Public policy
Trust & Data
How Ablo handles customer data, AI processing, integrations, international transfers, retention and deletion.
- Version
- 1.0
- Last updated
- 2026-08-31
- Reviewed
- 2026-08-31
Scope
Ablo is a business service for organizations. Users must be at least 18 years old and authorized to act for their organization.
Data and purposes
The exact content depends on how an organization configures its projects, Coworkers and integrations.
Account and organization data
Names, business email addresses, authentication identifiers, organization membership, roles and acceptance records.
Purpose: Authenticate users, administer organizations, apply access controls and maintain contractual records.
Project and workspace content
Projects, objectives, conversations, instructions, proposals, events, files, deliverables and other content supplied or created for the organization.
Purpose: Provide the Coordinator and Coworker workspace, preserve project history and deliver requested work.
AI request and execution data
Prompts, model responses, tool arguments and results, task messages, runtime files, logs, checkpoints and execution metadata.
Purpose: Run AI-assisted work, route model requests, operate isolated task environments and diagnose failed work.
Integration data
Connected-account identifiers, OAuth credentials held by the integration provider, selected permissions, tool inputs and outputs, and webhook events.
Purpose: Connect customer-selected services and perform actions that the customer or its authorized agents request.
Billing and transaction data
Organization billing identity, subscription and order references, credit balances, usage records, invoices and refund information.
Purpose: Provide paid services, account for usage, handle payments and meet accounting obligations.
Technical, security and analytics data
IP address, browser and device information, request timing, page and feature events, error details, security events and delivery logs.
Purpose: Secure and operate the service, investigate errors, measure product use and prevent abuse.
Communications and support data
Support messages, notification delivery details and information submitted when booking a call.
Purpose: Respond to questions, provide service notices and arrange requested sales or support conversations.
Data-handling principles
Ablo processes customer data only to provide, secure, support and administer the service, to follow customer instructions, and to meet legal obligations.
- Customer data is not sold.
- Customer prompts, responses or workspace content is never used by Ablo or its subprocessors to train AI models.
- New subprocessors, integrations, data types and processing locations require review before production use.
Data locations and international processing
Ablo's production Convex deployments use the EU region. Agent execution, Browserless and the checkpoint registry run on EU-based Hetzner infrastructure. Gogs repositories and Redis run in Railway's EU region. Deliverable object storage uses Backblaze's EU Central region.
These EU locations do not make the complete service EU-only. Authentication, application delivery, analytics, billing, email, integrations, AI routing and provider support may involve processing outside the EEA.
See the complete provider-by-provider disclosure in the subprocessor register.
AI and model processing
Ablo sends AI completion requests through OpenRouter. Ablo requires Zero Data Retention at the OpenRouter account, organization or guardrail level for every model group it uses. Every request must also include provider.zdr = true and provider.data_collection = "deny" and must fail rather than silently route to a non-compliant endpoint.
Prompt and response logging and the use of inputs or outputs for product improvement must remain disabled. Zero Data Retention applies to prompt and response content. OpenRouter may still retain operational metadata such as model, provider, token counts, latency and cost.
OpenRouter may route a request only through the inference providers listed in the public subprocessor register. The available provider depends on the selected model and the endpoints that can satisfy Ablo's privacy requirements at request time.
Integrations and connected accounts
Integrations are project-scoped. Ablo uses Composio-managed authentication to connect customer-selected services and execute approved tools. Composio holds and refreshes the connected-account credential; Ablo stores the connection identifiers needed to use and remove it.
Ablo limits integrations to the actions it exposes. Gmail is send-only and does not read the mailbox. Disconnect and organization-deletion flows must revoke upstream access and delete the Composio connected account.
Composio controls the scopes offered by its managed OAuth applications and the retention of its payload logs unless it provides an account-level or contractual control. Ablo discloses that limitation and requires the production scopes and retention terms to be reviewed before launch.
Analytics, telemetry and logs
PostHog analytics runs only with the appropriate consent. Session replay is disabled in authenticated product areas. Ablo does not intentionally include workspace content, prompts, responses, integration payloads, credentials or other customer secrets in analytics, error telemetry or routine logs.
Necessary security and delivery logs are kept separately from product analytics where practical. Access is limited to people who need the data to operate, secure or support the service.
Deletion and legal retention
Deleting an organization removes access immediately. Ablo's policy is to complete deletion from active systems within 30 days, including Ablo data, agent tasks and files, integrations, repositories, analytics identities and object storage.
Data may be retained longer only when law requires it. Norwegian primary accounting records may be isolated and retained for five years, or longer where a specific legal obligation applies. Legally retained records are separated from deleted product content and are not reused to provide the product.
Backups are retained only for a documented, time-bounded recovery window. Deleted customer content is not restored to active service except when necessary for disaster recovery, after which the deletion process resumes.
Retention schedule
Changes and contact
Questions or privacy requests can be sent to privacy@ablo.no. General product support is available at support@ablo.no.
Initial publication of the Trust & Data policy and subprocessor register.