Third Party Index

Snapshot 28737

Document
Subprocessor list
URL
https://praxianlabs.ai/privacy#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
81001 bytes
SHA-256 (raw)
9a517c14c1bcc931e6eaaa7743a111a169eb87baa4ff72826ade0a4bd56a5fdd
SHA-256 (normalized text)
dd1f34a4cc33d67bf874fa8f43c12969ccdd79ca00f5d3a2391a5723967e8407

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy Policy
Effective Date: August 25, 2026
This Privacy Policy describes how Praxian Labs, Inc., a Delaware corporation (“Praxian Labs,” “we,” “us,” or “our”), collects, uses, and shares information when you use our AI-powered civil engineering assistant, including features that let you upload, organize, and share your own documents (the “Service”).
1. Information We Collect
A. Account Information
When you sign in via WorkOS AuthKit (using Google, Microsoft, or email magic link), we collect:
Your name
Email address
Profile picture (if provided by your identity provider)
Note: We do not handle or store your passwords. Authentication is managed entirely by WorkOS and your chosen identity provider.
B. Usage Information
When you use the Service, we collect:
Your queries and the responses generated by the Service
Conversation history and threads
Citations and documents you view
Timestamps of your interactions
C. Documents You Upload
If you use Notebooks or My Documents, we collect and store the documents you upload and information we derive from them:
The files you upload (currently PDFs) and their contents
File details such as file name, size, page count, and any tags or notebook names you assign
Data we generate to make documents searchable, such as parsed text and vector embeddings stored in a private, access-controlled index
Documents you upload are private to you by default. They become accessible to other members of your organization only if you explicitly share them (see “Organizations and Shared Content” below).
D. Technical Data
We automatically collect certain technical information:
Cookies for session management (authentication) and theme preferences
IP addresses for security and abuse prevention
Browser type and device information for debugging and compatibility
2. How We Use Your Information
We use the information we collect to:
Provide, maintain, and improve the Service
Respond to your queries with relevant engineering specification information
Process, index, retrieve, and cite documents you upload, and enable the organization and sharing features you choose to use
Review conversations to improve service quality and accuracy
Ensure security and prevent abuse
Communicate with you about the Service
Comply with legal obligations
Important: We do not use your data to train AI models.
We may review your conversations to verify that the Service is functioning correctly and to improve our prompts and agent instructions. This review is conducted solely to improve service quality.
3. Third-Party Services (Sub-processors)
The Service uses the following third-party sub-processors. This is our current sub-processor list. We will post changes here at least 30 days before a new sub-processor begins processing customer data. Each processes data according to their respective privacy policies:
Sub-processor	What it does	Where data is processed
OpenAI	Generates answers from your queries	United States
Google	Reads uploaded documents into searchable text (Gemini)	Per Google’s Gemini API terms; may include facilities outside the United States
WorkOS	Sign-in and identity	United States
Amazon Web Services	Application hosting, database, file storage	United States (US East)
LanceDB	Vector search index	United States (AWS US East, Northern Virginia)
Praxian Labs’ own application, database, and file storage run in Amazon Web Services’ US East region.
OpenAI
Your queries are processed by OpenAI’s language models via their API to generate responses. Per OpenAI’s API data usage policy, data sent via the API is not used to train OpenAI’s models by default.
OpenAI API Data Policy
OpenAI Privacy Policy
Google
When you upload a document to My Documents or a notebook, we send its pages to Google’s Gemini models (through our LiteLLM proxy) to convert them into clean, searchable text. Under the applicable Gemini API terms, content sent through the API is not used to train Google’s models.
Google Gemini API Terms
Google Privacy Policy
WorkOS
We use WorkOS AuthKit for authentication. WorkOS processes your sign-in information and manages identity provider connections (Google, Microsoft, and email magic link) on our behalf.
WorkOS Privacy Policy
Amazon Web Services (AWS)
We use AWS to host our application and store data, including the documents and images you upload, which are kept in private, access-controlled Amazon S3 buckets, and our PostgreSQL database. This storage is encrypted at rest.
AWS Privacy Notice
LanceDB
We use LanceDB Cloud to store vector embeddings for document search functionality.
LanceDB Privacy Policy
A Data Processing Addendum (DPA) is available to business customers on request.
4. Data Retention and Deletion
Retention
We retain your account information, conversation history, and uploaded documents for as long as your account is active, so you keep your history, context, and document library. We do not automatically expire your content. Organizations may configure retention policies (for example, a maximum age for chat threads); where such a policy applies, affected content is deleted according to that policy.
Deletion
You can delete individual chat threads and uploaded documents at any time, and you can delete your entire account from the Settings page.
When you delete an individual thread or document, it is immediately hidden from the Service and then permanently purged from all of our systems, including our database records, stored files, and search index, after a short recovery window of up to 30 days. The recovery window exists so an accidental deletion can be reversed on request before the data is gone for good. If you delete a document you had shared with your organization, it is removed for the organization as well.
When you delete your account, we immediately and permanently delete your account information, all conversation threads and messages, all documents you have uploaded, and the associated files and search data.
Every deletion runs through a single deletion service that removes the data from each system and records the outcome in an internal deletion log, so we can verify that deletion actually happened across all of our data stores.
One exception applies to the operational logs described in “Data Security” below. Those logs age out on their own 30-day schedule rather than through the deletion process above, so for a short period after you delete a thread, a document, or your account, fragments of the related requests may still exist there. They are never used to train AI models, and they are erased automatically.
5. Data Security
We implement a range of security measures to protect your information, including:
Encryption in transit: all data is transmitted over encrypted connections (HTTPS/TLS)
Standard browser security protections on our web application, including HTTP Strict Transport Security (HSTS) to keep connections on HTTPS and safeguards against clickjacking
Encryption at rest: uploaded files and stored objects are encrypted with AES-256, and our database is encrypted with AWS-managed keys
Access controls and least-privilege permissions on our infrastructure
Tenant isolation: your data is private to you by default, and access is enforced on our servers on every request, so one user cannot access another user’s or another organization’s data
An internal audit record of sensitive organization actions, such as sharing a document with your organization and changes to organization membership or roles
Secure authentication via WorkOS AuthKit, so we never handle or store your password
Your content is never used to train AI models. We keep operational logs of requests to our AI providers for up to 30 days, so we can debug problems and track cost; those logs are deleted automatically on that schedule
If we confirm a security incident affecting your data, we will notify you without undue delay and within 72 hours, describing what we know, what we are doing about it, and what you need to do. An enterprise agreement may set a shorter, contractually binding notification window.
However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Organizations and Shared Content
The Service supports organizations so a firm’s members can collaborate. If your account belongs to an organization, please note:
Your personal data and documents stay private to you by default. Joining an organization never moves or exposes your existing data.
Sharing is always an explicit action. When you share a document with your organization, its members can search, view, and cite that document until you unshare it.
Members are added to an organization only by an owner or admin. Membership is never inferred from your email domain.
Organization owners and admins can manage membership and roles, but they do not gain access to members’ private, unshared documents or chats.
7. Your Rights
You have the right to:
Access your personal information
Delete your account and all associated data
Request information about what data we have about you
To exercise these rights, use the account deletion feature in Settings or contact us at the email below.
8. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Right to know what personal information we collect and how it is used
Right to delete your personal information
Right to opt-out of the sale of your personal information
We do not sell personal information.
9. Children’s Privacy
The Service is intended for professional use by civil engineers and related professionals. It is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will promptly delete such information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” above. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Praxian Labs, Inc.
Email: [email protected]