How Business Brain handles your business data
Reviewed 28 September 2026.
Reviewed 28 September 2026.
Files move in one direction: from your Drive, through a review you approve, into a database and a repository in your name, and on to whichever agent you choose.
Supabase’s Canadian region covers the database only. Google, GitHub and the AI model providers process data under their own regions and terms. Canadian database hosting does not mean every connected service stores or processes your data in Canada.
Every account in a Business Brain is yours. This is what we can reach in each one, and how you take that access back.
| Account | Owner | Attacca’s access | How to revoke it |
|---|---|---|---|
| Google Drive | You | Read-only access through Google sign-in (OAuth), granted by you. | Remove Attacca from the third-party connections in your Google account. |
| Supabase project | You, created in your account | Delegated access to set up and, on the retainer, maintain the database. | Remove our access from the project or organisation in your Supabase account. |
| GitHub repository | You, private, in your account | Collaborator access to set up and, on the retainer, maintain the repository. | Remove Attacca as a collaborator in the repository settings. |
| Your AI agent | You choose it and pay for it | None needed. We give you a handoff kit to point your agent at your repository and database. | Managed in your agent provider’s own settings. |
| Provider | What it holds or does | Where, and under whose terms |
|---|---|---|
| Google Drive | Holds your original files. Attacca reads them; nothing is moved until you approve. | Google’s own regions and terms. |
| Attacca operator tooling | Classifies your files so you can review and approve them in batches. | The AI model providers we use may process file content during classification. You can ask us to restrict which providers are used. |
| Supabase | Stores the structured database: projects, people, clients, tasks, decisions and documents. | A Canadian region. This covers the database only. |
| GitHub | Stores the text-based memory as a versioned private repository. | GitHub’s own regions and terms. |
| Your AI agent (Claude, ChatGPT, Codex or another) | Reads from and writes to your repository and database when you use it. | That provider’s own regions and terms. |
You can revoke Attacca’s access to any account at any time, from that account’s own settings, without asking us first. The database, the repository and your files stay where they are. If you cancel the retainer, the Business Brain stays with you, and our ongoing upkeep ends.
Business Brain data lives in your own accounts, and you delete it there, on your schedule. Records about our business relationship, such as correspondence and deposit records, are covered by our privacy policy.
| Area | You | Attacca |
|---|---|---|
| Accounts and billing | Own the Google, Supabase, GitHub and agent accounts, and pay the providers directly. | Set up the Business Brain inside those accounts. |
| Access | Grant access, decide which colleagues can see what, and revoke our access when you choose. | Use the access you grant only to deliver the setup and, if you keep it, the retainer. |
| Structure | Approve or re-route how files are sorted. | Write nothing to your structure until you approve it. |
| AI providers | Choose your agent and accept its terms. Tell us if content must stay away from particular providers. | Tell you which kinds of provider process content during classification and respect restrictions you set. |
| Retention and deletion | Keep or delete Business Brain data in your own accounts. | Answer questions about what our tooling touched during setup. |

Send questions about access, providers or a security concern to Lmduque@unify-ms.com. We reply within two business days, Pacific time.
This page was reviewed on 28 September 2026 and is updated when the setup or its providers change.