Part of the legal pack — see also: Terms of Service · Data Processing Addendum · Acceptable Use Policy · Refund Policy. The in-force privacy page this product operates under today is /privacy, unaffected by this draft.
Profusia AI — Privacy Policy
Effective date: [DATE]
This policy explains what Profusia AI stores, where it lives, how long it is kept, who else processes it, and how each data-protection right maps to something you can actually do in the product. It is the legal successor to the /privacy page published at profusia.ai and states the same facts.
Who we are. Evadaroo & Company, LLC, a Pennsylvania limited liability company trading as Profusia AI, [REGISTERED OFFICE ADDRESS], United States. Privacy questions and rights requests: legal@evadaroo.com.
Our role. For content you publish into your workspace, you are the controller (or, under US state laws, the "business") and we are the processor ("service provider"). For your own account and billing relationship with us, we are the controller. Where you are a controller subject to the GDPR, UK GDPR, or a US state privacy law, our Data Processing Addendum governs and takes precedence over this policy on the points it covers.
1. What we store, where it lives, and for how long
| Data | Where it lives | How long |
|---|---|---|
| Documents you publish, and every prior version | Cloudflare R2 (bytes) and D1 (metadata, plus a derived text index so search can read inside documents) | Until you delete them. Deleting moves them to your workspace trash; nothing is erased until you explicitly purge, or the workspace itself is deleted. The search index follows the document — it leaves search when the document is trashed and is erased when the document is erased. |
| Datasets behind live pages | Cloudflare D1 | Until you delete them (same trash-then-purge rule). |
| Accounts: email, optional name, salted password hash | Cloudflare D1 | While the account has a workspace membership. Erasable on request by a workspace admin. |
| Sign-in sessions, share links, access keys, connector tokens | Cloudflare D1 — as hashes only | Until they expire or are revoked. The secret itself is never stored. |
| Audit log (who did what, when) | Cloudflare D1 | 400 days, then swept by a daily job. |
| AI per-call ledger (who asked, which document, tokens, cost) | Cloudflare D1 | 90 days, then swept. Daily spend aggregates carrying no personal detail are kept longer for billing honesty. |
| Page-view counts | Cloudflare D1 | Counted per document per day. Visitors are never identified — no IP addresses or identifiers are stored with views. |
| Public-page visit counts: the UTC day, a page group (for example the home page, one guide, or the help pages), the referring site reduced to one word from a short fixed list (for example a search engine or an AI assistant) or to none, and a count | Cloudflare D1 | 400 days, then swept by a daily job. Nothing else is stored with the count — no IP address, user agent, cookie, page address, query string, or referrer URL. Pages on a customer's own workspace address are never counted here. |
| Portal visitors: the display name a visitor typed, and their session as a hash | Cloudflare D1 | Until the visitor or their portal is revoked, the session expires (90 days), or the workspace is erased. The name is self-reported and unverified; portal opens are counted per day with no IP address or fingerprint. |
| Email delivery ledger and suppression list (only where notification email is switched on) | Cloudflare D1 | The delivery record supports the monthly sending allowance; an address that hard-bounces or reports spam is recorded so we never write to it again. |
| Billing records | Paddle, our reseller and Merchant of Record (Section 3), plus the plan and subscription status with us | As long as required by tax and accounting law (generally 7 years). |
| A deleted workspace | — | Deletion makes the workspace unreachable immediately and is reversible by an owner for 30 days. After that, a daily job permanently erases its database rows and stored files. |
All of it is hosted on Cloudflare (Workers, R2, D1). We run no other datastore.
2. What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use your content to train AI models, and we do not permit our providers to do so on the tiers we route your content to (Section 4).
- We use no third-party analytics or advertising service. There is no Google Analytics, no advertising pixel, and no tracker anywhere in the product, and the product sets no third-party cookie — the one exception is Paddle's checkout on the payment page (Section 7). The only counting we do is our own, described in Section 7.
- We do not profile you or make automated decisions producing legal or similarly significant effects.
3. Subprocessors
| Subprocessor | Purpose | What it can see | Region |
|---|---|---|---|
| Cloudflare, Inc. (US) | All hosting, storage, delivery, and the database | Everything stored in the Service | Cloudflare's global network; storage in R2 and D1 under our account |
| Resend (US) — only where notification email is switched on | Delivering a notification when somebody mentions you | Your email address, the notification's title and body, and a link | US |
| Paddle (Paddle.com Market Limited and its affiliates) — only when you buy a plan | Our reseller and Merchant of Record for paid plans. It processes billing contact, payment and tax details as an independent controller under its own privacy notice (paddle.com/legal/privacy) | Billing contact, payment and tax details. Payment details go to Paddle, never to us. | UK and US |
| Clerk (US) — where the identity provider is switched on | Sign-up, email verification, invitation email, password reset | Email address and sign-in metadata | US |
| Uiia (uiia.app) — only if you use the help assistant on /help | The help assistant on /help, a separate product of the same company | Only the question you type there, and nothing from your workspace. It answers with AI models, so treat it like a public help forum | US |
| AI model providers — only where AI features are switched on and used | Answering a question about your document, plan, or card | The text sent in that request, and an audio clip if you asked out loud | See Section 4 |
That is the whole list. The Google Drive sync in Section 5 is the only case in which Profusia authenticates to another platform on your behalf, it happens only if you turn it on, and it only ever writes.
We maintain the current list at /privacy and will give 30 days' notice of a new or replacement subprocessor, as set out in the DPA.
4. AI providers, and what reaches them
Profusia's in-app AI is off unless the deployment has a provider configured, which is the normal state, and off entirely on the Free plan. Where it is on and you use it, the relevant document, plan, or card text is sent to the provider that answers, in that request, for that answer.
The providers in our catalogue are: Google (Gemini, via Google AI Studio), Groq, Cerebras, OpenRouter, Mistral, Cloudflare Workers AI, Anthropic, and OpenAI. Which of these are actually enabled is a deployment decision; none are enabled by default.
Three facts matter more than the list:
- No conversation is stored by us, and the models are given no tools — a model answering your question cannot act on your workspace.
- Several providers' free tiers reserve the right to train on inputs. Customer content is never routed to those tiers where the deployment serves more than the single workspace that accepted that trade. The restriction is enforced in code and fails closed — an unreadable count, a request naming no workspace, and a workspace absent from the permitted list are all refused.
- Spoken questions. If you ask out loud, the recording rides the same request to the answering provider (Google, for spoken questions) and is used only to answer it. We do not store the recording and keep no transcript. The audit log notes that a question was spoken and how long the clip ran — never the audio or the words. Nothing records without you pressing the button: there is no wake word and no open microphone. Answers are read back by your own browser's speech synthesis, so no hosted voice service is involved.
Each provider processes content under its own API terms. Where a provider offers zero-data-retention terms, we prefer them.
5. Google Docs & Sheets sync (optional)
If a workspace owner connects it, Profusia copies plans and documents into a Google Drive account you connect, so a NotebookLM notebook or a shared folder stays current.
- The authorization Google issues is stored encrypted at rest under a key held outside the database. It is never shown back to you or anyone else, never included in an export or any API response, and erased with your workspace.
- It uses Google's per-file (
drive.file) scope, so it permits access only to files Profusia itself created. Google enforces that, not us — the rest of your Drive is unreadable to Profusia, and there is no read path into your Google account at all. - Connecting is owner-only and requires a person, not a machine credential. Disconnect at any time: we revoke at Google and delete our rows. What is already in your Drive is yours and stays.
6. Assistants you connect (MCP)
You may connect an assistant — for example Claude or ChatGPT — over the Model Context Protocol. It acts as your workspace and only within it. What you type into that assistant's own client is governed by that vendor's privacy policy, not ours. We see only the calls the assistant makes to us.
7. Cookies
There is no cookie banner because there is nothing a banner would be consenting to. Profusia sets first-party cookies only, and only to make the page in front of you work: signing you in, remembering where you were working, keeping a password-protected link open once you have answered it, and remembering which version of a shared document your browser last opened so the page can say what changed since. None of them identifies you. No trackers, no analytics beacons. The one exception to first-party-only is the payment page (/pay), where Paddle's checkout sets its own cookies when you choose to pay, under Paddle's privacy notice. Anonymous page views are counted as numbers per document per day. The public pages themselves (the marketing site, the guides, the help topics, the templates, and the trust and legal pages) are counted the same way: a number per day, per page, and per referring site, where the referring site is reduced to a name from a short fixed list (for example a search engine or an AI assistant) or to none. No IP address, browser detail, cookie, or query string is stored with either count, visitors are never identified, and the public-page count never includes a page on a customer's own workspace address.
8. Your rights, as things you can do
| Right | How it works here |
|---|---|
| Access & portability | The console's "Take it with you" export packages every document you can see, plus plans, datasets, collections, the site structure, and the audit log — built in your own browser. No ticket, no waiting. |
| Erasure | A workspace owner can delete the whole workspace (unreachable immediately, reversible for 30 days, then permanently erased). A workspace admin can erase a person: their account, sessions, and invitations are removed and their name comes off surviving documents. |
| Rectification | Documents, plans, and profile details are directly editable. Fixing a record is using the product. |
| Restriction / objection | Write to legal@evadaroo.com. |
| Withdraw consent | Where processing rests on consent (for example the Google sync), disconnect it in the console; withdrawal does not affect prior lawful processing. |
| Complain | You may lodge a complaint with your supervisory authority. We would rather hear from you first. |
How to ask. Email legal@evadaroo.com. We will verify that you are who you say you are — usually by confirming control of the account email — and respond within 30 days (extendable once by a further 60 days where the request is complex, with notice). We do not charge for a rights request except where one is manifestly unfounded or excessive.
If you are a user in a customer's workspace, send the request to that customer, who controls the content. If you send it to us, we will forward it to them and tell you we have.
9. Legal bases (GDPR / UK GDPR)
Where the GDPR applies to our own processing:
- Performance of a contract — providing the Service, accounts, billing, support.
- Legitimate interests — securing the Service, preventing abuse, keeping the audit trail, and improving reliability. We have balanced these against your rights and consider the processing proportionate, in part because the data involved carries no identifiers beyond what the account itself needs.
- Consent — for the optional Google sync and for notification email you switch on.
- Legal obligation — tax, accounting, and responses to lawful requests.
For Customer Content processed on your instructions, your own legal basis governs; ours is the contract with you.
10. California and other US state privacy laws
We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" mechanism because there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out.
California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other state residents have rights to know, access, correct, delete, and appeal, and we do not discriminate for exercising them. Use legal@evadaroo.com for all of it, including an appeal of a decision — we will respond to an appeal within 45 days with our reasons.
Where we process personal data on a customer's behalf we act as a service provider / processor under those laws, on the terms in the DPA, and we do not retain, use, or disclose it for any purpose other than performing the Service.
11. Where processing happens, and international transfers
Cloudflare's network is global; data is stored in Cloudflare's R2 and D1 services under our account. We do not currently offer a regional-pinning guarantee, and this policy says so rather than implying one. We are a US company. Our other subprocessors are US-based, except Paddle, which operates from the UK and the US.
For transfers of personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, incorporated into the DPA, with the UK International Data Transfer Addendum where the UK GDPR applies.
12. Security
The security half of this picture is at /trust. In short: every database query runs through one workspace-scoping choke point; each workspace is served from its own subdomain; every credential is stored only as a hash; delivered pages run under a strict content security policy and never execute on our servers; privileged actions are recorded in an append-only audit trail you can export.
What we do not claim: no SOC 2 report, no ISO 27001, no HIPAA attestation, no third-party penetration test — none in progress. Isolation is logical, not physical. We say so here and at /trust rather than implying otherwise.
If you believe you have found a vulnerability, please tell us: security@profusia.ai, and the contact published at /.well-known/security.txt per RFC 9116. We do not run a paid bounty program and we will not pursue researchers who report in good faith.
13. Breach notification
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data we process for you, we will notify you without undue delay and in any event within 72 hours, with what we know at the time and updates as we learn more.
14. Children
The Service is for people aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, write to legal@evadaroo.com and we will delete it.
15. Changes to this policy
We will post any change here with a new effective date. For a material change we will give 30 days' notice to workspace owners by email and in the product.
16. Contact
legal@evadaroo.com — privacy questions, rights requests, and appeals. security@profusia.ai — vulnerability reports.
Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA