1. Scope and roles
This Privacy Policy explains how Proforma Labs handles personal information when you visit our websites, use our hosted or managed Proforma services, interact with our APIs, contact us, or otherwise communicate with us.
Proforma is an agent and operating intelligence layer for company data. Customers use workspaces to ingest Sources, define Models, build Pages, run Scripts, and collaborate in Chats. When a customer submits, connects, or asks Proforma to process data in a workspace, that information is Customer Data.
For Customer Data, Proforma Labs generally acts as a processor or service provider on behalf of the customer. For account administration, marketing, support, billing, security, website analytics, and our own business operations, Proforma Labs generally acts as a controller or business. If a separate written agreement says something different, that agreement controls for that customer.
2. Information we collect
We collect information directly from you, automatically through the service, and from third-party systems you choose to connect.
- Account and contact information: name, email address, password hash, authentication metadata, organization, workspace, role, invite status, preferences, and similar account details.
- Customer Data: data sources, uploaded files, warehouse metadata, table and column names, source and model descriptions, query text and results, Pages, Scripts, Chats, comments, recordings, workflow state, and other content you or your workspace members provide or generate.
- AI inputs and outputs: prompts, chat messages, tool calls, source/model/page/script context, generated text or code, and related execution traces needed to provide AI features.
- Integration and credential information: OAuth tokens, API keys, webhook secrets, ingest keys, Slack or email connection records, Notion connection data, and similar secrets or connection metadata. For Google Sheets Sources, this includes the connected Google account name and email, selected file identifiers and metadata, and an encrypted refresh credential. Secret values are stored encrypted where the product stores them.
- Google user data you choose to connect: the content and metadata of Google Sheets selected through Google Picker. Proforma exports each selected spreadsheet to an XLSX cache; it does not browse or mount the rest of your Google Drive.
- Usage, device, and log information: pages viewed, buttons clicked, feature events, referrer and UTM data, browser and device details, IP address, diagnostic logs, performance data, and error records.
- Session replay and tracking data: if enabled for a workspace or website deployment, Proforma analytics may record interaction events and replay chunks. Replay settings can mask inputs and block selectors, but customers should configure replay carefully for their own sites and applications.
- Communications and commercial information: emails, support requests, sales conversations, survey responses, payment and subscription information, and records needed to manage our relationship with you.
3. How we use information
Proforma Labs does not sell Customer Data. We do not use Customer Data to train our own foundation models. We also do not intentionally make Customer Data available to other customers. If a customer configures its own model provider, warehouse, integration, or API key, that third-party provider's terms and settings may also apply.
- Provide, maintain, secure, and improve the services.
- Create and administer accounts, organizations, workspaces, subscriptions, invitations, permissions, and support workflows.
- Ingest, query, transform, display, automate, and act on Customer Data as requested by customers and their authorized users.
- Operate AI features, including sending relevant prompts, context, metadata, and results to configured model providers when needed to answer a request or run a workflow.
- Use Google user data only to provide and improve the user-facing integration features you request, including linking, refreshing, displaying, copying, exporting, and using selected spreadsheet content in Chat. Proforma does not use Google user data for advertising or to train its own foundation models.
- Debug service issues, prevent abuse, enforce usage limits, investigate security events, and protect Proforma, customers, and the public.
- Send service, security, administrative, support, and marketing communications, subject to your choices and applicable law.
- Comply with legal obligations and enforce agreements.
5. AI features
AI features may use prompts, workspace context, data model metadata, query results, documents, code, messages, and tool outputs to respond to a user request. The specific information sent depends on the feature, the workspace context selected, and the model provider configured for the deployment.
Customers should avoid sending regulated, highly sensitive, or unnecessary personal information to AI features unless their deployment, provider configuration, and separate agreements are appropriate for that use. AI outputs can be incomplete or wrong and should be reviewed before use in business, legal, financial, medical, or safety-sensitive decisions.
7. Security
We use technical and organizational measures designed to protect information, including access controls, authentication, encryption for stored workspace secrets, origin checks for public ingest keys, usage limits, logging, and secret redaction patterns. No internet service is perfectly secure, and customers are responsible for configuring their own warehouses, cloud accounts, integrations, users, and secrets safely.
8. Retention and deletion
We retain information for as long as needed to provide the services, operate accounts and workspaces, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and preserve backups. Product telemetry, tracking events, replay data, logs, recordings, and workspace artifacts may have different retention settings depending on the workspace, deployment, plan, or feature configuration.
Customers can delete many workspace artifacts inside the product. Some information may remain in backups, logs, audit records, or legal/compliance archives for a limited period.
Removing a Google Sheet Source deletes its Proforma workbook cache without changing the Google file. Disconnecting an account removes its workspace credentials and linked caches. If the same Google grant is still used by another Proforma workspace, Proforma keeps that grant until the final connection is removed; the final disconnect revokes the stored Google credential.
9. Privacy rights and choices
Depending on where you live, you may have rights to access, correct, delete, export, object to, restrict, or opt out of certain processing of personal information. You may also have the right to appeal a privacy request decision.
If your information is processed in a customer workspace, please contact that customer first. We will support the customer as appropriate. For information Proforma Labs controls directly, contact us at contact@proformalabs.ai.
We do not knowingly sell personal information or share it for cross-context behavioral advertising as those terms are defined under California privacy law. If that changes, we will update this policy and provide required choices.
10. International transfers
We may process information in the United States and other countries where we or our service providers operate. Where required, we use appropriate transfer mechanisms and safeguards for international transfers.
11. Children
Proforma is for business use and is not directed to children. We do not knowingly collect personal information from children under 13, or under a higher age where required by law.
12. Changes and contact
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice.
Questions or privacy requests can be sent to contact@proformalabs.ai.