ProposalGen AI (“we”, “our”, “us”) takes your privacy seriously. This Privacy Policy explains what data we collect, why we collect it, and what we do with it. If anything is unclear, email privacy@proposalsgen.com.
1. The short version
- We don't train AI models on your proposals.
- We don't sell your personal data to third parties.
- You can export or delete your data at any time from your dashboard.
- Proposal content is encrypted at rest and in transit.
2. What we collect
We collect three categories of data: account data (email, password hash, account creation date), proposal data (the documents you create and the inputs you provide to generate them), and usage data (page views, feature usage, error logs).
For proposals you share via a public link, we also collect anonymous viewer analytics: visit timestamps, IP-derived country, device type, time-on-page, and scroll depth. This data is shown to you, the proposal owner, in your dashboard.
3. Why we collect it
- To deliver the service (you can't generate a proposal without inputs).
- To improve product reliability (error logs, performance monitoring).
- To prevent abuse (rate limiting, fraud detection).
- To honor legal obligations (tax records, ESIGN audit logs).
4. Third parties we use
We use a small set of trusted vendors to run the service. Each is bound by a data processing agreement.
- Supabase — hosts our database and authentication. Data is encrypted at rest.
- DeepSeek — powers AI text generation. Per their policy, prompts are not used for model training when accessed via the paid API.
- Creem — processes payments. We never see or store your full card number.
- Vercel — hosts the application. Standard server access logs are retained for 30 days.
5. AI and your proposal content
When you generate a proposal, the inputs you provide are sent to our AI provider (DeepSeek) to produce the output. We do not retain copies of these prompts beyond 30 days, and DeepSeek does not use API traffic for model training. The generated proposal is stored in your account so you can edit and re-export it.
6. Public share links
When you share a proposal via a public link, anyone with the link can view that single document until you disable or expire the link. The link does not expose your account or other proposals. You can revoke any share link from your dashboard.
Visitors to a shared proposal are tracked anonymously via an in-browser identifier. We do not attempt to deanonymize visitors.
7. Cookies
We use first-party cookies for authentication and a single first-party identifier for visitor analytics on public proposals. We do not use third-party advertising cookies or cross-site trackers.
8. Your rights
You can export all your proposals in JSON or PDF format from your dashboard. You can permanently delete your account, which removes all proposals, signatures, and analytics within 30 days. You can request a copy of any personal data we hold by emailing privacy@proposalsgen.com.
If you are based in the EU/UK, you also have rights under GDPR including the right to object to processing and to lodge a complaint with your local data protection authority.
9. Data retention
We retain account data for as long as your account exists. Signature audit logs are retained for 7 years to comply with ESIGN Act record-keeping requirements. Server logs are retained for 30 days.
10. Children
ProposalGen AI is not directed at children under 16, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
If we make material changes, we'll notify you by email at least 30 days before they take effect. Minor edits (typos, clarifications) will be reflected in the “Last updated” date above.
12. Contact
Questions about this policy? Email privacy@proposalsgen.com.