Trust Center
Last updated: 28 September 2026
ProofMyAI processes conversations between businesses and their customers, so we built it to collect as little as possible and to give each business control over what is stored and where it goes. This page answers the questions a data protection review usually asks.
Who we are
ProofMyAI is operated by Muhammad Usman, sole proprietor, Pakistan. About us. Contact: contact@usmanabbas.dev.
For customer data you send us, you are the data controller and ProofMyAI is your data processor. Our Data Processing Agreement (DPA) sets this out under GDPR / UK GDPR Article 28 and can be accepted online.
Controls you have, per project
- Masking before storage and AI checks (on by default): emails, phone numbers, card numbers, IBANs, IP addresses, UK postcodes, UK number plates, self-introduced names ("my name is …"), plus your own list of words (customer names, account numbers, internal codes).
- Results-only mode: keep verdicts, reasons and scores but never the conversation text.
- Automatic deletion after 7, 30, 90 or 365 days.
- AI provider off: checks run with rules and your own neural model only, so no data leaves ProofMyAI.
- Delete any time: audits, projects or your whole account, removed immediately from the live database.
- Upload instead of connect: audits can run on exported, anonymised files with no live connection to your systems.
Masking is pattern-based. It greatly reduces personal data, but it cannot guarantee that every free-text detail is caught. For highly sensitive data, combine it with results-only mode, short retention, AI off, or self-hosting.
Where data is processed
- Application and database: Railway, US West.
- AI judge (only when on for a project): masked text is sent to the AI provider listed below, only for the check, over HTTPS. The AI judge currently uses Google's free Gemini API tier, whose terms allow Google to use submitted content to improve its products. For customer data, switch AI checking off for the project (Settings → Data & privacy) until the paid tier is enabled.
- Transfers outside the UK/EEA are covered by the safeguards in our DPA (EU Standard Contractual Clauses and the UK Addendum).
Sub-processors
| Company | Purpose | Data | Location | In use |
|---|---|---|---|---|
| Railway Corporation | Application hosting and database | All service data | US West | Yes |
| Anthropic PBC (Claude API) | AI judge, only for projects with AI checking on | Masked chat text, agent runs, help articles | United States | No |
| Google LLC (Gemini API) | AI judge, only for projects with AI checking on | Masked chat text, agent runs, help articles | United States / global | Yes |
| Resend, Inc. | Emails (alerts, summaries, password resets) | Account email, alert summaries | United States | Yes |
| Paddle.com Market Ltd | Payments and invoicing (Merchant of Record) | Billing name, email, payment details | United Kingdom | Yes |
Our public website also uses Google Analytics (visits only, never inside the dashboard) and YouTube for videos (loaded only when you press play). We give at least 30 days' notice by email before adding a sub-processor that handles customer data.
Security measures
- HTTPS for every connection; security certificates managed by our host.
- Passwords hashed with scrypt; login sessions stored only as hashes in secure, http-only cookies; sign out of all devices at any time.
- Integration secrets (n8n/Make keys, bot headers) encrypted with AES-256-GCM.
- Every page and API call checks that the data belongs to the requesting account; API keys are per project and can be replaced instantly.
- Protection against requests to private networks (SSRF) for every outbound call, and rate limits on logins and the API.
- Administrator access is limited to the operator and every admin action is logged. Support staff never see API keys, and we only open a customer's conversations to help that customer, at their request.
- Personal data breaches are reported to affected customers without undue delay, and at most within 72 hours of us becoming aware.
Your AI integration stays safe
Our code snippets send data in the background with a 2-second limit, so monitoring can never slow down or break your chatbot or agent. Nightly tests should point at a test endpoint, never at a live WhatsApp/Twilio or SMS webhook.
Self-hosted and enterprise
For dealerships, finance, healthcare and other regulated businesses, ProofMyAI can run on your own server or cloud account, so conversations never leave your infrastructure, with an AI provider of your choice or none. Ask about self-hosting.
Questions and documents
Email contact@usmanabbas.dev for a signed DPA, a security questionnaire, or anything not answered here. See also our Privacy Policy and Terms.