Protoperfect Labs ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
We help create, and respect, your Personal Intelligence Infrastructure (PII). Your intelligence stays yours.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, and authentication credentials when you create an account
- Profile Information: Optional details you choose to add to your profile
- Payment Information: Billing address and payment method details (processed securely by our payment processors)
- Communications: Messages, feedback, and support requests you send to us
- User Content: Data, prompts, and content you create or upload while using our services
1.2 Information Collected Automatically
- Usage Data: Features accessed, actions taken, timestamps, and interaction patterns
- Device Information: Browser type, operating system, device identifiers, and IP address
- Log Data: Server logs including access times, pages viewed, and error reports
- Cookies and Tracking: Essential cookies for functionality; optional analytics cookies with your consent
1.3 Information from Third Parties
- OAuth Providers: Basic profile information when you sign in with Google, GitHub, or other providers
- Analytics Partners: Aggregated, anonymized usage statistics
2. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: To provide, maintain, and improve our products and services
- Personalization: To customize your experience based on your preferences and usage patterns
- Communication: To send service updates, security alerts, and support messages
- Security: To detect, prevent, and respond to fraud, abuse, and security incidents
- Analytics: To understand usage trends and improve our offerings
- Legal Compliance: To comply with applicable laws and legal processes
⚡ Our Commitment: No AI Training on Your Data
We do not use your prompts, content, or personal data to train machine learning models. Your inputs remain private and are processed solely to provide you with the requested service. This is core to our Personal Intelligence Infrastructure.
3. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
- Service Providers: With vendors who perform services on our behalf (hosting, payment processing, analytics) under strict confidentiality agreements
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users
- Legal Requirements: When required by law, subpoena, or legal process, or to protect our rights and safety
- With Your Consent: When you explicitly authorize us to share specific information
4. Data Retention
We retain your information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Maintain security and prevent fraud
Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access with multi-factor authentication
- Infrastructure: SOC 2 Type II compliant cloud providers
- Monitoring: Continuous security monitoring and vulnerability assessments
- Incident Response: Documented procedures for security incident handling
While we implement robust protections, no system is completely secure. We encourage you to use strong passwords and protect your account credentials.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request restriction of processing in certain circumstances
- Withdrawal: Withdraw consent where processing is based on consent
To exercise these rights, contact us at team@protoperfect.io. We will respond within 30 days.
7. Cookies and Tracking Technologies
7.1 Types of Cookies We Use
- Essential Cookies: Required for basic site functionality (cannot be disabled)
- Analytics Cookies: Help us understand usage patterns (optional, with consent)
- Preference Cookies: Remember your settings and choices
7.2 Managing Cookies
You can control cookies through your browser settings. Disabling certain cookies may limit functionality.
8. Data Residency and International Transfers
8.1 Primary Data Location
Your data is primarily processed and stored in the United States. Our infrastructure is hosted on:
- Google Cloud Platform (us-central1, us-east1)
- Cloudflare (global edge network, US-headquartered)
- Vercel (US-based edge deployment)
8.2 International Transfers
If you are located outside the United States, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU Commission-approved clauses for EU-US transfers
- UK International Data Transfer Agreement: For transfers from the United Kingdom
- Transfer Impact Assessments: Documented assessments of destination country protections
8.3 Sub-processors
We engage the following sub-processors to provide our services:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Infrastructure, AI | United States |
| Cloudflare | CDN, Security | Global (US HQ) |
| Firebase | Auth, Database | United States |
| Stripe | Payments | United States |
| Vercel | Hosting | United States |
For complete details, see our Data Processing Addendum.
9. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
10. Third-Party Links
Our services may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy with a new "Last Updated" date
- Sending email notification for significant changes
- Providing in-app notification where appropriate
Continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions or requests:
| Channel | Detail |
|---|---|
| team@protoperfect.io | |
| Company | Protoperfect Labs |
| Response Time | Within 30 days |
13. Jurisdiction-Specific Disclosures
13.1 California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
- Right to correct inaccurate personal information
- Right to limit use and disclosure of sensitive personal information
13.2 European Economic Area Residents (GDPR)
If you are in the EEA, our legal basis for processing is:
- Contract: Processing necessary to provide services you requested
- Legitimate Interests: Processing for security, fraud prevention, and service improvement
- Consent: Where you have provided explicit consent
- Legal Obligation: Processing required by applicable law
You have the right to lodge a complaint with your local supervisory authority.