Privacy Policy

Last updated: January 15, 2025

Your privacy is important to us. This Privacy Policy explains how Projexlight collects, uses, and protects your personal information.

1. Information We Collect

Account Information

When you create an account, we collect:

  • First and last name
  • Email address
  • Password (encrypted)
  • Organization name
  • Phone number (optional)
  • Country and region

Project and Usage Data

When you use our services, we collect:

  • Project names, descriptions, and metadata
  • Code schemas, epics, features, tasks, and scenarios you create
  • AI prompts and generated code
  • Test suites, test results, and execution logs
  • Defect reports and analytics data
  • Team collaboration data (comments, assignments, work logs)
  • Usage metrics (AI tokens consumed, container hours, storage used)

Technical Information

We automatically collect:

  • IP address and browser type
  • Device information (operating system, device type)
  • Log data (access times, pages viewed, clicks)
  • Cookies and similar tracking technologies
  • Error logs and performance data

Payment Information

For paid accounts:

  • Billing name and address
  • Payment method details (processed securely by Stripe)
  • Transaction history and invoices
  • Tax identification numbers (if applicable)

Note: We do not store full credit card numbers. All payment processing is handled securely by our payment processor, Stripe.

2. How We Use Your Information

We use the information we collect to:

Provide and Improve Our Services

  • Create and manage your account
  • Process your requests and transactions
  • Generate code using AI models
  • Execute tests in Docker containers
  • Store and organize your projects
  • Provide customer support
  • Improve our algorithms and features

Communication

  • Send service updates and notifications
  • Respond to your inquiries and support requests
  • Send billing statements and payment reminders
  • Notify you of security alerts or policy changes
  • Send marketing communications (with your consent)

Analytics and Optimization

  • Analyze usage patterns to improve performance
  • Generate aggregate statistics and insights
  • Optimize AI model selection and costs
  • Identify and fix bugs and errors

Security and Compliance

  • Detect and prevent fraud and abuse
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Protect the rights and safety of our users

3. How We Share Your Information

We may share your information in the following circumstances:

AI Model Providers

When you use our code generation features, your prompts and context are sent to third-party AI providers (OpenAI, Anthropic, Google, DeepSeek, etc.) to generate code. Each provider has their own privacy policy governing how they process this data.

Cloud Service Providers

We use AWS, Azure, and other cloud platforms to host our services and store your data. These providers may process your data as necessary to provide infrastructure services.

Payment Processors

Payment information is processed by Stripe, our payment processor. We do not store full credit card details on our servers.

Service Providers

We work with trusted service providers for:

  • Email delivery (SendGrid, Amazon SES)
  • Analytics (Google Analytics, Mixpanel)
  • Error tracking (Sentry)
  • Customer support (Zendesk)

Team Members

When you invite team members to your organization, they will have access to shared projects and data based on their assigned roles and permissions.

Legal Requirements

We may disclose your information if required by law, court order, or government request, or to protect the rights, property, or safety of Projexlight, our users, or the public.

Business Transfers

If Projexlight is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

We do NOT sell your personal information to third parties for marketing purposes.

4. Data Security

We implement industry-standard security measures to protect your data:

Encryption

Data is encrypted in transit (TLS 1.3) and at rest (AES-256)

Access Controls

Role-based access control (RBAC) and principle of least privilege

Secure Infrastructure

Isolated tenant databases, secure Docker containers, and network segmentation

Regular Audits

Security assessments, penetration testing, and compliance audits

Monitoring

24/7 security monitoring and automated threat detection

While we implement robust security measures, no method of transmission or storage is 100% secure. You use the Service at your own risk and should take appropriate precautions to protect your account credentials.

5. Data Retention

We retain your information for as long as necessary to provide our services:

  • Active Accounts: We retain all your data while your account is active
  • Deleted Accounts: After you delete your account, we retain your data for 30 days to allow for reactivation, then permanently delete it
  • Backup Data: Deleted data may persist in encrypted backups for up to 90 days for disaster recovery purposes
  • Legal Obligations: We may retain certain data longer if required by law (e.g., tax records for 7 years, audit logs for compliance)
  • Aggregated Data: Anonymized and aggregated data may be retained indefinitely for analytics and research

6. Your Privacy Rights

Depending on your location, you may have the following rights:

Access and Portability

Request a copy of your personal data in a portable format (JSON, CSV)

Correction

Update or correct inaccurate personal information through your account settings

Deletion

Request deletion of your personal data (subject to legal retention requirements)

Opt-Out of Marketing

Unsubscribe from marketing emails using the link in each email or through your account preferences

Restrict Processing

Request limitation of how we process your personal data

Object to Processing

Object to processing of your personal data for certain purposes

Withdraw Consent

Withdraw consent for data processing where we rely on consent as the legal basis

To exercise these rights, please contact us at privacy@projexlight.com. We will respond within 30 days.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Keep you signed in
  • Remember your preferences
  • Analyze usage patterns and improve our services
  • Measure marketing campaign effectiveness
  • Prevent fraud and abuse

Types of Cookies We Use:

Essential Cookies (Required)

Necessary for the Service to function (authentication, security)

Functional Cookies (Optional)

Remember your settings and preferences

Analytics Cookies (Optional)

Help us understand how you use the Service (Google Analytics)

Advertising Cookies (Optional)

Track the effectiveness of our marketing campaigns

You can control cookies through your browser settings. Disabling certain cookies may affect functionality. Essential cookies cannot be disabled.

8. International Data Transfers

Projexlight is based in the United States. If you access our services from outside the U.S., your data may be transferred to, stored, and processed in the United States or other countries where we or our service providers operate.

We implement appropriate safeguards for international data transfers, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with service providers
  • Compliance with GDPR, CCPA, and other applicable privacy laws

9. Children's Privacy

Our Service is not directed to children under 13 years of age (or 16 in the European Economic Area). We do not knowingly collect personal information from children.

If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@projexlight.com and we will delete it promptly.

10. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect, use, and share
  • Right to delete your personal information
  • Right to opt-out of the sale of personal information (we don't sell your data)
  • Right to non-discrimination for exercising your privacy rights

To exercise these rights, email us at privacy@projexlight.com or call our toll-free number at 1-800-XXX-XXXX.

11. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your personal data in accordance with the General Data Protection Regulation (GDPR).

Legal Basis for Processing:

  • Contract: To provide services you requested
  • Legitimate Interests: To improve our services and prevent fraud
  • Consent: For marketing communications (you can withdraw anytime)
  • Legal Obligation: To comply with laws and regulations

You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending an email to your registered email address
  • Displaying a prominent notice in the Service

Your continued use of the Service after changes are posted constitutes acceptance of the updated Privacy Policy.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Data Privacy Officer:

privacy@projexlight.com

General Inquiries:

support@projexlight.com

For general questions, please visit our Contact Page.