PRONOA
The Road Decide Operate Predict Who It's For Pricing Decision Governance Writing Launch List
Pronoa, Inc. · Legal

Privacy Policy

Effective 27 September 2026 · Last updated 27 September 2026See also the Terms of Service

This Privacy Policy explains how Pronoa, Inc. (“Pronoa,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with our decision-intelligence platform and related websites and services (collectively, the “Services”). It applies to visitors to our websites, individuals who register for or use the Services (“Authorized Users”), and prospective customers who interact with us.

Our role. For most business content that a customer submits to the Services, the customer is the controller of that information and Pronoa acts as a processor or service provider on the customer’s documented instructions, as described in the Terms of Service and the Platform Agreement. This Privacy Policy addresses the personal information for which Pronoa itself acts as a business or controller: primarily account, contact, billing, and website-usage information. It does not govern how a customer decides to use the Services, and it is not a substitute for the customer’s own privacy notices to its personnel.

Not for sensitive or regulated data. The Services are not designed to collect significant personal information and must not be used to submit sensitive information, protected health information, or payment card data into decision content. Please do not provide such information to the Services except as expressly described here.

Contents
  1. Information we collect
  2. How we use personal information
  3. Artificial-intelligence providers and model training
  4. How we share personal information
  5. Subprocessors
  6. Cookies and similar technologies
  7. Data retention
  8. How we protect personal information
  9. Your privacy rights
  10. International data transfers
  11. Children
  12. How to contact us
  13. Changes to this Policy

1.Information we collect

We collect the following categories of personal information:

  • Account and identity information. Name, business email address, and similar registration details we require to create and maintain an Authorized User account, consistent with the Personal Information provisions of our Terms of Service and Platform Agreement.
  • Contact and communications information. Information you provide when you contact us, request a demonstration, correspond with support, or subscribe to communications, including your name, email, telephone number, and the contents of your messages.
  • Billing information. Billing contact details and transaction records. Card and bank payment details are collected and processed by our payment processor; we do not store full payment card numbers.
  • Usage and device information. Limited technical information necessary to operate and secure the Services, such as IP address, browser and device type, and requested pages, recorded in standard server and security logs by our hosting providers. We do not use analytics or advertising technologies, and we do not use this information to track or profile visitors. Where required by applicable law, IP addresses and similar identifiers are treated as personal information.
  • Customer content (as processor). Business documents and inputs a customer submits into the Services. To the extent this content contains personal information, we process it on the customer’s behalf under the applicable agreement and, where required, a data processing agreement, not under this Policy.

2.How we use personal information

We use personal information to: provide, maintain, and secure the Services; create and administer accounts and authenticate Authorized Users; process transactions and manage billing; respond to inquiries and provide support; communicate with you about the Services, including service and security notices; understand and improve how our websites and Services are used; and comply with legal obligations and enforce our agreements.

De-identified usage data. As described in our Terms of Service and Platform Agreement, we may derive de-identified, aggregated usage data for calibration, benchmarking, product improvement, and analytics. Such usage data is de-identified in accordance with applicable standards (including CCPA/CPRA and, where applicable, GDPR), is not reasonably linkable to any individual or customer, and never includes the content of customer decision materials or outputs.

3.Artificial-intelligence providers and model training

The Services rely on third-party artificial-intelligence models to generate outputs. As of the effective date, our production model provider is Anthropic (Claude). If we engage any additional or substitute model provider, we will do so under equivalent zero-data-retention and no-training terms and provide notice as required.

No training on your content. We configure our use of this provider under zero-data-retention and no-training terms: content submitted to the Services is not retained by the model provider beyond what is necessary to return a response, and is not used to train its models. We do not sell personal information, and we do not use the content of customer decision materials to train models.

4.How we share personal information

We do not sell personal information. We share personal information only as follows:

  • Service providers and subprocessors. With vendors who process personal information on our behalf to operate the Services, under contracts that limit their use of the information to providing services to us. Our current subprocessors are listed in Section 5.
  • For legal and safety reasons. Where necessary to comply with law, respond to lawful requests, enforce our agreements, or protect the rights, property, or safety of Pronoa, our customers, or others.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction. When you or the applicable customer direct us to share information.

5.Subprocessors

We engage the following categories of subprocessors to provide the Services. Each is engaged under terms requiring appropriate security and confidentiality:

SubprocessorFunction
AnthropicAI model provider (Claude); generation of outputs. Zero-data-retention / no-training configuration.
SupabaseDatabase, authentication, and storage; encryption at rest and tenant isolation.
VercelApplication hosting and delivery.
StripePayment processing and billing.
SentryApplication error monitoring.
ResendTransactional email delivery.
LangfuseModel telemetry and observability; operational metadata only, not customer decision content.
NetlifyMarketing website hosting and website form submissions (prospect contact details).

Separately, we rely on standard business-operations providers, such as Google Workspace for email and correspondence, that may process contact information you send to us. These support our own operations rather than the Services and do not process customer decision content.

6.Cookies and similar technologies

We use only strictly-necessary cookies and similar technologies required to operate the Services, such as keeping you signed in and maintaining security. We do not use analytics, advertising, or other non-essential cookies, and we do not track visitors across websites. You can control cookies through your browser settings, though disabling strictly-necessary cookies may affect core functionality.

7.Data retention

We retain personal information for as long as needed to provide the Services, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements.

Customer decision records. The decision log is designed to function as a permanent institutional record during a customer’s active subscription. During the subscription, an authorized user can delete session data, which is moved to a recovery bin and permanently purged after thirty (30) days; executed decision records are retained as a permanent institutional record and are not deletable. On termination or expiration of a customer agreement, we return or delete customer data in accordance with the applicable agreement and applicable law.

Customer-directed purge. The Services allow an authorized customer administrator to permanently purge uploaded third-party confidential materials and derived content from a decision session during the term, to support the customer’s own confidentiality obligations, and we direct deletion of purged materials from subprocessor environments within a commercially reasonable period.

Residual copies and third-party retention. Deletion and purge apply to our active production systems. After deletion or purge, residual copies may persist in our encrypted backups and replicas until they are expired in the ordinary course, and they remain subject to the same protections in the meantime. Separately, our subprocessors retain their own security and operational records, such as access and system logs, under their own retention practices, and certain subprocessors are legally required to retain transaction records (for example, payment records held by our payment processor) that a deletion request does not override. Those subprocessor records are limited to technical and transactional information and do not include the content of customer decision materials.

8.How we protect personal information

We maintain administrative, technical, and organizational measures designed to protect personal information, including encryption in transit and at rest, tenant isolation, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9.Your privacy rights

United States (including California). Depending on your state of residence, you may have rights to know, access, correct, delete, or receive a portable copy of your personal information, and to be free from discrimination for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising. Where an individual’s personal information is contained in customer content, we will refer requests to the relevant customer as the controller.

EEA and United Kingdom. Where GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, or object to processing, and to data portability. Our legal bases include performance of a contract, our legitimate interests in operating and improving the Services, consent where required, and compliance with legal obligations.

To exercise any right, contact us using the details in Section 12. We will respond as required by applicable law and may need to verify your identity.

10.International data transfers

We are based in the United States, and we process personal information in the United States and in other countries where we or our subprocessors operate. The Services are provided from the United States. If you access or subscribe to the Services from the United Kingdom, the European Economic Area, or elsewhere outside the United States, your personal information will be transferred to, and processed in, the United States.

Where we transfer personal information that is subject to UK or EU data protection law to the United States, we rely on an appropriate transfer safeguard required by applicable law. For a customer subject to the EU GDPR or the UK GDPR, we make available a data processing agreement incorporating the applicable Standard Contractual Clauses and, for the United Kingdom, the UK Addendum or International Data Transfer Agreement, or we rely on an applicable adequacy framework where available. To request a data processing agreement, contact us using the details in Section 12.

11.Children

The Services are intended for business use by adults and are not directed to children. We do not knowingly collect personal information from anyone under the age of majority in their jurisdiction, and consistent with our agreements we do not collect information from children under 13.

12.How to contact us

For questions about this Privacy Policy or to exercise your rights, contact:

Pronoa, Inc.
contact@pronoa.io
1500 N Grant St, Ste R, Denver, CO 80203

13.Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last updated” date and, where required by law, provide additional notice. Your continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.

PRONOA
Pricing Decision Governance Writing Contact
DECISION GOVERNANCE · THE GOVERNED COMPANY · © 2026
Pronoa, Inc. · 1500 N Grant St, Ste R, Denver, CO 80203 contact@pronoa.ioPrivacy PolicyTerms of Service