Privacy Policy

Last updated: July 1, 2026

Data Collection

We collect the following categories of personal data when you use Probara:

  • Account data: email address and display name, collected when you register via Clerk.
  • API credentials: hashed API keys. We never store key plaintext after issuance.
  • Billing data: payment method details (card number, expiry) collected and stored by Stripe on our behalf. We receive only non-sensitive billing metadata (last 4 digits, billing country).
  • Usage logs: API request metadata including ingredient name, outcome, dose, response grade, timestamp, and anonymised IP address. Query content is logged for 90 days for abuse prevention and is not used to train AI models.
  • Technical data: HTTP method, status code, latency, and user-agent string for each API call.

We do not collect health information about end users of your products, and we do not receive data about the consumers who purchase products you label using our evidence.

How We Use Your Data

  • Service delivery: authenticating your API key, executing evidence queries, returning signed attestation cards.
  • Billing: invoicing through Stripe, enforcing plan limits, processing upgrades and cancellations.
  • Transactional email: sending key issuance confirmations, payment receipts, and critical service notices via Resend.
  • Abuse prevention: rate-limit enforcement and anomalous-usage detection.
  • Product improvement: aggregate, anonymised query analytics to understand which ingredient-outcome pairs are queried most. No personal data is shared or sold for advertising purposes.

If you are an EU or UK resident, the lawful bases for processing are: contract performance (service delivery, billing), legitimate interests (abuse prevention, product improvement), and legal obligation (financial record retention).

Data Sharing

We share data only with the third-party processors necessary to operate Probara. A full list is available at our subprocessors page. We do not sell your data. We do not share your data with advertising networks or data brokers. We may disclose data to law enforcement when required by a valid legal process.

Data Retention

  • Account data: retained for the duration of your subscription, plus 90 days after cancellation or deletion to allow dispute resolution.
  • API usage logs: retained for 90 days, then permanently deleted.
  • Billing records: retained for 7 years per US financial regulations; managed by Stripe under their own retention policy.
  • Issued attestation cards: attestation records (ingredient, outcome, grade, HMAC) retained for 12 months to support auditability; query payloads are not retained after the response is returned.

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. EU and UK residents also have the right to object to processing and to lodge a complaint with a supervisory authority (for EU: your national DPA; for UK: the ICO). California residents have rights under the CCPA, including the right to know what data is collected and to request deletion.

To exercise any of these rights, email hello@probara.dev with the subject line "Privacy Request". We will respond within 30 days.

Cookies and Tracking

The Probara API does not use cookies. The marketing site at probara.dev may use first-party cookies strictly necessary for session state. We do not use third-party advertising cookies or tracking pixels.

Contact Us

For privacy-related inquiries, contact Probara at hello@probara.dev.

Probara