Privacy Policy
Last updated: October 10, 2026
1. Introduction
Pranan is operated by INSIDEA, Inc., a Delaware corporation headquartered in Dover, Delaware, USA ("INSIDEA", "we", "us", "our"). We operate the pranan.ai website, the Pranan web application at app.pranan.ai, and the Pranan for Chrome browser extension (together, the "service"). INSIDEA, Inc. is the data controller for the personal information described in this policy. This policy describes what information we collect, how we use and share it, how long we keep it, and the choices you have.
Pranan creates draft replies for you to review. Pranan does not send email on your behalf. The only way Pranan posts a message for you is in Slack, and only when you press Send on a Pranan review card or when you have turned on scheduled Slack replies (see section 6).
2. Information We Collect
- Account information: your name, email address, sign-in details, plan and billing status. Payment card details are collected and stored by our payment processor, Stripe. Pranan does not store full card numbers.
- Connected Google account data: when you connect Gmail and Google Calendar, Pranan stores the content and metadata of your email messages (sender, recipients, subject, date, labels, and message body) and your upcoming calendar events. Section 10 describes this in detail.
- Connected Slack data: if you connect Slack, Pranan reads and stores your direct messages and group direct messages so it can draft replies, along with basic profile information about the people in those conversations.
- Connected HubSpot data: if you connect HubSpot, Pranan syncs contacts, companies, deals, their schemas, and recent sales email activity, read-only.
- Information derived from your communications: your voice profile (how you write), relationship context about the people you correspond with (for example their role, company, relationship tier, and communication cadence), memory entries (facts, commitments, and context extracted from your email, described in section 11), and the drafts Pranan creates.
- Content you provide: instructions, edits to drafts, notes, snippets, settings, and support messages.
- Chrome extension data: described in section 7.
- Public web research about your contacts: to add context to a draft, Pranan may look up publicly available information about a contact (for example their company or public professional profile) using their name, company, email domain, or LinkedIn URL.
- Usage and device data: how you use the service, error reports, and technical logs (such as IP address, browser type, and timestamps).
3. How We Use Your Information
- To provide the service: classify and label your inbox, build your voice profile and relationship context, create draft replies, prepare briefings, and track follow-ups.
- To operate, secure, debug, and improve the reliability of the service.
- To process payments and manage your subscription.
- To send you service messages, such as security alerts, billing notices, and briefings you have turned on.
- To respond to support and privacy requests.
No training on your data: we do not use your personal data or your communications to train or fine-tune general AI models. Your voice profile is a per-account profile built from your own sent mail and applied when Pranan drafts for you. It is not combined with other users' data.
4. How AI Processing Works
To classify messages, extract memory entries, and draft replies, Pranan sends the relevant parts of a conversation (and your voice profile and relationship context) to the large language model providers listed in section 6. We use these providers' business APIs, not their consumer products. Under their published API terms, content submitted through the API is not used to train their models. AI output can be wrong, so every email draft is left for you to review and send yourself.
You can tell Pranan never to draft for a specific contact. This stops drafts for that contact. It does not stop that contact's email from being synced, stored, labelled, or included in AI classification and memory extraction. If you need a conversation kept out of Pranan entirely, do not connect the account that holds it, or disconnect it.
5. Data Storage and Security
- Google, Slack, and HubSpot OAuth tokens are encrypted with AES-256-GCM before they are stored.
- The service is accessed over HTTPS, and Pranan calls provider APIs over HTTPS.
- Data is associated with your account and protected by application-level access controls and database row-level security.
- Access to production data is limited to authorized personnel who need it to operate the service.
Pranan is not currently represented as SOC 2 certified. For security reviews, contact us and we will confirm which controls are currently available.
6. Service Providers and Integrations
We do not sell your personal data, and we do not share it for advertising. We share it only with the service providers below, which process it on our behalf to run Pranan, and with the services you choose to connect.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication, and storage for the app | All account, connected-account, and derived data | Primary database hosted in Tokyo, Japan (ap-northeast-1) |
| Vercel | Hosting for the website and app, serverless functions, scheduled jobs | All data processed by the app while in transit; request logs | United States and global edge network |
| OpenAI | AI classification, memory extraction, drafting, and voice dictation transcription | Message content, voice profile, relationship context; audio clips you dictate in the extension | United States |
| Groq | AI classification and drafting | Message content, voice profile, relationship context | United States |
| Google (Gemini API) | Public web research about contacts, with Google Search grounding | Contact name, company, email domain, LinkedIn URL | United States |
| Tavily | Public web search for contact research (fallback) | Contact name, company, email domain | United States |
| Inngest | Background job processing (sync, labelling, drafting, memory extraction) | Job payloads, which can include identifiers and message content | United States |
| Upstash | Rate limiting and short-lived caching | Account identifiers, IP addresses, short-lived tokens | United States |
| Stripe | Payments and subscription billing | Name, email, billing address, payment details | United States |
| Resend | Transactional email (briefings, alerts, account email) and website contact form delivery | Email address, name, email content we send you, contact form messages | United States |
| Sentry | Error monitoring | Error reports, which can include account identifiers and request details | United States |
| PostHog | Product analytics in the app | Account identifiers and in-app usage events | United States |
| Axiom | Operational logging | Structured event logs with account identifiers | United States |
| Slack | Internal notifications to the Pranan team (for example website contact form submissions and service alerts) | Contact form fields, account identifiers | United States |
| Google (Tag Manager and Analytics) | Website analytics on pranan.ai, only after you accept analytics cookies | Pages viewed, device and browser data, approximate location | United States |
Services you connect: Google (Gmail, Google Calendar, and Google sign-in), Slack, and HubSpot receive requests from Pranan under the permissions you grant. If you connect Slack, Pranan can post a message as you when you press Send on a Pranan review card in Slack. If you turn on scheduled Slack replies (off by default), Pranan schedules the draft as a Slack scheduled message that sends after 48 hours unless you edit or cancel it in Slack. You can disconnect any of these services from Pranan settings.
AI apps you connect to Pranan: you can let an AI app such as Claude or ChatGPT read your Pranan context through the Pranan connector. Nothing is shared until you sign in to Pranan and press Allow for that app. The app can then ask Pranan, each time you ask it something, about your contacts, your memory, commitments from your sent mail, your upcoming meetings, and your writing style, and Pranan answers with short excerpts and links to your own Gmail. It cannot send, draft or delete email or change your mailbox. If you also allow it, the app can save notes you ask it to remember to your private Pranan memory. Unless you untick it, the app can also suggest things to remember from your conversation, such as a decision or a preference; each suggestion waits in your Pranan memory inbox and is saved only if you approve it. Suggestions you do not review are deleted after 30 days; the record of a suggestion you approved or rejected is deleted after 90 days (a rejected one is kept that long so it is not suggested again). Passwords, card and account numbers, health details and similar sensitive information are filtered out before they reach the inbox. Pranan never returns personal facts you marked sensitive, a teammate's private memory, or anything about people who asked us to erase their data. We log which tool ran, when, and how many items it returned, never the content. Once an AI app receives an answer, it handles it under its own terms and your settings in that app. You can disconnect an app at any time in Pranan settings, under Connected AI apps.
Meeting recaps: if you use Fathom, Pranan reads the recap emails Fathom sends to your Gmail after a meeting and suggests the key takeaways and next steps from them for your Pranan memory inbox. Pranan does not connect to your Fathom account and does not receive recordings or transcripts; it reads only the recap email, which is part of the mail you already let Pranan sync. Each suggestion is saved to your memory only if you approve it, and the same filtering, deletion periods and erasure requests described above apply. You can turn this off at any time on the Integrations page in Pranan.
Chat history you import: you can import your past ChatGPT or Claude conversations from the export file those apps email you. The file is read in your browser and is not uploaded to Pranan. From the conversations you choose, only the messages you typed are sent to Pranan, and to our AI provider to find decisions, preferences and similar things worth remembering; the AI's replies, files and images are left out. What it finds waits in your memory inbox and is saved only if you approve it, under the same filtering, deletion periods and erasure requests as other suggestions. The conversation text is not stored after it has been analysed.
Google Docs you choose: you can pick Google Docs in Google's own file picker, and Pranan suggests decisions, project details and similar things worth remembering from them. Google asks you to allow access only to the files you pick; Pranan cannot see the rest of your Drive. Each document you pick is exported as text in your browser, and only that text is sent to Pranan and to our AI provider for analysis. The temporary Google access used for this stays in your browser, is not sent to or stored by Pranan, and expires within the hour. What it finds waits in your memory inbox and is saved only if you approve it, under the same filtering, deletion periods and erasure requests as other suggestions. The document text is not stored after it has been analysed.
We may also disclose information if required by law, to protect the rights and safety of our users or the public, or as part of a merger or acquisition, in which case this policy will continue to apply.
7. Pranan for Chrome
The Pranan for Chrome extension works on Gmail (mail.google.com), Slack (app.slack.com), LinkedIn (www.linkedin.com), and app.pranan.ai, and on any other site you add yourself, as described below.
- What it reads: when you use a Pranan action on Gmail, Slack, or LinkedIn (for example drafting a reply, rewriting text, or opening the side panel), the extension reads the active conversation and the recipient's name, email address, or profile URL from the page and sends them to Pranan to produce the result.
- Optional features: features that send text in the background, such as inline writing suggestions while you type or learning from comments you post on LinkedIn, are off by default and run only if you turn them on in the extension settings.
- Voice dictation: if you use voice input, the audio clip is sent to OpenAI for transcription and the text is returned to you. Pranan does not store the audio.
- Sites you allow: you can add other work sites, one at a time, under "Sites Pranan can learn from" in the extension. Chrome asks you to allow each site you add; mail, chat and sign-in sites cannot be added. On those sites a "Remember this page" button appears. Only when you press it does the extension send that page's visible text, its title and its address (without the part after "?" or "#") to Pranan and to our AI provider, to suggest decisions and facts for your memory inbox. Login and payment pages are never read, nothing is read in the background, and the page text is not stored after it has been analysed. Suggestions are saved only if you approve them. Removing a site in the extension or in Chrome withdraws the access at once.
- What it stores in your browser: your Pranan sign-in tokens and extension settings, in Chrome extension storage on your device.
- What it does not do: it does not read pages on other websites, does not sell or share data for advertising, and does not send messages for you. Inserting a draft into a compose box is always your action.
Data the extension sends to Pranan is handled under the rest of this policy. Removing the extension or signing out of it deletes the sign-in tokens it stored in your browser.
8. Cookies and Similar Technologies
- Website (pranan.ai): we use Google Tag Manager and Google Analytics to understand how visitors use the site. We use Google Consent Mode, and analytics cookies are only set after you choose "Accept analytics" in the cookie banner. Until then, and if you choose "Reject", no analytics cookies are set. We do not use advertising cookies. Your choice is saved in your browser's local storage.
- App (app.pranan.ai): we use cookies and local storage that are strictly necessary to keep you signed in and to secure your session.
9. Data Retention and Deletion
- While your account is active: we keep your data so the service works. Formatted (HTML) copies of email bodies are removed after about 90 days; the plain-text content and metadata are kept so drafts, search, and relationship context keep working. Memory entries follow the retention described in section 11.
- Disconnecting an integration: described in section 10 for Google. Disconnecting HubSpot deletes the synced HubSpot data.
- Cancelling a paid plan: your account moves to the Free plan at the end of the billing period you have paid for. Your data stays in your account, subject to the Free plan's limits, until you delete it or delete your account.
- Deleting your account: you can delete your account from Pranan settings or by emailing privacy@pranan.ai. We delete your account data from our production systems when you do. Copies in encrypted backups are removed as the backups expire, within 30 days, except where we must keep information to comply with law (for example billing records).
10. Google API Services User Data Policy
Pranan's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Google data we access
When you connect your Google account, Pranan requests these scopes:
gmail.readonly: to read your sent mail (so we can learn your writing voice) and your incoming mail (so we know which threads need a draft).gmail.modify: to create draft replies as Gmail Drafts inside your account, and to apply Smart Labels (To Respond, FYI, Awaiting Reply, and others) for inbox triage. This scope would technically allow sending, but Pranan does not request the separategmail.sendscope and never sends mail on your behalf; you review and send every draft yourself.gmail.labels: to create the Pranan label set in your Gmail and apply those labels to threads.calendar.readonly: to read your upcoming events so meeting context can inform drafts, your daily briefing, and, if you connect an AI app, its answers about your meetings. We do not write to, modify, or delete calendar events.drive.file(only if you add Google Docs): requested separately, at the moment you choose documents, and only for the files you pick in Google's file picker, to read their text once for memory suggestions. It gives no access to the rest of your Drive, and Pranan does not keep this access after you leave the page.userinfo.email,userinfo.profile,openid: to identify which Google account is connected and display your name in the app.
How we use Google data: Limited Use commitment
Pranan's use of Google user data is limited to providing and improving the user-facing features described above. Specifically:
- We do not use Google user data to serve ads, retarget users, or build advertising profiles.
- We do not sell Google user data. We share it only with the service providers in section 6 that process it on our behalf to provide the service, and, when you choose to connect one, with an AI app you authorize through the Pranan connector, only in answer to your requests in that app (see section 6).
- We do not use Google user data to train, fine-tune, or improve generalized or shared AI/ML models. Your voice profile is built solely from your own data, used only to draft replies for your own account, and is never combined with other users' data.
- We do not allow humans to read your Google user data, except (a) with your explicit consent, (b) to comply with a valid legal request, (c) for security investigations into abuse or violations of our terms, or (d) where the data has been aggregated and de-identified for internal operations metrics.
How we store and protect Google data
- Google OAuth tokens are encrypted with AES-256-GCM before they are stored.
- Email and calendar data fetched from Google APIs is stored in our database (see section 6) with row-level security enforced per user.
- Data in transit between Pranan and Google is protected with HTTPS.
- Access to production data is restricted to authorized personnel.
How to disconnect and delete
You can disconnect your Google account at any time from Pranan settings. When you disconnect, we delete your stored Google OAuth tokens, revoke Pranan's access to your Google account, and delete the email and calendar data Pranan stored from that account. You can also revoke Pranan's access from your Google Account at myaccount.google.com/permissions; if you do, use the disconnect option in Pranan settings as well so the stored data is deleted.
11. Memory Entries
On every plan, Pranan extracts structured information from emails you receive ("memory entries") to help you respond more effectively. On Business plans, some memory entries are shared with your team. These entries may include:
- Facts about your contacts (their role, company, project context)
- Commitments they've made to you, or you've made to them
- The trajectory of your relationship (deal stage, escalations, milestones)
- Personal context they've shared with you
- Sentiment signals captured from email tone
Lawful basis (GDPR Article 6(1)(f)): We rely on legitimate interests for this processing. You have a legitimate interest in reading your own inbox more efficiently and maintaining accurate context about your professional relationships. We balance this against the contact's reasonable expectations through visibility controls, confidence thresholds, and post-extraction filtering for special categories.
Visibility: On solo plans, memory entries are visible only to you. On Business plans, fact, commitment, and relationship entries can be visible to your team. Sentiment entries are private to the user who captured them. Personal-context entries are visible only for inner-circle and team relationships. Your voice profile and your mailbox are never shared with your team. Memory entries are never sold or used for advertising, and are shared outside your organization only with an AI app you connect yourself (section 6), and only your own view of them.
Your contacts' rights: Anyone whose information appears in our system can request access, correction, or deletion by emailing privacy@pranan.ai. We respond within 30 days, as required by GDPR Article 12(3). We honor:
- Access (Article 15): a copy of the entries about the contact
- Rectification (Article 16): corrections to inaccurate entries
- Erasure (Article 17): removal of entries plus suppression to prevent re-extraction
- Restriction (Article 18) and objection (Article 21): we stop extracting new entries about the contact and add them to a suppression list
- Portability (Article 20): structured JSON export
Retention: Memory entries have type-specific retention. Commitments expire when their date passes. Sentiment entries decay after 90 days. Facts and personal context persist until you delete them, the contact requests deletion, or you delete your account.
Special categories: We do not intentionally process special-category data (health, religion, political views, sexual orientation). The extraction prompt instructs the model to skip such content, and a post-extraction filter screens entries before they are written. Any special-category entry created despite these mitigations is deleted upon discovery.
12. International Transfers
Our primary database is hosted in Tokyo, Japan (ap-northeast-1). Most of the service providers in section 6 are based in the United States, so your information is transferred to and processed in the United States and other countries. Where the law requires it, we rely on Standard Contractual Clauses or another valid transfer mechanism for transfers of personal data from the EU, EEA, UK, and Switzerland.
13. Your Rights and Choices
- Access and portability: request a copy of your data, including a structured export.
- Correction: update or correct your information.
- Deletion: delete your account and associated data (see section 9).
- Disconnect: disconnect Google, Slack, or HubSpot at any time.
- Analytics: accept or reject website analytics cookies at any time (see section 8).
You can start these requests in the app or by emailing privacy@pranan.ai. Depending on where you live, you may also have the right to object to or restrict processing, and to complain to your local data protection authority. We respond to privacy rights requests within 30 days.
14. Children
Pranan is not intended for anyone under 18, and we do not knowingly collect personal data from children.
15. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes via email or in-app notification at least 30 days before the changes take effect.
16. Contact
The data controller for the service is INSIDEA, Inc., a Delaware corporation headquartered in Dover, Delaware, USA. Questions about privacy or how we handle your data? Email us at privacy@pranan.ai. We reply to general questions within 48 hours and to formal privacy rights requests within 30 days. For product support and billing questions, email support@pranan.ai.
17. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the State of Delaware, USA, without regard to its conflict of law provisions. You and INSIDEA, Inc. submit to the exclusive jurisdiction of the state and federal courts located in Delaware for the resolution of any disputes arising from or relating to this Privacy Policy. Nothing in this section removes any mandatory data protection or consumer protection rights you have under the laws of your country of residence, including your right to complain to your local data protection authority.