Privacy
What Profusia stores, where it lives, how long it is kept, and how each data-protection right maps to something you can actually do in the product. The security half of this picture is at /trust.
Legal documents (drafts for attorney review): Terms · Privacy Policy · DPA · Acceptable use · Refund Policy
Who we are
Evadaroo & Company, LLC, a Pennsylvania limited liability company trading as Profusia AI, is the controller for account data — your account, your sign-in, and the billing relationship. For the documents and data a customer puts into its workspace, that customer decides what happens to them and we process them on its behalf. Privacy questions and requests: legal@evadaroo.com.
What we store, where, and for how long
| Data | Where it lives | How long |
|---|---|---|
| Documents you publish, and every prior version of them | Cloudflare R2 (bytes) and D1 (metadata, plus a derived text index so search can read inside documents) | Kept until you delete them. Deleting moves them to your workspace trash; nothing is erased until you explicitly purge, or the workspace itself is deleted. The search index follows the document: it leaves search when the document is trashed and is erased when the document is erased. |
| Datasets behind live pages | Cloudflare D1 | Kept until you delete them (same trash-then-purge rule). |
| Accounts: email, optional name, salted password hash | Cloudflare D1 | Kept while the account has a workspace membership. Erasable on request by a workspace admin (see “Erasure” below). |
| Sign-in sessions, share links, access keys, connector tokens | Cloudflare D1 — stored only as hashes | Until they expire or are revoked. The secret itself is never stored. |
| Audit log (who did what, when) | Cloudflare D1 | 400 days, then swept by a daily job. |
| AI per-call ledger (who asked, which document, tokens, cost) | Cloudflare D1 | 90 days, then swept. Daily spend aggregates (no personal detail) are kept longer for billing honesty. |
| Page-view counts | Cloudflare D1 | Counted per document per day. Visitors are never identified — no IP addresses or identifiers are stored with views. |
| Public-page visit counts: the UTC day, a page group (for example the home page, one guide or the help pages), the referring site reduced to one word from a short fixed list (for example a search engine or an AI assistant) or to none, and a count | Cloudflare D1 | 400 days, then swept by a daily job. Nothing else is stored with the count — no IP address, user agent, cookie, page address, query string or referrer URL. Pages on a customer’s own workspace address are never counted here. |
| Portal visitors: the display name a visitor typed, and their session (as a hash) | Cloudflare D1 | Until the visitor or their portal is revoked, the session expires (90 days), or the workspace is erased. The name is self-reported and unverified; portal opens are counted per day with no IP address or fingerprint. |
| Billing status: which plan a workspace is on, its status and renewal date, and the payment provider's reference numbers for the customer and subscription — never a card number | Cloudflare D1 | Kept while the workspace exists, and erased with it. A log of each notice Paddle sends us — what kind it was, Paddle's reference for it, and what we did with it — is kept as our own record, including after the workspace is erased; it holds no name, email or payment detail. Payment and tax records are held by Paddle, our reseller and Merchant of Record, under its own privacy notice. |
| A deleted workspace | — | Deletion makes the workspace unreachable immediately, and is reversible by an owner for 30 days. After that, a daily job permanently erases its database rows and stored files. |
All of it is hosted on Cloudflare (Workers, R2, D1) — Cloudflare is our infrastructure subprocessor. We run no other datastore.
Subprocessors
- Cloudflare — all hosting, storage and delivery.
- Resend, only if your deployment has email notifications switched on — when somebody mentions you and you have asked to hear about it, your email address, the notification's title and body, and a link are sent to Resend to deliver. It is off unless an operator configures a sender; an administrator can switch it off for the whole organisation, and you can switch it off for yourself in the notification bell. That is the only message Profusia sends: documents you follow are shown in the app and are not emailed, nothing is pushed to a device, and there is no marketing mail. An address that hard-bounces or reports a message as spam is recorded so we never write to it again.
- AI model providers, only if your deployment has AI features switched on: Google (Gemini), Groq, Cerebras, OpenRouter, Mistral, Cloudflare Workers AI, Anthropic, OpenAI. When you ask a document a question, that document's text is sent to the answering provider. The model is given no tools, and which providers are actually enabled is a deployment decision — none are enabled by default. Your own conversations with the assistant are kept for you alone, for ninety days, so you can pick one up again; you can delete any of them at any time, and an administrator can switch the keeping off for the whole workspace.
- Audio, if you ask a question out loud — the recording is sent to the answering provider (Google, for spoken questions) in the same request as the document, and is used only to answer it. Profusia does not store the recording, does not keep a transcript of it, and never records without you pressing the button: there is no wake word and no open microphone. The audit log notes that a question was spoken and how long the clip ran — never the audio or the words.
- A Google authorization, only if you switch on Google Docs/Sheets sync. Profusia stores the authorization Google issues, encrypted at rest under a key held outside the database. It is never shown back to you or anyone else, never included in an export, and erased with your workspace. It uses Google’s per-file scope, so it permits access only to the documents Profusia itself creates in your Drive — Google enforces that, not us, so the rest of your Drive stays unreadable to Profusia. Your projects and documents are copied into your own Google account; nothing is read out of it. Disconnect at any time; what is already in your Drive is yours and stays.
- Clerk, only if the sign-in provider is switched on — it would handle sign-up, email verification, invitation email and password reset, and see your email address and sign-in details. Until it is switched on, signing in is Profusia’s own and nothing goes to Clerk.
- Paddle, only when you buy a plan. Paddle (Paddle.com Market Limited and its affiliates) is our reseller and Merchant of Record for paid plans. On the payment page it processes your billing contact, payment and tax details as an independent controller under its own privacy notice. Payment details go to Paddle, never to us; what comes back to us is which plan the workspace is on, its status and renewal date, and Paddle’s own reference numbers for the customer and the subscription.
- Uiia, only if you use the help assistant on /help. The help assistant on /help is Uiia (uiia.app), a separate product of the same company; it receives only the question typed there and nothing from your workspace. It answers with AI models, so treat it like a public help forum and type nothing confidential there.
That is the whole list. Profusia uses no third-party analytics or advertising service; the only counting it does is its own, described under Cookies. The Google sync above is the only case in which Profusia connects to another platform on your behalf, it happens only if you turn it on, and it only ever writes — Profusia never reads another platform’s data on your behalf.
Your rights, as product actions
- Access & portability — the console's “Take it with you” export: every document you can see, plus projects, datasets, collections, the site structure and the audit log, packaged in your own browser. No ticket, no waiting.
- Erasure — a workspace owner can delete the whole workspace (unreachable immediately, reversible for 30 days, then permanently erased), and a workspace admin can erase a person: their account, sessions and invitations are removed and their name comes off surviving documents.
- Rectification — documents, projects and profile details are directly editable in the product; fixing a record is using it.
Anything a product act doesn't cover — and any privacy question at all — write to legal@evadaroo.com.
California (CCPA/CPRA)
Profusia does not sell personal information and does not share it for cross-context behavioral advertising. There is no “Do Not Sell or Share” mechanism because there is no sale or sharing to opt out of.
Cookies
There is no cookie banner because there is nothing a banner would be consenting to: Profusia sets first-party cookies only, and only to make the page in front of you work — signing you in, remembering where you were working, keeping a password-protected link open once you have answered it, and remembering which version of a shared document your browser last opened so the page can say what changed since. None of them identifies you. The one exception is the payment page, where Paddle’s checkout sets its own cookies when you choose to pay. No trackers, no analytics beacons. Anonymous page views are counted as numbers per document per day. The public pages themselves (the marketing site, the guides, the help topics, the templates, and the trust and legal pages) are counted the same way: a number per day, per page, and per referring site, where the referring site is reduced to a name from a short fixed list (for example a search engine or an AI assistant) or to none. No IP address, browser detail, cookie or query string is stored with either count, visitors are never identified, and the public-page count never includes a page on a customer’s own workspace address.
Where processing happens
Cloudflare's network is global; data is stored in Cloudflare's R2 and D1 services under our account. We do not currently offer a regional-pinning guarantee, and this page will say so until we do rather than implying one.