Board of AdvisorsBack to workspace

Your workspace, clearly explained

Privacy Policy

What we collect, how AI processing works, and the choices you have over your data.

Last updated: 7 September 2026

1. Who we are and how to contact us

Board of Advisors is an AI discussion service operated by Caesar Sengupta ("we", "us", or "our"). This Privacy Policy explains how we handle personal data when you visit the site, sign in, create boards, or use our AI and memory features. We handle personal data subject to Singapore’s Personal Data Protection Act 2012 (PDPA) and other applicable laws.

For privacy questions, access or correction requests, withdrawal of consent, or an account-deletion request, contact our privacy contact using the details at the end of this page.

2. Information we collect

  • Account information: your email address, account identifiers, and, when supplied by your sign-in provider, your name and profile picture. Google authenticates your Google account; we do not receive your Google password. Our authentication service handles tokens and sessions needed to keep you signed in.
  • Your content and choices: boards, selected advisors and models, questions, messages, generated answers and summaries, advisor requests, favourites, and appearance preferences. Content you submit can contain personal data about you or others.
  • Saved memory: facts, preferences and context derived from eligible discussion messages when memory learning is enabled, together with supporting source references, review decisions and removal records.
  • Service records: timestamps, request and job identifiers, model and token usage, costs, errors, and support correspondence. Our hosting, authentication and other infrastructure providers may also process IP addresses, browser or device information, and security logs.

Provide only information you have the right to share. Avoid submitting passwords, authentication secrets, payment-card details, identification numbers, or unnecessary sensitive information about yourself or other people.

3. Why we use it

We use this information to authenticate you; save and retrieve your workspace; generate advisor replies and summaries; personalise discussions using your chosen settings and saved memory; handle advisor requests; provide support; diagnose failures; prevent abuse; track service usage and spending; and meet legal obligations. We collect, use and disclose personal data with consent where required or under another basis permitted by applicable law. We will notify you and seek any consent required before using it for a materially different purpose.

Google account information is used for sign-in, account management and profile display. We do not request access to your Gmail, Google Drive or Calendar for this service. We do not intentionally include Google authentication tokens or your Google account profile in AI prompts; information you include in discussion content may be included in those prompts.

4. AI processing and saved memory

To produce an answer, we send the relevant prompt through OpenRouter to the selected model’s serving provider. This can include your question, earlier participants’ messages, discussion summaries, the advisor profile, and relevant saved memory. In later rounds, earlier discussion content may be sent again. Model routing and fallback can change the serving provider. Model providers can include OpenAI, Google, Anthropic, xAI, Qwen and others made available in the app.

When enabled and available, memory learning can process eligible messages in the background to suggest or save context for future discussions. The app may also compress a long discussion into a structured summary. These processes use AI providers too. Saved memory is fallible; review it rather than assuming every inference is accurate. You can control learning and future use of memory in Memory settings, review or remove saved items, and choose whether to use saved memory in a new discussion. Turning off learning does not itself delete existing memories or conversation history.

We do not operate a model-training pipeline using your private conversations. Provider-side logging, retention, caching and any permitted training depend on the provider and the applicable service configuration and terms; this service does not promise zero retention or a universal provider no-training guarantee. See OpenRouter’s data-handling explanation and privacy policy. Avoid submitting information whose disclosure to those providers would be inappropriate.

5. No sale of data; limited sharing

We will not sell your personal data. We will not share it with external companies for their own marketing, advertising, resale or unrelated commercial purposes. The exceptions to this sharing restriction are the necessary service-provider processing, legally permitted disclosures, and sharing among related products explained below. Service-provider processing includes the provider-specific data handling described in section 4; this is not a promise that no outside company processes your data.

Related products on czbz.ai or created by Caesar Sengupta

Products on czbz.ai, or products created by Caesar Sengupta, may share relevant data with one another solely to improve your user experience—for example, to carry over preferences, provide continuity between products, or improve features you use. We will limit sharing to data reasonably needed for the stated purpose. This permission does not extend to sale of your data, third-party advertising, or unrelated uses by outside companies.

Before introducing such sharing, we will identify the participating products and their operators, explain what data will be shared and why, and provide any notice and obtain any consent required by applicable law. This policy update does not itself enable automatic sharing between products or retroactively authorise new uses of existing data. Where sharing depends on consent, you may withdraw that consent by contacting our privacy contact. Google account information remains subject to the purposes in section 3 and applicable Google user-data requirements; it is not automatically made available for use across products.

Providers that operate the service

We use Vercel for hosting, Supabase for authentication and data storage, OpenRouter and model providers for AI processing, Inngest for background-job orchestration, and Google when you choose Google sign-in. They receive information needed for their respective services. Job orchestration uses identifiers and operational metadata; the app’s memory jobs are designed to avoid including source-message text in job events and step results. Names and supporting details submitted for persona research may be sent to research and search services.

Authorised administrators may access account, usage, memory or discussion information as needed to operate the service, investigate problems, respond to requests, or meet legal obligations. Your discussions are not published to other users as part of the ordinary service. We may disclose information when legally required, to protect lawful rights and safety, or to professional advisers assisting with those matters. A business transfer does not override the no-sale commitment or permit unrelated use of personal data; any transfer of personal data must have a lawful basis, appropriate notice and any consent required by law.

The service does not include targeted-advertising trackers. Other services’ own handling of data is also described in their privacy notices: Google, Vercel, Supabase, and Inngest.

6. Cookies and local storage

We use authentication cookies and similar storage for sign-in and session security. Browser local storage remembers preferences such as colour palette, light or dark mode, text size and favourites. Blocking or clearing this storage may sign you out or reset preferences. We do not currently install advertising cookies or a separate marketing-analytics tracker in the app.

7. Storage, overseas processing and security

The service uses a Supabase project in Singapore, but this does not mean all processing stays in Singapore. Hosting, authentication, AI processing, orchestration, support and backups may involve other countries, including the United States and locations used by the relevant providers.

Where the PDPA applies, overseas transfers must meet its transfer requirements, including comparable protection through appropriate arrangements unless a legal exception applies. We remain responsible for the obligations applicable to us; this policy does not waive them. We use access controls and other reasonable safeguards to protect personal data, but no internet service can guarantee absolute security. We will assess and notify reportable data breaches as required by applicable law.

8. Retention and deletion

Account and workspace information is stored to provide the service; conversations do not currently have an automatic expiry. You can delete a conversation in its discussion controls. This removes its stored messages and associated discussion records from the active application database. Deleting a saved board does not delete its conversations.

Conversation deletion removes associated memory source links and can deactivate memories that no longer have supporting sources. Separately saved memory, review history or removal records may remain; use Memory controls or contact us for a broader deletion request. Disabling memory does not erase previously processed data. Deletion cannot recall an AI request already sent to a provider.

Some records can remain where reasonably needed for security, usage accounting, resolving disputes or legal obligations. In particular, usage records can remain after a conversation is deleted. Backups and provider-held records may retain copies until their applicable retention cycles expire. We do not promise that every copy disappears immediately. We must cease retaining personal data, or remove its association with individuals, when its purpose is no longer served and retention is no longer needed for legal or business purposes.

9. Your choices and requests

Contact us to request access to personal data in our possession or control, information about its use or disclosure where applicable, correction of inaccuracies, withdrawal of consent, or deletion of your account and associated data. We may verify your identity and explain any lawful exception, permitted fee, or information we must retain. We will respond within the period required by applicable law; if we cannot fulfil a PDPA access or correction request within 30 days, we will provide the required written update on when we can respond.

Withdrawal of consent may prevent us from continuing features that need that processing; we will explain the consequences. You can also revoke Google access in your Google Account settings. Revocation does not automatically delete your Board of Advisors account or stored content. If your concern remains unresolved, you may contact Singapore’s Personal Data Protection Commission.

10. Age and changes to this policy

The service is intended for people aged 18 or older. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

We may update this policy and will show the revised date. We will provide appropriate notice of material changes and obtain fresh consent where required. A policy update does not by itself authorise new uses of previously collected data that require your consent.

Contact

Caesar Sengupta

support-czbz@googlegroups.com

Privacy PolicyTerms & ConditionsBoard of Advisors