Privacy Policy
Ruby Chen, Taipei, Taiwan, operates ProofAscent and is the contact responsible for this policy. Effective October 4, 2026. Contact: proofascentservice@gmail.com.
1. Information we collect
Account identifiers include your email, username, nickname, password hash, account ID, and sign-in sessions. We store passwords using salted one-way hashing, not plaintext. Your profile may contain your goal, current stage, country/region, timezone, available time, preferences, and an optional avatar.
We store proofs, uploaded files, calendar workouts, tasks, coach conversations, analysis results, certificates, support tickets, and files you choose to attach. Technical data includes IP addresses, timestamps, request and usage counters, security events, and basic activity/presence needed for security and the admin dashboard. We retain subscription status and billing references, not full payment-card numbers.
We ask for an age eligibility category, not your full date of birth. Do not upload government identifiers, health records, credentials, or other sensitive material unless strictly necessary and lawful.
2. Why we use information
We use information to authenticate you, personalize requested coaching, store your work, manage plan limits and billing, provide support, prevent abuse, and comply with legal obligations. We do not use your private career materials to build advertising profiles. Where consent is required, you may withdraw it for optional features without losing unrelated service features.
3. No sale, targeted-advertising sharing, or AI training
We do not sell personal information or share it for cross-context behavioral advertising. We do not use your data to train or fine-tune AI or machine-learning models. We use AI services to produce the answers and analyses you request, not to train on your uploads.
Atlas requests may include your message, relevant profile, proof context, and attached material needed for that request. Our AI service provider currently includes OpenAI. Service providers process information under their applicable service and data-protection terms; operational or abuse-prevention retention may still occur. No-training does not mean no processing or zero retention. We do not enable model-training use of your data.
4. Service providers and disclosures
Google Cloud provides hosting, database, private file storage, and secure secret management. Cloudflare provides domain routing and security and may process connection information. Google provides optional sign-in and Calendar authorization. Lemon Squeezy is the intended payment/merchant-of-record provider when billing is configured; its checkout and privacy terms apply to payment information it receives.
We share only what is needed for a requested service, security, legal compliance, or a lawful business transfer with appropriate safeguards. Authorized administrators may access account and support information when necessary to operate the service. We do not make uploads public merely because they are saved.
5. Google sign-in and Calendar
Google sign-in uses your verified Google identity and basic account information to authenticate or explicitly link your account. We do not silently link an existing password account solely because an email matches.
Optional Calendar access uses the calendar.app.created permission. It creates and manages only a dedicated ProofAscent-created calendar and its events. It does not request permission to read all your private calendars. Google authorization tokens are encrypted on the backend. Sync sends workout titles, details, and scheduled times to that dedicated calendar. Sync is one-way from ProofAscent, initiated by you, and is not a backup of Google Calendar.
Disconnecting removes our saved calendar access and local synchronization links, not the dedicated calendar or events already in your Google account. You may additionally revoke access in Google’s account permissions and delete the calendar there. Information received through Google APIs is used only for the requested user-facing features and follows applicable Google API Services User Data Policy, including Limited Use requirements.
6. Cookies and browser preferences
Essential HttpOnly cookies maintain your sign-in, remembered accounts, and one-time OAuth verification. Account selection does not expose access tokens to JavaScript. Optional local UI preferences may also be used; signed-in preferences are persisted on the server. We do not currently use advertising cookies. Global Privacy Control (GPC) signals are respected as an opt-out of sale/sharing; because we do neither, no advertising data flow is enabled regardless of the signal.
7. Storage, retention, and international transfers
Production application data is hosted in Google Cloud’s us-west1 region in Oregon, USA. Providers may process operational/security information elsewhere. The operator is based in Taiwan. International processing is subject to applicable safeguards and mandatory data-protection requirements.
We keep your account and content while necessary to provide your account and requested features. Request deletion to end normal account retention, subject to lawful billing, fraud-prevention, dispute, and backup exceptions. Backups expire under the configured retention schedule rather than immediately when an account is deleted. Expired login/OAuth state and temporary uploads are periodically cleaned up. We do not promise that all legal/security records can be erased immediately.
8. Your privacy rights
Depending on your location and applicable law, you may request access, correction, deletion, portability, information about disclosure, an appeal, and restriction or objection to certain processing. You may exercise rights without unlawful discrimination. Authorized agents may make requests with appropriate authority. We verify identity proportionately; never email us your password.
Use Account Center to edit information and request a data export, or email proofascentservice@gmail.com for any rights request, including if an automated feature is unavailable. Security throttles on self-service ZIP generation do not restrict statutory access rights; contact us if a legal request needs different timing. We will respond within the deadline required by applicable law, generally 45 days for applicable U.S. state requests, with legally permitted extensions and notice.
9. Do Not Sell or Share My Personal Information
We do not sell personal information or share it for cross-context behavioral advertising, so you are opted out by default. You can use the footer’s “Do Not Sell or Share My Personal Information” link or email proofascentservice@gmail.com to record or inquire about a preference. No account or fee is required to exercise this opt-out. We honor recognized browser opt-out signals where required. If our practices change, we will provide notice and required choices before enabling such processing.
10. Limit the Use of Sensitive Personal Information
We do not intentionally solicit sensitive personal information or use it for profiling beyond requested service, authentication, security, and legally permitted purposes. Optional uploads or messages may contain sensitive information you choose to provide. Avoid including it when unnecessary.
Use the footer’s “Limit the Use of Sensitive Personal Information” link or contact proofascentservice@gmail.com to request limitation or deletion, subject to permitted service/security/legal exceptions. Such requests do not require creating an account.
11. Children and security
ProofAscent is a general-audience career service, not directed to children under 13. Children under 13 are prohibited from using it. We do not knowingly collect their personal information. If we learn that an account belongs to a child under 13, we will restrict access and take appropriate steps to delete the information unless law requires retention. Parents or guardians should contact proofascentservice@gmail.com.
We use private storage, access checks, encrypted connections, backend-only credentials, password hashing, and abuse controls. No system is perfectly secure. Report suspected vulnerabilities privately to our support contact; do not access other users’ data or conduct destructive testing.
12. Updates and complaints
We will publish changes with an updated effective date and provide additional notice where required. Contact Ruby Chen at proofascentservice@gmail.com with questions or complaints. You may also complain to the competent regulator. This policy does not waive your nonwaivable privacy rights.