Legal
Privacy Policy
Last updated: April 15, 2026
1. Information We Collect
We collect information you provide directly: account details (name, email, password), organization information, business context shared with agents, and the content of your conversations. We also collect usage data (pages visited, features used, timestamps) and technical data (browser type, IP address, device information).
2. How We Use Your Information
We use your data to provide and improve the Service: processing agent interactions, generating outputs, maintaining business memory, authenticating sessions, sending transactional emails, and analyzing usage patterns to improve features. We do not use your business context or conversations to train AI models.
3. Data Storage & Security
All data is stored using Supabase with PostgreSQL and row-level security (RLS). Generated assets are persisted to Supabase Storage immediately upon creation. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We conduct regular security audits and maintain SOC 2 compliance standards.
4. Business Memory & Context
AI agents retain business context (organizational details, preferences, client information, tone) to provide better outputs over time. This memory is private to your organization and is never shared with other users. You can view, edit, or delete business memory at any time through Settings.
5. Third-Party Services
We use third-party services to operate the platform: Supabase (database & storage), Vercel (hosting), ShortAPI (AI model access for generation), and Stripe (payment processing, coming soon). Each provider has its own privacy policy. We only share the minimum data necessary for these services to function.
6. Data Sharing
We do not sell, rent, or trade your personal information. We may share data with: service providers operating on our behalf, law enforcement when legally required, or successor entities in the event of a merger or acquisition. We will notify you of material changes to data sharing practices.
7. Your Rights
You have the right to: access your data, correct inaccuracies, delete your account and associated data, export your generated assets, restrict processing, and object to certain uses. For GDPR-covered users, you may also exercise data portability rights. Requests can be made through Settings or by contacting us.
8. Cookies & Tracking
We use essential cookies for authentication and session management. We use analytics cookies to understand usage patterns (you can opt out through browser settings). We do not use advertising cookies or third-party tracking pixels.
9. Data Retention
Account data and generated assets are retained for the duration of your subscription. Upon account deletion, personal data is removed within 30 days. Generated assets are retained for 30 days to allow export, then permanently deleted. Anonymized usage analytics may be retained indefinitely.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notification at least 14 days before they take effect. The 'Last updated' date at the top reflects the most recent revision.
For privacy inquiries, contact privacy@primeaiteam.com or visit our contact page.