Privacy Policy
Table of Contents
- 1. Document Confidentiality and AI Training
- 2. What Information Do We Collect?
- 3. How Do We Use Your Information?
- 4. Third-Party Service Providers
- 5. Document Retention and Deletion
- 6. Data Security
- 7. Cookies and Tracking
- 8. Your Privacy Rights
- 9. International Data Transfers
- 10. Children
- 10a. Do-Not-Track Signals
- 10b. AI Service Provider Privacy Practices
- 11. Changes to This Policy
- 12. Contact
1. Document Confidentiality and AI Training
Core commitment: Your uploaded documents are strictly confidential. We will never train any AI models on your content. Our AI service providers (listed below) are also contractually prohibited from training models on data sent via their APIs.
Your documents are not shared with or sold to any third party. They are processed solely for the purpose of generating your feedback report and are handled in accordance with the retention policies described below.
2. What Information Do We Collect?
Information you provide
- Account information: your name, email address, and hashed password (or OAuth provider ID if you sign in with Google or Microsoft). Optionally, your institutional affiliation.
- Uploaded documents: grant proposals, research papers, solicitation documents, and other files you submit for review or store in your project workspace.
- Payment information: if you make a purchase, payment data is collected and processed by our Merchant of Record (Paddle). We do not store your credit card number or security code.
Information collected automatically
- Usage data: pages visited, features used, review types requested, and timestamps.
- Technical data: IP address, browser type, operating system, and device information, collected automatically via server logs.
- Analytics data: We use Cloudflare Web Analytics to collect anonymous, aggregated usage statistics (page views, visit counts, referral sources, country of origin). Cloudflare Web Analytics does not use cookies, does not track individual users across sites, and does not collect personally identifiable information. This data is used solely to understand overall traffic patterns and improve the service.
- Approximate location (country only): When you create an account, we record the two-letter country code of your connection, as reported by our network provider (Cloudflare). We may also record this country code when you interact with certain in-product buttons. We store only the country — never your IP address, city, or precise location — and we use it solely in aggregate to understand which countries our service is reaching. We do not use it to make decisions about individual users, and it is never displayed publicly or shared with third parties.
This information is used to maintain the security and operation of our service and for internal analytics. We do not use advertising cookies or third-party tracking pixels.
3. How Do We Use Your Information?
We process your information for the following purposes:
- To provide the review service — processing your documents through our AI systems and delivering feedback
- To create and manage your account and subscription
- To process payments and manage billing
- To send transactional emails (account verification, password reset, subscription notices)
- To maintain the security of our service (fraud prevention, abuse detection)
- To improve our service using aggregate, anonymized usage patterns
We do not sell your personal information. We do not use your documents to train AI models. We do not share your data with third parties for their marketing purposes.
4. Third-Party Service Providers
We share data with the following categories of service providers, each bound by contractual obligations to protect your information:
- AI processing — Anthropic (Claude API) and/or OpenAI: your documents are transmitted to our AI provider's API for analysis. Under their API terms, data sent via the API is not used for model training. API data may be retained briefly for standard safety monitoring, after which it is automatically deleted. See Anthropic's policies and OpenAI's enterprise privacy.
- Payment processing — Paddle: acts as our Merchant of Record, handling payment transactions and tax compliance globally. They receive your email and payment details but not your documents. See Paddle's privacy policy.
- Email delivery: our transactional email provider receives your email address and message content for the purpose of delivering account-related emails.
- Infrastructure: our hosting provider stores your data on secure servers. Access is restricted and encrypted. Encrypted backups are additionally stored off-site in DigitalOcean Spaces (object storage) in the United States.
We do not share your data with advertising networks, data brokers, or any other third parties beyond what is described above.
Business transfers: If ProofInk.AI is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, your personal data may be transferred as part of that transaction. Any successor entity will be bound by the commitments in this Privacy Policy with respect to your personal data, or you will be notified and given the choices required by applicable law before your data becomes subject to a materially different privacy policy.
5. Document Retention and Deletion
Retention periods depend on your plan. We are transparent about backup retention because deleted data may briefly persist in encrypted backups before being rotated out.
- Focused-review plans (Free, Professional): uploaded documents are treated as ephemeral and are automatically deleted from active storage within approximately 2 days of upload — typically within 48 hours, regardless of whether you close the page, log out, or take no further action. Deleted documents may persist in encrypted backups for up to 14 additional days before being permanently removed when the backup rotates.
- Lab Suite plans (3-Pack Lab Suite, Lab Bundle, Lab Suite, Institution, VIP): uploaded documents are retained in your project workspace for up to 1 year from upload. You can delete any document at any time from the document library. After 1 year, documents are automatically removed. Deleted documents may persist in encrypted backups for up to 14 additional days before being permanently removed when the backup rotates.
- Review reports (all plans): AI-generated feedback reports are retained for up to 1 year from creation. After 1 year, report content is automatically cleared. A minimal record (dates, review type, and quota usage) is preserved as the record of service delivery and to maintain accurate account history.
- Account deletion: you can permanently delete your account at any time from your profile settings. This deletes all your documents and clears all review content immediately, overriding the retention periods above. A minimal account-history record is retained for internal audit and abuse-prevention purposes only. This record includes: your original name and email (for fraud-prevention and account-recovery audit trails), tier at deletion, dates of registration and last login, counts of reviews completed, total cost and tokens consumed, and timestamps of when reviews ran. It does NOT include the content of any uploaded documents or AI-generated reviews.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- HTTPS/TLS encryption for all data in transit
- Encryption at rest for our managed database (account data, feedback reports, Q&A history) and for all off-site backups, which we additionally encrypt with AES-256 before upload
- Passwords hashed using scrypt with per-user salt (we never store plaintext passwords)
- CSRF protection on all forms and state-changing requests
- Rate limiting on authentication and sensitive endpoints
- Access controls ensuring you can only access your own data
- Input sanitization to prevent injection attacks
- Uploaded documents stored with randomized filenames in isolated project directories
While we take reasonable steps to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7. Cookies and Tracking
We use only essential cookies required for the service to function:
- Session cookie: keeps you logged in during your visit
- CSRF token: protects against cross-site request forgery attacks
We do not use advertising cookies, tracking pixels, third-party analytics cookies, or any non-essential cookies. Because we only use strictly necessary cookies, no cookie consent banner is required.
Our analytics service (Cloudflare Web Analytics) operates without cookies and without collecting personally identifiable information. It measures aggregate traffic patterns only and does not track individual users.
8. Your Privacy Rights
You have the right to:
- Access: view all personal data we hold about you (available in your profile)
- Delete: permanently delete your account and all associated data at any time
- Export: download your review reports in multiple formats (PDF, Word, Markdown)
- Correct: update your name, affiliation, and password in your profile settings
- Object: contact us to opt out of any data processing you disagree with
For EU/UK Residents
Under the GDPR (EU) and UK GDPR, our legal bases for processing your personal data are: (a) contract performance — providing the service you signed up for, (b) legitimate interest — service improvement using anonymized aggregate data, and (c) consent — where you have explicitly opted in. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
In addition to the general rights listed above, EU/UK residents have the right to:
- Data portability: receive your personal data in a structured, commonly used, machine-readable format
- Restriction of processing: request that we limit how we use your data while a complaint or dispute is resolved
- Object to automated decision-making: ProofInk.AI does not make any legally binding or similarly significant decisions based solely on automated processing
- Lodge a complaint: you have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, CNIL in France, BfDI in Germany, or your national supervisory authority)
For data protection inquiries, contact us at [email protected].
For California Residents
Under the CCPA, you have the right to know what personal information we collect, request deletion of your data, and opt out of the sale of personal information. We do not sell personal information.
For Canadian Residents
Under PIPEDA (Personal Information Protection and Electronic Documents Act) and applicable provincial privacy legislation, we process your information with your knowledge and consent. You may withdraw consent at any time, subject to legal or contractual restrictions. You have the right to access your personal information held by ProofInk.AI, challenge its accuracy, and request correction. Your data is transferred to and processed in the United States; by using the service, you consent to this transfer. We protect your data using safeguards comparable to those required under Canadian law, including encryption in transit and at rest. To make a privacy request, contact us at [email protected].
9. International Data Transfers
Your data is stored on servers in the United States. AI processing occurs via our AI providers' APIs (Anthropic and/or OpenAI), which operate in the United States. By using our service, you acknowledge that your data will be transferred to and processed in the United States.
For EU/EEA/UK users: We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914) and the UK International Data Transfer Agreement (IDTA) as the legal mechanisms for cross-border data transfers. These clauses are incorporated into our agreements with subprocessors and AI providers. You may request a copy of the applicable SCCs by contacting us.
For Canadian users: We ensure that personal information transferred outside Canada is protected by contractual or other safeguards that provide a comparable level of protection as required under PIPEDA and applicable provincial legislation.
Quebec residents (Law 25): If you are located in Quebec, additional rights apply to you under the Act respecting the protection of personal information in the private sector, as amended by Law 25. Specifically: (a) we obtain your consent before collecting your personal information, and that consent is requested separately from our other terms; (b) you have the right to request that we cease disseminating your personal information or to de-index any link attached to your name where dissemination causes you serious injury; (c) you have the right to receive the personal information you provided to us in a structured, commonly used technological format (data portability); (d) you have the right to be informed when your information is used to render a decision based exclusively on automated processing, and to submit observations on that decision — ProofInk.AI does not make automated decisions producing legal or similarly significant effects about you; and (e) we will notify you and the Commission d’accès à l’information of any confidentiality incident presenting a risk of serious injury.
For Swiss users: We rely on the Swiss-approved version of Standard Contractual Clauses for transfers of personal data from Switzerland.
We evaluate our subprocessors' data protection practices and require them to implement appropriate technical and organizational measures. A list of our current subprocessors is available on our Subprocessors page.
10. Children
ProofInk.AI is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
10a. Do-Not-Track Signals
Some web browsers transmit "Do-Not-Track" (DNT) signals. Because there is no universally accepted standard for how to respond to DNT signals, ProofInk.AI does not currently respond to DNT browser signals. However, we do not engage in cross-site tracking, behavioral advertising, or selling personal information to third parties. Our use of cookies is limited to strictly necessary session and security cookies as described in our Cookie Policy.
10b. AI Service Provider Privacy Practices
ProofInk.AI transmits document text to AI providers for analysis. For transparency, links to each provider's relevant privacy documentation are provided below:
- Anthropic: Privacy Policy — API data is not used for model training under commercial API terms.
- OpenAI: Enterprise Privacy — API data is not used for model training under enterprise/API terms.
Both providers are bound by contractual commitments that prohibit using your data for model training, as described in our Terms of Service and Subprocessors page.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by posting a notice of such changes prior to their implementation or by notifying registered users. The "Effective" date at the top of this page indicates when the policy was last revised. We encourage you to review the Privacy Policy frequently to stay informed.
12. Contact
For privacy-related questions, data access requests, or to exercise any of your rights, email [email protected].
ProofInk.AI LLC
56 Broad St #53795, Boston, MA 02109