PurplePrint
Privacy Policy
Effective · July 6, 2026
1. Principle — content-free
PurplePrintAI (the "Company") operates on a content-free principle. What you build and what you type — your content — is, as a rule, not stored on the Company's servers. Only the minimum information needed for account identification and service operation is processed.
2. Personal Data We Collect
- Account data: the email address, provider account identifier, and display nickname (the local part of the email) received from your login provider (Google or GitHub)
- Usage records (metadata): progress and usage metadata such as current Phase, command usage counts, trial/subscription status, and server review request counts
- Payment-related: email, account identifier, checkout/subscription status, and other payment-linking metadata at payment time (card numbers and other payment method details are handled by the payment processor)
3. How We Collect
Personal data is collected when you log in with a Google or GitHub account, and as metadata generated automatically while you use the Service.
4. Purpose of Use
- Account identification and login persistence
- Managing the free trial and paid subscription, and usage management
- Service delivery, session resumption (restoring your prior progress point), and quality improvement
- Preventing abuse, maintaining security, responding to incidents, and complying with legal obligations
5. Information Not Sent to Our Servers
The following stays only in your local environment and is not transmitted to or stored on the Company's servers.
- Ideas, conversation content, and design artifacts (context documents, design documents, UX designs, etc.)
- The execution content of research/verification engines (Hyper-Research, Scenario, etc.) — these run in your AI client and do not pass through our servers.
- Growth measurement (my-growth) — aggregated from behavioral signals only, without conversation content.
6. Exceptional Transmission by Server Review Engines
When you explicitly run the paid server-based review engines Hyper-Review or DAR (development-design review), the design document and review input you submit for review are transmitted to our AI sub-processor (Google Gemini API) to perform the review. This transmission occurs only when you invoke those engines. Code Audit runs locally on your machine and is not transmitted to our servers.
7. Sub-processors and Third Parties
The Company entrusts processing to, or uses the infrastructure of, the following providers to deliver the Service.
- Cloudflare, Inc. — server hosting and storage of account/state data (D1/KV)
- Polar Software Inc. — payment processing (Merchant of Record)
- Google LLC — login (OAuth) and AI processing for server review engines (Gemini API)
- GitHub, Inc. — login (OAuth)
8. Cross-border Transfer
The servers of the above sub-processors may be located outside your country, and your personal data may be transferred and processed abroad when you use the Service. Transferred items are limited to what is necessary to provide the Service.
| Recipient | Country | Items | Purpose | Retention |
|---|---|---|---|---|
| Cloudflare, Inc. | United States and others | Account data, progress and usage metadata | Hosting, D1/KV storage, security | For the account period or legally required retention period |
| Polar Software Inc. | United States and others | Payment email, account identifier, checkout/subscription status | Payment processing, receipts, tax handling | Under Polar policies and legally required retention periods |
| Google LLC | United States and others | OAuth account data; design documents and review input when server review engines are invoked | Login and Gemini API-based review | Under Google policies and legally required retention periods |
| GitHub, Inc. | United States and others | OAuth account data | Login | Under GitHub policies and legally required retention periods |
9. Retention Period
Personal data is retained while the account is active and destroyed without delay upon a deletion/withdrawal request. However, data needed for payment, settlement, dispute handling, security logs, or legally required retention may be separately retained for the applicable period.
10. Your Rights
You may request access to, correction of, deletion of, and suspension of processing of your personal data, as well as account withdrawal. Requests are received via the contact below.
11. Security Measures
The Company protects personal data through login-token expiry management, access control, HTTPS transmission, secret management, and the minimum-collection principle.
12. Contact
- Operated by: PurplePrintAI
- Contact: purpleprintai@gmail.com
13. Notice of Changes
If this policy changes, we will provide prior notice of the effective date and reason within the Service.
For terms of use, see the Terms of Service.