Effective September 3, 2026
Privacy Policy
This policy covers prosewire.com and Prosewire Cloud. It does not cover a deployment run by somebody else.This Privacy Policy describes personal data handled by prosewire.com and the hosted service at cloud.prosewire.com. Akshit Kr Nagpal, the current operator of Prosewire Cloud, is responsible for that processing. “Prosewire,” “we,” and “us” refer to that operator.
A self-hosted Prosewire deployment has its own operator. Contact that operator about its privacy practices. Prosewire does not receive customer or reader data merely because somebody installs the open source software.
Our roles
We act as a controller for account administration, service security, support, legal requests, and visits to our own website.
We act as a processor when a business customer puts personal data in its workspace or publication and asks us to host or publish it. That customer decides why and how to use the data. The DPA covers this processing. If your request concerns content on a customer’s publication, contact that customer first when practical.
Data we collect
Account and team data
We process the name and email address you provide, password authentication records, account status, workspace membership, role, invitations, and optional profile image. If social login is enabled and you choose it, we receive identifiers and profile details from the selected identity provider.
Content and configuration
We store publication settings, posts, Markdown and rendered HTML, authors, categories, snippets, revisions, redirects, API key metadata, and the content you choose to publish. Management keys are stored as hashes. You control what personal data appears in customer content.
Device, session, and security data
The Cloud service processes session identifiers, IP address, browser or device user agent, request time, security events, and audit records. We use these records to authenticate requests, investigate abuse, protect accounts, and preserve an editorial record.
Reader analytics
The built-in reader can send a randomly generated event identifier, post identifier, referrer, and event time. The identifier lives in the reader’s session storage and prevents duplicate counting during that browser session. Prosewire does not use it to build an advertising profile.
Messages and requests
If you contact us, we process your contact details, message, attachments, and the records needed to respond. Do not send a password, management key, or exploit details in an initial email.
Where data comes from
We receive data from you, your workspace administrators, your use of the service, and a browser that requests a Prosewire page. We may receive account data from an identity provider you choose. A customer may also submit personal data about authors, team members, invitees, and people mentioned in its content.
Why we use data
We process personal data for these purposes and legal grounds where those grounds apply:
| Purpose | Legal ground |
|---|---|
| Provide accounts, workspaces, publishing, APIs, exports, and support | Perform our contract and take requested pre-contract steps |
| Authenticate users, prevent abuse, debug failures, and secure the service | Legitimate interests in a safe and reliable service, and legal obligations where applicable |
| Send service messages and invitations | Perform our contract and follow customer instructions |
| Keep required financial, legal, and compliance records | Legal obligation and legitimate interests in handling claims |
| Improve service reliability using limited operational data | Legitimate interests, balanced against user privacy |
| Publish customer content and process business data | The customer’s instructions under the DPA |
Where consent is the required ground, you may withdraw it. Withdrawal does not affect earlier lawful processing.
Cookies and browser storage
Prosewire Cloud uses essential authentication cookies to keep you signed in and to protect account requests. It may use a preference cookie for the selected publication and dashboard layout. Public readers use session storage for the random view-event identifier. The marketing and legal site uses local storage to remember light or dark theme.
We do not use third-party advertising cookies or sell browsing activity for targeted advertising. Blocking essential storage may prevent account features from working.
Sharing
We disclose data only as needed to:
- infrastructure providers on the Subprocessors page;
- an identity provider you choose;
- professional advisers under duties of confidentiality;
- a buyer or successor during a proposed business transaction, subject to appropriate safeguards; or
- a court, regulator, or government body when law requires it or when needed to protect legal rights and safety.
We do not sell personal data. We do not share it for cross-context behavioral advertising.
Workspace owners and authorized members can see data allowed by their roles. Published content is available to the public and may be copied, cached, indexed, or archived by others. Removing it from Prosewire cannot remove copies held by third parties.
Data location and transfers
The Data location disclosure describes the current hosting model. Prosewire Cloud does not currently offer a contractual data residency region. Data may be processed outside your country.
Where a restricted international transfer requires contractual safeguards, business customers must complete the transfer terms described in the DPA before placing covered personal data in Cloud.
Retention and deletion
The Deletion and retention policy lists retention periods and deletion criteria. We keep data only while it serves the stated purpose, a customer instruction, security, dispute handling, or law.
Security
We use technical and organizational measures described on the Security page. No online service can promise absolute security. Protect your credentials and report suspected compromise promptly.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal data. You may also have the right to object, withdraw consent, appeal a decision, or complain to a data protection authority.
Use the Data request procedure to make a request. We may need to verify your identity and authority. Some rights have legal exceptions.
Children
Prosewire Cloud is not directed to children under 16, and account holders must be at least 18. Do not knowingly submit a child’s personal data without a lawful basis and any required parent or guardian authorization. Contact us if you believe a child provided account data without proper authorization.
Automated decisions
We do not use personal data to make decisions that produce legal or similarly significant effects through solely automated processing.
Changes
We will update the effective date when this policy changes. We will give existing Cloud account holders reasonable notice of a material change when we have a working contact address and law requires notice.
Contact
Email privacy questions and requests to privacy@prosewire.com with “Privacy” in the subject. The Data request procedure explains what to include.