Privacy Policy
Effective date: February 28, 2026
1. Introduction
ProposAI (“we,” “us,” or “our”) operates the ProposAI platform at getproposai.com. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service. By using the Service, you agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, and password when you register.
- Organization information: Company name, logo, brand colors, website, address, and phone number.
- Proposal content: Text, pricing, timelines, and other content you create within the Service.
- Client data: Names, email addresses, and contact information for your clients.
- Payment information: Billing details processed by Stripe. We do not store full card numbers.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, proposal activity, and timestamps.
- Device information: IP address, browser type, operating system, and user agent.
- Signature data: When a client signs a proposal, we log their IP address, user agent, and timestamp as part of the audit trail.
2.3 Information from Third Parties
- Clerk: Authentication and identity verification data.
- Stripe: Payment and subscription status information.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Process payments and manage subscriptions
- Send proposal emails, signature confirmations, and payment notifications
- Send transactional emails (account updates, billing receipts)
- Enforce our Terms of Service and detect fraud or abuse
- Generate AI content based on your inputs using third-party AI APIs
- Respond to support requests and communications
- Comply with legal obligations
We do not sell your personal data to third parties. We do not use your proposal content to train AI models.
4. Data Sharing
We share your information only with:
- Supabase: Database hosting and storage.
- Clerk: User authentication.
- Stripe: Payment processing and subscription management.
- Resend: Email delivery.
- Anthropic: AI content generation. Your prompts and content are processed by Anthropic’s API subject to their privacy policy.
- Vercel: Hosting and infrastructure.
- Law enforcement: When required by law or to protect rights and safety.
Your clients receive access to proposals you send them via a unique link. The proposal content and your organization branding is shared with them as part of the core functionality of the Service.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or compliance purposes (such as billing records).
Proposal data, including e-signature records, may be retained for up to 7 years to meet potential legal and audit requirements.
6. Security
We implement industry-standard security measures including encryption in transit (TLS), database row-level security, and access controls to protect your data. However, no system is completely secure and we cannot guarantee absolute security.
If you discover a security vulnerability, please report it to legal@getproposai.com.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your personal data.
- Portability: Request your data in a machine-readable format.
- Objection: Object to certain processing of your data.
- Restriction: Request restriction of processing in certain circumstances.
To exercise these rights, email us at legal@getproposai.com. We will respond within 30 days.
8. Cookies
We use essential cookies for authentication and session management (via Clerk). We do not use third-party advertising or tracking cookies. You can control cookies through your browser settings, but disabling essential cookies may prevent the Service from functioning correctly.
9. Children’s Privacy
The Service is not directed at children under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. International Data Transfers
Your data may be transferred to and processed in the United States and other countries where our service providers operate. By using the Service, you consent to these transfers. We ensure that appropriate safeguards are in place for any such transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or prominent notice in the Service. Continued use of the Service after the effective date of an updated Policy constitutes acceptance.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at: