Snapshot 28249
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy Policy Effective Date: August 25, 2026 This Privacy Policy describes how Praxian Labs, Inc., a Delaware corporation (“Praxian Labs,” “we,” “us,” or “our”), collects, uses, and shares information when you use our AI-powered civil engineering assistant, including features that let you upload, organize, and share your own documents (the “Service”). 1. Information We Collect A. Account Information When you sign in via WorkOS AuthKit (using Google, Microsoft, or email magic link), we collect: Your name Email address Profile picture (if provided by your identity provider) Note: We do not handle or store your passwords. Authentication is managed entirely by WorkOS and your chosen identity provider. B. Usage Information When you use the Service, we collect: Your queries and the responses generated by the Service Conversation history and threads Citations and documents you view Timestamps of your interactions C. Documents You Upload If you use Notebooks or My Documents, we collect and store the documents you upload and information we derive from them: The files you upload (currently PDFs) and their contents File details such as file name, size, page count, and any tags or notebook names you assign Data we generate to make documents searchable, such as parsed text and vector embeddings stored in a private, access-controlled index Documents you upload are private to you by default. They become accessible to other members of your organization only if you explicitly share them (see “Organizations and Shared Content” below). D. Technical Data We automatically collect certain technical information: Cookies for session management (authentication) and theme preferences IP addresses for security and abuse prevention Browser type and device information for debugging and compatibility 2. How We Use Your Information We use the information we collect to: Provide, maintain, and improve the Service Respond to your queries with relevant engineering specification information Process, index, retrieve, and cite documents you upload, and enable the organization and sharing features you choose to use Review conversations to improve service quality and accuracy Ensure security and prevent abuse Communicate with you about the Service Comply with legal obligations Important: We do not use your data to train AI models. We may review your conversations to verify that the Service is functioning correctly and to improve our prompts and agent instructions. This review is conducted solely to improve service quality. 3. Third-Party Services (Sub-processors) The Service uses the following third-party sub-processors. This is our current sub-processor list. We will post changes here at least 30 days before a new sub-processor begins processing customer data. Each processes data according to their respective privacy policies: Sub-processor What it does Where data is processed OpenAI Generates answers from your queries United States Google Reads uploaded documents into searchable text (Gemini) Per Google’s Gemini API terms; may include facilities outside the United States WorkOS Sign-in and identity United States Amazon Web Services Application hosting, database, file storage United States (US East) LanceDB Vector search index United States (AWS US East, Northern Virginia) Praxian Labs’ own application, database, and file storage run in Amazon Web Services’ US East region. OpenAI Your queries are processed by OpenAI’s language models via their API to generate responses. Per OpenAI’s API data usage policy, data sent via the API is not used to train OpenAI’s models by default. OpenAI API Data Policy OpenAI Privacy Policy Google When you upload a document to My Documents or a notebook, we send its pages to Google’s Gemini models (through our LiteLLM proxy) to convert them into clean, searchable text. Under the applicable Gemini API terms, content sent through the API is not used to train Google’s models. Google Gemini API Terms Google Privacy Policy WorkOS We use WorkOS AuthKit for authentication. WorkOS processes your sign-in information and manages identity provider connections (Google, Microsoft, and email magic link) on our behalf. WorkOS Privacy Policy Amazon Web Services (AWS) We use AWS to host our application and store data, including the documents and images you upload, which are kept in private, access-controlled Amazon S3 buckets, and our PostgreSQL database. This storage is encrypted at rest. AWS Privacy Notice LanceDB We use LanceDB Cloud to store vector embeddings for document search functionality. LanceDB Privacy Policy A Data Processing Addendum (DPA) is available to business customers on request. 4. Data Retention and Deletion Retention We retain your account information, conversation history, and uploaded documents for as long as your account is active, so you keep your history, context, and document library. We do not automatically expire your content. Organizations may configure retention policies (for example, a maximum age for chat threads); where such a policy applies, affected content is deleted according to that policy. Deletion You can delete individual chat threads and uploaded documents at any time, and you can delete your entire account from the Settings page. When you delete an individual thread or document, it is immediately hidden from the Service and then permanently purged from all of our systems, including our database records, stored files, and search index, after a short recovery window of up to 30 days. The recovery window exists so an accidental deletion can be reversed on request before the data is gone for good. If you delete a document you had shared with your organization, it is removed for the organization as well. When you delete your account, we immediately and permanently delete your account information, all conversation threads and messages, all documents you have uploaded, and the associated files and search data. Every deletion runs through a single deletion service that removes the data from each system and records the outcome in an internal deletion log, so we can verify that deletion actually happened across all of our data stores. One exception applies to the operational logs described in “Data Security” below. Those logs age out on their own 30-day schedule rather than through the deletion process above, so for a short period after you delete a thread, a document, or your account, fragments of the related requests may still exist there. They are never used to train AI models, and they are erased automatically. 5. Data Security We implement a range of security measures to protect your information, including: Encryption in transit: all data is transmitted over encrypted connections (HTTPS/TLS) Standard browser security protections on our web application, including HTTP Strict Transport Security (HSTS) to keep connections on HTTPS and safeguards against clickjacking Encryption at rest: uploaded files and stored objects are encrypted with AES-256, and our database is encrypted with AWS-managed keys Access controls and least-privilege permissions on our infrastructure Tenant isolation: your data is private to you by default, and access is enforced on our servers on every request, so one user cannot access another user’s or another organization’s data An internal audit record of sensitive organization actions, such as sharing a document with your organization and changes to organization membership or roles Secure authentication via WorkOS AuthKit, so we never handle or store your password Your content is never used to train AI models. We keep operational logs of requests to our AI providers for up to 30 days, so we can debug problems and track cost; those logs are deleted automatically on that schedule If we confirm a security incident affecting your data, we will notify you without undue delay and within 72 hours, describing what we know, what we are doing about it, and what you need to do. An enterprise agreement may set a shorter, contractually binding notification window. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. 6. Organizations and Shared Content The Service supports organizations so a firm’s members can collaborate. If your account belongs to an organization, please note: Your personal data and documents stay private to you by default. Joining an organization never moves or exposes your existing data. Sharing is always an explicit action. When you share a document with your organization, its members can search, view, and cite that document until you unshare it. Members are added to an organization only by an owner or admin. Membership is never inferred from your email domain. Organization owners and admins can manage membership and roles, but they do not gain access to members’ private, unshared documents or chats. 7. Your Rights You have the right to: Access your personal information Delete your account and all associated data Request information about what data we have about you To exercise these rights, use the account deletion feature in Settings or contact us at the email below. 8. California Residents (CCPA) If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA): Right to know what personal information we collect and how it is used Right to delete your personal information Right to opt-out of the sale of your personal information We do not sell personal information. 9. Children’s Privacy The Service is intended for professional use by civil engineers and related professionals. It is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will promptly delete such information. 10. Changes to This Policy We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” above. Your continued use of the Service after changes constitutes acceptance of the updated policy. 11. Contact Us If you have questions about this Privacy Policy, please contact us at: Praxian Labs, Inc. Email: [email protected]