Privacy Notice
Last updated 21 August 2026 · Policy version 2026-08-20
This notice explains, in plain terms, what Prooflane does with your information. We collect what we need to contact you and run your account. If you choose to allow optional analytics, we also collect limited behavioral events to understand the path from a marketing page to registration and product activation. Sensitive testing content remains outside analytics and stays local unless you separately enable an eligible cloud feature.
What we collect
- Details you give us. If you fill in our contact form we receive your name, company, phone number, email address, and your message, so that we can reply.
- Your account. Sign-in is handled by Auth0. That means we hold your email address and whether it has been verified, along with a user identifier and ordinary sign-in records such as times and IP address. We never see or store your password.
- Basic service records. Against your account we keep what the product needs to work: your plan and whether a trial has been used, the version and date of any agreement you accept, and summary results of tests you choose to publish — counts, scores, and durations.
- Optional analytics. If you allow analytics, we may record page paths and titles, CTA impressions and clicks, query-free referrers and UTM campaign attribution, registration funnel steps, browser/device/OS metadata, opaque anonymous or session identifiers, opaque account or organization identifiers after sign-in, high-level activation events, and trial lifecycle events. We use this to find usability and onboarding drop-offs and measure campaigns by registration and activation rather than clicks alone.
What we never collect
The Prooflane Inspector runs on your own machine. Analytics is not intended or permitted to collect passwords, credentials, API keys, access tokens, authorization headers, raw MCP configuration, raw prompts, model responses, MCP tool inputs or outputs, RAG documents or retrieved content, raw assurance evidence, security payloads, test payloads, source documents, or customer secrets. The analytics privacy guard rejects prohibited fields and suspected secret material before an event reaches a vendor.
Some optional features can store test evidence in the cloud so history and recovery work across machines. Those stay switched off until you explicitly accept the relevant terms, and what is stored is encrypted. You can decline and keep using Prooflane locally.
Cookies, storage, and your choice
Optional analytics is off until you allow it. Rejecting optional analytics prevents Prooflane's analytics adapters from initializing or sending events and removes Prooflane analytics identifiers and attribution from browser storage. Hiding the banner is not consent. You can change the same choice later through Privacy settings on the site or Privacy & Data in the product.
Prooflane stores the consent choice and versions in prooflane-analytics-consent. If analytics is allowed, it may also use prooflane-analytics-anonymous-id, prooflane-analytics-session-id, and prooflane-analytics-attribution. Google Analytics may set _ga cookies. The optional records are removed or disabled when you reject analytics. Separately, prooflane-theme remembers a theme you select, and Auth0 local storage maintains the sign-in session.
Prooflane honors an active Global Privacy Control signal and the browser's legacy Do Not Track value by keeping optional analytics off, even if an opt-in is attempted.
Who helps us run it
We use a small number of established providers, and they only handle information in order to provide their service to us:
- Google Cloud — hosting, database, and encryption.
- Auth0 — accounts, sign-in, and verification email.
- Microsoft 365 — our email, including any correspondence with you.
- FormSubmit — delivers contact form submissions to our inbox.
- Google Analytics 4 — optional aggregate acquisition and registration measurement, only when enabled and allowed.
Our infrastructure is hosted in the United States. Providers may also process information in the United States or other jurisdictions according to their infrastructure and our configured region, so information may be handled outside the country where you live.
How long we keep it
Only as long as we need it: enquiries for as long as it takes to deal with them and keep a sensible record, and account information for as long as you have an account. Our current maximums are two months for event-level Google Analytics data, 13 months for Prooflane's consented marketing attribution, and 24 months for aggregated analytics reports. Internal lifecycle records may be retained for the account lifetime plus 90 days. A shorter legal, contractual, or operational requirement takes precedence. Ask us to delete or suppress eligible information and we will propagate the request to enabled analytics providers unless we are required to keep it.
Your choices
Email us at prooflaneteam@prooflane.ai and we will tell you what we hold about you, correct it, delete it, or stop using it, subject to applicable requirements. If you gave us permission for optional analytics, you can withdraw it immediately through Privacy settings or Privacy & Data. You can also request account deletion. The consent audit records only the policy and consent versions, timestamp, selected categories, and update source; it does not need your email address.
Changes
Prooflane is in beta and the product is moving quickly. If we change how we handle your information we will update this page and the date at the top. Changes that affect the optional cloud features are also presented to you as a new agreement to accept before anything changes.
Contact
Questions about any of this: prooflaneteam@prooflane.ai.
This notice covers personal information only. Your use of the software is governed by our Terms of Service and Responsible Use Policy.