Snapshot 28250
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Trust & Data Handling AI & training Is customer data used to train AI models? No. Praxian Labs does not use your chats or uploaded documents to train AI models. We send data to OpenAI and Google through their paid APIs, whose standard terms exclude your content from model training. How are the documents we upload handled? Uploaded PDFs are kept in private, encrypted storage, and Google’s Gemini AI reads them into searchable text so answers can quote and cite them. They stay private to you unless you deliberately share them with your organization. Access & isolation Can other users or organizations see our data? No. Your chats and documents are private to you by default, and no user or organization can reach another’s. Every request is permission-checked on our own servers, and if a check can’t confirm you have access, the request is refused. Do you support organizations and access controls? Yes. Accounts can belong to an organization with owner, admin, and member roles. Members are added by an owner or admin, never by automatic matching on email domain. Owners and admins manage membership but cannot see members’ private chats or unshared documents. Sharing and changes to membership or roles are recorded in an audit log, which we provide on request. How do users sign in, and do you support SSO? Sign-in is handled by WorkOS, so Praxian Labs never sees or stores a password. Users can sign in with Google, Microsoft, or an email link. SAML SSO, directory sync, and restricting an organization to a single identity provider are available on request. Who can access our data? Only authorized Praxian Labs staff who need it for support and security, each using a named account with multi-factor authentication. Parts of the product are run by service providers: OpenAI (generates answers), Google (reads uploaded documents into text), WorkOS (sign-in), AWS (hosting and file storage), and LanceDB (search). Each processes your data only for that one function. Export, retention & deletion Can we get our data out? Yes. You can download any document you’ve uploaded from My Documents, in its original form, at any time. For a full export of an organization’s documents and conversation history, including on account closure, contact us at [email protected] and we will provide one. Do you store chats and account data? Yes. We keep your account information, conversation history, and uploaded documents for as long as your account is active. Nothing is deleted automatically unless your organization has a retention policy, which we set to your requirements and confirm with you before it takes effect. Operational logs of requests to our AI providers are kept for up to 30 days for debugging and cost tracking, then deleted automatically. Can we delete our data? Yes. You can delete individual chats and documents, or your entire account, from within the app. One deletion process removes the data from our database, file storage, and search index, and logs what it removed. Deleted items disappear from the product immediately and are permanently erased within 30 days, or within the window we agree with you. Hosting & security How is our data protected and hosted? Praxian Labs runs on Amazon Web Services in the United States. Data is encrypted in transit (TLS) and at rest, with uploaded files using AES-256 and the database encrypted with AWS-managed keys. What happens if there’s a security incident? If we confirm a security incident affecting your data, we notify you without undue delay and within 72 hours, with what we know, what we are doing about it, and what you need to do. An enterprise agreement can set a shorter, contractually binding notification window. Are you SOC 2 compliant? Not yet. Certification is planned, and many of the controls SOC 2 expects are already in place: encryption, strict tenant isolation, audit logging, and verified deletion. The infrastructure and identity providers underneath us (AWS, OpenAI, and WorkOS) are themselves SOC 2 Type II certified. For a security review, contact us at [email protected]. For full legal details, see the Privacy Policy and Terms of Service. Reporting a vulnerability Email [email protected] with steps to reproduce. We acknowledge reports within three business days and will keep you updated as we investigate. If you make a good-faith effort to comply with this policy during your research, we will not pursue legal action against you, and we will not share your identity without your consent. Please do not access or modify data that is not yours, degrade the service for others, or disclose an issue publicly before we have had a chance to fix it. Last updated: September 24, 2026 Bring a question from a live project Free during early access for individual engineers.Deploying to a firm or agency? See Enterprise. Sign UpBook a Demo Your chats and documents stay private and are never used to train AI models.