Privacy Policy
At PRDGen AI, we take your privacy seriously. This policy explains what information we collect, how we use it, and what rights you have regarding your personal data.
1. Information We Collect
We collect information to provide and improve our Service. This includes:
Account Information:
- Name and email address when you register
- Profile photo if you sign in via Google OAuth
- Password (stored as a bcrypt hash — never in plain text)
Usage Data:
- Documents and prompts you submit for AI generation
- Feature usage patterns and session activity
- IP address, browser type, and device information
- Log data including pages visited and timestamps
Payment Data:
- Transaction IDs and subscription status
- Card information is handled solely by our payment provider (Midtrans) and is never stored on our servers
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the PRDGen AI Service
- Process your requests and generate AI-powered documents
- Manage your account and subscription
- Send transactional emails (account verification, invoices, password resets)
- Communicate product updates or promotional offers (you can opt out anytime)
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal data to third parties. Period.
3. AI Processing and Your Content
When you submit prompts or content to generate PRDs, that input is:
- Transmitted to our AI provider (Google Gemini) for processing
- Not used to train AI models without your explicit consent
- Stored in our database to display your generation history
- Accessible only by you and authorized system administrators
Please avoid submitting highly sensitive or confidential proprietary information in your PRD prompts.
4. Cookies and Tracking
We use cookies and similar technologies to:
- Essential cookies: Required for authentication and session management
- Analytics cookies: Help us understand how users interact with our platform (anonymized)
- Preference cookies: Remember your settings and theme preferences
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect Service functionality.
5. Data Sharing and Disclosure
We share your data only in these circumstances:
- Service Providers: Trusted third parties who assist in operating the Service (hosting, email delivery, analytics). They are bound by confidentiality agreements.
- Legal Requirements: When required by law, court order, or governmental authority.
- Business Transfers: In the event of a merger or acquisition, your data may be transferred with prior notice.
- Safety: To protect the rights, safety, or property of PRDGen AI, our users, or the public.
6. Third-Party Services
Our Service integrates with third-party providers:
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide Services.
- Account data: Retained while your account exists, deleted within 90 days of account closure
- Generated documents: Deleted upon account deletion or upon explicit user request
- Payment records: Retained for 7 years for tax and legal compliance
- Log data: Retained for up to 12 months
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Correction: Update or correct inaccurate personal information
- Deletion: Request deletion of your account and associated data
- Portability: Receive your data in a machine-readable format
- Opt-out: Unsubscribe from marketing communications at any time
To exercise these rights, contact us at privacy@prdgen.ai.
9. Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.3
- Passwords are hashed using bcrypt with appropriate salt rounds
- Database access is restricted to authorized personnel only
- Regular security audits and vulnerability assessments
- Session tokens are short-lived and rotated regularly
No system is 100% secure. In the event of a data breach, we will notify affected users within 72 hours as required by applicable law.
10. Children's Privacy
PRDGen AI is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make significant changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you via email if changes are material
- Show an in-app notification for the first login after changes
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or how we handle your data:
© 2026 PRDGen AI. All rights reserved.