Privacy Policy
Last updated: 28 September 2026
This policy explains what data ProofMyAI collects, why, and your choices. ProofMyAI is operated by Muhammad Usman, sole proprietor, Pakistan. Contact us at contact@usmanabbas.dev with any privacy question.
For the conversations and other content you send us about your customers, you are the data controller and we are your processor under our Data Processing Agreement. Full details are in the Trust Center.
What we collect
- Account data: your email address and a securely hashed password (we never store the password itself).
- Content you provide: chat transcripts, knowledge base articles, test questions, AI agent runs and workflow execution data you upload or send.
- Connection details: API keys and webhook URLs for n8n, Make, bots and alert channels, stored encrypted.
- Technical data: basic server logs (such as IP address and time of request) to keep the Service secure.
Personal data masking
By default, emails, phone numbers, card numbers, IBANs, IP addresses, UK postcodes, UK number plates and self-introduced names inside transcripts and agent runs are masked before they are stored or sent to an AI model. Each project can add its own words to mask, keep results only (no conversation text), switch the AI provider off, and delete data automatically after 7 to 365 days (Settings → Data & privacy).
How we use data
Only to provide the Service: grading answers, running checks, sending alerts and reports you set up, account emails (such as password resets) and security. We do not sell your data and do not use it for advertising.
Service providers
- Hosting: Railway (application and database), US West.
- AI checking: Anthropic (Claude) or Google (Gemini), only for projects with AI checking on. Only the masked content needed for a check is sent. The AI judge currently uses Google's free Gemini API tier, whose terms allow Google to use submitted content to improve its products. For customer data, switch AI checking off for the project (Settings → Data & privacy) until the paid tier is enabled.
- Email: Resend, for alerts, summaries and password resets.
- Payments: Paddle.com is our online reseller and Merchant of Record. Paddle collects and processes your billing details; we never see your full card number.
Cookies
We use one essential cookie to keep you logged in, and your browser's local storage to remember your light/dark theme. We do not use advertising cookies. On our public pages (not inside the dashboard) we use Google Analytics to count visits and see which pages are useful; it sets analytics cookies and IP addresses are anonymised. You can block it with any ad blocker or browser privacy setting. When you sign up, send the contact form, start a trial or pay, our server tells Google Analytics that this happened (with the analytics ID from that cookie, the plan and price, never your name, email or any content) so we can see which marketing works. Our videos are hosted on YouTube and only load (from youtube-nocookie.com) after you click play.
Retention and deletion
Your data is kept while your account exists, or for the shorter period you set per project. You can delete individual audits and projects at any time, or delete your whole account in Account → Delete account, which permanently removes all your data. Backups are overwritten within 30 days.
Your rights
You can access, export (CSV and JSONL exports in the app), correct or delete your data. Email contact@usmanabbas.dev for any other request and we will reply within 30 days.
Security
Passwords are hashed with scrypt, credentials are encrypted with AES-256-GCM, connections use HTTPS, and every page checks that you own the data you view.
Changes
If we change this policy we will update the date above and, for important changes, email account owners. See also our Terms of Service.