Google Play Compliance ? Regos

Privacy Policy

How Regos collects, uses, protects, retains, and deletes information for its AI-powered regulatory intelligence and compliance operating system.

Last Updated ? 23 July 2026

Overview

Regos is an AI-powered Regulatory Intelligence and Compliance Operating System that helps organizations monitor regulations, assess business impact, manage compliance workflows, and generate reports. This Privacy Policy explains what information Regos collects, how it is used, how it is protected, and how users can request access, correction, or deletion.

This page is public and does not require a Regos account.

Information collected

  • Name and email address used for account access, support, notifications, and workspace membership.
  • Authentication information, including authentication identifiers, sign-in provider, session metadata, and security events.
  • Organization and workspace information, including organization name, industry, regulatory verticals, workspace roles, invitations, and membership.
  • User-generated content, including business profile details, compliance actions, comments, uploaded documents, generated artifacts, board packs, exposure reports, and audit-related records.
  • Device and browser metadata, such as IP-derived request metadata, browser type, operating system, timestamps, and diagnostic information from application or infrastructure logs.
  • Usage analytics, if enabled, such as feature usage, page performance, error rates, and operational telemetry. Regos does not use third-party advertising trackers on this page.

How information is used

  • To create, authenticate, and secure user accounts.
  • To operate Regos workspaces and enforce organization-level permissions.
  • To monitor regulations, match them to business context, generate interpretations, assign actions, send alerts, and prepare reports.
  • To provide support, transactional email, security monitoring, audit logging, troubleshooting, and service improvement.
  • To comply with legal, regulatory, security, and contractual obligations.

AI processing

Regos uses AI-assisted workflows to summarize regulatory content, assess business impact, draft compliance actions, and generate reports. Inputs may include regulatory documents, organization profile context, selected user content, and workflow metadata required to complete the requested task.

  • Supabase provides authentication, database, object storage, Edge Functions, and related backend infrastructure.
  • Google Authentication may be used when a user chooses Google sign-in. Google processes information necessary to complete authentication.
  • OpenAI may be used if enabled by Regos for AI processing. Where configured, content sent to OpenAI is limited to what is necessary for the requested workflow.
  • Other configured AI providers may process regulatory or business context where required to provide requested AI features.

AI-generated content may be incomplete or inaccurate and should be reviewed against original regulatory sources before business or compliance decisions are made.

Cookies and local storage

Regos uses essential cookies and browser storage for authentication, session persistence, security, and preferences such as theme or navigation state. Users can clear cookies and local storage in their browser, but doing so may sign them out or reset preferences.

Security

Regos uses encrypted transport, managed authentication, role-based access, organization-scoped authorization, private storage, audit logging, and managed secrets. No online service can guarantee absolute security, so users should protect account credentials and promptly report suspected unauthorized access.

Data retention

Account and workspace data is retained while needed to provide the service, comply with legal obligations, maintain security, resolve disputes, and preserve audit trails. Some compliance, security, or audit records may be retained after account deletion where legally required or necessary for regulatory accountability. Backup copies may persist for a limited period before routine expiry.

User rights

Depending on applicable law, users may request access, correction, deletion, restriction, withdrawal of consent, or a copy of personal information associated with their account. Organization-level records may require approval by an authorized organization administrator or legal representative.

Account deletion

Users can request permanent deletion of their Regos account. See the public Delete Account page for instructions. Deleting a personal account may not delete organization-owned compliance records, audit logs, or records that Regos is legally required to retain.

Contact information

For privacy, data rights, or account deletion requests, contact dpo@team.bwe.one. For product support, contact support@team.bwe.one.