Privacy Policy
Last updated: August 7, 2026
This Privacy Policy explains how Prabloe (“Prabloe”, “we”, “us”) collects, uses, discloses, retains, and protects personal data when you use the Prabloe platform, its applications, its programmatic interfaces, and any related service (together, the “Service”). It forms part of, and should be read with, our Terms of Use. Capitalised terms not defined here have the meaning given in the Terms.
We have written this policy to be specific rather than reassuring. Where a practice is uncertain, limited, or not yet available, it says so.
1. Who we are and the capacity in which we act
For personal data you give us as an individual user — your account details, your prompts, the content you create with the Service — Prabloe is the controller(or, under India’s Digital Personal Data Protection Act, 2023, the Data Fiduciary). We decide why and how that data is processed.
Where an organisation — a school, university, employer, or business — provisions the Service for its members and instructs us on its use, that organisation is the controller and Prabloe acts as a processoron its documented instructions under a Data Processing Agreement. In that case the organisation’s own privacy notice governs, this policy describes our processing on its behalf, and rights requests should be directed to the organisation first. See Section 16.
Contact for all privacy matters, including rights requests and the grievance mechanism required under the DPDP Act: privacy@prabloe.com.
2. Summary
| Question | Short answer |
|---|---|
| Do you read my conversations? | Not routinely. Staff access to identifiable content is restricted to named personnel, requires a documented reason (abuse investigation, a support request you raised, a legal obligation), and is logged. |
| Where are my conversations stored? | By default, in your browser’s local storage on your own device. Features that require a server — account settings, shared lessons, generation jobs, billing — store only what that feature needs, as listed in Section 4. |
| Do you train models on my content? | Only with consent, and you can withdraw it. Incognito sessions are never used, never stored, and never leave a record. See Section 8. |
| Do you sell my data? | No. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. |
| Does my content leave your systems? | Yes — the text of your prompt and the context needed to answer it is transmitted to the third-party model provider that serves your request. That is unavoidable: it is how the answer is produced. Section 6 describes exactly what is sent. |
| Do you see my card details? | No. Payments are taken by a third-party merchant of record. Card and bank details are entered on their systems and never reach ours. |
3. Personal data we process
We group personal data into the categories below. “Source” is where it comes from: you (you provide it), device(collected automatically from your browser or client), or third party(received from another service).
| Category | Examples | Source |
|---|---|---|
| Identity and account | Display name, email address, account identifier, authentication state, sign-in method, onboarding answers, profile preferences. | You; third party (your identity provider, if you sign in with one) |
| Content you submit | Prompts and questions, conversation history, uploaded documents and images, notes, custom instructions, learning-style descriptions, memory you import from another assistant, generation prompts. | You |
| Content we generate for you | Answers, lessons, slide decks, study plans, quizzes, flashcards, diagrams, problem sets, research summaries, generated images and video, and the metadata describing them. | Us, from your input |
| Voice | Speech transcribed to text in voice mode. Where transcription runs in your browser, the audio itself does not leave your device; where it does not, the audio is transmitted for transcription and is not retained after the transcript is produced. | You |
| Usage and telemetry | Features used, session counts and length, coarse location inferred from IP address, device and browser type, referring page, product events, thumbs-up/down feedback signals. | Device |
| Security and abuse | IP address, timestamps, request outcome codes, rate-limit counters keyed to your account identifier or IP address, aggregate spend counters, error reports and stack traces. | Device |
| Provider credentials you supply | Where the Service offers it, credentials for a model provider account of your own, together with the label and provider you assign them. | You |
| Billing | Credit balance, an append-only ledger of grants and spends, the payment processor’s transaction and event identifiers, plan status, and the billing country and tax identifiers the processor passes back to us. Never card numbers, CVV codes, or bank credentials. | You; third party (the merchant of record) |
| Correspondence | Support messages, bug reports, and anything you send us by email. | You |
Data we ask you not to send
The Service is not designed for, and must not be used to process, special category data under the GDPR (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation), payment card numbers, government identity numbers, or protected health information. Do not paste such data into a prompt or upload. If you do, you do so on your own instruction and at your own risk, and we may remove it.
4. Where each kind of data actually lives
This section is deliberately concrete, because “we store your data” is not an answer anyone can act on.
| Data | Location | Notes |
|---|---|---|
| Conversations, decks, study plans, settings, memory | Your browser’s local storage, on your device | Clearing site data removes them. Where you enable account sync, a copy is written to our database so the same account sees the same history on another device. |
| Message content sent for an answer | Not stored by us | Our chat endpoint writes no message content to any database and does not log request or response bodies. It records the outcome status and which provider served the request, and nothing more. |
| Account, profile, onboarding answers | Our managed database | Row-level security restricts each row to its owner. |
| Rate-limit and aggregate spend counters | Our managed database | Keyed to an account identifier or IP address. It holds no content by construction: the counter records that a request happened, never what it said. |
| Lessons you choose to share by link | Our managed database, readable by anyone with the link | Sharing is opt-in per lesson. Revoking the link removes public access. Treat a share link as public. |
| Image and video generation jobs | Our managed database | Stores your prompt, the model used, job status, and the result location. Accessible only through our server, which enforces ownership; there is no direct client access path. |
| Credits balance and ledger | Our managed database | Append-only. Required as a financial record. |
| Incognito sessions | Nowhere | See Section 5. |
5. Incognito
An incognito session is held in memory for as long as the tab is open and is written to no store — not your browser’s local storage, not your memory, not our database, not our analytics. Nothing about it is used to train or evaluate anything. It does not survive a reload, and closing or leaving the session destroys it. The prompt is still transmitted to the model provider that answers it, because there is no way to produce an answer without doing so; incognito controls what we keep, not the fact that a request leaves your device.
6. How the Service processes your content with AI models
Routing across multiple models
The Service is not a single model. A request is routed to one of several third-party models chosen by the capability you invoked (conversation, lesson generation, diagramming, research, image or video generation), the Prabloe model family you selected, availability, and capacity. Model names presented in the product are Prabloe’s own; the underlying model serving a given request may change at any time.
What is transmitted
When a request is made, we transmit to the selected provider:
- the text of your prompt;
- the conversation turns and attachments needed as context for it;
- the instructions that shape how Prabloe teaches — which may include your stated learning style, custom instructions, and relevant memory, because personalisation is not possible without them;
- model parameters and our own account credentials for that provider.
We do not transmit your email address, name, or account identifier to model providers.
What providers do with it
Providers process the request to return a response, under contractual terms that engage them as our processors and, where applicable, restrict use of the content to serving the request. We cannot and do not warrant a provider’s internal practices beyond those terms. Providers may retain content briefly for abuse detection under their own policies. A current list of the model providers in use is available from privacy@prabloe.com, and is provided as standard to organisations under a Data Processing Agreement.
Automated decision-making
The Service produces automated output — explanations, lessons, assessments of your answers, difficulty adjustments. This is automated processing, and it shapes what you are taught next. It does not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR: we do not use it to decide credit, employment, insurance, admission, or any comparable outcome, and you should not use the Service to make such decisions about anyone else. Automated assessments are advisory, are visible to you, and can be disregarded.
AI transparency
Content the Service generates is generated by artificial intelligence. It is labelled as such in the product, and you must not present it as human-authored where that distinction matters. Where generated audio, image, or video output is technically capable of carrying provenance metadata, we apply it.
7. Purposes and legal bases
For users in the EEA, the UK, and other jurisdictions that require a lawful basis, we rely on the bases below. “Legitimate interests” means we have assessed that our interest is not overridden by your rights; you may object at any time (Section 14).
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the Service: answer, teach, generate, save your work | Identity, content you submit, content we generate | Performance of a contract |
| Personalise teaching to your level and stated preferences | Content, usage, personalisation settings | Performance of a contract; consent where the setting is optional |
| Authenticate you and secure your account | Identity, security and abuse data | Performance of a contract; legitimate interests (security) |
| Prevent abuse, enforce limits, protect capacity and cost | Security and abuse data, usage | Legitimate interests (integrity and availability of the Service) |
| Diagnose faults and improve reliability | Usage, telemetry, error reports | Legitimate interests (a working product) |
| Evaluate, fine-tune, and train models | Content you submit, content we generate, feedback signals | Consent, withdrawable at any time |
| Take payment and maintain financial records | Billing data, identity | Performance of a contract; legal obligation (accounting and tax) |
| Route requests using credentials you supply | Provider credentials you supply | Performance of a contract, at your instruction |
| Send service and security notices | Identity | Legitimate interests; legal obligation for breach notification |
| Send product news and marketing | Identity | Consent, withdrawable in every message |
| Comply with law; establish or defend legal claims | Any category, as strictly necessary | Legal obligation; legitimate interests |
Under the DPDP Act, processing is on the basis of your consent or a legitimate use recognised by that Act, and the notice requirements of Section 5 of that Act are met by this policy and the consent presented at sign-up.
8. Model training, and how to turn it off
We use your content to train or fine-tune models only where you have consented.Consent is requested at sign-up and is recorded against your account. You can withdraw it at any time in the product’s privacy settings or by writing to privacy@prabloe.com.
Regardless of your setting, the following are never used for training:
- incognito sessions;
- content processed for an organisation under a Data Processing Agreement;
- billing data and the credits ledger;
- content submitted by a user we know to be a child;
- requests routed through provider credentials you supplied yourself — that content is yours and your provider’s, and we take no training interest in it.
Where training does occur, we take reasonable steps to remove direct identifiers and to aggregate before use. Withdrawing consent stops future use immediately; it does not reverse processing already carried out, and parameters already learned by a trained model cannot practically be disentangled from it — a limitation of the technology, not a policy choice. Withdrawal will reduce personalisation quality, and we will say so rather than pretend otherwise.
9. Provider credentials you supply
Where the Service offers you the option to connect a model provider account of your own, the following applies. Credentials you supply are secrets; we treat them as such.
- They are encrypted before storage and are never written to logs, analytics, error reports, or support tickets.
- After they are saved we display only a non-reversible fragment sufficient to identify which credential is which. We cannot show you the full value again, and we cannot recover it for you.
- They are used for one purpose: to authenticate requests you initiate to the provider you nominated. They are never used for another user, for our own workloads, or for evaluation or training.
- Deleting a credential removes it from our systems. It does not revoke it at the provider — do that in the provider’s own console, which is the only place it can be done.
- When a request runs on your credential, the provider is your counterparty: their terms, their privacy policy, their retention, and their charges apply to that request directly, and we have no visibility into or control over them.
10. Payments
Where the Service is offered on paid terms, payment is taken by a third-party payment provider acting as merchant of record. That provider is the seller for the transaction and is responsible for the checkout, for payment-card handling under PCI DSS, and for the assessment and remittance of applicable taxes.
We never receive your card number, CVV, or bank credentials. They are entered on the provider’s systems. What the provider returns to us, and what we store, is: a transaction identifier, an event identifier used to make webhook delivery idempotent, the purchase outcome, what you are entitled to as a result, and the billing country and any tax identifier needed for our records. We hold a credit balance and an append-only ledger of grants and spends against your account, which is what lets you audit your own usage and lets us investigate a billing dispute.
11. Recipients and sub-processors
We disclose personal data to the categories of recipient below, each under a written contract imposing confidentiality and processing restrictions.
| Category | Purpose | Data disclosed |
|---|---|---|
| Application hosting and edge network | Serve the Service; deliver static assets | Security and abuse data, usage; request payloads in transit |
| Managed database and authentication | Store account data; issue and verify sessions | Identity, account, and the server-side data listed in Section 4 |
| Model and inference providers | Produce responses and generated media | Prompt text, context, attachments (see Section 6) |
| Identity provider, where you use one to sign in | Authenticate you | Email address and the profile fields you authorise |
| Payment provider (merchant of record) | Take payment; handle tax and invoicing | Billing data. Handled by them, not by us. |
| Product analytics | Understand feature usage in aggregate | Usage and telemetry. Not prompt or response content. |
| Email delivery | Sign-in codes, service and security notices | Email address, message content we send you |
| Professional advisers, auditors, insurers | Legal and financial advice; audit | As strictly necessary, under professional duties of confidence |
A current, named list of sub-processors is available from privacy@prabloe.com and is supplied as standard to organisations under a Data Processing Agreement, together with our commitment to give advance notice of a change and to accept reasonable objections.
We also disclose personal data where required by valid legal process, where necessary to protect the rights, property, or safety of users, the public, or Prabloe, and in connection with a merger, acquisition, financing, or sale of assets — in which case the recipient remains bound by this policy for data already collected, and we will give notice where the law requires it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We use no third-party advertising cookies or advertising trackers.
12. International transfers
Prabloe and its providers operate globally, and personal data may be processed in countries other than your own, including the United States and India. Where personal data is transferred out of the EEA or the UK to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where the UK GDPR applies), supported by a transfer risk assessment and, where appropriate, supplementary technical measures including encryption in transit and at rest and minimisation of the data transferred. You may request a copy of the relevant safeguards from privacy@prabloe.com.
13. Retention
We keep personal data no longer than necessary for the purpose it was collected for. The periods below are maximums; we delete earlier where we can.
| Data | Retention | Why |
|---|---|---|
| Content held in your browser | Until you delete it or clear site data | It is on your device; you control it |
| Incognito session content | Not retained at all | Never written anywhere |
| Account and profile | Life of the account, then up to 30 days | A short window to recover an accidental deletion |
| Synced content, where you enable sync | Life of the account, then up to 30 days | Same |
| Shared lesson links | Until you revoke the link or delete the account | The link must keep working while you intend it to |
| Generation jobs and their prompts | Up to 90 days | Deliver the result, support retries, investigate failures |
| Rate-limit and spend counters | Up to 90 days | Abuse patterns are only visible over time |
| Server and security logs | Up to 90 days, longer for an open investigation | Security, debugging, incident response |
| Provider credentials you supply | Until you delete them or close the account | Held only to serve your own requests |
| Credits ledger, invoices, tax records | As required by applicable accounting and tax law, typically up to 8 years | Legal obligation; survives account deletion |
| Support correspondence | Up to 24 months | Continuity of support and dispute handling |
| Consent and preference records | For as long as needed to evidence the choice | We must be able to show what you agreed to and when |
Backups are retained on a rolling schedule and are overwritten in the ordinary course. Data you delete may persist in a backup until that backup ages out; it is not restored to live systems.
14. Your rights
Subject to the law that applies to you, you have the right to access your personal data and obtain a copy; rectify inaccurate data; erase data; restrict or object to processing, including processing based on legitimate interests and direct marketing; port data to another controller in a structured, machine-readable format; withdraw consent at any time; and not be discriminated againstfor exercising any of them. Under the DPDP Act you additionally have the right to nominate another person to exercise your rights in the event of death or incapacity, and the right to a grievance redressal mechanism — which is the contact address below.
Much of this is self-service: content in your browser is deletable from Settings, and account data is exportable and deletable from your account settings. For anything else, write to privacy@prabloe.com. We respond within the period the applicable law requires — one month under the GDPR (extendable by two where a request is complex), 45 days under California law (extendable by 45). We will ask you to verify your identity before acting on a request, and we may refuse a request that is manifestly unfounded or excessive, telling you why.
Complaints.You may complain to your supervisory authority — in the EEA, the authority where you live or work; in the UK, the Information Commissioner’s Office; in India, the Data Protection Board. We would prefer you raise it with us first, but you are not required to.
California
The categories in Section 3 map to the CCPA/CPRA categories of identifiers, commercial information, internet activity, geolocation (coarse, IP-derived), audio, and inferences. The business and commercial purposes are those in Section 7; the recipients are those in Section 11. We do not sell or share personal information and have not in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16. You may exercise your rights, including through an authorised agent, at privacy@prabloe.com. Sensitive personal information is used only for purposes permitted without a right to limit.
15. Children and learners under the age of majority
The Service is not directed to children under 13, and we do not knowingly collect their personal data. If you are between 13 and the age of majority where you live, you may use the Service only with the consent of a parent, guardian, or your educational institution, who accepts the Terms on your behalf. In jurisdictions setting a higher digital-consent age — up to 16 in parts of the EEA — that higher age applies.
Under India’s DPDP Act, processing the personal data of a child requires verifiable parental consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children in any jurisdiction. Where we know a user is a child, their content is excluded from model training.
If you believe a child has provided us personal data without the required consent, write to privacy@prabloe.com and we will delete it.
Schools and universities. Where an institution provisions the Service for students, it is the controller, we are the processor, and we process student data only on its documented instructions. We do not use student data for advertising and do not use it for model training under those arrangements. Institutions subject to student-records legislation should contact us for the applicable contractual terms before rolling the Service out.
16. Enterprise and institutional customers
On request, and without charge, we make available to organisations:
- a Data Processing Agreement incorporating Standard Contractual Clauses and the UK Addendum;
- a current named sub-processor list, with advance notice of changes and a right to object;
- a description of our technical and organisational measures (Section 17);
- a completed security questionnaire, and support for your own review;
- a contractual security-incident notification commitment, without undue delay and in any event within 72 hours of our becoming aware;
- assistance with data-subject requests, data-protection impact assessments, and prior consultations;
- deletion or return of processed data on termination.
What we do not claim. Prabloe does not currently hold SOC 2, ISO/IEC 27001, or any comparable third-party audit certification, and is not configured for HIPAA-regulated workloads. We would rather tell you that than be asked in a procurement review. Write to privacy@prabloe.com to discuss what your programme requires.
17. Security
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption. All traffic is served over HTTPS with modern TLS. Data at rest in our managed database is encrypted. Credentials you supply are additionally encrypted at the application layer before storage.
- Credential isolation.Provider and platform secrets are held server-side in the deployment platform’s secret store and are never exposed to a browser. Privileged database keys are used only by server code.
- Access control. Row-level security restricts each record to its owner. Sensitive tables are readable only by server-side code with no client-facing policy at all. Administrative access to production is limited to named individuals, requires multi-factor authentication, and is logged.
- Abuse and cost controls.Durable per-identity and per-IP rate limits, request size limits, and an aggregate spend ceiling. Paid entitlement checks fail closed — if we cannot confirm your balance, we decline the request rather than proceed.
- Data minimisation by design. The chat endpoint persists no message content; rate-limit records hold no content at all; incognito writes nothing anywhere. These are properties of the code, tested in our test suite, not policy promises.
- Change control. Changes go through version control and review; automated tests enforce security-relevant invariants; secrets are excluded from the repository.
No system is perfectly secure. Use a unique credential, enable the strongest sign-in method offered, keep your device secure, and tell us immediately at security@prabloe.com if you suspect unauthorised access. We welcome good-faith vulnerability reports to that address and will not pursue legal action against researchers who report responsibly, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosure.
18. Personal data breaches
If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to you, we will notify you directly and without undue delay, describing what happened, the likely consequences, and what we are doing about it. Where we act as a processor, we will notify the controller without undue delay and assist with their own notification duties.
19. Cookies and local storage
We use the minimum set of browser storage the Service needs. We do not use third-party advertising cookies.
| Kind | Purpose | Consent needed? |
|---|---|---|
| Authentication cookies and tokens | Keep you signed in; protect against request forgery | No — strictly necessary |
| Local storage: conversations, decks, plans, settings | Your work, kept on your device | No — strictly necessary to the feature you asked for |
| Preference storage | Remember interface choices such as sidebar state | No — strictly necessary |
| Product analytics | Aggregate feature usage and performance | Yes where required by local law; declining does not restrict the Service |
You can clear browser storage at any time in your browser settings; doing so signs you out and removes locally held work. We honour Global Privacy Control signals where the law requires it.
20. Changes to this policy
We update this policy as the Service changes. The “Last updated” date at the top always reflects the current version. For material changes — a new purpose, a new category of recipient, a change in legal basis — we will give notice in the product or by email before the change takes effect and, where the change relies on consent, we will ask again rather than assume. We keep prior versions and will provide one on request.
21. Contact
Privacy questions, rights requests, and grievances: privacy@prabloe.com. Security reports: security@prabloe.com. Everything else: legal@prabloe.com. We acknowledge privacy correspondence within 7 days.