Privacy Policy
Last updated: August 25, 2026
1. Introduction
PRAMPTA Corporation ("Company", "we", "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Our role with respect to a given piece of data depends on context: for account, authentication, and billing data we are the controller; for a registered subject's public registry entry we are the controller of the registry record itself, while the rights holder or their organization controls the underlying decision to register it; when an AI provider verifies a generation, that provider is independently responsible for its own end users' data, and we act as a processor of the specific fields we return to them. This policy describes our current privacy practices and is intended to support compliance with the California Consumer Privacy Act (CCPA/CPRA), the EU and UK General Data Protection Regulation (GDPR), and other applicable privacy laws — it is not legal advice and does not replace a jurisdiction-specific notice or agreement where one is separately required.
2. Our Role by Data Category
The table below is our own good-faith characterization to help you understand who is responsible for what — not a legal conclusion, and not a substitute for advice specific to your situation. Several rows involve genuinely shared responsibility (for example, a subject's registration data: we control how the registry itself processes it, but the registering user controls whether it should exist at all and warrants its accuracy), which data protection law sometimes treats as joint controllership rather than a clean controller/processor split.
| Data category | Purpose | PRAMPTA role | Other party | Legal basis | Retention |
|---|---|---|---|---|---|
| Account, auth & security | Run and secure your account | Controller | — | Contract | While active + limited period |
| Subject registration data | Operate the registry, enforce license rules | Controller of the record | Registrant controls the decision to register & its accuracy | Contract, legitimate interest | While subject active |
| Uploaded images & likeness | Display, registration evidence | Controller | Consent comes from the subject, obtained by the registrant | Consent, contract | Until deleted, see §4 |
| Authority evidence | Adjudicate authority claims | Controller | Registrant warrants accuracy | Legitimate interest, contract | Fixed period after decision, see §5 |
| Dispute evidence | Resolve disputes | Controller | Parties to the dispute | Legitimate interest, legal obligation | Until resolved + limited period |
| AI provider's end-user data | Provider-user binding, if a provider enables it | Processor | AI provider is controller of its own end users' data | Provider's own basis with its users | Per our contract with the provider |
| Provider identity links | Link a provider to its end users at the protocol level | Processor | AI provider | Provider's own basis with its users | Per our contract with the provider |
| Payment metadata | Process payments, payouts | Controller of our own transaction records | Payment processor is independently responsible for its own compliance | Contract, legal obligation | Per accounting/tax law — exceeds account retention |
| Verification requests | Enforce license rules | Controller | — | Contract, legitimate interest | Indefinite — part of the audit chain |
| Generation receipts | Provenance record of a generation | Controller of the record; content is provider-attested | AI provider attests to accuracy | Contract, legitimate interest | Indefinite — audit-adjacent |
| Audit logs | Tamper-evident integrity chain | Controller | — | Legitimate interest | Indefinite by design — see §9 |
| Analytics | Understand Service usage | Controller (decides to run it) | Google is an independent processor under its own terms | Consent (cookie banner) | Per Google Analytics' retention settings |
3. Information We Collect
Account & Security: username, email address, hashed password, two-factor authentication metadata (your TOTP secret is stored encrypted at rest and never displayed to us or to you after enrollment), and login/session metadata. If you sign in with Google, we receive and store the email address, name, profile picture, and Google account identifier associated with that Google account.
Subject Data: subject identifiers, PRE-GEN registry codes, public keys, aliases, descriptions, and license rules you configure.
Uploaded Content: images you upload (such as portraits, banners, and gallery photos). These may depict you or another person whose likeness you have the rights and consent to upload. Images you attach to a public subject are publicly visible in the Library.
Authority & Dispute Evidence: if you go through authority review or a dispute, documents you submit — which can include identity documents, representation agreements, or other proof of authority — encrypted at rest (see "Authority & Dispute Evidence" below).
Licensing & Provider Data: licensee IDs, provider IDs, links between an AI provider and its own end users where a provider integrates that feature, generation/verification records, prompt hashes (not raw prompts), and output hashes.
Payment Data: where checkout is offered, payment metadata (amount, currency, status, and processor references) — see "Fees, Payments & Payouts" in the Terms for what we do not collect.
Reports: if you report a subject, we collect the report details and associate them with your account so operators can follow up.
Diagnostics: when a client-side error occurs, the Service may send an automated error report containing the error message, a stack trace, the page URL where it happened, your browser's user-agent, and any note you choose to add. These are used only for debugging and retained for a limited period alongside our security logs.
Usage & Audit Data: verification requests, API calls, timestamps, and signed audit log entries recording what happened (an event type, the affected record, and an actor reference) — not the content of what was generated.
Notifications: records of notifications the Service has sent you, so you can review them.
Technical Data: IP addresses, browser type, and device information collected automatically.
Analytics & Cookies: if you accept, Google Analytics usage data — see "Cookies & Local Storage" below.
We do NOT collect: social security numbers, precise geolocation, or full payment card numbers (payments, where offered, are handled by a third-party processor via a hosted checkout page — our servers never receive card numbers).
4. Images, Likeness & Biometric-Adjacent Data
Images of identifiable people are sensitive by nature, and some laws (such as the Illinois Biometric Information Privacy Act and GDPR Article 9) treat biometric identifiers derived from them as a special category. Our approach, as of the effective date above: we store uploaded images exactly as you provide them; PRAMPTA itself does NOT generate biometric identifiers, faceprints, voiceprints, or face-recognition templates from them; and we do not use them to identify or recognize individuals. This describes what PRAMPTA's own systems do — it does not extend to independent processing by an AI provider you license your subject to, to any third-party service, or to features introduced after the effective date, which (if they process images this way) will be disclosed here first. Images are used to display the subject in the Service, to document what identity a registration covers, and where relevant, as evidence in an authority review or dispute. Registering an identifiable living person requires that person's consent (see the Terms of Service, "Likeness & Identity Consent"). You may delete uploaded images at any time from the subject's settings; this removes the active copy from the Service and from display immediately, subject to routine backup retention (see "Data Retention") and any copy already held by a licensee under a license issued before deletion.
5. Authority & Dispute Evidence
Some flows ask for documents beyond a photo — for example, proving you have authority to register someone else, or supporting your side of a dispute. This can include identity documents, representation agreements, or other proof of authority. These are encrypted at rest with a key kept separate from the one protecting the rest of the database, specifically so a database compromise alone does not also expose this material. Access is logged: every time an operator opens a document, that access is recorded and reviewable. We retain evidence for a fixed period after the decision it supported, then purge the file itself — the record that a review happened, and its outcome, is kept as an audit entry (see "Data Retention"), but not the document. A legal hold or an active dispute pauses purge until it is resolved. Uploading a document does not make it true: an operator's approval is a human's judgment call under our review process, not a court's determination of ownership, and we do not warrant that any submitted document is genuine. As of the effective date, evidence upload requires a decryption key to be configured in production; if it is not, the upload and review endpoints return an error rather than accepting a file we could not later decrypt or protect.
6. How We Use Your Information & Legal Bases
We use collected information to: (a) provide and maintain the Service — performance of our contract with you; (b) process verification requests and maintain cryptographic audit trails — performance of contract and our legitimate interest in the integrity of the registry; (c) communicate with you about your account — performance of contract; (d) detect and prevent fraud or abuse — legitimate interest; (e) comply with legal obligations — legal obligation. Where we rely on consent (for example, optional communications), you may withdraw it at any time.
7. Data Sharing & Sub-processors
We do not sell your personal information. We may share data with:
(a) AI providers — a verify request returns more than a bare allow/deny. The signed decision a provider receives can include: the subject ID and license ID; a hash of the prompt (never the raw prompt text itself); the requested model and modality; the licensed rules and obligations that apply (for example, a required watermark or AI-disclosure notice); the subject's registration trust level; and timing/expiry fields the provider uses to know when to re-check. It does not include your account email, your uploaded images themselves, or your payment information. A provider is contractually required to use this only to decide whether and how to generate, and is independently responsible — under its own privacy practices, not ours — for any data about its own end users that it chooses to send us or retain itself.
(b) service providers acting on our instructions, listed below;
(c) law enforcement when required by law;
(d) in connection with a merger, acquisition, or sale of assets, with notice to you.
Subprocessors — current as of the "Last updated" date above:
We verified each provider's own published data-processing terms before listing its safeguards here rather than asserting them generically. We'll update this list when we add or remove a subprocessor, and update the "Last updated" date when we do.
| Provider | Purpose | Data processed | Location | Role |
|---|---|---|---|---|
| Oracle Cloud Infrastructure | Application hosting, database | All Service data — this is the underlying infrastructure everything else runs on | EU (Netherlands) | Processor |
| Resend (Plus Five Five, Inc.) | Transactional email (verification, password reset, notifications) | Email address, email content | US — DPA with EU/UK SCCs and EU-US Data Privacy Framework certification | Processor |
| Google LLC (Google Analytics) | Website analytics — only if you accept cookies | Page views, device/browser info, approximate location from IP; no ad personalization, Google Signals off | US — Google's Data Processing Terms incorporate SCCs | Processor |
| Google LLC (Sign-In) | Optional account sign-in with Google | We receive and store your Google email, name, profile picture and Google account identifier if you use this option; Google processes the sign-in itself under its own terms | US — Google acts as an independent controller for the sign-in flow; its own privacy terms apply to that flow | Independent controller for the flow; we store what it returns under Contract |
| Stripe | Payment processing — where checkout is enabled (see Terms §9) | Payment/checkout metadata; never full card numbers | US (Stripe, LLC) or EU (Stripe Payments Europe, Ltd.) depending on account routing — DPA with SCCs and Data Privacy Framework certification | Processor |
8. International Data Transfers
Our primary application infrastructure — the database and servers that run the Service — is hosted in the Netherlands (EU). Some service providers we use to operate the Service are based in, or process data in, the United States (see our subprocessor list, "Data Sharing & Sub-processors" above). If you access the Service from the EEA, the UK, or another region with data-transfer restrictions, your core account and registry data is processed within the EU, and only the specific data a given US-based subprocessor needs to do its job (for example, an email address for delivering a transactional email, or analytics identifiers if you accept cookies) leaves the EU for that purpose. Where a transfer to the United States or another country without an adequacy decision occurs, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or a subprocessor's own certification under the EU-US Data Privacy Framework where applicable.
Backups: encrypted database backups are replicated off-site for disaster recovery. We will not tell you something we cannot guarantee: depending on our operational configuration, an encrypted backup replica may be stored outside the EU. Backup contents are age-encrypted before leaving the primary infrastructure, backup copies roll off on a fixed schedule, and any transfer involved in backup storage relies on the same safeguards described above. We have not yet designated an EU representative under GDPR Article 27 or a UK representative under the equivalent UK GDPR provision; this is a known gap, not a claim that one exists.
9. Data Retention
Account data is retained while your account is active, and for a limited period after deletion to prevent immediate re-registration abuse and to satisfy legal and accounting obligations.
Uploaded images are deleted when you remove them or delete the subject they belong to, as described in "Images, Likeness & Biometric-Adjacent Data" above.
Authority and dispute evidence is retained and purged as described in that section above — the document itself for a fixed period, the fact that a review happened indefinitely.
Payment and checkout records are retained as long as required by tax, accounting, and financial-recordkeeping law, which in most jurisdictions exceeds account retention.
Audit log entries — a record of what happened (an event type, the record it affected, and an actor reference), each cryptographically chained to the one before it — are retained indefinitely. This is deliberate, not an oversight: the chain's value as tamper-evident proof (for you, for an AI provider, for a court) depends on no entry ever being removable, including at our own request. We minimize what goes in it — an entry does not carry your uploaded images, documents, or free-text content — but an entry can still be personal data (for example, an actor reference tied to your account), so a deletion request removes what we can remove and explains, specifically, what is kept in the chain and why. Security logs are retained for a limited period for incident investigation, then rotated out.
Backups roll off on a fixed schedule; a deletion is not guaranteed to be reflected in a backup already taken until that backup's own retention period elapses.
Legal holds — an active dispute, subpoena, or investigation — pause deletion of the specific records involved until it is resolved, regardless of the retention period that would otherwise apply.
10. Your Rights
California (CCPA/CPRA): you have the right to know what personal information we collect, use, and disclose; to request deletion; to correct inaccurate information; to opt out of sale or sharing (we do not sell your data); to limit use of sensitive personal information; and to non-discrimination for exercising these rights. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to decline optional analytics — Google Analytics does not load, even if you accepted it on a past visit before turning GPC on.
EEA/UK (GDPR): you have the right of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.
Other U.S. states: where another U.S. state privacy law applies to you, we extend the same core rights described above for California residents — to know/access, delete, correct, and opt out of any sale or sharing (we do not sell or share your personal information), with no discrimination for exercising them — through the same request process, and we honor Universal Opt-Out Mechanisms such as GPC the same way.
Some of this is self-service today: you can delete an uploaded image or a subject you own directly from its settings at any time, no request needed (see "Images, Likeness & Biometric-Adjacent Data" above). You can also delete your entire account yourself, from Settings → Delete Account, in three steps rather than one click — deliberately, so a compromised login session cannot instantly and irreversibly erase your account on your behalf. First, we email a confirmation link to the address on the account; nothing changes until you click it. Clicking it starts a 30-day window: any subjects you own are paused (not withdrawn) rather than made permanently unavailable, and you can log back in and cancel at any time before the window ends to restore everything exactly as it was. If the window elapses without cancellation, we erase your name, email address, avatar and login credentials, withdraw every subject you own so it can no longer be licensed, and close any license request still awaiting a decision — yours on someone else's subject, or someone else's on yours — so nothing is left pending a response that can never come. Three things deliberately survive that final step, and we would rather say so here than let you discover it afterwards: licenses already issued on your subjects (they are contracts held by someone else and stay valid for their term), the signed audit log (it is a tamper-evident chain — removing entries would destroy its integrity for everyone), and the record that you accepted these documents (kept to defend legal claims). None of them identify you once the account is erased: they reference an internal account identifier with no personal data left behind it.
For anything else — access, correction, or portability — the process is currently a request you send us, not an automated self-service flow, and we are telling you that plainly rather than describing a portal that does not exist yet:
1. Email privacy@prampta.com with what you are requesting and the account or email address it concerns.
2. We verify you are who you say you are before acting — typically by confirming the request comes from the email address on the account, or asking for additional information if it does not, so we do not hand your data (or delete your account) for someone impersonating you.
3. We identify what can be deleted or returned versus what we must keep — see "Data Retention" above for what that's usually limited to (accounting/payment records, an active legal hold, or audit-log metadata) — and tell you specifically what we kept and why, not just a blanket "some data is retained."
4. We respond within the timelines required by applicable law (45 days under CCPA, one month under GDPR, both extendable where permitted) — sooner where we reasonably can.
5. If you are not satisfied with the response, you may ask us to reconsider by replying to the same thread; beyond that, a California resident may contact the CPPA and an EEA/UK resident may lodge a complaint with their supervisory authority, both listed above.
6. An authorized agent may submit a request on your behalf; we will still verify your identity (typically directly with you, not only through the agent) before acting, for the same impersonation-prevention reason as step 2.
11. Cookies & Local Storage
We use essential storage always: authentication tokens kept in your browser's localStorage to maintain your session (functionally similar to an essential cookie), and a record of your cookie-banner choice. Once you accept our cookie banner, we also load Google Analytics (Google LLC) to understand how the Service is used — page views, general device/browser information, and an approximate location derived from your IP address. Google Analytics is not loaded before you accept, and does not run at all if you decline or have not yet decided. We do not use Google Analytics for advertising, do not enable Google Signals or ad personalization, and do not set any other advertising or ad-targeting cookies. Google acts as a data processor for this purpose; see Google's Privacy Policy for how it handles the data. You can opt out at any time via the cookie banner (footer "Your Privacy Choices") or with the Google Analytics Opt-out Browser Add-on.
12. Security & Breach Notification
We implement industry-standard security measures including: encryption in transit (TLS), Ed25519 cryptographic signatures, hash-chained audit logs, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify you and the relevant authorities without undue delay, as required by applicable law (including within 72 hours to supervisory authorities where GDPR applies).
13. Children & Minors
Two different roles matter here, and they have different rules.
Account holders — the people who operate accounts — must be at least 18 (see the Terms of Service). We do not knowingly allow anyone younger to hold an account; if we learn an account is held by someone under 18, we will delete it promptly.
Subjects — the identities registered in the registry — may be of any age, including minors, when registered by a parent, guardian, or authorized agent who meets the account age requirement and holds that person's consent (see the Terms of Service, "Likeness & Identity Consent"). In that case we knowingly process the minor's registry data (for example, their image), under the consent of their guardian and subject to heightened protections: subjects flagged as a minor get no automatic commercial licensing, no shortcut to commercial status without operator review, and permanently denied categories at verification regardless of any license. See our Trust Model for what those protections do and do not cover.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes we will provide notice (for example by email or a prominent notice in the Service) before they take effect, in addition to posting the new policy on this page and updating the "Last updated" date.
15. Contact Us
For privacy-related inquiries:
PRAMPTA Corporation
Email: privacy@prampta.com
California, United States
EEA/UK residents may also contact their local data protection authority.