Legal

Privacy Policy

Last updated: February 28, 2026

1. Information We Collect

We collect information you provide directly: your name, email address, and organization details when you create an account. We also collect data you import into the Service through integrations or manual uploads, such as support tickets, feedback, and usage analytics. Additionally, we collect basic usage data about how you interact with the Service, including pages visited, features used, and session duration.

2. How We Use Your Information

We use your information to: (a) provide, operate, and maintain the Service; (b) process and analyze your imported data using AI to generate insights and recommendations; (c) communicate with you about your account, updates, and support requests; (d) improve and develop new features for the Service; and (e) ensure the security and integrity of the platform. We do not use your data to train AI models for other customers.

3. AI Data Processing

When you use AI-powered features, your data is processed in isolated, stateless workflows scoped to your organization. Prompts are constructed from your data only and are not retained in memory between requests. We use third-party AI providers (such as OpenAI) to power these features. Data sent to AI providers is used solely to generate responses for your requests and is not used for model training. You can supply your own API key for AI processing through your account settings.

4. Data Sharing

We do not sell your personal information or your organization's data to third parties. We share data only with the sub-processors necessary to operate the Service (listed on our Security page). These include our infrastructure provider, authentication service, AI provider, analytics platform, and email delivery service. Each sub-processor receives only the minimum data required to perform its function.

5. Third-Party Integrations

When you connect third-party tools (such as project management, support, or analytics platforms), we access data from those services on your behalf using OAuth tokens you authorize. We store integration credentials in encrypted form. You can review and disconnect integrations at any time. Each third-party service has its own privacy policy that governs how it handles your data.

6. Data Security

We implement technical and organizational measures to protect your data, including: encryption of credentials at rest using AES-256-GCM, strict tenant isolation ensuring your data is never accessible to other organizations, serverless architecture with no shared state between requests, and JWT-based authentication with short-lived tokens. For more details, see our Security page.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. When you delete your account, we initiate deletion of your data from our systems and sub-processors. Some data may be retained in backups for a limited period as part of our disaster recovery process. Anonymized, aggregated data that cannot identify you may be retained indefinitely for analytics purposes.

8. Your Rights

Depending on your location, you may have the right to: (a) access the personal data we hold about you; (b) correct inaccurate data; (c) request deletion of your data; (d) export your data in a portable format; (e) object to or restrict certain processing; and (f) withdraw consent where processing is based on consent. To exercise any of these rights, contact us at hello@productbet.io.

9. Cookies and Tracking

We use essential cookies required for the Service to function, such as authentication and session management. We use PostHog for product analytics, which collects anonymized usage events and session metadata. We do not use third-party advertising cookies or trackers. You can manage cookie preferences through your browser settings.

10. International Data Transfers

Your data may be processed in countries other than your own, including the United States and the European Union, where our sub-processors operate. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where applicable.

View our Data Processing Agreement (DPA)

11. Children's Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at hello@productbet.io.