Privacy Policy
What One Water OS collects, how APAS.ai uses and retains it, and the choices available to visitors and contributors.
1. Who operates the service
One Water OS is operated and completely powered by APAS.ai. This policy applies to My Water OS, Workforce Competency OS, the public knowledge graph, Graph to Work Studio, Knowledge Risk Scan, Capture Call, OneWater TV, The Minute, Academy, Directory, Research Exchange, Lexicon, and related services.
2. Information we collect
Visitors: questions, pages and videos interacted with, navigation destinations clicked, referrals, feedback, votes, and information voluntarily supplied, such as name, email, organization, role, and sector. Graph to Work processes the requested outcome, user context, constraints, and selected public source paths. A draft remains in the browser unless the visitor requests steward review or asks One Water OS to email a secure report link. A report delivery record contains the report, verified source ledger, recipient, optional organization and role, delivery status, secure access token, branding snapshot, revision history, and coarse location. My Water OS members: role lens, competency pathway, followed topics and organizations, saved graph answers, public source paths, learning and assessment records, credentials, Capture questions, conversation activity, organization branding settings, logo, colors, report footer, and member-owned deliverables. Contributors: profile information, contributions, visibility choices, voice recordings, transcripts, and review history. Technical: a random first-party identifier, coarse Cloudflare location such as country, region, and city when available, and standard service logs. Raw IP addresses are not stored in the audience analytics layer.
Voice agents: When a visitor affirmatively starts a voice conversation, the service provider may process microphone audio, generated speech, conversation transcripts, agent events, and technical session information to operate and evaluate that conversation. The Droobi page keeps the displayed transcript in the browser unless the visitor requests delivery. An email or text delivery request stores the transcript, recipient address or phone number, an unguessable access token, delivery method, and delivery time for up to 30 days.
3. How we use information
We use information to provide answers, create requested work products, apply saved organization branding, deliver requested reports and voice transcripts, support editing and export, maintain a member deliverables dashboard, show delivery records to authorized Console administrators, operate accounts, personalize My Water OS, preserve learning progress, calculate competency evidence summaries, support organizational readiness reporting, moderate conversations, secure the service, credit contributors, and report aggregate product adoption. We do not sell personal information. We do not use private organizational contributions to generate public content.
4. Private delivery links and recipient access
A report or transcript delivery contains an unguessable link. Anyone who has that link can view the linked material until the record expires or is deleted. Report recipients may also edit, print, or download a Word copy. Transcript recipients may download a branded HTML copy or print it as a PDF. Recipients should not forward a private link to people who should not have access. A member-owned report also appears in that member's private Deliverables dashboard. Administrative Console access is separate from recipient access.
5. AI and editorial processing
Questions, work-product instructions and context, transcripts, and images submitted for extraction may be processed by AI service providers to deliver the requested feature. Graph to Work sends selected public graph evidence and separately labeled user context to the language model. It requires evidence gaps and assumptions to remain visible. Generated report fields pass through an editorial normalization step that removes em dashes, en dashes, and selected generic AI phrases. Human review remains required for consequential work.
6. Service providers and processing locations
Service providers may include Cloudflare for hosting and storage, Anthropic for language-model processing, ElevenLabs for speech services, Resend for email, Twilio for requested text delivery and capture calls, and Vimeo for video. Information may be processed in the United States and other locations where these providers operate.
7. Retention
Requested Droobi transcript delivery records and private links expire after 30 days. Detailed first-party audience events are designed to expire after 90 days. Optional professional audience profiles, Graph to Work steward-review requests, secure report links, delivery records, report revisions, and branding snapshots attached to those reports expire after 180 days. Knowledge Risk Scan follow-up requests expire after 12 months. Member profile branding remains until changed or the account is deleted. A transcript or draft saved only in a browser remains until that visitor clears it. Aggregate counters may be retained longer.
8. Public knowledge and government records
Public contributions may display contributor credit and remain in the commons under the published license. Private and organizational contributions do not automatically become public. A saved graph answer, My Water OS brief, competency score, interoperability export, Graph to Work report, delivery record, or review request does not automatically enter the public graph. Public-sector participants should consult their records officer because work products may be subject to applicable public-records requirements.
9. Your choices and requests
Members may update or remove organization branding, delete individual deliverables and disable their links, remove saved graph answers, export learning records, or delete their account. Account deletion removes desk personalization, branding, private deliverables, report links, learning state, competency selection, and saved graph answers. Public commons contributions may remain with credit preserved or may be anonymized where appropriate. Depending on location, users may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information. Requests may be sent to hardeep@apas.ai.