CCPA & US privacy — Frequently asked questions

How Prolytiq handles your personal information under the CCPA and CPRA, the United States privacy standard, in plain language. Based in Brazil? See your rights under the LGPD.

What is the CCPA?

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is the California law that governs how businesses handle the personal information of California residents. It is the most comprehensive consumer privacy law in the United States and the closest US counterpart to the GDPR and the LGPD. In broad terms: you own your personal information, and we are its temporary custodian while you use the platform. We extend these protections to all of our United States users, not only Californians.

What personal information does Prolytiq collect about me?

We collect only the categories needed to provide the service:

  • Identifiers: full name, email, ORCID (optional), institution, specialty.
  • Platform content: systematic review projects you create, PDF articles you upload, inclusion/exclusion criteria you define, annotations.
  • Internet activity: pages visited, AI requests, login timestamps, IP address (anonymized to /24 after 30 days).
  • Commercial information: billing is handled by Stripe, so we receive only the subscription status, never card data.

We do not collect sensitive personal information (a CPRA category, such as health data or precise geolocation). Our Terms prohibit submitting identifiable PHI (Protected Health Information) to the platform.

What are my rights under the CCPA and CPRA?

If you are a United States resident, you have the right to:

  • Know: see what personal information we collect, use and disclose about you.
  • Delete: ask us to delete your account and the associated personal information.
  • Correct: fix inaccurate personal information.
  • Opt out of sale or sharing: we do not sell or share your personal information, so there is nothing to opt out of.
  • Limit sensitive information: we do not use sensitive personal information beyond what is needed to run the service.
  • No discrimination: we will never charge you more or degrade the service because you exercised a privacy right.
  • Information about disclosure: the list of third parties we share data with (sub-processors).

How do I exercise these rights?

Almost all of them are self-service, inside your own account:

Special cases (no account access, authorized agents, disputes, bulk requests): write to contact@prolytiq.ai. We respond within 45 days, as the CCPA requires.

Who handles privacy requests?

Our privacy team, led by Joao Pedro de Britto. Full details at /legal/dpo. Email: contact@prolytiq.ai.

How does permanent deletion work?

When you click Delete account, two things happen:

  1. Immediately: your personal information is masked (your name becomes "Deleted Account", your email becomes anonymous, avatar and links are cleared). You are logged out and the account can no longer sign in.
  2. 30 days later: an automated job permanently erases the remaining data fields. Only anonymous IDs and audit logs remain (fraud-control and legal obligation).

During the 30-day window, you can write to our privacy team to reverse the deletion. After that, it is irreversible.

How long do you keep my information?

Retention policy (summary):

  • Active account: for as long as you use it.
  • After deletion: 30 days masked, then anonymous IDs forever (audit).
  • Audit logs with IP/userAgent: 30 days with raw data, then anonymized (/24 + browser family).
  • Account inactive over 24 months: a future policy, and we will notify you by email before taking any action.
  • Billing data: retained by Stripe under United States tax and accounting obligations. We only see the status.

Do you sell or share my personal information?

No. We do not sell your personal information and do not share it for cross-context behavioral advertising (the CCPA definitions of "sell" and "share"). We disclose data only to the technical sub-processors required to operate the service, all audited and listed at /legal/subprocessors. Because there is no sale or sharing, an opt-out-of-sale signal such as the Global Privacy Control (GPC) has nothing to act on.

How will I know if there was a breach?

If we identify a security incident that could expose your personal information:

  1. We notify you directly by email without unreasonable delay.
  2. We notify the relevant authorities, including the California Attorney General, as required by law.
  3. We publish technical details at /legal.

To report a vulnerability you found: write to contact@prolytiq.ai. Details in our security.txt.

Prolytiq uses AI. Does my content train the model?

No. We use the Anthropic API (Claude) for article screening. Under Anthropic's current policy for commercial use, inputs and outputs are not used to train models. Our DPA with Anthropic and the public PIA (Privacy Impact Assessment) document this commitment.

Page maintained by the privacy team. Last reviewed: May 14, 2026. Suggestions and corrections: contact@prolytiq.ai.