prom
ProductSystemWorkflowsWhy PROMPricingDocs
Sign inGet early access →

Legal

Privacy Policy

Last updated: May 16, 2026

This Policy explains what we collect, how we use it, and the rights you have. This document is provided for the private beta and is being finalized for the public release.

Contents
  1. 01Overview
  2. 02Information we collect
  3. 03How we use information
  4. 04AI processing and your content
  5. 05Legal bases for processing
  6. 06How we share information
  7. 07International data transfers
  8. 08Data retention
  9. 09Security
  10. 10Your rights and choices
  11. 11Cookies and similar technologies
  12. 12Children's privacy
  13. 13Third party links and services
  14. 14Changes to this Policy
  15. 15Contact us

01Overview

This Privacy Policy explains how PROM (we, us, or our) collects, uses, shares, and protects personal information when you use our websites, applications, and services (the Service).

In short: your graph is yours. We process your information to operate the Service for you, we do not sell personal information, and we do not use your content to train models that serve other customers.

Where we process personal data on behalf of an organization that uses the Service, that organization is the controller and we act as a processor under its instructions. This Policy then describes our practices, while the organization's own privacy notice governs its decisions about that data.

02Information we collect

Account information: when you register we collect your name, email address, password credentials, and optional profile details such as an avatar.

Organization information: workspace and organization names, member roles, invitations, and domain verification details.

Content: the specifications, documents, research, decisions, tickets, comments, and other materials you and your team create or upload (your Content). Your Content may itself contain personal information that you choose to include.

Usage information: actions you take in the Service, feature usage, log data, approximate location derived from IP address, and diagnostic information used to operate and improve the Service.

Device information: browser type, operating system, device identifiers, and similar technical data.

Cookies and similar technologies: identifiers used for authentication, preferences, security, and analytics, as described in the Cookies section.

03How we use information

We use information to: provide, maintain, and secure the Service; authenticate users and manage accounts and organizations; deliver AI features you request; respond to support requests; monitor, prevent, and investigate abuse, fraud, and security incidents; analyze and improve the Service; and communicate with you about updates, security, and administrative matters.

We process information only for the purposes described here or for compatible purposes, and we minimize the personal data we use to what is necessary for each purpose.

04AI processing and your content

AI features draft documents, summaries, plans, and other materials using your Content and inputs so the output is relevant to your context.

We do not use your Content to train foundation models that serve other customers. Where AI features are delivered using third party model providers, content is processed under contractual terms that restrict use to providing the feature and prohibit training on your data, to the extent offered by the provider.

AI output is generated for human review and may be inaccurate. You remain responsible for reviewing it before relying on it.

05Legal bases for processing

Where the GDPR or similar laws apply, we rely on the following legal bases: performance of a contract, to provide the Service you request; legitimate interests, to secure, analyze, and improve the Service in ways that do not override your rights; consent, where required, for example for certain cookies or marketing; and legal obligation, where processing is required by law.

Where we rely on consent, you may withdraw it at any time without affecting prior processing.

06How we share information

Within your organization: content and activity are visible to other members according to the roles and permissions configured by your organization.

Service providers and subprocessors: we use vetted vendors for hosting, infrastructure, communications, analytics, and AI model inference. They may process information only on our instructions and under confidentiality and data protection obligations. A current list of subprocessors is available on request.

Legal and safety: we may disclose information if required by law, to enforce our terms, or to protect the rights, property, or safety of users, the public, or us.

Business transfers: if we are involved in a merger, acquisition, or asset sale, information may be transferred subject to this Policy and appropriate safeguards.

We do not sell personal information and we do not share it for cross context behavioral advertising.

07International data transfers

We may process and store information in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards such as Standard Contractual Clauses or an equivalent legally recognized mechanism.

08Data retention

We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.

When you delete content or close your account, we delete or anonymize associated personal information in the ordinary course, subject to a limited grace period, legal retention requirements, and routine backups that are cycled out over time.

09Security

We use technical and organizational measures designed to protect information, including encryption in transit, access controls, role based permissions, audit logging, and monitoring.

No method of transmission or storage is completely secure. We work to protect your information but cannot guarantee absolute security, and you are responsible for safeguarding your account credentials.

10Your rights and choices

Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. You may also have the right to lodge a complaint with a supervisory authority.

If your data is controlled by an organization that uses the Service, please direct requests to that organization, and we will assist them as a processor. Otherwise, you can exercise your rights through the contact page, and we will respond within the time required by applicable law.

We will not discriminate against you for exercising any of these rights.

11Cookies and similar technologies

We use strictly necessary cookies for authentication and security, preference cookies to remember settings such as theme, and analytics cookies to understand and improve usage.

You can control non essential cookies through your browser settings or any consent controls we provide. Disabling some cookies may affect how the Service works.

12Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.

13Third party links and services

The Service may link to or integrate with third party products. Their privacy practices are governed by their own policies, and we are not responsible for them. Please review those policies before providing information.

14Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice through the Service or by other reasonable means and update the date above. Your continued use after a change takes effect constitutes acceptance of the updated Policy.

15Contact us

For privacy questions, requests, or to reach the person responsible for data protection, use the contact page. For procurement, you can request our Data Processing Addendum and current list of subprocessors.

prom

The AI-native operating system for product teams. From idea to launch, on a single system.

operational· status.prom.systems
product
  • Features
  • System
  • Workflows
  • Why PROM
  • Pricing
  • Changelog
resources
  • Docs
  • API reference
  • Brand
  • Status
company
  • About
  • Blog
  • Careers
  • Contact
legal
  • Terms
  • Privacy
  • Security
  • DPA
© 2026 prom.systems — built with intent.
v0.2 · private beta