1. Scope and responsibility
This Privacy Policy explains how ProInstincts Enterprises, Inc., the operator of Phasoric, handles personal information for Phasoric websites, hosted accounts, and optional connected features. For ordinary direct accounts, Phasoric determines the purposes and means of the account and service data described here. When a customer organization directs us to process personal data in its workspace, that customer is the controller or equivalent decision-maker and Phasoric acts as its processor or service provider under the Data Processing Addendum.
2. Local-first storage boundaries
Storage is selected per vault and applies to routed artifact payloads such as Markdown, attachments, captures, generated media, conversations, transcripts, canvases, governed projections, indexes, and future artifact types.
- Local-only or unmapped vaults: Payloads stay in the browser storage for that Phasoric origin. Creating an account does not upload them or change storage mode.
- Customer-selected providers: Content mapped to Dropbox, Google Drive, or GitHub remains in the authorized device cache and that provider unless you invoke another hosted feature.
- Phasoric Hosted: Content explicitly mapped to Phasoric Hosted is stored in private hosted storage scoped to the account and vault mapping.
- Coordination data: Signed-in workspaces may synchronize bounded metadata and encrypted recovery sidecars so authorized devices can discover, reconcile, and restore a workspace without silently hosting the underlying local-vault payloads.
3. Information we process
- Account and policy data: Name, email address, password hash, verification state, plan and entitlement data, communication preferences, account status, and the policy versions and time accepted.
- Workspace and content data: Content you deliberately host or send to a hosted feature; note and folder metadata such as titles, paths, bounded previews, organizational fields, links, task counts, and timestamps; collaboration, exchange, automation, and connected-service records.
- Connection data: Provider identifiers, scopes, status, encrypted credentials or tokens, synchronization state, and audit events needed for connections you authorize. Secrets are not included in account exports.
- Payment data: Customer, subscription, invoice, transaction, tax, and entitlement identifiers received from Stripe. Phasoric does not receive or store full payment-card or bank-account numbers.
- Signing and exchange evidence: Participant name and email, authentication method, envelope or exchange state, event timestamps, user-agent information, and a one-way network-address hash where used to establish an evidence trail. Encrypted exchange packages and signing documents are stored only for the workflow and retention period described to participants.
- Education and delegated identity data: Organization, roster, course, role, pseudonymous learner, standards, assignment, evidence, review, and integration records authorized by an institution. The Education Data Addendum supplies additional limits.
- Support and feedback: Messages, attachments, contact details, diagnostic information you choose to provide, and an audit record of authorized support access.
- Service and device data: Session and security-cookie state, approximate request and device information, rate-limit and abuse-prevention records, reliability codes, consent state, and bounded first-party signup, billing, activation, and service events. Essential operational events exclude note content, titles, vault names, filenames, searches, private share identifiers, and payment credentials.
- Basic traffic measurement: Aggregate visitor and pageview counts operate independently of optional measurement choices through an analytics infrastructure service. Google Analytics and Microsoft Advertising also receive limited consent-mode signals before optional consent, with analytics and advertising cookie storage denied. Public campaign labels may be included; private link identifiers, arbitrary query values, and workspace content are excluded.
- Optional measurement: With your consent, Google Analytics and Microsoft Advertising may use measurement cookies and receive deeper product or advertising attribution events. OpenAI Ads conversion delivery requires optional consent. Measurement excludes note content, titles, searches, filenames, email addresses, and private link identifiers. You can withdraw optional consent in Settings; baseline traffic counts and limited consent-mode signals continue.
4. Why we process it
We process information to provide requested features; authenticate users; synchronize and recover authorized workspaces; deliver support; secure and troubleshoot the service; administer subscriptions and taxes; communicate operational notices; comply with law; and improve service reliability. Where applicable, our legal bases include performing a contract, legitimate interests in operating and securing the service, consent for optional measurement, and compliance with legal obligations. A customer determines the purpose and legal basis for personal data it instructs us to process.
We do not sell personal information, use private workspace content for personalized advertising, or train a general-purpose model on private workspace content. Source content is treated as user data, not as an instruction that can silently override product controls.
5. Sharing and service providers
We disclose information only as needed to provide a directed feature, comply with law, protect rights and safety, complete a business transaction subject to appropriate safeguards, or with your consent. Categories include hosting and content delivery, managed database and private object storage, transactional email, customer support, payment processing, security and reliability, optional measurement, and hosted-intelligence routing or model processing.
Stripe processes payments. Google Analytics and Microsoft Advertising process the limited consent-mode signals described above and fuller measurement when you grant optional consent. OpenAI Ads receives consented conversion reporting. Other Google and Microsoft integrations process the data needed for features you enable. Dropbox, Google Drive, and GitHub process content you direct to your own connected account under their terms. The public Service Provider & Subprocessor Register describes categories and the process for obtaining the exact current provider list when legally or contractually required.
6. Hosted intelligence and connected providers
Local search, supported transcription, text recognition, and supported local assistance stay on the device. If you enable a hosted route and initiate a request, Phasoric sends the bounded instructions and authorized context needed for that request to hosted-intelligence routing and model services. The route and provider may process that request under their applicable terms. If you connect your own provider, its privacy and retention terms apply. Connected credentials are encrypted at rest, remain server-side, can be revoked in Settings, and are deleted with the account.
7. Cookies and similar storage
Phasoric uses essential browser storage and cookies for sessions, security, preferences, consent, referral attribution, and time-limited protected-share access. Aggregate web traffic measurement does not require analytics cookies. Google Analytics and Microsoft Advertising tags load in a limited consent mode with optional storage denied until consent. Withdrawing optional consent denies that storage, stops deeper product measurement and OpenAI Ads conversion delivery, and clears optional cookies accessible to Phasoric. Basic counts and limited consent-mode signals continue. Withdrawal does not remove data already held by another provider under its retention rules.
8. Retention and deletion
We keep each category only as long as needed for the purposes above, a customer instruction, or law.
- Local data remains until it is deleted on each device, the vault is removed, or browser site data is cleared.
- Hosted account, policy-acceptance, workspace, and Phasoric Hosted content records are deleted through the account-deletion workflow, subject to completion of durable storage cleanup and legally required records.
- Expired verification and reset tokens are cleaned up within 7 days. Webhook events and inbound email operational records are generally purged after 90 days. Transactional email records are generally deleted after 180 days. System alerts are generally kept for 90 days. Backups are retained for no more than 30 days.
- Signing, exchange, billing, security, suppression, and legal records may follow a longer disclosed or legally required period. Where retention is controlled by an organization, requests should be directed to that organization first.
Permanent account deletion immediately revokes sessions, developer and capture tokens, public shares, collaboration access, and active billing. It does not delete local-only content from your devices or content independently stored by Dropbox, Google Drive, GitHub, another participant, or an organization authorized to retain it.
9. Security and international processing
We use access controls, encryption in transit, encrypted secret storage, tenant scoping, audit records, least-privilege processes, security testing, and deletion controls appropriate to the service. No method is perfectly secure. Data may be processed in the United States or another country used by a service category. Where law requires a transfer mechanism, the parties will use an applicable contractual or statutory mechanism; confidential provider and transfer details are available through the DPA process.
10. Your choices and rights
Hosted users can manage connections and optional consent, export hosted account data, separately export local or provider-hosted vaults, and request account deletion in Settings. Depending on applicable law, you may also request access, correction, portability, restriction, objection, or deletion, or complain to a data-protection authority. We may verify identity and may direct an organization-managed request to the organization that controls the workspace.
11. Education and younger users
Phasoric does not invite people who cannot form a direct service contract to create independent hosted accounts. Institution-authorized education use is governed by the institution's instructions and the Education Data Addendum. We do not use covered learner data for personalized advertising or general-purpose model training.
12. Web Clipper
The Phasoric Web Clipper accesses an active tab only when you open it or invoke a capture, highlighting, reader, or OCR command. Depending on the feature, it may process the page title, URL, selected passage, article content, visible-page image, supported PDF content, image URLs, publication metadata, Schema.org data, highlights, and formatting needed to prepare portable Markdown.
Article extraction, template rendering, PDF inspection, and OCR run locally with packaged code and models. Reviewed clips remain in extension storage until you choose to synchronize them to a paired Phasoric workspace. A browser-local vault mirror and agent proposals remain protected by an extension-generated token and explicit approval controls. You can delete clips, reject proposals, rotate the token, export settings, or remove extension-local data by uninstalling the extension or clearing its storage. Information received from Google APIs is handled under the applicable Google API and Chrome Web Store limited-use requirements.
13. Changes and contact
Material changes will be posted with a new version and effective date and, when reasonably practicable, notified through the service or account email. Contact privacy@phasoric.com for privacy questions or rights requests.
