Trust
Privacy policy
Last updated September 2, 2026
What Phronetos Proof processes
Proof processes account details, workspace configuration, feedback reports, operational evidence, decision records, and service logs. A report may include a work email, page location, screenshot, and context supplied by the customer's application.
Why we process it
We use this data to provide, secure, support, and improve the service. We do not sell personal information. We do not use customer evidence to train shared machine-learning models without written permission.
The marketing site uses a random, in-memory page-session identifier to count page views and pilot application starts and completions. It also sends page views, advertising campaign parameters, referrers, and those three funnel events to PostHog Cloud in the European Union. Non-campaign query parameters are removed first. No application answers, email addresses, or company names are sent.
Marketing analytics uses no cookies or persistent browser storage. Session replay, automatic interaction capture, and person profiles are disabled. First-party funnel counts are deleted after 90 days. PostHog may retain anonymous marketing events for up to seven years unless they are deleted earlier.
Signal intake derives a keyed, pseudonymous rate-limit value from the request network address. Proof does not store the raw address in the rate-limit table. Hourly cleanup deletes minute buckets older than 24 hours.
The Chrome extension acts only when a reporter opens it. A submitted report may include the page origin, path, title, query parameter names, viewport, document size, scroll position, navigation timing, display preferences, language, timezone, basic connection indicators, Chrome platform details, a reporter-selected control, team, workflow, release, recurrence, estimated time lost, affected people, optional cost exposure, workaround, and an optional reporter-reviewed screenshot. Query values are excluded by default. Sensitive query keys are redacted when query capture is enabled.
The extension does not monitor browsing, read history or cookies, capture keystrokes or clipboard data, scrape page contents, inspect network traffic or console logs, or take screenshots in the background. It uses temporary access to the active tab after a reporter invokes it.
Customer control
The subscribing organization controls the operational records in its workspace. Workspace owners can request an export, correction, or deletion. Reporters should contact their organization first because it determines why the report is collected.
Storage and subprocessors
Before customer data enters production, Phronetos will provide the deployment-specific subprocessor schedule and data processing addendum during procurement. Contracted providers may access data only for the documented service purpose, delivery, security, and incident response.
Retention and security
We retain workspace data for the subscription term and the agreed recovery period. We use tenant scoping, encrypted transport, access controls, audit trails, and private evidence storage. No service can eliminate all risk.
Contact
Send privacy questions or rights requests to privacy@phronetos.com.