Privacy
Last updated: April 8, 2026
ProposalSprint is an early-stage SaaS for SEO freelancers and digital marketing agencies. This page explains, in plain language, what data the product currently handles and what it does not claim.
What we collect
- Account information: email address, password hash, and optional account name used for login and account access.
- Proposal and business content: information you enter to generate and save proposal drafts (for example client name, website, industry, budget context, goals, discovery notes, and generated proposal content).
- Agency profile information: details you save for reuse in drafts (for example agency name, branding defaults, and profile text).
How data is stored and hosted
- The app runs on Vercel.
- Core application data (accounts, profiles, and proposals) is stored in managed Postgres through Prisma.
- We rely on our hosting and database providers for infrastructure-level controls such as network protections and platform backups according to their services.
Authentication and sessions
- ProposalSprint currently uses email + password authentication via Auth.js credentials.
- Sessions are handled using JWT-based Auth.js sessions.
Optional payment processing
If paid checkout is enabled, checkout is handled by Stripe. In that flow, Stripe receives the billing information needed to process payment. ProposalSprint currently uses a checkout-session integration and does not claim a full billing entitlement system yet.
AI generation mode
Proposal generation can run in demo mode (without a paid AI key) or optional AI mode. When AI mode is enabled by the operator, proposal input may be sent to the configured AI provider to generate draft output.
What we do not claim
ProposalSprint does not currently claim SOC 2, ISO 27001, or enterprise compliance certifications. This is an MVP/live-stage product and security/privacy controls are practical baseline controls for this stage.
Contact
For privacy questions or account help, use the public support page at /support.