Prospalytics Privacy Policy
Effective date: September 1, 2026
Version: 09-01-2026
Provider: DataHarbor Labs, doing business as Prospalytics
Contact: prospalyticshelp@gmail.com
Mailing address: 6254 Wilmington Pike #1134, Centerville, OH 45459, United States
This Privacy Policy explains how DataHarbor Labs and Prospalytics ("Prospalytics," "we," "us," or "our") collect, use, disclose, retain, and protect information when you visit our website, create an account, use our market-intelligence platform, request support, receive communications from us, or otherwise interact with us.
Prospalytics is a business-to-business market-intelligence and social-listening service. The Service helps business customers analyze publicly available online conversations, including public Reddit communities and similar public sources, to identify themes, pain points, demand signals, product opportunities, competitive context, and related business insights.
This Policy is written for a U.S.-focused B2B service. It does not replace any signed order form, statement of work, master services agreement, data processing addendum, or other written agreement between us and a customer. If a signed agreement conflicts with this Policy about our processing of customer data, the signed agreement controls for that customer to the extent of the conflict.
1. Scope and privacy roles
This Policy applies to:
- the public Prospalytics website, landing pages, demo pages, support pages, and related web pages;
- the Prospalytics account area, dashboards, reports, exports, scheduled monitoring, team-access features, and support workflows;
- communications with us, including sales, support, legal, and operational messages; and
- information processed to provide, secure, maintain, improve, and enforce the Service.
We process information in several contexts:
- Account and website information. Information about website visitors, prospects, account owners, administrators, authorized users, delegates, support contacts, and similar business contacts.
- Customer content and instructions. Research prompts, selected communities, search terms, role or sector labels, report settings, schedules, monitoring preferences, support messages, uploaded or submitted materials, generated reports, exports, artifacts, and related workspace information.
- Public-source content. Public posts, comments, public usernames or handles, public profile or community metadata, timestamps, URLs, engagement metadata, excerpts, and similar information made available by public sources or third-party source access methods.
- Operational and security information. Authentication events, session state, usage metadata, logs, diagnostics, error reports, service activity, audit records, storage metadata, and other information used to operate and secure the Service.
When we process personal information on behalf of a business customer under a written agreement, we may act as a service provider or processor for that customer. For other activities, including account administration, website operation, billing, security, legal compliance, customer support, and decisions we make about public-source analytics and service improvement, we may act as an independent business or controller.
The Service is intended for business and professional use by users who are at least 18 years old and located in the United States. It is not intended for personal, family, household, children’s, employment-screening, credit, insurance, housing, healthcare, law-enforcement, or other regulated eligibility decisions about individuals.
2. Information we collect
The information we collect depends on how you interact with Prospalytics.
2.1 Information you provide directly
We may collect:
- Identifiers and business contact information, such as first name, last name, email address, account ID, company or organization name, role, and similar information.
- Account information, such as authentication status, password-related metadata handled through our authentication provider, user roles, workspace membership, team invitations, permissions, display name, plan code, settings, preferences, and delegated-access records.
- Customer instructions and research inputs, such as prompts, business questions, selected subreddits or communities, relevant sectors, role labels, objectives, filters, tracking settings, schedules, frequency choices, and analysis defaults.
- Customer content and outputs, such as generated reports, report HTML, CSV/JSON/PPTX/HTML artifacts, folder and favorite preferences, report history, dashboard slugs, job metadata, and support context.
- Support and communications, such as support-request subject lines, messages, replies, email communications, attachments if enabled, and records of our responses.
- Billing and commercial information, such as plan selections, subscription status, credit blocks, credit usage, invoices, payment status, and transaction records. If a third-party payment processor is used, we do not intend to store full payment-card numbers on our systems.
- Legal and compliance information, such as legal-acceptance records, consent records, security reports, privacy requests, authorized-agent materials, and dispute or enforcement correspondence.
Please do not submit Social Security numbers, government ID numbers, payment-card numbers, protected health information, children’s data, biometric data, precise geolocation, private credentials, private messages, non-public platform data, or other sensitive regulated information unless we have expressly agreed in writing to process that information for a specific purpose.
2.2 Public-source content
The Service may process publicly available online content and metadata to generate market-intelligence outputs. Depending on the source and the customer’s query, this may include:
- public post or comment text, titles, excerpts, URLs, and permalink references;
- public usernames, handles, community names, subreddit names, flair, public profile or community metadata, and public engagement metadata;
- timestamps, public scores or counts, public tags, public links, and other public context;
- topics, summaries, classifications, sentiment, relevance scores, clusters, or inferences generated from public content; and
- information that a public author chose to include in public content, which may incidentally include sensitive topics.
We do not intentionally collect non-public messages, non-public Reddit account information, private browsing history, private votes, private saved content, private email addresses, or source-platform credentials from public-source platforms.
Public-source content is processed to provide business-level market intelligence, not to identify, contact, track, target, profile, or make decisions about individual public authors. We restrict customers from using Prospalytics outputs for surveillance, harassment, ad targeting, background checks, eligibility decisions, people search, lead lists, identity resolution, contact enrichment, doxxing, or similar individual-level uses.
2.3 Information collected automatically
When you use the website or Service, we and our service providers may automatically collect:
- IP address, browser type, device type, operating system, referring URLs, page views, interactions, approximate location inferred from IP address, and similar technical information;
- authentication/session events, token metadata handled by our authentication provider, login status, account state, and security events;
- service activity, routes, request metadata, job status, report status, artifact-access events, signed URL requests, and service usage records;
- error logs, diagnostic context, route information, browser/device metadata, workspace identifiers, actor identifiers, and timestamps; and
- cookie, local storage, session storage, and similar browser-storage information described in the Cookie Notice section below.
2.4 Information from service providers and third parties
We may receive information from:
- authentication, hosting, database, storage, email, payment, AI/inference, logging, and security providers;
- public websites, public platforms, data-access tools, or publicly available sources used to provide the Service;
- your organization, administrators, authorized users, delegates, or team members; and
- professional advisors, business partners, or other parties involved in legal, security, commercial, or compliance matters.
3. How we use information
We use information to:
- provide, operate, authenticate, secure, troubleshoot, and maintain the website and Service;
- create and manage accounts, workspaces, permissions, team invitations, delegated access, settings, and support workflows;
- process customer instructions, selected communities, prompts, schedules, and monitoring configurations;
- generate, store, display, export, and deliver reports, dashboards, artifacts, summaries, charts, structured files, and related market-intelligence outputs;
- run one-time, emergency, preview, discovery, global, community-specific search, and scheduled analysis workflows;
- administer plans, credits, usage limits, subscription status, invoices, payments, refunds, taxes, and account administration;
- respond to support requests, legal requests, privacy requests, security inquiries, and customer communications;
- detect, investigate, prevent, and respond to fraud, abuse, service misuse, platform misuse, security incidents, and technical failures;
- enforce our Terms of Service, Terms of Use, contracts, policies, source-platform restrictions, and legal rights;
- improve quality, reliability, usability, performance, and security of the Service, including by using aggregated or de-identified usage information where appropriate;
- comply with legal obligations, regulatory requirements, subpoenas, court orders, law-enforcement requests, and audit obligations; and
- support business transfers, financing, diligence, restructuring, merger, acquisition, or sale of assets, subject to appropriate confidentiality and legal safeguards.
We do not use public-source content or report outputs to make employment, credit, insurance, housing, healthcare, criminal justice, immigration, education, lending, or similar regulated eligibility decisions about individuals, and customers are not permitted to use the Service for those purposes.
4. AI, automated analysis, and report outputs
Prospalytics may use automated processing, machine learning, large language models, AI-assisted summarization, classification, clustering, scoring, retrieval, filtering, and other analytical methods to generate reports and related outputs.
Inputs to these workflows may include customer instructions, selected communities, business context, job title, market segment, public-source content, metadata, report configuration, operational context, and service logs needed to provide and secure the Service. Outputs may include summaries, excerpts, charts, rankings, classifications, recommended actions, Decision Cards, topic clusters, sentiment indicators, relevance scores, and other business insights.
AI-assisted outputs may be incomplete, inaccurate, outdated, biased, non-representative, or unsuitable for a particular business decision. You should review outputs with human judgment and appropriate qualified professionals before relying on them. Prospalytics does not provide legal, financial, tax, investment, medical, employment, compliance, safety, or other regulated professional advice.
We use AI and infrastructure providers as service providers or processors to deliver the Service. We do not intentionally enable third-party foundation-model training on Customer Content or non-public report outputs unless the customer has authorized that use, the applicable service setting or agreement permits it, or we have disclosed that use in an applicable written agreement or policy. Service providers may process information according to their applicable service terms, retention settings, security controls, and our agreements with them.
We do not use public-source content or report outputs to make employment, credit, insurance, housing, healthcare, criminal-justice, immigration, education, lending, or similar regulated eligibility decisions about individuals, and customers are not permitted to use the Service for those purposes.
5. How we disclose information
We may disclose information to the following categories of recipients:
- Service providers and subprocessors. Vendors that help us provide hosting, serverless functions, authentication, database, storage, email, payment processing, AI/inference, logging, support, analytics if enabled, security, and other operational services.
- Your organization and authorized users. Account owners, administrators, delegates, authorized users, and team members may access workspace information, reports, settings, support context, usage information, and other account data according to their permissions.
- Public-source platforms and data sources. We may send access requests, tokens, user agents, query parameters, or other technical information to public-source platforms as necessary to retrieve or verify public content, comply with platform requirements, or maintain access.
- Professional advisors. Lawyers, auditors, accountants, insurers, banks, consultants, and other advisors where reasonably necessary for business, legal, security, or compliance purposes.
- Authorities and legal parties. Courts, regulators, law enforcement, government authorities, litigants, or other parties when we believe disclosure is required by law or reasonably necessary to protect rights, safety, security, property, users, the public, or the integrity of the Service.
- Business transaction parties. Parties involved in an actual or potential merger, financing, acquisition, reorganization, bankruptcy, diligence review, sale of assets, or similar transaction.
- With your direction or consent. Other recipients when you direct us to disclose information or consent to the disclosure.
We do not sell account personal information for money. We do not currently use third-party advertising cookies, retargeting pixels, or cross-context behavioral advertising technologies in the reviewed implementation. The Service may provide business customers with analytical outputs derived from public-source content, and some outputs may include limited public excerpts, public usernames, URLs, or metadata where relevant to a customer’s research. We contractually restrict customers from using those outputs for individual-level targeting, identification, sale, sharing, lead generation, people search, background checks, surveillance, or regulated decisions.
6. Cookie Notice and similar technologies
This section is the Prospalytics Cookie Notice. It explains how we use cookies, local storage, session storage, and similar technologies on the website and Service.
6.1 What cookies and similar technologies are
Cookies are small text files placed on a browser or device. Local storage and session storage are browser-based storage mechanisms that can store application data. Pixels, tags, SDKs, log files, and similar tools may collect usage or device information. In this Policy, we use "cookies" broadly to refer to these technologies.
6.2 Current cookie and browser-storage posture
Based on the current Prospalytics implementation, we use cookies and browser storage primarily for essential, security, authentication, preference, and workflow purposes. We do not currently use third-party advertising cookies, retargeting pixels, or cross-context behavioral advertising technologies.
The Service relies on authentication/session storage to keep users logged in; browser storage for saved preferences such as favorites, folders, guided-tour state, analysis defaults, and active dashboard view; and session storage for temporary workflow state such as an active discovery job. Server logs and diagnostic events may also collect technical information, but those are not always stored in the browser.
6.3 Categories of cookies and storage we use
Strictly necessary and authentication
- Purpose: Log you in, maintain your session, route authenticated requests, prevent unauthorized access, support password resets, and enforce account permissions.
- Examples: Supabase authentication/session storage, access/refresh token state, account session state. Exact names may vary by Supabase project and browser.
- Required?: Yes. The Service cannot function properly without these technologies.
Security and diagnostics
- Purpose: Detect errors, debug issues, maintain reliability, investigate abuse, and protect the Service.
- Examples: Request IDs, route logs, error logs, browser/device metadata, workspace IDs, actor IDs, account/user IDs in diagnostic context.
- Required?: Yes for security and reliability.
Preferences and product state
- Purpose: Remember user choices and interface preferences.
- Examples: prospalytics:favorites:v1, prospalytics:folders:v1, prospalytics:guidedTourSeen:v2, prospalytics:analysis-defaults:v1, and similar settings saved in your account or browser.
- Required?: Usually optional, but disabling may reduce functionality.
Temporary workflow storage
- Purpose: Preserve active state during a browser session.
- Examples: prospalytics:activeView:v1, prospalytics:discover-job:<workspace>:<actor>, active analysis/discovery workflow state, temporary job IDs, and in-progress page state.
- Required?: Often necessary for the relevant workflow.
Payment or checkout technologies
- Purpose: Process payments, prevent fraud, manage invoices, and maintain checkout state if a payment provider is enabled.
- Examples: Payment processor cookies or checkout session identifiers.
- Required?: Required if you purchase through that checkout flow.
Analytics
- Purpose: We do not currently use third-party behavioral analytics cookies in the reviewed implementation. If we add analytics, we will update this Policy and provide required choices.
- Examples: Website or product analytics tools, if later enabled.
- Required?: Depends on implementation and law.
Advertising or targeted advertising
- Purpose: We do not currently use these technologies.
- Examples: Retargeting pixels, cross-site ad cookies, ad-network identifiers, or cross-context behavioral advertising identifiers.
- Required?: No; not currently used.
6.4 Specific examples
Exact names, durations, and storage behavior can vary by browser, device, deployment, and vendor configuration. Examples include:
- Supabase authentication/session storage. Used to persist login state and access tokens. Duration depends on session settings, token expiration, sign-out, and browser storage controls.
- prospalytics:favorites:v1. Used to store user-selected favorite reports in local storage. It generally remains until you clear it, remove favorites, or the application changes the storage format.
- prospalytics:folders:v1. Used to store report-folder preferences in local storage. It generally remains until you clear it or the application changes the storage format.
- prospalytics:guidedTourSeen:v2. Used to remember whether the guided tour has already been shown. It generally remains until you clear browser storage.
- prospalytics:analysis-defaults:v1. Used when analysis defaults are saved locally. It generally remains until cleared or overwritten.
- prospalytics:activeView:v1. Used in session storage to remember the active app view in the current session, and may also be cleared from local storage for compatibility.
- Discover/session workflow storage. Used to remember temporary state in the current browser tab or session, including active discovery job state. It is generally cleared when the tab or session ends.
- Cookie or consent preference storage, if implemented. If we add a cookie preference center, we may store your preference so we do not repeatedly ask for it.
6.5 Managing cookies and browser storage
You can control cookies and browser storage through your browser settings. Most browsers allow you to block cookies, delete cookies, clear local storage, clear session storage, or receive alerts before cookies are set. Blocking or deleting strictly necessary technologies may prevent login, dashboards, saved preferences, report access, signed artifact access, or other core features from working.
Signing out of the Service should clear or invalidate certain authentication state, but you may need to clear browser storage manually to remove all local preferences or cached state from your device.
6.6 Global Privacy Control and Do Not Track
Some browsers or extensions send privacy preference signals, including Global Privacy Control or similar universal opt-out signals. Because we do not currently sell personal information, share personal information for cross-context behavioral advertising, or use targeted advertising cookies in the reviewed implementation, these signals do not currently change our website behavior. If we add processing that is subject to state-law opt-out rights, we will update this Policy and honor legally required opt-out signals where required.
Some browsers send "Do Not Track" signals. There is no uniform industry standard for responding to those signals, and we do not currently respond to them unless required by law.
7. Retention
We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain accounts, preserve report history, support recurring monitoring, administer subscriptions and credits, comply with legal obligations, enforce agreements, resolve disputes, maintain security, prevent fraud and abuse, and support legitimate business records.
Retention periods vary depending on the type of information and the context. For example:
- account, subscription, invoice, credit, legal-acceptance, and business records may be retained for the account term and any legally required recordkeeping period;
- reports, artifacts, prompts, job metadata, schedules, and dashboard history may be retained while the account is active or as needed to provide report history, monitoring, exports, support, and deletion/recovery workflows;
- public-source content or excerpts may be retained as part of customer reports unless deleted, replaced, removed, or no longer needed, subject to source-platform restrictions and applicable law;
- logs, diagnostics, security records, and audit records may be retained as needed for reliability, security, fraud prevention, legal compliance, and enforcement; and
- backup copies may persist for a limited period before being overwritten or deleted according to backup practices.
When we no longer need information, we may delete, aggregate, de-identify, or otherwise handle it according to applicable law and our operational requirements.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, misuse, loss, alteration, and disclosure. These safeguards may include encrypted transport, authentication, role-based access controls, Supabase row-level security, signed URLs for artifacts, limited service-role access, audit logs, security headers, monitoring, and vendor security controls.
No transmission or storage system is completely secure. You are responsible for keeping your login credentials confidential, using strong passwords, maintaining device security, promptly removing unauthorized users from your workspace, and notifying us of suspected compromise.
9. Your choices and privacy rights
Depending on your relationship with us, your location, and whether a relevant law applies to our business, you may have rights to request:
- confirmation of whether we process your personal information;
- access to personal information we maintain about you;
- correction of inaccurate personal information;
- deletion of personal information;
- a portable copy of certain personal information;
- opt-out of certain sales, sharing, targeted advertising, or covered profiling;
- limitation of certain uses or disclosures of sensitive personal information, where applicable;
- appeal of a denied privacy request, where applicable; and
- non-discrimination for exercising privacy rights.
To submit a request, email prospalyticshelp@gmail.com or use the Support page if available. Please include enough information for us to understand, verify, and respond to your request. We may ask for additional information to verify your identity, confirm your authority, identify the relevant account or workspace, locate public-source content, or process an authorized-agent request.
If your request relates to personal information we process on behalf of one of our business customers, we may refer the request to that customer or require the customer’s instruction before responding, unless applicable law requires otherwise.
If your request relates to public-source content, please provide the relevant URL, username/handle, subreddit/community, approximate date, report reference if known, and the action you are requesting. We will evaluate the request under applicable law, our customer agreements, source-platform requirements, and our internal safety and privacy standards.
10. U.S. state privacy notice
This section provides additional information for residents of states with comprehensive privacy laws, including California and other states where applicable. Rights and obligations vary by state and may depend on whether a particular law applies to our business.
10.1 Categories collected, sources, purposes, and disclosures
The table below describes the categories of personal information we collect or may collect, the sources of that information, our business or commercial purposes, and the categories of recipients to whom we disclose it. Where applicable law requires a look-back disclosure, this table also reflects our practices during the preceding 12 months to the extent applicable.
Identifiers
- Examples: Name, email, account ID, user ID, public username/handle, IP address, device identifiers, authentication identifiers.
- Sources: You, your organization, authorized users, service providers, public sources, browser/device.
- Purposes: Account administration, authentication, service delivery, public-source analysis, support, security, legal compliance.
- Disclosed to: Service providers, authorized users, public-source platforms where needed, advisors, legal recipients.
Customer records / business contact information
- Examples: Business contact details, account details, support information, invoice or commercial records.
- Sources: You, your organization, service providers.
- Purposes: Account management, billing, support, contracts, compliance, communications.
- Disclosed to: Service providers, payment processors if enabled, advisors, legal recipients, authorized users.
Commercial information
- Examples: Plans, subscription status, credit purchases or grants, credit usage, invoice/payment status.
- Sources: You, administrators, payment processors, our systems.
- Purposes: Billing, subscriptions, credits, fraud prevention, customer support, analytics, legal compliance.
- Disclosed to: Service providers, payment processors if enabled, advisors, legal recipients, authorized users.
Internet or electronic network activity
- Examples: Login events, routes, page views, app interactions, service usage, logs, diagnostics, browser/device data.
- Sources: Browser/device, service providers, our systems.
- Purposes: Security, reliability, troubleshooting, analytics if enabled, abuse prevention, service improvement.
- Disclosed to: Service providers, advisors, legal recipients, authorized users where relevant.
Geolocation data
- Examples: Approximate location inferred from IP address.
- Sources: Browser/device, service providers.
- Purposes: Security, fraud prevention, localization, operational analytics.
- Disclosed to: Service providers, advisors, legal recipients.
Professional or employment-related information
- Examples: Business role, company name, professional contact details, customer-requested role or sector labels.
- Sources: You, your organization, public sources if publicly posted.
- Purposes: Account administration, customer context, support, service delivery, market analysis.
- Disclosed to: Service providers, authorized users, advisors, legal recipients.
Audio/visual/electronic information
- Examples: Support attachments or uploaded materials if enabled; screenshots or files you provide.
- Sources: You, authorized users.
- Purposes: Support, troubleshooting, service delivery, legal compliance.
- Disclosed to: Service providers, advisors, legal recipients, authorized users.
Inferences and analytics
- Examples: Topics, summaries, classifications, sentiment, relevance scores, preference settings, report insights.
- Sources: Customer instructions, public-source content, service usage.
- Purposes: Generate market-intelligence outputs, improve quality, support decisions at a business level.
- Disclosed to: Service providers, authorized users, advisors, legal recipients.
Sensitive personal information
- Examples: Not intentionally requested. May appear incidentally in customer submissions or public-source content if a person chose to publish it.
- Sources: You, authorized users, public sources.
- Purposes: Only as necessary to provide requested analysis, secure the Service, comply with law, or respond to requests; not for inferring characteristics about an individual for regulated decisions.
- Disclosed to: Service providers, authorized users where included in outputs, advisors, legal recipients.
10.2 Sale, sharing, targeted advertising, and profiling
We do not currently sell account personal information for money. We do not currently share account personal information for cross-context behavioral advertising. We do not currently use third-party advertising cookies or retargeting pixels in the reviewed implementation.
The Service is a market-intelligence product that may provide business customers with analytical outputs derived from public-source content. Some outputs may include limited public excerpts, public usernames, URLs, or metadata when relevant to a customer’s research. We restrict customers from using those outputs to identify, contact, target, track, or make decisions about individuals. We also prohibit using the Service as a data broker, people-search, contact-enrichment, lead-list, background-check, ad-targeting, or surveillance tool.
If applicable law treats any processing we perform as a sale, sharing, targeted advertising, or profiling activity subject to an opt-out right, you may submit an opt-out or privacy request at prospalyticshelp@gmail.com. If we later add targeted advertising or cross-context advertising technologies, we will update this Policy, provide required notices and choices, and honor legally required opt-out signals where required.
10.3 Authorized agents and appeals
You may designate an authorized agent to submit a privacy request where applicable law allows it. We may require proof of authorization and may also require you to verify your identity directly.
If we deny a request and applicable law gives you a right to appeal, you may appeal by replying to our denial email with the word "Appeal" and a short explanation of why you disagree. We will review and respond as required by applicable law.
11. Public-source authors and removal requests
If your publicly available content appears in a Prospalytics report or analysis, you may contact us to request review, removal, deletion, or limitation of that content in our Service. Please include enough detail for us to locate the content. We will evaluate the request under applicable law, source-platform rules, our customer contracts, and our safety and privacy standards.
Where we receive a valid removal request, platform removal notice, deletion signal, or legal request, we may remove, suppress, restrict, replace, de-identify, or stop displaying the relevant content in future outputs where reasonably feasible and legally required. Because public-source content may be re-posted, archived, cached, quoted, or made available by third parties outside our control, removal from Prospalytics does not guarantee removal from the original source platform or the internet generally.
12. International users
The Service is intended for users located in the United States. If you access the Service from outside the United States, you understand that information may be processed in the United States and other locations where we or our service providers operate. Do not use the Service from a jurisdiction where doing so would require legal or operational obligations we have not expressly agreed to meet in writing.
13. Changes to this Policy
We may update this Policy from time to time. The effective date above indicates the current version. If we make material changes, we may provide notice through the website, account area, email, or other reasonable means. Your continued use of the Service after the updated Policy becomes effective is subject to the updated Policy.
14. Contact
Questions, privacy requests, cookie questions, public-source removal requests, and legal notices about this Policy may be sent to:
DataHarbor Labs / Prospalytics
Email: prospalyticshelp@gmail.com
Mailing address: 6254 Wilmington Pike #1134, Centerville, OH 45459, United States