LEGAL · EFFECTIVE JULY 17, 2026
Privacy Notice
This notice describes high-level handling for the Profundo AI site, account portal, and customer API. It does not claim a certification or completed legal review.
Data we handle
Account data
We handle your email address, password hash, verification state, session records, admission/access state, fair-use restriction state, and account security events to create and protect your account.
Billing data
If paid access becomes available, we may handle commercial membership attribution, founding eligibility, subscription/customer references, payment status, billing events, and cancellation status. Payment service providers may process payment details under their own notices; the portal does not need to display full payment-card details.
Support data
We handle information you choose to provide through existing correspondence so we can investigate account, key, billing, privacy, access, or security questions. Do not include passwords, full API keys, or unnecessary sensitive content.
Usage and security data
We handle accepted-request identifiers and timestamps, account/key events, audit records, and limited technical/security information needed to enforce access, apply fair-use and service-protection controls, investigate failures, and protect the service. The customer usage view shows no more than 30 recent accepted-request timestamps and is not a complete activity or billing record.
API request handling
Messages and request settings sent to the API are processed by service systems and inference service providers to produce a response. Current source records accepted-request metadata rather than prompt or response content in customer usage history. That does not mean request content can never exist transiently in memory, transport, security processing, or service-provider systems. Do not send sensitive, regulated, or third-party data unless you have authority and have decided the service is appropriate.
How we use data
We use data to provide and secure accounts and API access, operate admission and billing boundaries, enforce fair-use and service-protection policy, respond to support requests, prevent misuse, diagnose failures, maintain audit records, and meet legal obligations. The current product has no documented sale-of-data or advertising function.
Service providers
We may use service providers for hosting, email delivery, billing, security, and inference. They process data to perform those functions under their own terms and our operational arrangements. Provider identities and detailed infrastructure are not published on customer pages.
Retention
We do not publish a fixed retention period or promise a deletion schedule because neither has been approved. Operational, security, founder/billing attribution, audit, dispute, legal, and backup records may persist, including after account deletion. A final category-by-category policy remains a pre-launch legal decision.
Cookies
The portal uses an HttpOnly session cookie to keep you signed in and protect authenticated pages. It is necessary for account operation, unavailable to browser scripts, and removed or invalidated through sign-out/session controls. The portal does not document advertising cookies.
Security
Controls include password hashing, expiring/revocable server sessions, one-time API-key display, and customer-key lookup material rather than plaintext keys. No system is perfectly secure. Protect credentials and report suspected exposure through Support without sending the secret.
Your choices
You may avoid optional support content, rotate or revoke an API key, sign out, request deletion from Settings after recent authentication, or stop using the service. Deletion can be unavailable when required cancellation work cannot complete; then the account remains unchanged. Use Support for access, correction, privacy, or deletion questions. Additional rights may apply based on location.
Children
The service is intended for adults and is not directed to children under 18.
Changes
We may update this notice as the service or its data handling changes. We will post the revised date and provide additional notice when required.
Contact
Use the Support route and existing correspondence for privacy requests.
Last updated: July 17, 2026.