Privacy Policy

How Prolytics collects, uses, stores, shares, and protects information.

Prolytics OS · Current Insights and policies are preserved while the new version is prepared.
Markdown

Prolytics Limited

Last updated: July 30, 2026

1. Introduction

Prolytics Limited ("Prolytics," "we," "us," or "our") operates Prolytics OS and the website located at prolyticshq.com.

This Privacy Policy explains how we collect, use, store, disclose, and protect information when you:

  • visit our website;
  • create an account;
  • use the Prolytics platform;
  • connect third-party sources;
  • interact with support, billing, or product workflows.

For account, website, billing, support, security, and Prolytics product-usage data, Prolytics generally acts as a controller.

For data that business customers connect to the Services from their own systems, Prolytics generally acts as a processor or service provider on behalf of the customer. The customer remains responsible for determining what data is provided to Prolytics and for obtaining required notices, consents, permissions, and legal bases.

Providing account, authentication, billing, workspace, and service-operation information may be required to create an account, use paid features, connect integrations, or receive support. If you do not provide required information, we may not be able to provide some or all of the Services. Website analytics, advertising measurement, and other non-essential cookies are optional and may be controlled through the cookie consent banner where required.

1.1 Hong Kong Personal Information Collection Statement

Prolytics Limited is registered in Hong Kong. For personal data that we collect directly through our website, account, support, billing, and product workflows, Prolytics generally acts as the data user. For Customer Data that a business customer connects from its own systems, Prolytics generally acts as a data processor or service provider on the customer's documented instructions.

We collect and use personal data for the purposes described in this Privacy Policy, including to:

  • provide, authenticate, secure, operate, and support the Services;
  • manage accounts, workspaces, permissions, subscriptions, payments, and credits;
  • connect customer-selected sources and provide product workflows;
  • communicate with customers and respond to requests;
  • monitor reliability, investigate incidents, prevent abuse, and protect the Services;
  • improve the website and Services where permitted; and
  • comply with legal obligations and enforce our agreements.

Personal data may be transferred to the service providers, subprocessors, professional advisers, authorities, courts, and regulators described in this Privacy Policy and our Subprocessor List. We do not use personal data for purposes incompatible with the purposes described here without providing additional notice or obtaining consent where required.

Some information is required to create an account, provide paid Services, connect an integration, process a payment, or respond to a request. If required information is not provided, we may be unable to provide the relevant Service or complete the requested action. Optional analytics and advertising-related technologies are managed through the cookie controls described in our Cookie Policy.

You may request access to or correction of personal data as described in the section titled "Your rights". To make a request or ask about our personal data practices, contact legal@prolyticshq.com. Where information is collected through a specific form or workflow, we may provide additional collection notice at or before the point of collection.

2. Information we collect

2.1 Account and workspace information

We may collect:

  • name;
  • email address;
  • organization or workspace name;
  • user role and permissions;
  • authentication session information;
  • login method, such as magic link, GitHub login, or Google login;
  • workspace settings and configuration;
  • support communications;
  • product usage information related to your use of Prolytics.

Authentication is implemented using Better Auth and related local application systems.

2.2 Billing information

Payments and subscriptions are processed through Stripe.

We may store billing and subscription records such as:

  • Stripe customer, subscription, payment, invoice, and event identifiers;
  • plan, subscription, and credit information;
  • payment status and transaction metadata;
  • credit balances and credit transaction history;
  • billing-related communications.

Prolytics does not store full payment card numbers or CVV codes.

Raw Stripe webhook JSON may be stored temporarily for billing audit/debugging and is redacted after 180 days by retention cleanup. Canonical billing, payment, subscription, credit, tax, legal, and audit records may be retained for longer where needed.

2.3 Customer data processed through the platform

Customers may connect Prolytics to product analytics, billing, reliability, error monitoring, and related business systems. Depending on the connected sources and workflows used, Prolytics may process and store:

  • product usage metrics;
  • analytics event metadata;
  • source identifiers such as customer, person, event, subscription, issue, or payment identifiers;
  • Stripe customer, subscription, payment, and billing identifiers;
  • Sentry issue, error, trace, or reliability records;
  • PostHog analytics metadata, event catalog information, schema information, or related source data;
  • provider snapshots and evidence packs;
  • schema mappings and connector state;
  • derived metrics and KPI summaries;
  • Health snapshots, alert history, Radar findings, watches, and issue workspace records;
  • Engine prompts, investigation sessions, messages, evidence manifests, AI outputs, and visualizations;
  • logs and operational records needed to secure, debug, or support the Services.

Prolytics minimizes raw provider data where possible, but it stores the service records needed to operate the product, preserve customer-visible history, support investigations, maintain auditability, process billing, and secure the platform.

2.4 Website and analytics information

When you visit our website or use the Services, we may collect:

  • page views;
  • device and browser information;
  • approximate location derived from IP address;
  • session information;
  • referring page or campaign information;
  • interactions with website or product pages.

We may use Google Analytics and PostHog for website and product analytics. Google Tag Manager may manage consented tags on public website and documentation routes. Browser-based PostHog analytics and Google tags are controlled through the relevant cookie consent choice where required.

2.5 AI feature information

When you use AI-assisted features, Prolytics may process and store:

  • user prompts;
  • investigation questions;
  • selected metrics and evidence;
  • provider context;
  • source metadata;
  • AI outputs;
  • investigation history;
  • support, debugging, auditability, and security records related to AI feature usage.

Prolytics may use Google Vertex AI/Gemini and Anthropic to provide AI-assisted features.

Prolytics stores prompts, evidence packs, AI outputs, and investigation history to provide customer-visible service history, support, security, debugging, auditability, and workflow continuity.

Production customer prompts, evidence packs, and AI outputs are not reused by Prolytics for model training or evaluation datasets by default. Non-operational reuse requires separate customer authorization.

AI providers may process AI inputs and outputs according to their own service terms, data-processing terms, retention settings, abuse-monitoring rules, and customer configuration.

3. How we use information

We use information to:

  • provide, operate, maintain, and improve the Services;
  • authenticate users and manage accounts;
  • manage workspaces, roles, permissions, and access;
  • connect to customer-selected data sources;
  • generate metrics, alerts, findings, investigations, issue records, visualizations, and reports;
  • provide AI-assisted outputs;
  • process payments, subscriptions, invoices, credits, and refunds of eligible failed-investigation credits;
  • provide support and respond to inquiries;
  • monitor performance, reliability, abuse, and security;
  • debug, test, and maintain service quality;
  • comply with law, enforce agreements, and protect rights;
  • analyze website and product usage, where permitted.

Where a legal basis is required, we rely on one or more of the following:

  • performance of a contract, including providing the Services;
  • legitimate interests, including securing, operating, improving, and supporting the Services;
  • consent, including where required for non-essential analytics cookies, advertising measurement, or certain marketing communications;
  • compliance with legal obligations;
  • customer instructions, where we process Customer Data as a processor or service provider.

5. How we share information

We do not sell personal information.

We may share information with service providers and subprocessors that help us operate the Services, including:

  • cloud hosting and infrastructure providers;
  • payment processors such as Stripe;
  • email delivery providers such as Resend;
  • analytics providers such as Google Analytics and PostHog;
  • monitoring and reliability providers such as Sentry and Better Stack;
  • AI model providers such as Google Vertex AI/Gemini and Anthropic;
  • professional advisers, where needed;
  • authorities, courts, or regulators where required by law.

These providers are authorized to process information only as needed to provide services to Prolytics, comply with law, protect security and rights, or fulfill their contractual obligations to Prolytics.

A current Subprocessor List is available on our legal page.

6. International transfers

Prolytics Limited is registered in Hong Kong. Our infrastructure and service providers may operate in the United States and other jurisdictions.

Production infrastructure is hosted on Google Cloud in the United States, including the us-west1 region where configured.

Information may be transferred to, stored in, or processed in Hong Kong, the United States, Canada, the European Economic Area, the United Kingdom, and other jurisdictions where Prolytics, customers, service providers, or subprocessors operate.

Where required, we use appropriate safeguards for international transfers, such as data processing agreements, contractual protections, standard contractual clauses, UK transfer terms, or equivalent mechanisms. Customers that require specific transfer terms should contact legal@prolyticshq.com.

7. Retention

We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.

Current retention practices include:

  • account and workspace records are retained while the account or workspace remains active, unless support-assisted deletion applies;
  • provider credentials, connector state, and workspace configuration are retained while the integration or workspace remains active;
  • rebuildable provider snapshots and cache rows with explicit expiry are removed by retention cleanup;
  • raw Stripe webhook JSON in payment event records is redacted after 180 days;
  • canonical payment, subscription, credit, tax, legal, audit, and financial records may be retained longer as required or permitted;
  • Health metric snapshots and jobs are pruned according to product maintenance rules;
  • Radar findings, alert occurrences, watches, issue workspace records, investigations, prompts, evidence packs, AI outputs, Pulse history, credit transactions, quarantine controls, and operation events are preserved by default as customer-visible product, business, audit, or workflow records while the workspace remains active;
  • managed production database backups expire no later than 90 days after creation unless a legal hold or incident-preservation requirement applies.

Deletion and export requests are support-assisted for MVP. Backup copies may remain until backup retention periods expire.

8. Cookies

We use cookies and similar technologies for authentication, security, site functionality, analytics, and performance.

Non-essential analytics cookies, advertising measurement, and related browser tracking are controlled through the cookie consent banner where required.

More information is available in our Cookie Policy.

9. Security

We use technical and organizational measures designed to protect information from unauthorized access, loss, misuse, alteration, and disclosure.

These measures may include TLS encryption in transit, restricted production access, encrypted managed database backups, access controls, monitoring, and incident response procedures.

No method of transmission or storage is completely secure.

More information is available in our Security Overview.

10. Your rights

Depending on your jurisdiction, you may have rights to:

  • access personal information;
  • correct inaccurate information;
  • request deletion;
  • restrict or object to certain processing;
  • request portability;
  • withdraw consent where processing is based on consent;
  • opt out of certain analytics, advertising measurement, or marketing uses;
  • lodge a complaint with a data protection authority.

To make a request, contact legal@prolyticshq.com.

We may need to verify your identity, authority, and relationship to the relevant workspace before responding.

For Customer Data processed on behalf of a business customer, we may refer the request to the customer or process it according to the customer's instructions.

11. California privacy notice

We do not sell personal information for money.

We do not use personal information for cross-context behavioral advertising as part of the Services unless we separately disclose that use and provide legally required choices.

California privacy laws may apply only to businesses that meet specific legal thresholds. Where California privacy rights apply, California residents may have rights to know, access, correct, delete, and opt out of certain uses of personal information.

Requests may be sent to legal@prolyticshq.com.

12. Children

The Services are not intended for children. You may not use the Services to knowingly collect, submit, or process children's personal information unless Prolytics agrees in writing and appropriate legal requirements are satisfied.

13. Changes to this policy

We may update this Privacy Policy from time to time. Updated versions will be posted on prolyticshq.com with a revised "Last updated" date.

14. Contact

Prolytics Limited

Website: prolyticshq.com

Email: legal@prolyticshq.com