Legal information
Privacy Notice
This page gives users a complete, readable structure during the private pilot. The legal operator must confirm its registered contact details, governing law, processor list, international-transfer safeguards and final retention schedule before public launch or paid checkout.
1. Controller and contact
The legal operator intends to act as the controller for Prophet.today account and service data. Its identity, full registered address, privacy contact and any representative or data-protection officer details must be confirmed before production launch.
2. Data we process
- Account data: email address, tenant or organization, role and account status.
- Security data: session identifiers, privacy-safe keyed hashes used for abuse prevention, authentication events and audit records. Raw API keys are not shown to the browser.
- Usage data: questions asked, feature use, plan allowances, timestamps, technical diagnostics and answer records. Public permanent-answer links may retain the submitted question and answer.
- Legal records: accepted document versions, timestamps and integrity fingerprints.
- Billing data: plan and payment status when payments are enabled. Paid checkout is currently disabled.
- Support data: information you provide when contacting the operator.
3. Why we process it
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, answers and requested features | Contract or steps requested before a contract |
| Protect accounts, enforce limits and investigate abuse | Legitimate interests in a secure, reliable service; legal obligations where applicable |
| Keep acceptance, audit and accounting records | Contract, legitimate interests and legal obligations |
| Improve reliability using bounded operational diagnostics | Legitimate interests, balanced against user privacy |
| Optional marketing | Consent where required; it must remain separate and withdrawable |
4. Where data comes from
Most personal data comes directly from you or is generated when you use the Service. Organization administrators may provide membership information. Security and technical data are generated by browsers, servers and protective infrastructure.
5. Sharing and processors
Data may be processed by hosting, database, authentication, email, support, AI-model and—once enabled—payment providers acting under appropriate terms. Model providers are used only for enabled and eligible flows; deterministic answers remain available without them. A named processor list, purposes, locations and contracts must be published before production.
6. International transfers
Some providers may operate outside your country. Before production, the legal operator must document transfer locations and the safeguards relied on, such as adequacy decisions or approved contractual clauses, and explain how users can obtain more information.
7. Retention
Data is kept only as long as needed for the purposes above, legal obligations, dispute handling and security. The final schedule must state periods for active and closed accounts, support, billing, security logs, Ask usage, legal acceptance and public answer snapshots. Until that schedule is approved, production signup and paid checkout should remain disabled.
8. Cookies and similar storage
The pilot uses strictly necessary session, security and anonymous allowance cookies. The WordPress preview carries no analytics or advertising tags. Non-essential cookies must not be added without an updated notice and valid consent where required.
9. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing. Identity may need to be verified. You may also complain to your local data-protection authority. The final privacy contact and lead supervisory authority must be inserted before launch.
10. Automated decisions
Prophet produces automated signals and forecasts for decision support. It is not intended to make decisions that produce legal or similarly significant effects about an individual without meaningful human involvement.
11. Security and children
Prophet uses access controls, tenant separation, server-side secrets, integrity records and bounded logging. No system is perfectly secure. The Service is not directed to children, and the minimum account age and regional parental-consent rules must be confirmed before production.
12. Changes
A new dated version will be published when this Notice changes. Fresh acknowledgement will be requested where law or the significance of a change requires it.