Privacy Policy

Effective: July 17, 2026 · Last updated: August 27, 2026 (updated: optional Mama Network Protection data flow, resolver, and retention; earlier: Twilio voice processing for the disabled-by-default Echo protected-call lab)We prioritize protection over engagement No ad-tech tracking

Project PRINCE AI (“Project PRINCE”, “we”, “us”) safeguards the integrity of human communication. This policy explains what we collect, why, how we protect it, and the choices you have. It applies to our websites, apps, and AI-powered services (together, the “Services”).

Shield Bot
Live privacy posture: minimal collection • encryption in transit • role-based access • rapid deletion on request.

Quick Summary

We collect:
  • Account details (e.g., email) when you sign up
  • Content you submit for scanning/analysis
  • Device/usage data for security & reliability
  • Payment info via our processor (we don’t store full card data)
We don’t:
  • Sell your personal information
  • Run ads or ad-tech trackers
  • Use your personal data to train third-party foundation models

1) Information We Collect

  • Account & Contact. Name, email, subscription tier, plan metadata, and a mobile number only when you explicitly enroll in a text-message feature.
  • Bot Submissions. Text, links, publicly shared images/screenshots, and context you provide to our bots for analysis.
  • Device/Usage. IP address, device/browser type, timestamps, pages, diagnostics, crash reports, performance metrics.
  • Mama Network Protection (optional). When you turn it on, this phone's network traffic is encrypted to a private PRINCE VPN gateway. The gateway processes destination domain names, IP addresses, connection timing, and data volume only as needed to route connections and block verified scam destinations. When Mama stops a destination from the signed warning list, the app sends that destination to PRINCE only to recheck the current warning evidence. PRINCE immediately converts a confirmed stop into a keyed, unreadable security-event identifier and does not store the raw destination. The minimized event stops contributing to protection continuity after 30 days and scheduled cleanup removes it. PRINCE does not decrypt the contents of protected HTTPS connections and does not create or keep a browsing history. Allowed system DNS lookups go through the encrypted tunnel to Cloudflare 1.1.1.1; Cloudflare may keep limited resolver logs for up to 25 hours and may keep combined statistics. This network data is not sold or used for advertising.
  • Transactional. Purchase history, amounts, currency, limited Stripe tokens (no full card numbers stored by us).
  • Community/Support. Messages you send to support or feedback you choose to provide.
  • Sensitive Personal Information. We don’t ask for SPI; if you submit it, we process it only to provide the requested service and protect users (see Limit Sensitive PI).

Victim-safety first. When users submit links or evidence about scams/abuse, we remove direct identifiers before any awareness use and follow least-privilege access internally.

2) Sources

We collect data directly from you, automatically via the Services, and from service providers acting on our behalf (e.g., payments, cloud hosting, fraud prevention). We may also ingest publicly available signals you point us to (e.g., a public social post URL) to detect impersonation or deception.

3) Cookies & Similar Technologies

We use a small number of essential and functional cookies (e.g., session, security, rate-limit). We do not run behavioral advertising cookies. You can control cookies in your browser. If we add analytics, we will use privacy-preserving settings and update this page.

4) How We Use Data

  • Provide, maintain, and improve the Services (including safety detections)
  • Authenticate users, prevent fraud, abuse, and security incidents
  • Respond to support requests and communicate about the Service
  • Generate aggregate, de-identified insights and threat statistics
  • Meet legal, regulatory, and compliance obligations

Not legal/medical/financial advice. Outputs are AI-generated safety signals to help you decide; they are not professional advice or certification of fact.

5) Lawful Bases (EEA/UK only)

  • Contract — to provide the Services you request
  • Legitimate interests — security, fraud prevention, service improvement (balanced with your rights)
  • Consent — where we rely on it (you may withdraw at any time)
  • Legal obligation — to comply with applicable laws

6) Sharing & Sub-processors

We share personal data only with service providers that process it for us under contracts that require confidentiality and appropriate safeguards. We may also disclose data to comply with law, protect users, or in a merger/acquisition (with notice and choices where required).

Optional Trusted Circle protection totals. Mama Network Protection does not share browsing activity with family members. If you separately choose a current Trusted Circle member, that person can see only seven-day aggregate counts of protected situations, stops or slow-downs, and moments paused for verification. They never receive sites, destinations, messages, caller words, contacts, case identifiers, or browsing history. The grant expires automatically, can be stopped immediately, and is checked against current Circle membership every time the totals are opened.

See Appendix A for our core sub-processors.

7) International Transfers

We are U.S.-based. When transferring personal data internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses with our processors, plus additional measures (encryption in transit, access controls). Where local law requires different mechanisms, we follow those requirements.

8) Retention

We keep personal data only as long as needed to provide the Services, comply with law, resolve disputes, and protect users. You can request deletion at any time (see Make a Request). Aggregated, de-identified metrics may be retained for service integrity.

Mama Network Protection. The PRINCE VPN gateway processes routed traffic in transit but does not write destination domains, IP addresses, timing, or data volume to a browsing-history or traffic log. The technical STOP receipt with its readable destination stays only on your phone and expires after 24 hours; allow-once receipts expire after ten minutes. For a current signed-warning STOP, the app sends the stopped destination transiently to PRINCE for server-side evidence revalidation. The raw destination is not stored. A keyed, unreadable event identifier with fixed protection labels and timestamps may be retained under your account; it stops contributing after 30 days and scheduled cleanup removes it. If you separately grant access, seven-day aggregate protection totals are computed from those minimized events for the Trusted Circle member you selected; no browsing timeline is created. Cloudflare may keep limited DNS resolver logs for up to 25 hours and may keep combined statistics under its resolver privacy commitments. Turning protection off stops future VPN routing. Deleting your account revokes its device credentials and deletes the minimized events and protection-sharing grants, but it cannot retroactively remove resolver records already handled under Cloudflare's retention terms.

Your scans. When you run a scan, the raw content you submit — the message text, any image, and the full web address with its path and parameters — is used to produce your answer and is not retained afterward. For accounts with a command center (dashboard), we keep a signal-only record of what the scan found: the verdict, its severity, the website's bare domain (never the full link), which guardian answered, threat-intelligence flags about the site, and the timestamp. This record is never shared, auto-deletes after 90 days, and can be cleared by you at any time. If you switch on "Help others," a separately sanitized threat record (no message, no personal details) may be added to the public feed — see your permissions page for details.

Solomon story originals. If you explicitly choose Keep this original recording or Keep this photo in PRINCE, we retain that audio or photo privately with your life-story chapter until you delete the original or your account. These originals are not public, are not available to Trusted Circle members, are not sent to an AI model, and are never used to clone or synthesize your voice. The app gives you visible play/view, export, and permanent-delete controls for each original.

Helping the guardians learn. If you choose to share (either by leaving "Help others" on for a genuine threat, or by tapping "Help improve PRINCE" on a specific result), the raw example — the message, image, or link — may be kept in a de-identified training set for up to 30 days to make the guardians better at real scams, then it auto-deletes. It is tied to a one-way hash, never to your name or account, is used only to improve detection under review, and is never sold or shown publicly. If you don't share, nothing about your scan enters this set.

The confirmed-threat pattern library. A scam that is confirmed real teaches the guardians the most — so when a shared example is confirmed (because it matched a known-scam list, was independently reported by several unrelated households, was verified by our team, or was judged a threat by our deterministic evidence check), a redacted, de-identified version of it may be kept in a durable threat-pattern library with no fixed deletion date, the way antivirus software keeps virus definitions permanently. Before anything is stored, the content is scrubbed: names, emails, phone numbers, web links, dollar amounts, and long number strings are replaced with typed placeholders (such as [NAME] or [LINK]). What remains is the manipulation pattern and the brand or agency the scammer impersonated — never your identity, and never the raw message. Each entry is tied to a one-way hash, never to your name or account; it is used only under human review to improve detection; and it is never sold, never shown publicly, and never used to profile any individual. Only shared examples that are confirmed are added: uncertain or harmless scans never enter it, and if you don't share, nothing of yours does either. We keep these de-identified signatures indefinitely because a scam pattern we can still recognize years from now protects more people over time.

Deleting your account. You can delete your PRINCE account and its data yourself from your account page or the app. This erases your profile, plan access, scan-signal history, Solomon memories and stored story originals, trusted-circle records, survey and feedback responses, and connected devices. An active subscription is canceled immediately so it cannot renew; unused time is not automatically refunded. If other people still belong to a team you own, deletion stops until a safe handoff or closure is arranged. Two things remain by design: (1) Billing records — invoices and payment history are retained as financial-record and tax law require, while PRINCE removes their link to your account. (2) Already-shared, de-identified contributions to the public threat feed, the 30-day training set, or the durable confirmed-threat pattern library are not tied to your identity and are covered by the timelines above; because a redacted, confirmed scam pattern is stripped of everything that points back to you, it stays part of the shared shield after your account is gone.

9) Security

  • Encryption in transit; limited, logged access in production
  • Role-based access control; principle of least privilege
  • Backups and disaster recovery for core systems
  • Vulnerability and abuse monitoring

No security program is perfect; if we identify a breach affecting you, we will notify you and regulators as required.

10) AI Systems & Model Training

  • We use reputable AI providers (currently Mistral AI for analysis and image reading; Together AI for inference and audio transcription; Amazon Web Services for translation, image/video safety analysis, threat-speech scoring, backup AI inference, and voice; and Google, Microsoft Azure, and ElevenLabs for speech synthesis of our answers — see Appendix A) to process the content you submit for safety signals, under data-processing terms; they do not use your content for their own purposes.
  • We do not use your personal data to train third-party foundation models. Where a provider allows it, we disable training/retention; otherwise we minimize, pseudonymize, or redact.
  • We may train our own lightweight classifiers on de-identified, aggregated patterns to improve threat detection. These training sets are stripped of direct identifiers and are not used to profile individuals for ads or unrelated purposes.
  • We keep a durable, de-identified library of confirmed scam patterns (see Retention) to help our own guardians recognize known manipulation over time. Its entries are redacted before storage, tied only to a one-way hash, retained with no fixed deletion date, and used solely under human review to improve our detection — never to profile people and never sold or shared for advertising.

11) Automated Decision-Making & Profiling

Our bots generate risk ratings and flags automatically. These are assistive signals for you; we do not make consequential decisions about individuals (e.g., credit, employment, housing) without human review. You may contest or request human review of any automated output that materially affects you.

12) Your Privacy Rights

Make a request: email legal@projectprince.ai from the address associated with your account. We may ask you to verify your identity. Authorized agents may submit with proof of authority.
Global rights (where applicable)
  • Access a copy of your data
  • Correct inaccurate data
  • Delete your data
  • Port your data (machine-readable copy)
  • Object to or restrict certain processing
  • Withdraw consent where relied upon
U.S. State rights (e.g., CA/CO/CT/VA/UT/NV)
  • Do Not Sell/Share personal information (we don’t sell; we also avoid cross-context behavioral ads)
  • Limit Use of Sensitive PI to the minimum necessary to provide services you request
  • Appeal a decision if we deny your request

EEA/UK users: you can lodge a complaint with your local supervisory authority. We’ll cooperate in good faith with all regulators.

13) Children’s Privacy

The Services are not directed to children under 13, and we do not knowingly collect their data. If you believe a child provided data, contact us for deletion.

14) “Do Not Track”

Browsers may send a DNT signal. Because there’s no common industry response standard, we don’t respond to DNT at this time; we already avoid behavioral ads and minimize tracking.

15) Changes to this Policy

We may update this policy to reflect changes to the Services or law. We post updates here and, if changes are material, we’ll provide additional notice.

16) Contact Us

Email our privacy team at legal@projectprince.ai. If we appoint an EU/UK representative or Data Protection Officer, we will update this section.

Appendix A · Core Sub-processors

  • Google Firebase / Google Cloud — hosting, databases, authentication, security, and text-to-speech for spoken answers; data may be processed in the U.S. and other regions per Google’s terms and SCCs.
  • Stripe — payment processing; we do not store full card numbers.
  • Twilio — transient voice transport, transcription, speech synthesis, and call control for the disabled-by-default Echo protected-call lab. PRINCE does not instruct Twilio to record these calls, does not persist the call transcript, and retains only short-lived minimized decision state needed to complete or safely end the controlled call.
  • Mistral AI — AI inference to analyze content you submit, including reading images you ask us to check; inputs minimized, not used to train their models.
  • Together AI — AI inference and audio transcription for voice features you start (Lingua, Echo Ears).
  • Amazon Web Services — guardian voice synthesis (Polly); translation of text you ask us to translate (Amazon Translate); safety analysis of images and videos you submit for scanning (Amazon Rekognition public-figure checks, Amazon Nova video understanding); threat-speech scoring of audio you submit for scanning (Amazon Transcribe — the audio is staged transiently and deleted immediately after analysis); backup AI inference (Amazon Bedrock) when our primary AI provider is unavailable; and the private Mama Network Protection gateway and network egress. VPN traffic is processed in transit without a PRINCE browsing-history log, and protected HTTPS content remains encrypted through the gateway. All under AWS data-processing terms; your content is not used to train their models.
  • Cloudflare 1.1.1.1 — encrypted DNS resolution for allowed system DNS lookups while Mama Network Protection is on. Cloudflare may keep limited resolver logs for up to 25 hours and may keep combined statistics under its public resolver privacy commitments.
  • Microsoft Azure — backup voice synthesis (same scope as above: our answers, not your submissions).
  • ElevenLabs — premium voice synthesis used in limited demonstration modes (same scope: our answers only).
  • Brave Search API — live web verification of claims and links during a scan.
  • Link & sender reputation services — during a scan we check links, domains, and network addresses (never your message text) against Google Safe Browsing, VirusTotal, urlscan.io, AbuseIPDB, GreyNoise, and WhoisXML (domain age). Each receives only the link, domain, or IP being checked.
  • ipinfo.io — approximate, city-level geolocation of network addresses. We use it mainly to map where a threat is hosted (the scam site's server), and, for your own dashboard, an approximate location for your account's activity. An IP address is sent to obtain a coordinate and is then discarded; the IP itself is not stored, only the approximate location.

We may update this list as infrastructure changes. Material changes to sub-processors for personal data will be reflected here prior to use when required by law.