Who we are
Proofsource is a service of Proofsource AI Pvt Ltd, a company registered in India ("Proofsource", "we", "us"). This policy explains what personal data we collect when you visit proofsource.co, use the Proofsource app at app.proofsource.co, or contact us, and what we do with it.
Proofsource is a business tool. It measures how AI answer engines mention and cite your brand, and helps you act on what it finds. It is meant for companies and the people who work for them, not for personal use.
The short version
- We collect what we need to run your account and your workspace, and little else.
- We don't sell personal data and we don't use it for advertising.
- We don't use your data to train AI models.
- You can ask us for a copy of your data, or to delete it, at any time.
What we collect
- Account details: your name, work email address, and a profile picture if you upload one. Your role in your workspace and the workspaces you belong to.
- Workspace content: the brands, domains, competitors, markets and prompts you track, your settings, reports, notes, content drafts, files you upload, and the questions you ask our assistant.
- Measurement data: the answers AI engines give to your tracked prompts, the sources they cite, and copies of cited public web pages.
- Data from services you connect: for example Google Search Console, Google Analytics, CDN analytics, server logs and your website. Logs we receive can include IP addresses and user agents of AI crawlers.
- Credentials for services you connect, such as access tokens and keys. We store these encrypted.
- Billing details: your billing name, email, address, country and tax details. Payment card and bank details are collected by our payment provider, Dodo Payments, not by us.
- Messages: emails, contact form submissions and support conversations.
- Security and usage data: IP address, browser and device type, sign-in times, and actions taken in your workspace.
- Website analytics: see Cookies and analytics below.
Please don't put personal data about other people into your tracked prompts. Prompts are sent to AI engines as written, and the service doesn't need personal data to work.
How we use it
- To provide the service: run your prompts on AI engines, analyse the answers, build your reports, send your alerts, and run the features you turn on.
- To create and secure your account, sign you in, and prevent fraud and abuse.
- To bill you and keep the records the law requires.
- To talk to you: sign-in codes, results, alerts, service and billing notices, and replies to your questions.
- To understand how our website is used and improve the product.
- To meet legal obligations and enforce our Terms of Service.
Data we receive from Google is used only as described under Google user data below.
Legal bases
Where the GDPR or UK GDPR applies, we rely on these legal bases: performance of our contract with you or your company, to provide the service; our legitimate interests in securing, supporting and improving the service; your consent, where we ask for it, which you can withdraw at any time; and legal obligation. Under India's Digital Personal Data Protection Act, 2023, we process your personal data for the purposes described here with your consent, or for legitimate uses the Act allows.
AI models and your data
- We don't use your data to train AI models.
- To measure your visibility, we send your tracked prompts to AI engines, the same way a buyer would ask them.
- Some features send workspace content to an AI model to do their job. We share with AI providers only what a task needs.
- AI answers we capture are third-party content. We show them to you as evidence of what the engines said.
Google user data
Proofsource asks Google only for what each feature needs, and only when you start that feature.
- Sign in with Google (scopes userinfo.email and userinfo.profile): Google shares your name, email address and profile picture. We keep your name and email address and use them only to create your account and sign you in. We don't keep a Google token for sign-in.
- Connect Search Console (scope webmasters.readonly, read-only): we read the list of Search Console sites you can access, so you can pick the one for your brand, and that site's search performance: queries, pages, clicks, impressions, click-through rate and position.
- Connect Google Analytics (scope analytics.readonly, read-only): we read the list of Google Analytics properties you can access, so you can pick the one for your brand, and that property's reports: sessions, traffic source and channel, landing pages, key events, transactions and revenue.
How we use it: only to show it back to you and your workspace in Proofsource. That means the Organic search and AI referrals pages, reports you create, agent steps you add, and ranking which of your tracked prompts matter most. We never write, change or delete anything in your Google accounts.
Storage and security: Google tokens are encrypted at rest. Imported data is stored in our database on AWS, kept separate per organisation, and visible only to members of your workspace.
Sharing: we don't sell Google user data, use it for advertising, or use it to develop, improve or train generalized AI or machine-learning models. We transfer it only as needed to run the features above: to our hosting provider, and, if an agent you build feeds a Google Analytics step into an AI step, to the AI model provider that runs that step. Beyond that we share it only to comply with the law, or as part of a merger or acquisition with notice to you. Proofsource staff don't read your Google data unless you ask us to for support, it's needed for security, or the law requires it.
Disconnecting and deletion: you can disconnect Search Console or Google Analytics at any time on the Integrations page. When you disconnect, we delete our stored copy of the token and stop syncing. If no other connection of yours uses that Google account, we also ask Google to revoke Proofsource's access. Your other connections keep working. You can also remove Proofsource's access at myaccount.google.com/permissions. Data already imported stays in your workspace until you delete your account or ask [email protected] to delete it. We then delete your Google tokens and imported data.
Proofsource's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who we share it with
We don't sell personal data, and we don't share it with advertisers or data brokers. We share it only with service providers that help us run Proofsource, each limited to what its job needs:
- Cloud hosting and infrastructure.
- AI model and search data providers.
- Email and notification delivery.
- Payments: Dodo Payments, our merchant of record, which bills you and handles sales tax.
- Website analytics.
- Services you connect, such as Google.
A current list of providers is available on request at [email protected].
We may also disclose personal data when the law or a valid legal process requires it, to protect the rights, property or safety of our users, the public or us, or as part of a merger, acquisition or sale of assets.
Services you connect
When you connect a service such as Slack, a webhook or your website, we send data to it because you asked us to. Those services handle the data under their own terms. You can disconnect any of them at any time on the Integrations page.
International transfers
We store and process data in the United States, and our team works from India. Some providers process data in other countries. Where the GDPR or UK GDPR applies, we protect transfers with Standard Contractual Clauses or another lawful mechanism. Transfers out of India follow the Digital Personal Data Protection Act, 2023.
How long we keep it
We keep data only as long as needed to provide the service, meet legal obligations and resolve disputes. You can ask us to delete it at any time by emailing [email protected].
Security
We protect data with encryption in transit and at rest, access controls, and isolation between customers. No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant authorities as the law requires. To report a vulnerability, email [email protected].
Cookies and analytics
- The app (app.proofsource.co) uses only cookies it needs to work, such as keeping you signed in and remembering your active workspace. It uses no analytics or advertising cookies.
- Our website (proofsource.co) uses PostHog for analytics. By default it sends anonymous page views and a few anonymous button events (for example, opening the contact form), without setting cookies or storing identifiers in your browser.
- With your consent, PostHog sets a cookie to recognise a returning browser and records clicks and session replays. Anything typed into a form field is masked in replays, and the contact form is not recorded.
- If your browser sends Do Not Track or Global Privacy Control, we treat it as no.
- You can change your choice any time through Cookie settings at the bottom of every page.
- We don't use advertising cookies, and we don't let third parties track you across other sites through our website.
Your rights
Wherever you are, you can ask us to access, correct, update, export or delete your personal data, and you can withdraw consent you have given. Some laws give you more specific rights:
- European Union, EEA and United Kingdom: the rights of access, rectification, erasure, restriction, data portability and objection, and the right to complain to your local data protection authority.
- India: under the Digital Personal Data Protection Act, 2023, the right to a summary of your personal data and how it is processed, to correction, completion, updating and erasure, to grievance redressal, and to nominate someone to exercise your rights. If we don't resolve your grievance, you can complain to the Data Protection Board of India.
- California: the right to know what personal information we collect, use and disclose, and to delete and correct it. We don't sell or share personal information for cross-context behavioural advertising, and we won't treat you differently for using your rights.
To use any of these rights, email [email protected]. We may need to confirm your identity first. We reply within the time required by applicable law. If your request concerns a workspace your company controls, we may refer it to your workspace owner.
When your company is in charge
For data that customers put into Proofsource, the customer decides what goes in and we process it on their behalf as a processor. Our Terms of Service and any data processing agreement with the customer govern it. To request a data processing agreement, email [email protected].
Children
Proofsource is for businesses. It is not meant for anyone under 18, and we don't knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.
Changes to this policy
We will post any change on this page and update the effective date. If a change is material, we will tell you by email or in the app.
Contact and grievance officer
- Privacy questions and requests: [email protected]
- Grievance Officer (India): Lokesh Basu, [email protected]. We acknowledge and resolve grievances within the time the law requires.
- Everything else: [email protected]
Proofsource AI Pvt Ltd, Bengaluru, Karnataka, India.