Privacy policy

Last updated:
29/07/2026
In force since:
pending

Draft pending legal review. This text describes how Proofly works today, but nobody responsible has approved it yet. The sections marked as pending are deliberately left unwritten.

Who processes your data

The data controller is [MARIO: full name], tax ID [MARIO: NIF / tax ID], with an address for notices at [MARIO: postal address], Spain. For anything to do with privacy you can write to soporte@proofly.es.

What data we keep

Proofly keeps the information you add and the minimum needed for your account to work:

  • Your email address, which comes from your Google account when you sign in.
  • The entries you create: title, date it happened, categories, people or teams involved and description.
  • The projects you group those entries into.
  • The screenshots you upload as evidence.
  • Each entry's change history: what was modified and when.
  • The messages you send us from the feedback button, together with the screen you sent them from.
  • Like any web service, the technical access logs (IP address, browser and the date of each request), which we use only for security and diagnostics.

We don't ask for or keep your name, your profile picture or any data about your company. Proofly doesn't know where you work either: that only appears if you write it inside an entry.

What we use them for

Only to provide the service: to keep your professional history, show it to you and let you download it. Your entries are not used for anything else.

Your information is not shared with your company or with third parties, is not sold, and is not used to train artificial intelligence models.

Legal basis

We process your data on three legal bases from article 6 of the GDPR:

  • Performance of a contract (art. 6.1.b): everything needed to provide the service — creating your account with your Google email, storing your history and your screenshots, showing them to you and letting you export and delete them.
  • Consent (art. 6.1.a): analytics cookies. They're only switched on if you accept them, and you can withdraw your decision at any time from the cookie policy, with the same gesture you used to give it.
  • Legitimate interest (art. 6.1.f): the security and sound running of the service — technical error logging (filtered as described below), usage limits against abuse, and the technical access logs.

Who they're shared with

Proofly relies on these providers to work. Each one receives only what it needs:

  • Google, to sign you in. Proofly receives your email address; Google doesn't receive the content of your entries.
  • Supabase, where the database and the screenshots are stored. That's where your history lives.
  • Vercel, which hosts the application and serves the pages. Like any hosting provider, it processes your IP address and technical request logs; it never analyses the content of your entries.
  • Sentry, which receives the application's technical errors when something fails in production, along with an internal identifier for your account that lets us investigate the failure. What gets sent is filtered: no titles, descriptions, people involved, project names, screenshots or your email address.
  • Google Analytics, only if you accept analytics cookies. It never receives the content of your entries.
  • Resend, which sends the email that notifies us when you write to us from the feedback button. That email carries what you wrote and your address, so that we can reply to you. It receives nothing else: not your entries, not your projects, not your screenshots. If you don't use that button, Resend receives nothing of yours.

The database and your screenshots are stored on Supabase servers in the European Union (Frankfurt, Germany), and technical errors are processed on Sentry servers also in the EU. Google (sign-in and, only if you accept them, analytics), Vercel (hosting) and Resend (the feedback notification) may process data in the United States; those transfers are covered by the adequacy decision for the EU-U.S. Data Privacy Framework, under which all three providers are certified, and in the alternative by standard contractual clauses. One clarification about Resend: the email is sent from servers in Ireland, but its logs — including the content of the notification, that is, whatever you wrote — are kept in the United States.

How long they're kept

Your data is kept for as long as your account is open. When you delete your account from Settings, your entries, projects, evidence and change history are deleted.

When you delete your account, your data is removed immediately and permanently from the database and from storage; we keep no additional backups. Technical access and error logs are kept for a maximum of [MARIO: log retention days on the Vercel/Sentry plan in use] days.

Your rights

You can take your whole history with you at any time from the Report screen: it generates a document with your entries, your projects and your screenshots that you save as a PDF from your own browser. The document is put together on your device and never goes through a server of ours.

When you save it, your browser recompresses the images and strips their metadata —including the date and the technical information the original file carried—. It reads just as well; if you need the screenshots exactly as you uploaded them, you can ask us for them by writing to soporte@proofly.es.

You can delete your account and all your data from Settings, without asking anyone. You can also delete just the content and keep the account.

Beyond the above, you have every right the GDPR grants: access, rectification, erasure, objection, restriction of processing and portability. You exercise most of them yourself, straight from the application: editing or deleting your entries, exporting your history, wiping your content or deleting the whole account. For anything else —including a copy of your data in a structured, machine-readable format— write to us at soporte@proofly.es and we'll reply within one month at the latest.

If you believe we haven't handled your data properly, you have the right to lodge a complaint with the Agencia Española de Protección de Datos (the Spanish data protection authority, www.aepd.es).

Minimum age

Proofly is a tool for your working life and requires you to be at least 16. If we find an account that doesn't meet this requirement, we'll delete it along with its data.

Cookies and analytics

Proofly uses the cookies that are strictly necessary to keep you signed in, and analytics cookies only if you accept them. You can read the detail in the cookie policy.

Security

Your history is private: only you can see it. Screenshots are kept in private storage and served through temporary links that expire; there are no permanent public addresses to your files.

No system is infallible. Proofly applies the measures described above, but cannot guarantee absolute security of the information.

We use analytics cookies to understand how Proofly is used and improve the product. We never send Google Analytics the content of your entries, projects, people involved or screenshots. Cookie policy