contract to: process Personal Data only on our instructions; apply appropriate security measures; not use the data for its own purposes (including model training, for AI providers); and support deletion and breach-notification obligations. International transfers to Subprocessors rely on Standard Contractual Clauses where required (GDPR Compliance Statement, Section 6).

4. Current Subprocessors

  • Subprocessor: Cloud hosting provider (compute for API and application servers) | Function: Runs the Service's backend and databases (PostgreSQL, Redis) | Data Processed: All Service data at rest and in processing | Location of Processing: Data-center region(s) selected for the Service
  • Subprocessor: Cloudflare, Inc. — R2 object storage & network services | Function: Stores user-uploaded files (avatars, covers, attachments) and provides network delivery | Data Processed: Uploaded media and attachments; request metadata | Location of Processing: Global (distributed)
  • Subprocessor: Google LLC — Firebase Cloud Messaging | Function: Delivers push notifications to mobile devices | Data Processed: Device registration tokens; notification titles/bodies | Location of Processing: Global (Google infrastructure)
  • Subprocessor: DeepSeek | Function: AI model inference for Output generation | Data Processed: Prompts assembled from Customer Content as described in the AI Policy, Sections 4–5 | Location of Processing: Provider's API infrastructure
  • Subprocessor: Transactional email provider | Function: Sends account, security, and notification emails | Data Processed: Recipient email address; message content | Location of Processing: Provider's infrastructure
  • Subprocessor: Payment processor(s) | Function: Processes Premium plan payments | Data Processed: Payment credentials (held by the processor, not by us); transaction records | Location of Processing: Provider's infrastructure

Note: Where a row names a function rather than a single vendor, the engaged vendor for your account is available on request to info@ababilx.cloud; the contractual protections in Section 3 apply identically.

5. Connected Platforms (Not Subprocessors)

The following process your data because you connect them and direct the Service to interact with them. They act under their own terms as independent controllers, not as our Subprocessors:

  • GitHub, Inc.:** Repository, commit, PR, and profile data read with your token; commits/branches/PRs created at your direction
  • Slack Technologies:** Channel lists read and messages posted to workspaces you authorize
  • Google LLC (Sign-In):** Identity verification when you sign in with Google

Disconnecting an integration in AbabilX stops our access but does not delete data those platforms hold — manage that with the platform directly.

6. Change Notification

We update this list at least 14 days before adding or replacing a Subprocessor. Business customers under the DPA may subscribe to change notices and object as described in DPA Section 7 by emailing info@ababilx.cloud with the subject "Subprocessor notifications." Every change is recorded in Section 8.

7. Contact

Questions and notification subscriptions: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

8. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.

AbabilX Vulnerability Disclosure Policy

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Version: 1.0.0


1. Our Commitment

Security research conducted in good faith makes AbabilX safer for everyone. We welcome reports of vulnerabilities in our Service, will work with you to understand and remediate them, and will not pursue action against research that follows this Policy.

2. Definitions

  • "Vulnerability" — a weakness in the Service that could compromise the confidentiality, integrity, or availability of the Service or its users' data.
  • "Good-faith research" — accessing systems only to the extent needed to demonstrate a Vulnerability, without harming users, data, or availability, and reporting promptly under this Policy.

3. Scope

In scope:

  • the AbabilX web application and websites;
  • the AbabilX API and WebSocket endpoints;
  • AbabilX desktop and mobile applications;
  • authentication and session mechanics (OAuth flows, token exchange and refresh, pairing codes, connect tickets, cookies);
  • webhook endpoints;
  • AI features, including prompt-injection and authorization-bypass issues (AI Policy, Section 11).

Out of scope:

  • GitHub, Google, Slack, and other third-party platforms (report to them directly);
  • our Subprocessors' infrastructure (report to the vendor; tell us too if AbabilX data is affected);
  • social engineering of AbabilX personnel or users;
  • physical attacks;
  • denial-of-service testing of any kind.

4. Rules of Engagement

You must:

  1. test only against accounts you own or created for testing — never access, modify, or delete another user's data;
  2. stop and report immediately if you encounter someone else's Personal Data; do not copy, store, or further examine it;
  3. avoid degrading the Service — no volumetric attacks, no automated scanning at disruptive rates (respect HTTP 429 responses);
  4. not exfiltrate data beyond the minimum proof of concept;
  5. not use a Vulnerability for any purpose other than verification and reporting — no extortion, no leverage, no "proof" pivoting into further systems;
  6. comply with applicable law and, except as authorized by this Policy, the Acceptable Use Policy;
  7. keep findings confidential until coordinated disclosure (Section 8).

5. How to Report

Email `info@ababilx.cloud` with:

  1. a descriptive title and the affected component/endpoint;
  2. reproduction steps or proof of concept (requests, payloads, screenshots);
  3. observed impact and your assessment of severity;
  4. the account identifiers you used for testing;
  5. your contact details and, if you wish, a name/handle for recognition (Section 10).

Report in English or Bangla. Encrypted reports: request our key at the same address.

6. What to Expect From Us

  • Acknowledgment: Within 3 business days
  • Triage and severity assessment: Within 7 business days
  • Status updates: At least every 14 days while open
  • Remediation: Critical: immediate priority; High: days; Medium/Low: prioritized schedule (Security Policy, Section 13)
  • Resolution notice: We tell you when the fix ships and credit you if desired

7. Safe Harbor

For good-faith research conducted in accordance with this Policy:

  1. we will not initiate legal action against you or refer you for prosecution, and will state that your research was authorized if a third party raises it;
  2. we waive claims under anti-circumvention and computer-misuse theories to the extent they arise solely from Policy-compliant research;
  3. we will not suspend or terminate your account for the research itself.

This safe harbor does not extend to research that materially violates Section 4, harms users, or breaks laws we cannot waive. If you are unsure whether planned testing is covered, ask info@ababilx.cloud before testing.

8. Public Disclosure

We support coordinated disclosure. Please give us 90 days from acknowledgment (or a mutually agreed timeline) before publishing details. We may request a short extension for complex fixes; we will not use the process to indefinitely suppress publication. Where a fix ships sooner and users are protected, earlier coordinated publication is fine — talk to us.

9. Out-of-Scope Findings

The following are ordinarily not accepted as Vulnerabilities (unless you demonstrate concrete exploitability):

  • missing security headers without a demonstrated attack;
  • rate-limit responses on endpoints that are, in fact, rate-limited;
  • clickjacking on pages with no sensitive state-changing action;
  • self-XSS requiring the victim to attack themselves;
  • reports from automated scanners without validation;
  • version disclosure of server software;
  • password/OAuth policy opinions without an exploit path;
  • best-practice suggestions (send those to info@ababilx.cloud — still appreciated).

10. Recognition

We do not currently operate a paid bug bounty. With your consent, we credit meaningful findings in our changelog or an acknowledgments page. If a bounty program launches, this Policy will be updated with its terms.

11. Changes to This Policy

Changes are versioned in Section 13. The Policy version in effect when you begin testing governs that research.

12. Contact

Security reports: info@ababilx.cloud
Postal: AbabilX, Sector 4, Uttara, Dhaka, Bangladesh.

13. Revision History

  • Version: 1.0.0 | Date: July 9, 2026 | Summary: Initial publication.