Privacy Policy
Last updated: March 25, 2026
1. Introduction
Proofwork Labs ("we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our website, MCP servers, APIs, and related services ("Services").
2. Information We Collect
Account information: When you create an account, we collect your email address, display name, and authentication provider (Google, Microsoft, or email/password). If you sign in via a third-party provider, we receive your name and email from that provider.
Organization information: If you create or join an organization, we collect the organization name, billing email, and email domain for automatic team member association.
Billing information: Payment processing is handled by Stripe. We do not store credit card numbers. We store your Stripe customer ID, subscription status, and billing history references.
Usage data: We record MCP tool calls including timestamps, tool names, success/failure status, and response latency. This data is associated with your user ID and organization for billing and analytics purposes.
Product inputs: When you use our MCP tools, product descriptions and related inputs are processed to deliver classification results. We do not persistently store the content of your product descriptions beyond what is needed to complete the request.
Technical data: We collect standard web server logs including IP addresses, browser type, and referring pages. Our hosting provider (Google Cloud) may collect additional infrastructure-level data.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Services
- Authenticate your identity and manage your account
- Process billing and manage subscriptions
- Track usage for freemium tier limits and billing
- Send transactional communications (account verification, billing notifications)
- Monitor and prevent abuse or unauthorized access
- Comply with legal obligations
4. What We Do Not Do
- We do not sell your personal information to third parties
- We do not use your product descriptions or inputs to train AI models
- We do not share your data with third parties for their marketing purposes
- We do not serve advertising
5. Information Sharing
We share information only in the following circumstances:
- Service providers: We use Google Cloud Platform for hosting, Stripe for payment processing, and Google Cloud Identity Platform for authentication. These providers process data on our behalf under their respective privacy policies.
- Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- With your consent: We may share information for other purposes with your explicit consent.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including encryption in transit (TLS/HTTPS), encrypted storage for sensitive credentials, and access controls. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
We retain your account information for as long as your account is active. Usage data is retained for billing reconciliation and analytics. If you delete your account, we will delete your personal information within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records).
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Object to or restrict certain processing activities
- Export your data in a portable format
To exercise these rights, contact us at [email protected].
9. Cookies and Tracking
We use Google Analytics to understand how visitors use our website. We use authentication cookies (session tokens) to maintain your signed-in state. We do not use third-party advertising cookies or cross-site tracking.
10. Children's Privacy
The Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.
11. International Data Transfers
Our Services are hosted in the United States (Google Cloud, us-central1). If you access the Services from outside the United States, your information will be transferred to and processed in the United States.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the email address associated with your account. Continued use of the Services after changes constitutes acceptance of the updated policy.
13. Contact
Questions about this Privacy Policy may be directed to [email protected].