Privacy Policy
Last updated: 24 March 2026
The controller of your personal data is Giuseppe Trebini, a natural person operating the “Prosphir AI” service. Address: Via Claudio Monteverdi, 74010 Statte (Province of Taranto), Italy. Privacy contact: assistance.prosphir.ai@outlook.com.
Processors and main service providers
We use providers that may act as processors on our behalf (Art. 28 GDPR) or as independent controllers for specific functions (e.g. payments). Main technical providers currently integrated:
• Clerk (Clerk Inc.) — authentication and user profile • Stripe — card payments and paid order handling • Supabase — PostgreSQL database and related application data infrastructure • OpenAI — AI models for analysis and text generation • Vercel — hosting, CDN, and execution of the web application • Tavily — automated web search for market context (only if the API key environment variable is set; otherwise this processing does not occur)
Their own privacy notices on official sites also apply where they process data as controllers (notably Stripe for payment data and Clerk for authentication).
Data we process
Account and authentication data (e.g. via Clerk): identifiers, email, name.
Form data you submit for analysis: idea description, market context, team, budget, location, etc.
Usage and technical data: security logs, IP addresses, timestamps for requests needed to run the service and to protect against abuse or payment disputes.
Payment data is processed by Stripe; we do not store full card numbers on our infrastructure.
Purposes and legal bases (indicative)
Providing the service, accounts, and requested digital reports (contract / pre-contract steps).
Accounting or tax obligations where applicable (legal obligation).
Security, fraud prevention, defending legal claims including payment disputes (legitimate interest where permitted).
Essential service communications; any marketing only with consent where required.
Processing and retention
Processing is electronic and may involve processors/sub-processors (hosting, database, payments, email).
We keep data as long as needed for these purposes and as required by law; security or service-delivery logs may be kept for periods compatible with chargeback windows, as defined in internal policies.
Transfers outside the EU/EEA
Some providers may be located outside the EEA. Where transfers occur, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses) unless another approved mechanism applies.
Your rights
Depending on applicable law (including GDPR), you may have rights of access, rectification, erasure, restriction, objection, portability where applicable, and the right to lodge a complaint with a supervisory authority.
Requests: assistance.prosphir.ai@outlook.com
Cookies and similar technologies
We use strictly necessary cookies/similar technologies for operation, security, and session preferences. Analytics or marketing tools will only be added with a dedicated notice and consent where required.