Privacy policy
Effective 4 September 2026
In short
- Propab holds three kinds of data: your account, your research content (questions, uploaded files, and everything the agent produces for you), and the usage records that make your plan and your invoice correct.
- We do not sell or share your data for advertising, we show no advertising, and we do not use your research content to train models.
- To do the work, parts of your research content are processed by the model providers you select and by the infrastructure providers that run the platform, each under contract and only for that purpose.
- Your research content is stored in the European Union and stays until you delete it or close your account.
- You can export everything, delete any run or file yourself, and ask us to delete your account. Write to shani@propabai.com.
1. Who this applies to
This policy explains how Propab (“Propab”, “we”, “us”) collects, uses, stores and shares personal data and research content when you visit propabai.com, create an account, or use the Propab service (together, the “Service”). It applies to individual researchers, to members of a team or lab workspace, and to visitors of our website. If you use Propab through an organisation that has its own agreement with us, that agreement governs where the two differ, and your organisation’s administrator may have access to the workspace as described in section 5.
2. The words this policy uses
- Account data
- Your name, email address, the sign-in method you use, your plan, and the settings you choose.
- Research content
- Everything you put into the Service and everything it produces for you: the questions and instructions you give, the files and datasets you upload, the messages you send to a running task, and the transcripts, code, tables, figures, notebooks, reports and other artifacts the agent creates, together with the record of how each was produced.
- Agent
- The automated research system that carries out your task: it searches the scientific literature, plans and runs computations in an isolated environment, and writes up its findings.
- Usage data
- Measurements of how the Service is used: how much model inference and compute your tasks consumed, when tasks started and ended, which features were used, and the technical information described in section 3.
- Processor
- A company that handles data on our behalf and under our instructions so that the Service can operate — for example the providers that run the AI models, host the platform, deliver email, or process payments.
3. What we collect
3.1 Data you give us
- Account data when you sign up or sign in. Sign-in is by a one-time code sent to your email, or through an identity provider you already use; in either case we receive your email address and, from the identity provider, your name and profile picture if you have set one. We never receive or store a password.
- Research content as you use the Service: the questions you ask, files you upload, messages you send to a running task, and the feedback you give on results.
- Billing information when you subscribe: your plan, billing address and the country used to determine tax. Card details are entered directly with our payment processor and never reach our systems.
- Compute account details if you choose to connect your own compute provider so the agent can run jobs on it: the credential you provide, stored encrypted and used only to place, monitor and stop the jobs you or the agent start.
- Correspondence when you contact us.
3.2 Data the Service generates
- The agent’s work product: transcripts, plans, code, intermediate files, artifacts, and the provenance record that ties every result to the source, code and model that produced it.
- Usage records: the model inference and compute each task consumed, measured so that your plan allowance is applied fairly and your invoice is correct.
- Technical information collected automatically when you use the website or the Service: IP address, browser and device type, operating system, referring page, the pages you visit and the actions you take, timestamps, and error reports. We use this to keep the Service secure and working.
3.3 Data from others
When you sign in with an identity provider, it sends us your verified email address and basic profile. If a team administrator adds you to a workspace, we receive your email address from them. We do not buy data about you from anyone.
4. Your research content
Research content is the point of the Service and it is yours. This section says exactly what happens to it.
- Storage. Uploaded files, transcripts and artifacts are stored in encrypted object storage and a database operated for us in the European Union, and each task’s computations run in an isolated environment that is created for that task and removed when it ends.
- Model providers. To reason, plan and write, the agent sends prompts to the AI model you select. A prompt contains your question, relevant parts of your files and the transcript so far. The providers we use to reach those models are bound by contract to process prompts only to return a response, and not to train on them. You choose which model a task uses; the picker in the workspace tells you what is available on your plan.
- The scientific literature. The agent searches an index of scientific works that we maintain. Searching it sends nothing about you to the index’s original sources. When the agent reads a paper’s full text, it fetches that text from the publisher or an open-access repository; that request does not carry your identity.
- Compute you connect. If a job runs on a compute provider you connected, the files that job needs are placed on that provider’s machine for the duration of the job and the provider’s own privacy terms apply to its infrastructure.
- Sharing. Research content is private to your workspace. It is visible to the other members of a team workspace and to that workspace’s administrators. We do not make it public and we do not share it between workspaces.
- Our access. Our staff do not read your research content except to operate the Service, to investigate a failure you reported or that we detected, to respond to a legal obligation, or with your permission. Such access is logged.
5. How we use it
We use the data described above for the following purposes, and no others:
- To provide the Service: run your tasks, store and show your results, keep you signed in, and let your team work in a shared workspace.
- To apply your plan and bill you: measure the inference and compute your tasks use against your allowance, issue invoices, and detect fraud or abuse of the Service.
- To keep the Service reliable and secure: monitor errors, investigate failures, defend against attacks, and enforce these terms.
- To communicate with you: sign-in codes, receipts, notices about your account and changes to the Service or to this policy, and replies to your messages. We send product news only if you opted in, and you can opt out at any time.
- To improve the Service, using aggregated or de-identified usage data — for example, how long tasks take or which features are used — never your research content.
- To comply with law, including tax and accounting obligations and lawful requests from authorities.
Where the law of your region requires a legal basis, we rely on: performance of our contract with you (providing the Service, billing); our legitimate interests in keeping the Service secure, reliable and improving (balanced against your rights, and never involving your research content); legal obligations; and your consent where we ask for it, which you can withdraw at any time.
6. No training on your work
We do not use your questions, files, transcripts or results to train, fine-tune or evaluate any model, and we contractually require the model providers we use not to do so either. If that ever changes for any category of data, it will be opt-in, explained in plain words in the workspace, and off by default.
7. Who processes it for us
We share personal data and research content only with processors that we need to run the Service, each under a written agreement that limits them to acting on our instructions and to the purpose named:
| Category of processor | What they receive | Why |
|---|---|---|
| AI model providers | The prompts the agent sends for the model you selected | To return the model’s response |
| Hosting and storage providers (European Union) | Everything the Service stores | To run the platform and keep your data |
| Authentication provider | Your email address and sign-in events | To sign you in without a password |
| Email delivery provider | Your email address and the message | To deliver sign-in codes and account mail |
| Payment processor (merchant of record) | Your name, email, billing address and payment details | To take payment, apply tax and issue receipts |
| Compute providers | The files a job needs, for the duration of the job | To run computations that need more than the included environment |
Beyond processors, we disclose data only: to a team workspace’s administrators, as described in section 4; to a successor if Propab is acquired or merges, in which case this policy continues to apply and we notify you; and to authorities where the law requires it, in which case we tell you unless we are legally prohibited from doing so. We never sell personal data.
8. Where it is stored and international transfers
Research content and account data are stored in the European Union. Some processors operate outside the EU — in particular the AI model providers — and prompts sent to them are transferred to where they run. Where a transfer leaves the European Economic Area, the United Kingdom or Switzerland, it is covered by an adequacy decision or by standard contractual clauses and supplementary measures, and you may ask us for details of the safeguards in place for a given processor.
9. How long we keep it
| Data | Kept for |
|---|---|
| Research content | Until you delete it or your account is closed; a deleted item is removed from backups within 35 days |
| Account data | For the life of the account, then removed within 30 days of closure |
| Usage and billing records | For as long as tax and accounting law requires us to keep invoices |
| Technical logs | 30 days, then deleted or de-identified |
| Compute credentials you connected | Until you disconnect the provider or close your account |
| Correspondence | Up to two years after the matter is closed |
10. Security
Every connection to the Service is encrypted in transit, and stored data is encrypted at rest. Each task’s code runs in an isolated environment with no access to other workspaces. Access to production systems is limited to the people who operate the Service, uses individual credentials, and is logged. Sign-in uses one-time codes or an identity provider you trust, so there is no password to steal. No system is perfectly secure; if we learn of a breach that affects you, we will tell you without undue delay and, where the law requires, notify the relevant authority.
11. Your rights and choices
Wherever you are, you can:
- see and export your research content and account data from the workspace at any time;
- delete any run, file or artifact yourself, immediately;
- disconnect a compute provider or change your plan from the workspace;
- ask us to correct account data, or to delete your account and everything under it — we do so within 30 days and confirm it;
- opt out of product news with one click in any such email.
If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the rights the GDPR and equivalent laws give you: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent, and you may lodge a complaint with your supervisory authority. If you are a California resident, you have the rights the CCPA gives you, including to know, delete and correct, and the right not to be discriminated against for exercising them; we do not sell or share personal information as those terms are defined there. Residents of other regions with similar laws have the corresponding rights. To exercise any of them, email shani@propabai.com from the address on your account; we may ask you to confirm your identity before acting.
12. Cookies and similar technologies
The Service sets a session cookie that keeps you signed in and, on the sign-in page, a short-lived cookie that protects the sign-in flow from forgery. Both are strictly necessary. We do not set advertising or cross-site tracking cookies, and we respect browser settings that block non-essential storage. The workspace remembers a few preferences, such as your theme, in your browser’s local storage; they never leave your device.
13. Children
The Service is for adults and for researchers acting for an institution. We do not knowingly collect personal data from anyone under 18; if you believe we have, write to us and we will delete it.
14. Changes to this policy
When we change this policy we update the date at the top. For any change that affects what we collect, how we use it or who processes it, we email account holders at least 14 days before it takes effect, and the previous version stays available on request.
15. Contact
Propab, propabai.com. For anything in this policy, including requests to exercise your rights: shani@propabai.com.
See also the terms of service.