Promigence Privacy Policy
Effective October 4, 2026 · Last updated October 4, 2026
Promigence AI, Inc. ("Promigence," "we," "us" or "our") provides Promigence, a platform that runs software and AI agents in isolated environments ("sandboxes"). This Privacy Policy explains how we collect, use, disclose and otherwise process personal data when you visit our websites, join our waitlist, create or use an account, use our API, command-line tool, software development kits (SDKs) and integrations, claim free credit, buy our services, or communicate with us (together, the "Services").
Please read this policy together with our Terms of Service and, if you are a business customer, our Data Processing Addendum ("DPA"). If you do not agree with this policy, please do not use the Services.
In short
- We are the controller of the personal data we use to run our business: account, billing, website, waitlist, support, marketing and security information.
- We process the code, data and other content that customers run and store in the Services ("Customer Content") on our customers' behalf and on their instructions.
- We do not sell personal data, and we do not share it for cross-context behavioral advertising.
- Our public websites do not use cookies or third-party analytics or advertising tools.
- We use automated checks to prevent fraud and abuse, and you can ask a person to review a decision.
- Questions and requests: support@promigence.ai.
1. Who we are and what this policy covers#
1.1 Controller. Promigence AI, Inc., a Delaware corporation, 490 Post St Ste 500, PMB 2258, San Francisco, CA 94102, United States, is the controller of the personal data described in this policy, except Customer Content. Under some US state laws we are the "business" or "controller" for that data.
1.2 Customer Content. "Customer Content" means code, files, data, prompts, commands and their output, environment variables, secrets, snapshots, images and any other content that a customer, its users or its agents submit to, store in, run in or generate with the Services, including content the Services retrieve from repositories or other services at the customer's direction. We process Customer Content as a processor or service provider for the customer (section 4). If your personal data is part of a customer's Customer Content, that customer's privacy notice applies, and requests about it should go to that customer.
1.3 Professional use. The Services are designed for developers and organizations. If you use the Services for an organization, that organization's agreement with us also applies.
1.4 Not covered. This policy does not apply to third-party websites, services or applications. That includes accounts you sign in with, services you connect to the Services, and services your sandboxes or agents reach. Their own terms and privacy notices apply.
1.5 Nature of this policy. This policy is a notice. It is not a contract and does not create rights or obligations beyond those that apply under law or under your agreement with us.
2. Personal data we collect#
We collect personal data that you give us, that we collect automatically when you use the Services, and that we receive from other sources. Some information is needed to provide a service, for example an email address to create an account or a payment method for a paid plan. If you do not provide it, we may not be able to provide that service.
2.1 Account and sign-in information#
- Account details: your email address and whether it is verified, a user identifier, your sign-in method, and when you created your account and last signed in.
- Third-party sign-in: you may sign in with an account you hold with another provider, such as a code-hosting or email account. If you do, that provider shares with us, through our identity provider, your email address and its verification status. Where available, it also shares your name, a link to your profile picture, your username and your account identifier with that provider.
- Credentials: our identity provider handles your password and any second factor. We do not receive your password. If you use a passkey, any fingerprint, face or PIN check takes place on your own device; we and our identity provider receive only a public-key credential, never biometric data.
- API keys: we show each API key's secret once. We keep a record of the key, including its name, when it was created, when it was last used and when it expires. Keys created when you sign in with our command-line tool are named after your computer's hostname.
- Organizations: the organizations and projects you belong to, your role, and invitations, including the email addresses of the people invited.
2.2 Billing and payment information#
- Your plan, usage, credits, charges, invoices, and payment history and status.
- When you add a payment method, our payment processor collects your card details and related billing information directly, on a page it operates. We do not receive or store full card numbers. We receive a customer identifier, the card brand, the last four digits, the funding type (for example, whether the card is prepaid) and a card fingerprint that lets us recognize the same card again without knowing its number.
- To set up billing, we give our payment processor your organization's name and identifier and the email address of the account owner.
2.3 Information we use to apply free-credit rules and to prevent fraud and abuse#
When you sign up, sign in, request or claim free credit, use a referral code or add a payment card, we may collect:
- your email address, including a normalized form so that variations of one address are treated as one, and the identifier of any code-hosting account you sign in with;
- a one-way hash of your computer's identifier and a random identifier for your installation of our command-line tool, which the tool sends when you sign in or request a free-credit claim link;
- a one-way hash of characteristics of your browser (such as its graphics capabilities, time zone, languages and screen), computed on our free-credit claim page;
- your IP address and the network block it belongs to, whether the connection appears to come from a VPN, proxy or hosting provider, and, where available, a technical fingerprint of the connection's encryption handshake;
- your payment card's fingerprint and funding type;
- a record of your acceptance of the applicable terms, with the version, the time, your IP address and your browser's user agent; and
- for giveaways and campaigns, the code-hosting username you give us, public account details we look up from it (such as its identifier and creation date) and the outcome.
2.4 Usage, device and log information from the Services#
- API and tool use: the time, operation, result and duration of requests to our API, the API key used, the version of our command-line tool or SDK, and an optional label that you or an integration can set to identify the framework making a request.
- Security and audit records: actions taken in an account, such as creating or revoking API keys, inviting or removing members, claiming credit or deleting an organization, with the time, IP address and browser user agent. We also keep sign-in records, and we use them, for example, to tell you when your account is signed in to from a new IP address.
- Service operation data: information about how sandboxes and other resources run, such as resources used, duration, outcomes and error codes, and network traffic volumes and connection metadata. We use it to bill for, operate, secure and improve the Services and to detect abuse.
2.5 Website, waitlist and request forms#
Server logs: when you visit our websites, our servers and content delivery providers record:
- your IP address and approximate country and network;
- the date and time;
- the page requested, including any campaign parameters in the link;
- the referring page and your browser's user agent;
- technical details of the response.
Waitlist and free validity report requests: we collect:
- your email address, as you typed it and in a normalized form;
- where on our site you submitted the form;
- your approximate country;
- the network block of your IP address (we store only the network block with your submission, not the full address);
- whether the connection appears to come from a VPN or hosting provider, and a technical fingerprint of the connection;
- anything you enter, such as your company, a repository and command, expected volume, your current provider and notes.
We notify our team by email of new submissions. We do not accept disposable or forwarding email addresses on the waitlist.
2.6 Communications#
- When you email us, book or join a call, reply to our outreach or give feedback, we collect your contact details, the content of the communication and anything you choose to share.
- We keep records of the emails we send you, including their content and whether they were delivered, bounced or reported as spam, and your email preferences. Our emails do not contain tracking pixels, and we do not track whether you individually open them or click their links.
2.7 Integrations you connect#
If you install our app on a code-hosting account, we receive information about the installation: the account's name, identifier and type, and which repositories you made available. We also receive information about the repositories, branches and commits you ask us to use, including notifications when they change. We access repository contents only to carry out actions you request, such as building an environment from a repository. Repository contents are Customer Content.
2.8 Information from other sources#
- Your organization: an organization owner may give us your email address to invite you.
- Invitations and referrals: if we invite you to the Services, we may record your name or a note about you with your invitation. If you sign up with another customer's referral code, we record the referral.
- Public and professional sources: to find and contact people who may be interested in the Services, we collect business contact and professional information. We get it from public sources, such as public code-hosting profiles and activity, personal and company websites, publications and public posts, and from professional networking platforms. This may include your name, employer, role, public handles and public statements you have made about technical problems relevant to the Services.
- Social media, events and campaigns: information you share with us when you interact with our social media accounts, attend an event or enter a giveaway.
- Service providers: for example, payment status from our payment processor and sign-in security information from our identity provider.
2.9 Sensitive information#
We do not ask for sensitive personal data, such as health information, government identification numbers or information about racial or ethnic origin. Please do not send it to us through forms or support messages. Account log-in credentials are treated as sensitive under some laws; we use them only to sign you in and keep your account secure. What Customer Content contains is the customer's responsibility (section 4).
3. How we use personal data, and our legal bases#
The legal bases below apply where EEA or UK data protection law applies to you.
| What we do | Information used | Legal basis (EEA and UK) |
|---|---|---|
| Create and run your account, authenticate you, and provide the Services and the features you ask for, including integrations | Account and sign-in, organization, usage and log, integration information | Performance of our contract with you (Art. 6(1)(b) GDPR). Where you use the Services for an organization that is our customer: our legitimate interest in providing the Services to that customer (Art. 6(1)(f)) |
| Bill, collect payments, apply credits and manage plans | Billing and payment, usage, account | Contract; compliance with legal obligations, such as tax and accounting rules (Art. 6(1)(c)) |
| Send service, security, billing and account messages; provide support; answer questions | Account, communications, usage and log | Contract; legitimate interests in running and supporting the Services |
| Manage the waitlist and free validity report requests, and invite you to the Services | Website and form information | Steps you ask us to take before entering into a contract (Art. 6(1)(b)); legitimate interests in managing demand and preventing abuse |
| Apply free-credit rules; prevent, detect and investigate fraud, abuse and security incidents; enforce our terms | Information in section 2.3, account, usage and log, payment card fingerprint | Legitimate interests in protecting the Services, our customers, third parties and us, and in offering free credit fairly; legal obligations where they apply |
| Operate, maintain, troubleshoot, measure and improve the Services and our websites, and develop new features | Usage and log, server logs, communications and feedback | Legitimate interests in running and improving our business |
| Send marketing about our products, offers and events, and contact business prospects | Contact details, communications, information from other sources | Legitimate interests in promoting our business; consent where the law requires it (Art. 6(1)(a)) |
| Comply with law; respond to lawful requests; protect rights, property and safety; establish, exercise or defend legal claims | Any of the above, as needed | Legal obligations; legitimate interests |
| Corporate transactions (section 6) | Any of the above, as needed | Legitimate interests |
| Other purposes we describe when we ask for your consent | As described at the time | Consent |
We may also create de-identified or aggregated data and use it for any lawful purpose. We keep de-identified data in de-identified form and do not attempt to re-identify it, except as the law permits.
Where we rely on legitimate interests, you can contact us for more information about how we balanced our interests against your rights.
4. Customer Content#
4.1 Instructions. We process Customer Content on our customers' documented instructions, unless the law requires otherwise. Those instructions are set out in our agreement with each customer and given through the customer's use and configuration of the Services.
4.2 Use. We use Customer Content to provide, maintain, secure and support the Services for the customer, to prevent and investigate abuse and security incidents, and to comply with law. We do not use Customer Content to train artificial intelligence models.
4.3 Access by our personnel. We do not routinely inspect Customer Content. Our personnel may access it when needed to provide support the customer asks for, to keep the Services running and secure, to investigate a specific report or signal of abuse, or to comply with law.
4.4 Customer responsibilities. Customers decide what Customer Content to process. They are responsible for:
- having a lawful basis for that processing;
- giving any notices and obtaining any consents required;
- configuring their sandboxes, including network access and secrets;
- not processing data that the law or our agreement prohibits.
4.5 Retention and deletion. We keep Customer Content as described in our agreement with the customer and our documentation. Customers can delete Customer Content through the Services. Deleted content is removed from the customer's account straight away, but copies may remain in our storage systems and backups for some time afterwards.
4.6 Requests from individuals. If we receive a request from an individual about Customer Content, we will refer the individual to the relevant customer where we can identify it, and we will assist the customer as our agreement requires.
4.7 Sub-processors. We use sub-processors to process Customer Content, as described in our DPA. A list of our sub-processors is available to customers on request, subject to confidentiality.
5. Automated decisions and abuse screening#
We use automated systems to keep the Services secure and to offer free credit fairly. For example:
- Free credit. When you claim free credit or add a payment card, automated checks compare the information described in section 2.3 with other accounts. They apply our one-offer-per-person rule and look for fraud. A claim may be granted, held for review, made conditional on adding a payment card, or declined. Some holds are released automatically after a period of time or when a qualifying payment card is added.
Abuse and security. We automatically monitor service operation data (section 2.4), such as resource use and patterns of network activity, to detect activity like cryptocurrency mining or network scanning. Depending on what is detected and on the account, the system may do any of the following, and may notify the account:
- flag the activity for review;
- limit a sandbox's network activity;
- stop a sandbox;
- suspend an account.
- Sign-in security. Our identity provider checks sign-ins and passwords to protect accounts. For example, it refuses passwords known to have been exposed in data breaches.
We use these systems because they are necessary to provide the Services securely and on fair terms, and to protect our customers, third parties and us. If you think an automated decision about you is wrong, contact us at support@promigence.ai. You can ask for a person to review the decision, give your point of view and contest it. We may not explain exactly how our checks work, because doing so would help people evade them.
6. How we disclose personal data#
We disclose personal data only as described in this section.
Service providers. These are companies that process personal data on our behalf and under our instructions, in these categories:
- cloud hosting, computing, storage, database, content delivery and backup providers;
- identity and sign-in providers that operate our sign-in pages and account security features;
- email delivery providers, and business email, calendar, scheduling and other communication providers;
- payment processors;
- security, monitoring and logging services;
- productivity, collaboration and software development tools, including artificial intelligence tools that help our personnel build, operate, support and secure the Services.
A list of our service providers is available to customers on request, subject to confidentiality. If you exercise a right of access under data protection law, you can ask us to identify the recipients of your personal data.
- Your organization. If your account belongs to an organization, its members can see each member's email address, role and join date. Its owners can also see the API keys created in it and the organization's activity records, including which member took an action and the IP address it came from. Owners also receive security and billing notices about the organization.
- Services you choose. Sign-in providers you choose, code-hosting services you connect, and other services that you or your agents direct the Services to reach receive the information needed to carry out your instructions.
- Our payment processor's own purposes. Besides processing payments for us, our payment processor uses payment information for its own purposes, such as fraud prevention and meeting its legal obligations, under its own privacy notice.
- Professional advisers. Lawyers, accountants, auditors, insurers and similar advisers, under duties of confidentiality.
Legal, safety and enforcement. We may disclose personal data to law enforcement agencies, regulators, courts and other parties when we believe in good faith that disclosure is:
- required by law or valid legal process;
- needed in an emergency involving a risk of death or serious physical injury;
- needed to protect the rights, property or safety of Promigence, our customers, users or others;
- needed to detect, prevent or respond to fraud, abuse or security issues;
- needed to enforce our agreements.
We report apparent child sexual exploitation material to the appropriate authorities as required by law.
- Business transfers. Buyers, investors, successors and their advisers, in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of all or part of our assets, or transfer of the Services to another provider. Personal data may be transferred as part of such a transaction.
- Affiliates. Any current or future parent, subsidiary or affiliate, for the purposes described in this policy.
- With your consent or at your direction.
We may disclose de-identified or aggregated information that cannot reasonably be used to identify you.
No sale and no targeted advertising. We do not sell personal data, and we do not share personal data for cross-context behavioral advertising (targeted advertising). We have not done so in the past 12 months.
7. Cookies and similar technologies#
- Websites. Our public websites do not set cookies, do not use local storage or similar browser storage, and do not load third-party analytics, advertising or social media tracking tools. We understand how our websites are used from the server logs described in section 2.5.
- Sign-in pages. Our identity provider operates our sign-in pages for us. They use cookies that are strictly necessary to sign you in, keep the sign-in session secure and protect against forged requests. The identity provider's security features may also assess characteristics of your browser, device and network to detect suspicious sign-ins.
- Free-credit claim page. This page does not set cookies. It computes a one-way hash of your browser's characteristics, described in section 2.3, and sends it to us when you claim free credit.
- Command-line tool. Our command-line tool stores your API key and a random installation identifier on your computer. When you sign in or request a free-credit claim link, it sends that installation identifier and a one-way hash of your computer's identifier (section 2.3). It does not send usage analytics.
- Emails. Our emails do not contain tracking pixels. Images in our emails are the same for every recipient. If your email program loads them, our websites' server logs record the request like any other website visit.
- Changes. We will update this policy before we use cookies or similar technologies other than those described here, and we will ask for your consent first where the law requires it.
We do not track you across other companies' websites, so we do not change our practices in response to browser "Do Not Track" signals. Where the law requires it, we treat a Global Privacy Control signal as a request to opt out of the sale or sharing of personal data; as section 6 explains, we do not sell or share personal data.
8. International transfers#
We are based in the United States. We and our service providers process personal data primarily in the United States, and some service providers may process it in other countries. These countries may not provide the same level of data protection as the country where you live.
When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been found to provide adequate protection, we use appropriate safeguards. These include the standard contractual clauses approved by the European Commission, with the UK and Swiss adaptations where needed. We may instead rely on another mechanism permitted by law. You can ask us for a copy of these safeguards by contacting us; we may redact commercial terms.
9. How long we keep personal data#
We keep personal data for as long as we need it for the purposes described in this policy, as shown below.
| Information | How long we keep it |
|---|---|
| Account and organization information | While the account is active. After an account or organization is deleted, we keep the records we need for the purposes below, such as billing history, security and audit records, and what we need to apply our one-offer-per-person rule. We delete or de-identify the rest within a reasonable time. |
| Billing and transaction records | As long as needed for tax, accounting, audit and dispute purposes, and as the law requires. |
| Free-credit and fraud-prevention information | As long as needed to apply our free-credit rules and to prevent fraud and abuse. This may continue after an account is closed. |
| Security, audit and abuse records | As long as needed to protect the Services, investigate incidents and abuse, and establish or defend legal claims. Routine system logs are generally kept for about 30 days. |
| Website server logs | Up to 13 months. |
| Waitlist and request forms | Until the waitlist or request is no longer active or you ask us to remove you, and then for a limited time to keep a record of our communications. |
| Communications and support | As long as needed to handle your request and to keep a record of our relationship with you. |
| Email records and preferences | Message records for as long as needed for the purposes above. Unsubscribe and suppression records for as long as needed to honor them. |
| Customer Content | As set out in our agreement with the customer and our documentation (section 4). |
| Backups | Deleted information may remain in backup copies for a limited time, until those copies expire in the normal course. |
We may keep personal data for longer where the law requires it, under a legal hold, or to establish, exercise or defend legal claims. We may keep de-identified or aggregated data without a time limit.
10. Security#
We use reasonable administrative, technical and organizational measures designed to protect personal data against accidental or unlawful loss, access, use, alteration and disclosure. Examples include:
- encryption of data in transit and of stored data;
- encrypted storage of customer secrets;
- storage of API key secrets in a form that cannot be read back;
- access limited to personnel who need it;
- multi-factor authentication for our personnel;
- records of administrative actions.
No method of transmission over the internet or of electronic storage is completely secure, and no set of measures can prevent every incident. We therefore cannot guarantee the security of personal data. To the extent the law permits, you provide personal data at your own risk.
You are responsible for keeping your passwords, API keys and devices secure, and for the configuration and content of your sandboxes. If you believe your account or an API key has been compromised, revoke the affected keys and contact us at support@promigence.ai.
If we become aware of a security incident that affects your personal data, we will notify you and the relevant authorities where the law requires us to.
11. Your choices and rights#
11.1 Account information. You can review some of your information in the Services, such as your API keys and organizations. To correct other information, contact us.
11.2 Marketing and onboarding emails. You can unsubscribe at any time using the link in the email or by contacting us. We will still send you messages about security, billing and your account, which are part of the Services.
11.3 Deleting an organization or an account. Organization owners can delete an organization in the Services, after ending its sandboxes, deleting its snapshots and canceling any paid plan. To delete your user account, contact us. Deletion does not remove the records we keep under section 9.
11.4 Your privacy rights. Depending on where you live, you may have the right to:
- know about, access and receive a copy of the personal data we hold about you;
- correct inaccurate personal data;
- delete your personal data;
- receive your personal data in a portable format and have it transmitted to another controller;
- restrict or object to our processing;
- withdraw consent where we rely on it, without affecting processing that happened before you withdrew;
- not be subject to decisions based solely on automated processing that have legal or similarly significant effects on you, and contest such decisions;
- complain to a data protection authority.
These rights have limits and exceptions under applicable law. For example, we may keep information we need to comply with law, to prevent fraud and abuse, to protect the rights of others, or to establish or defend legal claims.
11.5 How to make a request. Email support@promigence.ai with "Privacy request" in the subject line. Tell us what you are asking for. If you have an account, send the request from the email address on your account. We will respond within the time required by applicable law.
11.6 Verification. We will take reasonable steps to verify your identity before we act on a request. For example, we may ask you to confirm control of your account's email address or to give us information that matches our records. We may ask for more information where needed, and we use it only to verify the request. We may decline a request we cannot verify.
11.7 Authorized agents. If an agent makes a request for you, we may ask for proof that you authorized it, such as your signed permission. We may also ask you to verify your identity with us directly, unless the agent holds a valid power of attorney.
11.8 If we decline. If we decline your request, we will tell you why where the law allows. Where the law gives you a right to appeal, you can appeal by replying to our decision with "Appeal" in the subject line. If you are still not satisfied, you can contact your data protection authority or, in the United States, your state attorney general.
11.9 Requests about Customer Content. See section 4.6.
11.10 No discrimination. We will not discriminate against you for exercising your privacy rights.
12. Additional information for the EEA, the United Kingdom and Switzerland#
- Controller: Promigence AI, Inc. (contact details in section 16).
- Legal bases: described in section 3.
- Right to object: where we rely on legitimate interests, you can object at any time on grounds relating to your particular situation. We will then stop, unless we have compelling legitimate grounds or need the data to establish, exercise or defend legal claims. You can object to direct marketing at any time, and we will stop.
- Automated decisions: described in section 5.
- Transfers: described in section 8.
- Complaints: you can lodge a complaint with the supervisory authority in the country where you live or work or where you believe an infringement occurred. In the UK that is the Information Commissioner's Office, and in Switzerland the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.
13. Additional information for California and other US states#
13.1 Categories of personal information. In the past 12 months we have collected the following categories of personal information. For each, the table shows the recipients to whom we disclosed it for a business purpose.
| Category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email address, account and user identifiers, usernames of linked accounts, IP address, hashed device and browser identifiers, API key records | Service providers; your organization; services you choose; our payment processor (email address and organization identifiers); legal and safety recipients |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address, limited payment card information (brand and last four digits) | Service providers; our payment processor; legal and safety recipients |
| Commercial information | Plans, usage, credits, charges, invoices and payment history | Service providers; our payment processor; your organization's owners; legal and safety recipients |
| Internet or other electronic network activity | Server logs, API and sign-in records, browser user agent, browser and connection characteristics, service operation data | Service providers; your organization's owners (activity records); legal and safety recipients |
| Approximate location | Country and network block derived from an IP address. We do not collect precise geolocation. | Service providers; legal and safety recipients |
| Professional or employment-related information | Company, role and work details you provide or that are publicly available | Service providers; legal and safety recipients |
| Inferences | Assessments of eligibility for free credit and of fraud or abuse risk | Service providers; legal and safety recipients |
| Sensitive personal information | Account log-in credentials, handled by our identity provider | Service providers (our identity provider) |
Any category may also be disclosed in a business transfer (section 6).
13.2 Sources and purposes. We collect personal information from the sources described in section 2, for the business and commercial purposes described in section 3.
13.3 No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
13.4 Sensitive personal information. We use and disclose sensitive personal information only for purposes permitted by the CCPA regulations (Cal. Code Regs. tit. 11, § 7027(m)), such as providing the Services and keeping them secure. We do not use it to infer characteristics about you.
13.5 Retention. Described in section 9.
13.6 Your rights. If you are a California resident, you have the right to:
- know what personal information we collect, use and disclose, and access specific pieces of it;
- delete it;
- correct it;
- not receive discriminatory treatment for exercising these rights.
You also have rights to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. Because we do not sell or share personal information or use sensitive personal information beyond permitted purposes, those rights do not currently require any action from us.
Residents of other states with comprehensive privacy laws may have similar rights, including to confirm whether we process their personal data, to access, correct, delete and obtain a portable copy of it, and to appeal our decision on a request. Some of those laws also give a right to opt out of targeted advertising, sale and certain profiling. We do not engage in targeted advertising or sales, or in profiling in furtherance of decisions that produce legal or similarly significant effects as those laws define them.
13.7 How to exercise your rights. See sections 11.5 to 11.8.
13.8 Direct marketing disclosures. We do not disclose personal information to third parties for their own direct marketing purposes.
14. Children#
The Services are not directed to children. You must be at least 18 years old to use them, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will take steps to delete it.
15. Changes to this policy#
We may change this policy from time to time. We will post the new version with a new "Last updated" date. If a change materially affects how we use personal data we already hold, we will give notice as required by applicable law, for example by email to account owners or a notice in the Services. We will ask for consent where the law requires it.
16. Contact us#
Promigence AI, Inc.
490 Post St Ste 500, PMB 2258
San Francisco, CA 94102
United States
support@promigence.ai (please put "Privacy" in the subject line)