Legal
Privacy Policy
Last updated 25 July 2026
Template notice. This draft describes the intended data practices of the product. It has not been reviewed by a lawyer and is not a compliance sign-off for GDPR, UK GDPR or CCPA. Have counsel review it before launch.
1. What we collect
You give us
- Account details — name, email address and password credentials, handled by our authentication provider.
- Billing details — plan, billing cycle and country. Card numbers go directly to Stripe; we never see or store them.
- Content — the prompts you submit and the outputs generated from them.
- Correspondence — messages you send us via the contact form or email.
We collect automatically
- Usage records — which tool ran, when, and the token cost. This is what powers your usage history and balance.
- Technical data — IP address, browser and device type, and error logs, used for security and debugging.
2. Why we use it
- To provide the Service and generate what you ask for;
- To meter tokens accurately and show you your balance and history;
- To take payment and manage subscriptions;
- To respond to support requests;
- To detect abuse, fraud and attempts to circumvent metering;
- To meet legal and accounting obligations.
We do not sell your personal data, and we do not use your prompts or outputs to train our own models.
3. Processors we share with
We share the minimum necessary with providers who process data on our behalf:
- OpenAI — receives your prompts in order to generate output.
- Stripe — payment processing and card handling.
- Clerk — authentication and session management.
- Hosting and database providers — to run the application and store your data.
We may also disclose data where legally required, or to protect our rights and the safety of users.
4. International transfers
Our providers may process data outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
5. How long we keep it
- Account data — while your account is open, then deleted or anonymised within 90 days of closure.
- Prompts and outputs — until you delete them, or until account closure.
- Usage and billing records — retained as long as tax and accounting law requires, typically six years.
6. Your rights
Depending on where you live, you may have the right to access, correct or delete your data, to export it, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact us and we will respond within the period the applicable law requires — 30 days in most cases.
7. Security
We use encryption in transit, scoped access controls and reputable infrastructure providers. Card data never touches our servers. No system is perfectly secure, and we will notify you and any relevant regulator of a breach affecting your data as required by law.
8. Cookies
We use cookies that are strictly necessary for authentication and session management. If we later add analytics or marketing cookies, we will ask for consent first and update this policy.
9. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has registered, tell us and we will remove the account.
10. Changes and contact
We will post material changes here and notify you by email or in-product notice. Questions or requests: contact us or email privacy@proaimasterclass.com. See also our Terms of Service.