← Prathm

Privacy Policy

Version 2026-08-18

Draft — not yet reviewed by a lawyer. The description of how the product handles documents and data is accurate. The clauses that need legal advice are marked [to be drafted] rather than guessed at. Replace this wording before onboarding a paying client, and bump TERMS_VERSION in the API when you do, so existing consent records keep naming the text people actually saw.

What we hold

There are three kinds of thing, and they behave differently:

Your account. Your email address, your role, when you last signed in, and a hash of your password — never the password itself. If you asked for access rather than being invited, also the name, company, role and message you typed on that form.

Your documents.The files you upload and the data extracted from them. These are commercial documents and they routinely contain other people’s details — a supplier contact, a signature on an inspection report. We treat all of it as yours to control.

What happened.A step-by-step record of each document’s journey through the system: permission to upload, bytes fetched, read, mapped, checked, saved, and every way any of those failed. This exists so we can explain a failed extraction to the person who uploaded it.

Where it lives

Everything is hosted in AWS Mumbai (ap-south-1) and nowhere else. Documents are stored in object storage under a prefix belonging to your tenant; extracted data is in a managed Postgres database with row-level security enforcing the same boundary.

The one exception is extraction itself: the text read from your documents is sent to Google’s Gemini API to be mapped into structured fields, and that call may be served outside India. Text is sent — not the original file.

Who we share it with

No one, other than the infrastructure providers the product runs on: Amazon Web Services for hosting and storage, Google for the extraction model, and Vercel for serving the web application. We do not sell data and we do not use your documents to train models.

[to be drafted — the full sub-processor list with each one's role and location, once the stack is settled]

How long we keep it

Documents and extracted data stay until you delete them or ask us to close your account. The step-by-step record of what happened to a document is kept alongside it and goes when it goes.

[to be drafted — specific retention periods for backups, logs, and closed accounts]

Your rights over it

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to hello@prathm.ai and we will action it.

One honest limit: your colleagues’ documents in a shared account are not yours alone to delete, and deleting your account does not delete the company data other people are still working on.

Consent records

When you accept these documents we record which version you accepted, when, and the address and browser you accepted from. We keep that record so we can show what was agreed — including after the wording changes.

Cookies

One cookie, for your session. It holds a random identifier and nothing else — no claims, no personal data — and deleting it signs you out. There is no advertising or third-party tracking on this application.

Security

Traffic is encrypted in transit. Passwords are hashed. Sessions are server-side rows that can be revoked, so “sign this person out now” is a question with an answer. Tenant separation is enforced by the database rather than by application code remembering a filter.

No system is perfectly secure. If you find a problem, write to hello@prathm.ai and we will take it seriously.

Who to contact

[to be drafted — the registered legal entity, its address, and a named data protection contact]

Questions about this page: hello@prathm.ai · Terms · Privacy