Privacy Policy

Last updated: November 22, 2025

1. Introduction

Welcome to Protheus AI ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our software architecture analysis platform.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password when you create an account
  • Project Data: Project descriptions, requirements, and specifications you submit for analysis
  • Payment Information: Billing details processed securely through Stripe (we do not store credit card information)
  • Communications: Messages, feedback, and support requests you send us

2.2 Automatically Collected Information

  • Usage Data: Pages visited, features used, time spent on platform
  • Device Information: Browser type, operating system, IP address
  • Analytics: We use Google Analytics and PostHog to understand platform usage
  • Cookies: Session management and preference storage

3. How We Use Your Information

  • Provide, maintain, and improve our architecture analysis services
  • Generate ADRs, feasibility reports, and project documentation
  • Process payments and manage subscriptions
  • Send service updates, technical notices, and security alerts
  • Respond to your support requests and feedback
  • Analyze platform usage to improve user experience
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your data with:

  • Service Providers: Supabase (database), Vercel (hosting), Stripe (payments), Render (API backend)
  • Analytics Tools: Google Analytics, PostHog (anonymized usage data)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In case of merger, acquisition, or sale of assets

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (HTTPS/TLS) and at rest
  • Secure authentication via Supabase Auth with Google OAuth
  • Regular security audits and monitoring
  • Access controls and role-based permissions
  • PCI DSS compliant payment processing via Stripe

6. Your Data Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and data
  • Export: Download your project data in portable format
  • Opt-out: Unsubscribe from marketing communications
  • Object: Object to certain data processing activities

To exercise these rights, contact us at: harlens.valdes@gmail.com

7. Data Retention

We retain your information for as long as your account is active or as needed to provide services. After account deletion, we may retain certain data for legal compliance, fraud prevention, and dispute resolution purposes (typically 30-90 days).

8. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We use Supabase (EU region) and Vercel (global CDN) with appropriate safeguards in place to protect your data.

9. Children's Privacy

Protheus AI is not intended for users under 18 years of age. We do not knowingly collect data from children. If you believe we have collected information from a child, please contact us immediately.

10. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Authentication, security, session management
  • Analytics Cookies: Google Analytics, PostHog usage tracking
  • Preference Cookies: Remember your settings and choices

You can control cookies through your browser settings, but disabling essential cookies may affect platform functionality.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or platform notification. Continued use of Protheus AI after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

13. GDPR Compliance (EU Users)

If you are located in the European Economic Area (EEA), you have additional rights under GDPR:

  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local data protection authority
  • Right to data portability in machine-readable format
  • Right to restrict processing in certain circumstances

Our legal basis for processing includes: consent, contract performance, legal obligations, and legitimate interests.