Privacy & data practices

Privacy Policy

This policy describes how Praevyn collects, uses, stores, and protects personal and organizational information. It also explains your rights and how to exercise them.

Who we are

Praevyn is a business-to-business cybersecurity maturity intelligence platform operated by Praevyn, USA. Our contact email for privacy and data-protection questions is support@praevyn.com.

This page is maintained by Praevyn to answer common security and privacy questions about the platform. It is not an independent certification or legal opinion.

What we collect and why

We collect only the information needed to provide, secure, and improve the platform.

  • Account information. Email address, full name, and organization details (such as organization name and state/region) are collected when you register or update your profile. We use this to identify you, manage your subscription, and communicate about your account.
  • Authentication data. Password hashes, multi-factor authentication enrollment (TOTP and email MFA), and secondary sign-in emails are handled by our authentication backend. We cannot see your password.
  • Assessment and platform content. Answers to security assessments, remediation status, incident records, chat messages with the AI assistant, and generated reports are stored so you can review, update, and share them within your organization.
  • Billing information. When you subscribe to Praevyn Professional, Stripe processes your payment details. We store Stripe customer and subscription identifiers in our backend; we do not store full payment card numbers.
  • Usage analytics. We collect page paths, anonymous visitor and session identifiers, referrer host/URL, UTM parameters, country (derived from IP headers), and browser user-agent string. This helps us understand product usage and measure the effectiveness of partner referrals.

Cookies and local storage

We use browser localStorage and sessionStorage to keep you signed in, remember first-touch attribution data, and avoid duplicate analytics beacons. These are first-party storage mechanisms; we do not use third-party advertising cookies.

How we use your information

  • Provide, maintain, and improve the platform and its features.
  • Authenticate users and protect accounts, including through Organization-enforced MFA.
  • Process payments and manage subscriptions.
  • Generate maturity scores, remediations, roadmaps, and executive reports.
  • Communicate about your account, security alerts, and product updates.
  • Analyze usage trends and measure partner-referred traffic.
  • Comply with legal obligations and protect our rights and users.

We do not sell personal information. We do not use your assessment data to train third-party AI models.

AI and automated processing

Praevyn uses language models to draft roadmap items, remediation narratives, and assistant responses based on your assessment inputs. The AI layer does not change the deterministic maturity score. AI outputs are generated on demand and should be reviewed by a qualified person before being relied upon for security or compliance decisions.

Data sharing and subprocessors

We rely on a small number of service providers to operate the platform. These subprocessors process data only on our behalf and under appropriate agreements:

  • Supabase — authentication, database, and storage services.
  • Stripe — payment processing and subscription management.
  • Google — optional social sign-in (OAuth) only when you choose to use it.

We may disclose information if required by law, to protect our rights, or in connection with a business transfer such as a merger or acquisition.

Data security

We use industry-standard security practices, including TLS for data in transit, row-level access controls in the database, optional multi-factor authentication, and least-privilege access for internal operations. Our infrastructure providers handle encryption at rest. No security program is perfect; users are responsible for maintaining the confidentiality of their credentials and reviewing MFA options.

Data retention and deletion

Assessment data, risk records, generated reports, and account analytics will be deleted from active production systems within 30 days after account deletion. Residual copies may remain in encrypted backups for up to 90 days before being automatically overwritten. Limited records may be retained longer when reasonably necessary for legal compliance, billing, fraud prevention, dispute resolution, or security purposes.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export your personal information. You can update your name, organization, and security settings in the Settings tab. To request deletion of your account and associated data, use the account-deletion option in Settings or contact support@praevyn.com.

If you are in the European Economic Area or California, you may also have the right to object to certain processing and to lodge a complaint with your local data-protection authority. We will respond to verifiable requests in accordance with applicable law.

Children

Praevyn is a business-to-business cybersecurity platform and is not intended for children. Users must be at least 18 years old, and Praevyn does not knowingly collect personal information from anyone under 13. If you believe we have collected information from a child under 13, please contact us so we can delete it.

International data transfers

Praevyn is operated from the United States. If you access the platform from outside the United States, your data may be transferred to and processed in the United States or other jurisdictions where our subprocessors operate. We rely on standard contractual clauses and service-provider agreements for transfers that require them.

Changes to this policy

We may update this Privacy Policy from time to time. The "Last reviewed" date at the bottom of this page indicates when it was last revised. Material changes will be communicated through the platform or by email where appropriate.

Contact us

For privacy questions, data requests, or security concerns, contact us at support@praevyn.com.

Last reviewed: September 2026. This page is maintained by Praevyn to answer common security and privacy questions about the platform.