Protegy

Privacy Practices

Plain English Privacy

We know you're sharing sensitive business information with us. This page explains exactly how we handle it — in plain language, not legal boilerplate. Our full legal Privacy Policy is linked at the bottom.

What we collect

When you use Protegy, we collect:

  • Your name, email address, and business details (entered during signup and onboarding)
  • Your interview transcript — the conversation you have with our AI consultant
  • Your generated reports — workflow diagrams, org structure, team data, tools analysis, and recommendations
  • Your subscription and payment status (we never see your card number — Stripe handles all payment data)
  • Basic usage data such as login timestamps and which features you've accessed

We do not collect financial data about your business, employee personal information, or any data beyond what you actively choose to share during the interview.

How your data is used

Your data is used exclusively to provide the Protegy service to you:

  • Your interview transcript is analyzed by AI to generate your workflow diagram and recommendations
  • Your business profile personalizes the AI consultation to your industry and company size
  • Your reports are stored so you can access them again at any time from your dashboard
  • Your email is used to send account-related notifications (no marketing email without your consent)

Who can see your data

You — full access to your profile, interview, and all reports from your dashboard.

Your Protegy consultant — if you were onboarded through a Protegy consultant (such as a Four Front Systems / Protegy Solutions engagement), your consultant can view your interview and reports in the admin portal. This is the same access model as working with a business consultant who keeps notes on your engagement.

No one else — other businesses on the platform cannot see your data. Our database enforces row-level security, meaning each account is technically isolated at the database level, not just by application logic.

We do not sell, rent, license, or share your data with third parties for marketing, advertising, or any commercial purpose.

AI and your data — the important part

Your interview is processed by Anthropic's Claude AI. Here's what that means in practice:

Anthropic does not store your business data. Your interview content is transmitted to Anthropic's API, analyzed in real time to generate your report, and is not retained by Anthropic beyond the API call.

Your data is not used to train AI models. Anthropic's API usage policy explicitly prohibits using API inputs and outputs to train or improve their models. What you tell Protegy will never become training data for any AI system.

Your report lives in Protegy, not Anthropic. Once your interview is analyzed and your report is generated, the results are saved securely in Protegy's database. Anthropic retains no record of the transaction.

You can verify Anthropic's data usage policy at anthropic.com/legal/privacy.

Your rights

You have full control over your data at any time:

Export your data

Download a complete copy of your profile and all interview data from Settings → Profile → Export My Data.

Delete your account

Permanently delete your account, all interviews, and all generated reports from Settings → Profile → Danger Zone. Deletion is immediate and irreversible.

Contact us

To request data corrections, ask questions about your data, or submit a formal GDPR/CCPA data request, email [email protected].

Data retention

Your data is kept for as long as your account is active. If you delete your account, all associated data is deleted immediately from our database. We do not retain backups of deleted accounts beyond our standard 30-day infrastructure backup window.

If you cancel your subscription but keep your account, your data remains accessible. Downgrading to the free tier does not delete your reports.

Security infrastructure

We use industry-standard services to protect your data:

  • Clerk — handles all authentication, passwords, and session management with enterprise-grade security
  • Supabase — PostgreSQL database with row-level security (RLS) enforced at the database layer
  • Stripe — handles all payment processing; we never see or store card numbers
  • Cloudflare — CDN, DDoS protection, and encrypted transit for all traffic to protegyai.com
  • All data in transit is encrypted via TLS 1.2+. All data at rest is encrypted by Supabase.
© 2026 Protegy Solutions. All rights reserved.