Probeli AI is a tool for businesses that shows how AI engines (ChatGPT, Gemini, Google AI Mode and Perplexity) talk about a brand and its competitors. This policy explains what personal data we process when you visit our website, create an account, use the app, receive our emails or pay for a plan, and when our crawler reads public web pages.
The short version: we collect what we need to run Probeli AI, we don't sell personal data, and we don't use advertising or analytics trackers on our website or in the app.
1. Who is responsible and how to contact us
In brief: Probeli AI is responsible for your personal data. Write to [email protected] with any privacy question or request.
The controller responsible for the processing described in this policy is Probeli AI, operating as Probeli AI ("we", "us"), which operates our website at probeli.ai and the Probeli AI app at app.probeli.ai. Probeli AI is established outside the European Union. For any privacy question or request, write to [email protected].
When our customers track prompts and brands in Probeli AI, they decide what goes into their workspaces. For personal data inside that content, we act on the customer's behalf (see section 21).
2. Summary
| Situation | Personal data | Why | Legal basis (GDPR) | How long |
|---|---|---|---|---|
| You visit our website | IP address, browser details, pages requested | Deliver and protect the website | Legitimate interests, Art. 6(1)(f) | Up to 30 days |
| You contact us | Name, email, topic, message, and company and website if you add them | Answer you | Legitimate interests, Art. 6(1)(f); steps before a contract, Art. 6(1)(b) | As long as needed to handle your request |
| You create an account and sign in | Name, email, password hash, passkeys, two-factor data, Google profile, session IP address and browser, bot-check signals | Run your account and keep it secure | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) | Until you delete your account; sessions 30 days after last use |
| You use Probeli AI | Workspace content, team members, invitations, activity | Provide the service | Contract, Art. 6(1)(b) | Until the workspace is deleted; full answer text per plan |
| Our crawler reads public pages | Anything a public page contains, such as names | Find indirect mentions and run site audits | Legitimate interests, Art. 6(1)(f) | Page text 90 days, page records 365 days after the last citation |
| We send you emails | Email address, name, email content; hashes of your address and of the requesting network | Sign-in, invitations, reports and alerts | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) | Resend keeps sent emails for 30 days; our sending records 2 days |
| You pay for a plan | Paddle customer and subscription IDs, plan status | Manage plans | Contract, Art. 6(1)(b); legal obligations, Art. 6(1)(c) | Until the workspace is deleted; Paddle keeps invoices as tax law requires |
| Something goes wrong in the app or on our website | User ID and workspace ID (app only), technical error details | Find and fix errors | Legitimate interests, Art. 6(1)(f) | Up to 30 days |
| You start a free trial | User ID, one-way hash of your email, hash of your IP address, website domain | Limit repeated free trials | Legitimate interests, Art. 6(1)(f) | Kept after deletion (see section 10) |
The sections below explain each situation in detail.
3. When you visit our website
In brief: Our website runs without analytics, advertising pixels or tracking cookies. Our hosting provider sees the technical data every website visit sends.
3.1 Hosting and server logs
Our website is hosted by Railway. When you open a page, your browser sends technical data: your IP address, browser and device details, the page requested, the referring page and the time. Our hosting provider processes this data to deliver the page and may keep it in server logs to keep the website secure and fix problems.
- Legal basis: our legitimate interest in running a secure, working website (Art. 6(1)(f) GDPR).
- Retention: up to 30 days, after which the logs expire automatically.
3.2 No analytics, advertising or social media plugins
We don't use analytics tools, advertising pixels or social media plugins on our website. Fonts and images are served from our own servers, so opening our website doesn't send your data to font or image services. We don't show a cookie banner because we don't set cookies that need your consent (see section 11).
3.3 Contact form
When you use our contact form, we receive your name, email address, the topic and your message, and, if you add them, your company and website. The form sends your message by email to our team's inbox, [email protected], through our email provider, Resend. Our inbox is hosted by Zoho Mail, and we reply from it. We don't store your message in our database; it stays in that inbox. The same applies when you write to [email protected] directly. To prevent spam, our server keeps your IP address (for IPv6, only your network's part of it) in its memory for at most 24 hours after the last message you sent, to limit how many messages can be sent. It is not stored.
- Purpose: to answer your message.
- Legal basis: our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR) or, if you ask about a plan or your account, steps before or under a contract (Art. 6(1)(b) GDPR).
- Retention: as long as needed to handle your request and any follow-up, unless the law requires us to keep it longer.
3.4 Error reports
When an error happens on our website, on our servers or in your browser, we send a technical report to Sentry, hosted in the EU (Germany): the error message and where it happened, the page address with personal values such as email addresses removed, and your browser and operating system. It contains no IP address, no cookies and nothing you typed into the contact form, and reports from your browser go through our own server first. Error reporting on our website sets no cookies and stores nothing in your browser, and we don't record sessions or screens.
- Legal basis: our legitimate interest in running a working website (Art. 6(1)(f) GDPR).
- Retention: up to 30 days.
4. When you create an account and sign in
In brief: We store what you need to sign in and keep your account safe, including the IP address and browser of each session, which you can see in your security settings.
4.1 What we process
- Account details: your name, email address, whether your email is verified, your language and, if you add one, a profile picture.
- Password: if you use one, we store only a secure hash, never the password itself.
- Sign-in and verification links: one-time sign-in (magic) links, email verification and password-reset links, which expire after a short time.
- Passkeys: the public key, credential ID and device type your device creates. Your fingerprint or face data never leaves your device.
- Two-factor authentication: the secret for your authenticator app and your backup codes, if you turn it on.
- Sign-in with Google (where offered): your name, email address, profile picture and account ID from Google, and the access tokens it issues, which we store to keep the connection working. Your browser, and the browsers of your team members, load these profile pictures directly from Google, which then receives the viewer's IP address and browser details.
- Sessions: for each sign-in, the IP address, browser (user agent), time and expiry. You can see and end your active sessions in your account's security settings.
- Bot protection: our sign-up, sign-in and email-link forms use Cloudflare Turnstile, which receives your IP address and browser and device details to check that you are not a bot.
- Security limits: we count sign-in attempts per IP address to slow down attacks. This count is kept in memory only. We also keep short-lived records of the account emails we send, to limit email abuse (section 10.2).
4.2 Why and on what legal basis
We use this data to create your account, let you sign in and keep your account secure. The legal basis is our contract with you or your organization (Art. 6(1)(b) GDPR) and our legitimate interest in preventing unauthorized access and abuse (Art. 6(1)(f) GDPR).
When you choose to sign in with Google, Google processes your data as an independent controller under its own privacy policy.
4.3 Who helps us
Supabase (our database), Railway (our app hosting), Resend (sign-in and verification emails), Cloudflare R2 (profile pictures) and Cloudflare Turnstile (bot protection). See section 12.
4.4 How long we keep it
Until you delete your account. Sessions end 30 days after you last use them, or when you sign out. Sign-in, verification and reset links expire after a short time. Profile pictures are not yet deleted from our file storage automatically when you delete your account: ask us at [email protected] and we will delete them.
5. When you use Probeli AI
In brief: Your workspaces hold business data: your website, brands, competitors, prompts and the AI answers to them. Your prompts go to our data provider, which asks the AI engines. Don't put personal data into prompts.
5.1 What we store in a workspace
- your website address and its homepage title and description;
- your brand's name, domains and aliases, and those of the competitors you track;
- your prompts, including archived ones and the wording each answer was asked with;
- the AI answers: their full text, the sources they cite, the searches the engine ran and the brands they name;
- the results of our analysis: mentions, position, sentiment, citations and Insights (with their status);
- AI site audit results and which team member started each audit;
- the workspace's name and logo, its members, their roles and invitations;
- when a member last opened the workspace, which we use to pause inactive trials;
- your notifications and notification settings.
Most of this is business information. It contains personal data where you enter some (for example a prompt about a named person) or where an AI answer mentions a person.
Legal basis: our contract with you or your organization (Art. 6(1)(b) GDPR).
5.2 How your prompts are processed
To collect answers, we send your prompts, together with the workspace's location and language settings, to our data provider DataForSEO (Estonia). DataForSEO submits them to the AI engines we measure, which today are ChatGPT, Gemini, Google AI Mode and Perplexity. These engines are operated by OpenAI, Google and Perplexity. DataForSEO then returns the answers to us. We don't send your name, email address or other account details with your prompts.
To suggest competitors and prompts, we send your brand name, domain, homepage description, competitor names and existing prompts to DataForSEO, which has an AI model (today one of OpenAI's) write the suggestions.
We have no contract with the operators of the AI engines. They process prompts under their own terms, and we cannot control whether they store or use them. This is why you should not put personal data or confidential information into prompts, brand names or aliases.
5.3 How answers are analyzed
Our analysis is rule-based. We match brand names, aliases and domains, record the order in which tracked brands appear, and calculate a word-based sentiment score. It concerns brands, not people, and we make no automated decisions about people (see section 20). We do not use your data to train AI models.
5.4 Website icons from Google
To show the icon of each website next to brands, competitors and sources, your browser loads these icons from Google's favicon service. Google then receives your IP address, browser details and the domain whose icon is shown, and may use its own cookies under Google's privacy policy.
Legal basis: our legitimate interest in an interface where websites are easy to recognize (Art. 6(1)(f) GDPR).
5.5 Team invitations
When a workspace owner or admin invites someone, we store the invitee's email address, the role, who sent the invitation and its status, and we send the invitation by email through Resend. This also applies to people who don't have a Probeli AI account yet. The invitation record stays with the workspace until the workspace, or the account of the person who sent it, is deleted.
Legal basis: the legitimate interest of the inviting customer and our own in letting teams work together (Art. 6(1)(f) GDPR).
5.6 Access by our staff
Authorized Probeli AI staff can view accounts and workspaces and can sign in as a user to give support, investigate problems, and prevent abuse or security incidents. When staff sign in as a user, this is recorded on the session. Staff can also block accounts that break our Terms of Service.
Legal basis: our contract (support) and our legitimate interest in running a secure service (Art. 6(1)(b) and (f) GDPR).
5.7 How long we keep workspace data
- Full text of AI answers: kept for the period that applies to the workspace's plan, shown on our pricing page as "Full answer text kept". During a free trial, the period of our lowest-priced plan applies. A daily job then deletes the text, oldest first. While a payment has failed, we keep it for our longest period until the payment issue is resolved.
- Everything else in a workspace (including mentions, citations and metrics): kept until the workspace is deleted, so that your history stays complete. Changing a workspace's website deletes the AI answers, competitors, prompts, Insights and audit results of the previous website.
- Workspaces whose trial or plan has ended: we don't currently delete these automatically. Their data stays until someone deletes the workspace.
6. Public web pages our crawler reads (ProbeliAIBot)
In brief: Our crawler, ProbeliAIBot, reads public web pages that AI answers cite, and your own website during audits. Those pages can contain personal data. When it reads cited pages and runs audits, it follows robots.txt, except for the requests listed on our ProbeliAIBot page.
6.1 What we fetch and store
Probeli AI fetches public web pages with its own crawler, which identifies itself as ProbeliAIBot:
- Homepages: yours, when you create a workspace or change its website, and a competitor's, when you add one, to read their title and description.
- Pages that AI answers cite, to find indirect mentions of tracked brands. We store the page text (up to a size limit), its title and the domains it links to, in one cache shared by all workspaces.
- Your workspace's website during an AI site audit. The audit reads a limited number of pages and files such as robots.txt and sitemaps. It keeps only the results and the score, not the page text.
6.2 Personal data on public pages
Public pages can contain personal data, such as an author's name or a team page. We don't look for or build profiles of individuals. We only search the text for the brands our customers track.
Legal basis: our legitimate interest, and our customers', in understanding which public sources AI engines rely on and how they mention brands (Art. 6(1)(f) GDPR). We only process information that was published openly.
6.3 How long we keep it
The stored text of a page is deleted after 90 days in which no AI answer cited it. The rest of the page record (address, title and linked domains) is deleted after 365 days without a citation.
6.4 How to block ProbeliAIBot or object
ProbeliAIBot follows the rules in robots.txt when it reads cited pages and runs audits, except for the requests listed on our ProbeliAIBot page (such as robots.txt itself, sitemaps and the redirects an audit follows), and limits how often it requests pages from each site. To block it on your website, add this to your robots.txt:
User-agent: probeliaibot
Disallow: /
Our ProbeliAIBot page explains what it reads, how often, and which requests robots.txt doesn't cover. You can also object to this processing or ask us to delete a page from our cache by writing to [email protected].
7. Emails we send
In brief: We only send emails about your account and your workspaces, and announcements about Probeli AI. There is no newsletter. Reports and alerts can be switched off in your settings.
7.1 Service emails
These emails are part of the service, so you can't switch them off while you have an account:
- email verification and confirmation of a change of email address;
- password reset links and sign-in (magic) links;
- workspace invitations;
- a welcome email when you sign up.
7.2 Workspace reports and notices
These are on by default. You can switch each type off, for email and in the app, in your account's notification settings:
- the weekly visibility report, sent to workspace owners and admins;
- visibility-drop alerts, sent to workspace owners and admins (at most one every 7 days per workspace);
- a notice when daily tracking pauses, sent to workspace owners and admins;
- announcements about changes to Probeli AI.
7.3 No marketing emails
We don't send newsletters or marketing emails. If we start, we will update this policy and ask for your consent where the law requires it.
- Legal basis: our contract (Art. 6(1)(b) GDPR) for service emails, reports and alerts; our legitimate interest in telling customers about changes to the service (Art. 6(1)(f) GDPR) for announcements.
- Who helps us: Resend sends our emails and keeps them for 30 days in the United States (see sections 12 and 13).
8. Payments
In brief: Paddle sells our plans as Merchant of Record and handles your payment details. We only receive references to your subscription.
When you buy a plan, you pay through the checkout of Paddle (Paddle.com Market Limited), our reseller and Merchant of Record. The checkout opens on our checkout page, which loads Paddle's checkout script from Paddle, and runs in Paddle's own window. Paddle collects your name, email address, billing address, payment details and, if you give one, your VAT ID. Paddle processes this data as an independent controller under its own privacy policy, together with the payment processors it works with. Paddle also runs the billing portal that opens when you click "Manage billing".
We send Paddle only the plan chosen, the workspace's ID and, if the workspace has bought before, its Paddle customer ID. From Paddle we receive the customer ID, subscription ID, the plan and the subscription status, which we store to manage the workspace's plan. We never receive your full card details.
- Legal basis: our contract (Art. 6(1)(b) GDPR) and legal obligations such as tax and accounting rules (Art. 6(1)(c) GDPR).
- Retention: our plan records are deleted together with the workspace. Paddle keeps invoices and transaction records for as long as tax law requires.
9. Error monitoring and logs
In brief: When something breaks in the app, we receive a technical report with IDs, not names or email addresses.
9.1 Error reports (Sentry)
When an error happens in the Probeli AI app or on our website, on our servers or in your browser, we send a technical report to Sentry, hosted in the EU (Germany). A report contains the error message and where it happened, the page address, browser and operating system, and your user ID and workspace ID. Before a report is sent, we remove names, email addresses, IP addresses, cookies, sign-in tokens, request contents, and the text of prompts and answers. Reports from your browser go through our own server first. We don't record sessions or screens.
9.2 Server logs
Our app servers at Railway write technical logs, which contain IDs and error messages and occasionally an email address, for example in a warning about a failed email.
- Legal basis: our legitimate interest in running a reliable, secure service (Art. 6(1)(f) GDPR).
- Retention: error reports and server logs are kept for up to 30 days, after which they expire automatically.
10. Preventing fraud and abuse
In brief: To stop people from repeating free trials, we keep a small record of each trial start, even after an account is deleted.
10.1 Trial records
When a workspace is created, or an unpaid workspace changes its website, we record your user ID, a one-way hash of your email address (normalized, for example without a +tag), a keyed one-way hash of your IP address (for IPv6, of your network), the website's domain, the workspace and the time. We use these records to limit how many free trials one person, one network and one website can start. So that deleting an account doesn't reset this limit, these records are not deleted when you delete your account or workspace. They currently have no fixed deletion date.
- Legal basis: our legitimate interest in preventing abuse of free trials (Art. 6(1)(f) GDPR). You can object (see section 16).
10.2 Other measures
- We count requests per IP address, in memory only, to limit sign-in attempts and contact-form messages.
- For each sign-in, verification, invitation or welcome email we send, we record a one-way hash of the recipient's address and a keyed hash of the requesting network, to limit email abuse. These records are deleted after 2 days.
- We keep a record of the cost of each run per AI engine. It contains no personal data and is kept after a workspace is deleted.
- We may block accounts that break our Terms of Service.
11. Cookies and similar technologies
In brief: We only use cookies and browser storage that the website and app need to work or to remember your settings. There are no analytics or advertising cookies.
We only use cookies and browser storage that are strictly necessary to provide the service you ask for, or that remember choices you make in the interface. These don't need your consent under the ePrivacy rules.
11.1 Our website
Our website sets no cookies and uses no browser storage.
11.2 The Probeli AI app
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
better-auth.session_token |
Keeps you signed in | 30 days | Necessary |
better-auth.session_data |
Short-lived, encrypted copy of your session | 60 seconds | Necessary |
better-auth.dont_remember |
Ends your session when you close the browser, if you chose not to be remembered | Browser session | Necessary |
better-auth.two_factor |
Holds a pending two-factor check | A few minutes | Necessary |
better-auth.trust_device |
Skips two-factor checks on a device you trust | 30 days | Necessary |
better-auth.state, better-auth.oauth_state |
Protects sign-in with Google | A few minutes | Necessary |
better-auth-passkey |
Holds a pending passkey check | A few minutes | Necessary |
better-auth.admin_session |
Keeps a staff member's own session while they help a user | Browser session | Necessary (staff only) |
better-auth.last_used_login_method |
Highlights the sign-in method you used last | 30 days | Functional |
NEXT_LOCALE |
Your interface language | Browser session | Functional |
NEXT_TIME_ZONE |
Your time zone, to show dates correctly | 365 days | Functional |
sidebar_state |
Whether the sidebar is open | 7 days | Functional |
sidebar_groups |
Which navigation groups are collapsed | 365 days | Functional |
insights-view.<workspace ID> |
List or board view on the Insights page | 365 days | Functional |
theme (local storage) |
Light, dark or system theme | Until you clear it | Functional |
probeli:chunk-reload-at (session storage) |
Reloads the page once after an update | Browser tab session | Necessary |
On secure connections, some names start with __Secure-. Loading website icons from Google (section 5.4) is a request to Google, not a cookie we set, but Google may use its own cookies there. The same goes for the checkout (section 8): Paddle's checkout window may use Paddle's own cookies and storage to process the payment and prevent fraud.
11.3 Managing cookies
You can delete cookies and browser storage in your browser settings at any time. If you block the necessary ones, you won't be able to sign in.
12. Recipients and sub-processors
In brief: A few service providers help us run Probeli AI. They only get the data they need for their task.
| Provider | What they do for us | Data involved | Where |
|---|---|---|---|
| Supabase, Inc. | Database hosting | All account and workspace data | EU (Germany) |
| Railway Corporation | Hosting of our app, background jobs and website; server logs | All data in transit, server logs | EU |
| DataForSEO OÜ | Asks the AI engines your prompts, and has an AI model write competitor and prompt suggestions | Prompts, location and language settings, brand and competitor names, domain, homepage description | Estonia (EU); passes prompts to the AI engines and suggestion requests to an OpenAI model (below) |
| Plus Five Five, Inc. (Resend) | Sends our emails, including contact-form messages to our team | Email addresses, names, email content | United States (Data Privacy Framework) |
| Zoho Corporation (Zoho Mail) | Hosts our team's inbox, [email protected], which receives contact-form messages and your emails | Email addresses, names, email content | United States |
| Functional Software, Inc. (Sentry) | Error monitoring for the app and the website | User and workspace IDs, technical error details | EU (Germany) |
| Cloudflare, Inc. (R2) | File storage | Profile pictures and workspace logos | Cloudflare's network; Cloudflare, Inc. is in the United States (Data Privacy Framework) |
| Cloudflare, Inc. (Turnstile) | Bot protection on sign-in and sign-up forms | IP address, browser and device signals | Cloudflare's network; United States (Data Privacy Framework) |
These recipients are independent, not our processors:
- Paddle.com Market Limited (United Kingdom) and the payment processors it works with, for purchases (section 8).
- Google, when you sign in with Google or your browser shows a profile picture from it (section 4), and for website icons (section 5.4).
- The operators of the AI engines (today OpenAI, Google and Perplexity), which receive prompts, and in OpenAI's case the inputs for suggestions, from DataForSEO (section 5.2).
We may also disclose personal data to authorities when the law requires it, to our professional advisers, and to a buyer or successor if our business is sold or merged, in each case only as far as necessary.
13. International transfers
In brief: Our core data is stored in the European Union. We are established outside the EU, and some providers are in the United States; we use the legal safeguards the GDPR requires for them.
Our database is in Germany and our app servers are in the European Union. Error reports are stored in the EU, and DataForSEO is based in the EU. Probeli AI itself is established outside the European Union (section 1), and we access this data from there to run the service. Some providers are based in the United States, even where they store data elsewhere. Resend stores emails in the United States, Zoho hosts our team's inbox there, and Cloudflare, Inc., a US company, stores profile pictures and workspace logos on its network and also runs Turnstile, the bot check on our sign-in and sign-up forms. The operators of the AI engines, which receive prompts through DataForSEO, may process them in the United States and other countries.
Where personal data goes to a country without an adequacy decision of the European Commission, we rely on the EU-US Data Privacy Framework for certified companies, or on the European Commission's Standard Contractual Clauses. Cloudflare and Resend, for example, are certified under the Data Privacy Framework, and their data processing agreements include the Standard Contractual Clauses. You can ask for a copy of the safeguards at [email protected].
14. How long we keep data
| Data | How long |
|---|---|
| Account details and sign-in methods | Until you delete your account |
| Sessions | 30 days after last use, or until you sign out |
| Sign-in, verification and reset links | A short time, until used or expired |
| Workspace data | Until the workspace is deleted |
| Full text of AI answers | The period of the workspace's plan, shown on our pricing page |
| Cached public page text | 90 days without a new citation |
| Cached public page records | 365 days without a new citation |
| Contact-form messages | As long as needed to handle your request |
| Trial records (section 10) | Kept after deletion; no fixed deletion date yet |
| Email-sending records (section 10) | 2 days |
| Profile pictures and workspace logos | Until you ask us to delete them |
| Server logs and error reports | Up to 30 days |
| Database backups | Up to 7 days, then overwritten |
| Plan records | Until the workspace is deleted (Paddle keeps invoices as tax law requires) |
15. Deleting your data
In brief: You can delete a workspace or your account yourself. Deleting your account also deletes the workspaces you are the only member of.
- Delete a workspace (owners, in the workspace's general settings): locks the workspace at once and, 3 days later, deletes its AI answers, prompts, competitors, metrics, Insights, audit results, members and invitations and its plan records, and ends its plan. Until then an owner can restore it; after that this can't be undone. It needs a sign-in within the last day: if yours is older, sign out and sign in again first. The workspace logo stays in our file storage until you ask us to delete it ([email protected]).
- Change a workspace's website: deletes the AI answers, competitors, prompts, Insights and audit results of the previous website.
- Leave a workspace, or be removed from one: deletes your membership only.
- Delete your account (in your account settings): deletes your profile, your sign-in methods (password, passkeys, two-factor data and a linked Google account), your sessions, memberships, the invitations you sent, your notifications and your notification settings.
- It also deletes every workspace you are the only member of right away (without the 3-day wait), which ends their plans immediately. It cancels any subscription billed to your account rather than to a workspace.
- A workspace that has other members stays, without you. While you are its only owner, you can't delete your account: make another member an owner, or remove the other members, first.
- To delete your account, you need to have signed in within the last day: if yours is older, sign out and sign in again first.
- The trial records with the hashes of your email address and IP address remain (section 10).
- Your profile picture remains in our file storage until you ask us to delete it.
- Paddle keeps its own records (section 8).
- Backups: data you delete stays in our database backups for up to 7 days, until they are overwritten.
- Get a copy of your data: Probeli AI doesn't have a self-serve export. Write to [email protected] and we will send you a copy.
For anything else, write to [email protected].
16. Your rights under the GDPR and UK GDPR
In brief: You can ask us what data we hold about you, correct it, delete it, limit or object to its use, and take it with you. You can also complain to a data protection authority.
You have the right to:
- access the personal data we hold about you (Art. 15 GDPR);
- have inaccurate data corrected (Art. 16). You can change your name and email address yourself in your account settings;
- have your data deleted (Art. 17);
- restrict how we use your data (Art. 18);
- receive your data in a structured, machine-readable format (portability, Art. 20);
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation (Art. 21). This includes our crawler's page cache (section 6) and trial records (section 10);
- withdraw consent at any time, where we rely on consent;
- complain to a data protection authority, in particular in the country where you live or work, or where you believe your rights were infringed (Art. 77).
To use these rights, write to [email protected]. We may need to confirm your identity first. We answer within one month; for complex requests, this can be extended by two further months, and we will tell you if it is.
If your data is part of a customer's workspace, for example because a prompt or an AI answer mentions you, we may pass your request to that customer, who decides on it, and help them answer it.
17. US state privacy rights
In brief: We don't sell your personal information or share it for targeted advertising.
Depending on where you live in the United States (for example California, Colorado, Connecticut, Virginia, Utah, Texas or Oregon), and as far as these laws apply to us, you may have additional rights:
- to know what personal information we collect, use and disclose, and to get a copy;
- to have it corrected or deleted;
- to opt out of the sale or sharing of personal information, or its use for targeted advertising. We don't sell personal information, don't share it for cross-context behavioral advertising and don't use it for targeted advertising;
- to limit the use of sensitive personal information. We only use your sign-in details to let you sign in;
- not to be treated differently for using these rights.
What we collect: identifiers (name, email address, IP address, account IDs), commercial information (your plan and subscription status), internet activity (sessions, browser details, when you last opened a workspace) and professional information (your workspaces, brands and team). The sources, purposes and recipients are described in sections 3 to 12.
How to make a request: write to [email protected]. You can use an authorized agent, and we may ask them for proof that you gave them permission. If we decline your request, you can appeal by replying to our decision. If your appeal is declined, you can contact your state's attorney general.
18. Security
In brief: We protect your data with standard technical measures, but no system is completely secure.
Our measures include:
- encrypted connections (HTTPS) everywhere, and session cookies that scripts can't read and that are only sent over secure connections;
- passwords stored only as secure hashes, verified email addresses, and optional two-factor authentication and passkeys;
- a membership and role check on every request to a workspace;
- row-level security on every database table;
- a safety check on every web address that users can influence, which blocks private and internal network addresses;
- error reports with personal data and secrets removed;
- access to customer accounts only for authorized staff, with sign-ins as a user recorded;
- encryption of stored data by our hosting providers.
We don't hold security certifications. If you find a security problem, please tell us at [email protected].
19. Children
Probeli AI is a tool for businesses and is not directed at children. You must be old enough to enter into a contract to use it. We don't knowingly collect personal data from children under 16. If you believe a child has given us personal data, write to [email protected] and we will delete it.
20. Automated decision-making
We don't make decisions about people based solely on automated processing that have legal or similarly significant effects on them (Art. 22 GDPR), and we don't profile individuals. Our analysis concerns brands, not people.
The only automated checks about you as a person are the trial allowance in section 10, the limits on sign-in attempts and account emails (section 10.2), and the bot check on our sign-in forms (section 4). The trial allowance can stop you from starting another free trial, for a while or, for the same website, for good; workspaces with a paid plan don't count towards it. If you think a check stopped you by mistake, contact us.
21. Customer content and our role
In brief: For personal data inside a customer's workspace content, the customer decides and we act on its behalf.
Customers decide which websites, brands, competitors and prompts they track. For personal data in that content, and in the AI answers and results we store for it, the customer is the controller and we process the data on its behalf as a processor. Customers who need a data processing agreement under Article 28 GDPR can contact us at [email protected].
For everything else in this policy, such as accounts, sign-in, emails, payments, security, our website and our crawler's page cache, we are the controller.
22. Changes to this policy
We may update this policy when our service or the law changes. The "Last updated" date at the top shows the current version. If we make material changes, we will tell you by email or in the app before they take effect.
23. Contact
Probeli AI operates the website probeli.ai and the app at app.probeli.ai.
- Privacy contact: [email protected]
For other questions about Probeli AI, you can use our contact page.