Privacy Policy
Last updated: July 13, 2026
ProofLedger (“ProofLedger,” “we,” “us”) provides a trust and audit platform for AI agents. This policy explains what we collect, how we use it, and the choices you have. It covers both our website and the ProofLedger service (the “Service”).
Our roles: controller and processor
For account, billing, and website data we act as a data controller. For the audit records your agents send us — events, runs, tool calls, model executions, policy decisions, and outcomes (“Customer Data”) — we act as a data processor on your behalf. You control what your agents send and are the controller of that data.
What we collect
- Account data: name, email, organization, and authentication identifiers (via our auth provider).
- Billing data: plan, subscription status, and customer/subscription identifiers. Card details are handled by Stripe; we do not store card numbers.
- Customer Data: the agent identity metadata and audit events you send through the SDK or API. We recommend sending summaries rather than raw prompts or sensitive payloads; what you include is your choice.
- Usage & diagnostics: request logs, error reports, and aggregate product analytics used to operate and improve the Service.
How we use data
To provide and secure the Service, authenticate you, process payments, enforce plan limits, detect and prevent abuse, provide support, and comply with legal obligations. We do not sell your data, and we do not use Customer Data to train models.
Subprocessors
We rely on a small set of infrastructure providers to run the Service, which may process data on our behalf: hosting/compute, managed PostgreSQL, and payment processing. We require appropriate safeguards from each. A current list is available on request; we will give notice of material changes.
Retention
Customer Data is retained according to your plan’s retention window, after which it is deleted by an automated process. Account and billing records are kept for as long as your account is active and as required for legal, tax, and accounting purposes.
Security
Access is authenticated and tenant-scoped; audit records are stored in a tamper-evident hash chain, and sensitive secrets (such as signing keys) are encrypted at rest. No system is perfectly secure, but we work to protect your data using industry-standard measures.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete personal data. For Customer Data we process on your behalf, we act on your instructions; contact us to exercise a request and we will respond within the timeframe required by applicable law.
International transfers
The Service is operated using infrastructure that may process data in the United States and other regions. Where required, we use appropriate transfer mechanisms for personal data moving across borders.
Contact
Questions or requests: info@tejos.co. See also our Terms of Service.