Legal

Privacy Policy

We do not sell personal information or customer materials. This policy explains the limited circumstances in which information is processed or disclosed to operate Prudence Report—including by AI service providers.

Effective and last updated August 5, 2026

1. Scope and our role

This Privacy Policy explains how Prudence AI, LLC (“Prudence,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the Prudence Report websites, applications, reports, and related services (collectively, the “Service”).

When an organization provides information through the Service, that organization may control the information and Prudence may process it on the organization’s behalf. In that situation, direct privacy questions to the organization first. This Policy does not govern third-party sites or services that you access separately.

2. Our core privacy commitments

  • We do not sell personal information or Customer Content.
  • We do not share information for cross-context behavioral advertising and do not permit service providers to use Customer Content for their own advertising.
  • We disclose information only as needed to provide, secure, support, and administer the Service; follow your instructions; complete a business transaction; or comply with law and protect rights.
  • The Service necessarily uses AI and other service providers, as described below. Those operational disclosures are not sales, but they do mean information leaves Prudence’s systems for processing.

3. Information we collect

Depending on how you use the Service, we collect:

  • Account and organization information, such as name, email address, organization, membership, role, invitations, and account preferences;
  • Customer Content, such as project descriptions, questions, prompts, documents, images, spreadsheets, audio, feedback, report instructions, and information about the people or companies you ask us to analyze;
  • Report and research information, including generated reports and audio, citations, public-source material, processing status, and revision history;
  • Transaction information, such as products, credits, prices, payment status, receipts, refunds, and limited billing details. Our payment processor handles payment-card numbers; we do not need the complete card number or security code;
  • Device, usage, and security information, such as IP address, browser and device type, pages or features used, timestamps, authentication events, error logs, and security signals; and
  • Communications, including support requests, feedback, and other messages you send us.

Customer Content may contain personal, confidential, or sensitive information about people other than the account holder. The submitting user or organization is responsible for having authority to provide that information and for giving any notices or obtaining any permissions required by law.

4. How we use information

We use information to:

  • provide, personalize, maintain, and improve the Service;
  • process projects, search sources, extract content, generate and deliver reports, and support revisions;
  • create and administer accounts, organizations, memberships, invitations, credits, transactions, and customer support;
  • authenticate users, prevent fraud and abuse, troubleshoot problems, monitor reliability, and protect the Service and its users;
  • communicate about accounts, transactions, reports, security, support, policies, and Service updates;
  • comply with law, enforce our Terms of Service, resolve disputes, and protect rights, safety, and property; and
  • create aggregate or de-identified information that cannot reasonably identify an individual, and use that information for lawful business purposes.

We do not use Customer Content to train a Prudence foundation model. We also seek contractual and technical restrictions against AI providers using Customer Content to train their general-purpose models, as explained below.

5. AI providers and zero-data-retention limitations

AI processing is essential to the Service. Relevant Customer Content, instructions, and limited technical metadata may be sent to one or more AI model, search, document-processing, transcription, or speech providers to perform requested functions. Different features may use different providers, and a report may involve multiple providers.

Where commercially and technically available, we use enterprise, zero-data-retention, no-training, or comparably restricted provider configurations and agreements. These protections are not an absolute guarantee. A provider or feature may not support zero retention; a provider may keep transient copies, safety or abuse logs, operational metadata, legally required records, or backups; and provider controls, contracts, or practices may change. We therefore cannot promise that every provider will retain no information or that deletion from every provider system will be immediate or complete.

We select and configure providers with the goal of limiting their use and retention of Customer Content, disclose only what is reasonably needed for the requested function, and do not authorize them to use Customer Content for advertising or unrelated independent purposes.

6. When we disclose information

We may disclose information to:

  • Service providers and subprocessors that provide AI, search, document processing, hosting, databases, storage, security, authentication, task processing, payments, email, customer support, and similar operational services. They may process information only for contracted services or as law permits;
  • Your organization and authorized users. Reports, projects, files, activity, membership details, and other organization content may be available to members according to their roles;
  • Professional advisers such as lawyers, accountants, auditors, and insurers who are subject to confidentiality obligations;
  • Authorities or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, property, users, the public, or the integrity of the Service; and
  • Transaction participants in connection with a financing, diligence process, reorganization, merger, acquisition, sale, insolvency, or transfer of some or all of our business, subject to appropriate confidentiality protections where practicable.

We may disclose information at your direction or with your consent. We may also disclose aggregate or de-identified information that cannot reasonably identify an individual.

7. Cookies and similar technologies

We and our service providers may use cookies, local storage, and similar technologies needed for authentication, security, preferences, checkout, reliability, and basic performance measurement. We do not use Customer Content for targeted advertising and, as of this Policy’s effective date, do not sell or share personal information for cross-context behavioral advertising.

Browser settings may block some technologies, but doing so can prevent login, checkout, preferences, or other Service features from working.

8. Retention and deletion

We retain information for as long as reasonably needed to provide the Service, maintain accounts and report history, honor organization instructions, secure the Service, resolve disputes, enforce agreements, and meet legal, tax, accounting, and compliance obligations. Retention depends on the type of information, why it was collected, the sensitivity and risk involved, and applicable requirements.

Deleted content may remain temporarily in backups, security records, provider systems, or legally required records. Public-source information may remain publicly available even after removal from Prudence. We may retain de-identified information that cannot reasonably be linked back to an individual. AI-provider retention is also subject to the limitations described in Section 5.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information in light of its nature and the risks involved. We also seek appropriate safeguards from service providers. However, no system, transmission, provider, or storage method is completely secure, and we cannot guarantee absolute security, confidentiality, integrity, or availability. You are responsible for protecting your email account, devices, login links, and organization permissions.

10. International processing

Prudence and its service providers may process information in the United States and other countries whose privacy laws may differ from those where you live. Where required, we use recognized legal mechanisms intended to protect personal information transferred across borders.

11. Your choices and privacy rights

Depending on where you live and subject to legal exceptions, you may have rights to request access to, correction of, deletion of, or a copy of personal information; object to or restrict certain processing; withdraw consent where processing relies on consent; and appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

To make a request, email hello@prudence.report with “Privacy Request” in the subject. You may also use available account or organization controls. We may verify your identity and authority before acting. If Prudence processes information only for an organization, we may direct the request to that organization. Authorized agents may submit requests where law permits, subject to verification.

California notice. The categories collected are described in Section 3, the purposes in Section 4, and the categories of recipients in Section 6. We do not sell personal information or share it for cross-context behavioral advertising and have not done so during the preceding 12 months. Because we do not engage in those practices, there is no sale or advertising share to opt out of. We use sensitive personal information only to provide and protect the Service or as otherwise permitted by law. This statement does not concede that Prudence is subject to any particular privacy law.

12. Children

The Service is not directed to children under 18, and we do not knowingly collect personal information directly from children. Do not submit information about a child unless you have lawful authority and the Service is appropriate for that use. Contact us if you believe a child has provided information directly to us.

13. Changes to this Policy

We may update this Policy to reflect changes in law, providers, features, or practices. We will post the revised Policy and update the effective date, and provide additional notice or obtain consent where required. We will not apply a materially more permissive use of previously collected personal information retroactively without notice or consent when the law requires it.

14. Contact us

Questions, concerns, or privacy requests may be sent to Prudence AI, LLC at hello@prudence.report.