← Back to home

Privacy Policy

Last updated: June 25, 2026

1. Overview

Prufer LLC ("Prufer", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and share information when you use the Prufer platform and related services ("Service"). By using the Service, you consent to the practices described in this policy.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, organization name, role, and authentication credentials. If you sign in with Google, we receive your Google profile information (name, email, profile picture).

Governance Data

When you use Prufer to govern AI agents, we process data about agent actions, policy evaluations, enforcement decisions, escalation events, and audit logs. This data is stored within your fleet and is unique to your organization.

Usage & Analytics

We collect anonymized usage data such as feature engagement, API call volumes, error rates, and performance metrics. This data is used to improve the Service and is not linked to individual users.

Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers or sensitive payment details on our servers. We retain only a Stripe customer ID and subscription status for billing management.

Cookies & Tracking

We use essential cookies for authentication and session management. We do not use third-party advertising cookies. Analytics cookies (if any) collect only anonymized, aggregated data. For full details on the cookies we use and how to manage your preferences, see our Cookie Policy.

3. How We Use Your Data

  • To provide, maintain, and improve the Prufer governance platform.
  • To authenticate users and manage access control.
  • To process payments and manage subscriptions via Stripe.
  • To send transactional emails (account setup, password resets, trial notifications, billing alerts).
  • To monitor service performance and respond to support requests.
  • To improve the Service based on aggregated, anonymized usage patterns.
  • To enforce our Terms of Service and Acceptable Use Policy.

4. Enforcement Engine & Data Processing

Prufer's core enforcement engine is deterministic and rule-based. It does not use large language models (LLMs) or probabilistic AI for enforcement decisions. Important details:

  • Your data is not used to train models without your explicit, written consent.
  • Enforcement evaluations are performed in real-time based on rules you configure. Results are stored only within your fleet's audit logs.
  • Governance outputs are operational tools, not legal advice. They should not be treated as compliance guarantees or safety certifications.
  • Some ancillary features (e.g., governance insights, benchmarking) may use aggregated, anonymized data. These features never expose your raw governance data.

5. Data Sharing

We do not sell your personal data. We may share data with:

  • Service providers: Stripe (payments), cloud infrastructure providers (hosting), and email providers (transactional emails). These providers are bound by data processing agreements.
  • Legal requirements: When required by law, regulation, subpoena, or court order.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, in which case the successor entity will be bound by this Privacy Policy.
  • With your consent: In other cases only with your explicit authorization.

6. Data Retention

Account data is retained for the life of your account. Governance audit logs are retained according to your plan's retention policy:

  • Free: 7 days
  • Pro: 30 days
  • Enterprise: 365 days or custom (per MSA)

Upon account deletion, personal data is removed within 30 days. Audit logs are removed according to your retention policy. You may request a data export before account deletion.

7. Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+), hashed passwords (bcrypt), API key rotation support, role-based access control (RBAC), and fleet-level data isolation. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. In the event of a data breach, we will notify affected users and relevant authorities as required by applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal data.
  • Export your governance data in a portable format.
  • Opt out of non-essential data processing.
  • Restrict or object to certain processing activities.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a data protection authority.

To exercise these rights, contact [email protected]. We will respond within 30 days.

9. International Data Transfers

If you are located outside the United States, your data may be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer. For EU/EEA data subjects, transfers are conducted under appropriate safeguards, including Standard Contractual Clauses (SCCs). Enterprise customers may enter into a Data Processing Agreement (DPA) to address specific transfer requirements.

10. Contact

For questions about this Privacy Policy, contact us at [email protected].