Back to home

Legal

Privacy policy

What we collect, why we collect it, and the choices you have.

Last updated: June 2026

1. Information you give us

Account data: your name, work email, workspace name and password (stored only as a bcrypt hash — never in readable form). If you sign in with Google we receive your name, email address and profile picture from Google.

Content data: the briefs, transcripts, proposals, client details, pricing and brand assets you create or upload in order to use the product.

Billing data: plan, invoices and payment status. Card and UPI details are handled entirely by our payment providers — they never reach our servers.

2. Information we collect automatically

Basic usage and diagnostic data: pages visited, feature usage, approximate country, device and browser type, and timestamps. IP addresses are stored hashed where retained at all.

Aggregated performance counters so we can see error rates and latency. We do not build advertising profiles and we do not sell data to anyone.

3. How we use it

To operate the product: generate proposals, render exports, share links, record client acceptance, and keep your workspace secure.

To bill you correctly, prevent abuse, provide support, and send essential service email such as email verification, password resets and payment receipts.

4. AI processing

When you generate or edit a proposal, the relevant text is sent to our AI providers to produce the draft. We send only what is needed for that request, keep no third-party copies beyond the provider's own transient processing, and record only metadata — provider, model, latency, and the size of the request — never the prompt content.

Your proposals are not used to train public models.

5. Service providers

We rely on a small set of processors: cloud hosting and database, AI model providers, an email delivery service for transactional email, and payment gateways. Each receives only the data required for its function.

6. Retention

Workspace and proposal data is kept while your account is active. Delete a proposal and it is removed from your workspace; request account deletion and we remove your personal data, keeping only what tax and accounting law requires us to retain for invoices.

Diagnostic events are short-lived and aggregated metrics are pruned on a rolling window.

7. Security

Traffic is encrypted in transit with TLS. Passwords are hashed with bcrypt, sessions use httpOnly cookies, staff access is role-restricted and audited, and sensitive keys live only in server-side secrets.

No system is perfect — if we ever discover a breach affecting your data, we will tell you.

8. Your rights

You can access, correct, export or delete your data, and object to non-essential processing. Email support@propojo.com and we will action verified requests within 30 days.

9. Children

Propojo is a business tool and is not intended for anyone under 18.

10. Changes

If we make a material change we will update this page and notify account owners by email before it takes effect.

Questions about this document? Write to support@propojo.com and a human will reply.