Proofling
Back to Proofling

Legal

Privacy Policy

Effective date: August 4, 2026

This policy explains how Proofling handles account data, customer contacts, written and video testimonials, customer logos, consent, billing, and integrations.

1. Introduction

Proofling is operated by Jake Baden North trading as Donkeh Labs (ABN 87 636 703 254). This Privacy Policy explains how we collect, use, disclose, and protect information when you use Proofling.

Proofling helps businesses ask for testimonials privately, capture written or guided video responses and consent, approve proof cards, and publish proof walls, customer-logo walls, and website embeds.

2. Information We Collect

  • Account information such as name, email address, avatar, organization name, and authentication provider details.
  • Workspace and campaign information such as product names, websites, proof wall settings, email copy, labels, sending state, and subscription status.
  • Customer contact information you provide, such as recipient names, email addresses, company details, and campaign membership.
  • Testimonial content such as written responses; uploaded or recorded video and audio; automatically generated captions; display names, roles, and companies; consent state; optional structured recommendation intent and private improvement notes; referral opportunity activity, attribution, conversion state, snapshotted reward terms, reward beneficiary and lifecycle state, and opaque external fulfillment references; proof card approval state; and public proof wall, embed, or testimonial share content.
  • Video processing and diagnostic information such as recording source, media type, duration, dimensions, prompt and duration settings, upload and processing status, playback identifiers, capture notes, and errors. Proofling does not need your device contact list, photo library, or unrelated files.
  • Integration data such as Stripe account metadata, selected products or prices, event and subscription status metadata, customer names and business-email domains, scheduling state, and encrypted restricted API keys where you choose to connect Stripe automation or customer-logo sync.
  • Customer-logo data such as a Stripe customer email, detected or manually supplied public business website, logo source URL, normalized logo image, product and subscription lifecycle state, permission request and decision history, and publication state. Draft logo files are private. Proofling does not publish or export a logo until the customer grants permission and a workspace Owner or Admin publishes it.
  • If you enable Review Watch, monitored profile identifiers, temporary external-review content, provider event metadata, alert and workflow state, synchronization and deletion state, and encrypted provider credentials. The exact information retained depends on the connected provider and its policies.
  • Billing information processed by Stripe, such as subscription, invoice, checkout, and payment status metadata. Proofling does not store full card numbers.
  • Technical information such as IP address, browser, device, logs, error reports, cookies, and usage events needed to operate, secure, and improve the Service.
  • Support communications you send to us.

3. How We Use Information

  • Provide, maintain, secure, and improve Proofling.
  • Authenticate users and manage workspaces.
  • Send testimonial requests, customer-logo permission requests, follow-ups, response links, opt-out links, and account emails.
  • Capture, upload, process, caption, moderate, and display written and video testimonial responses, consent, optional recommendation intent, warm referral actions, reward tracking, proof cards, proof walls, share pages, and embeds.
  • Operate Stripe-triggered testimonial automation when enabled by a workspace.
  • Reconcile active Stripe subscribers, fetch public website logo assets, normalize those assets, and maintain an approved customer-logo wall when enabled by a workspace.
  • Monitor external-review profiles, apply deterministic alert rules, notify authorized workspace users, reconcile provider changes, and support review-response workflows when Review Watch is enabled.
  • Process billing, subscriptions, invoices, plan access, and usage limits.
  • Respond to support requests and troubleshoot product issues.
  • Detect fraud, abuse, security incidents, bounced emails, complaints, and unsubscribes.
  • Comply with legal obligations and enforce our Terms.

4. Camera, Microphone, Video, and Captions

On a private testimonial request page, a recipient may choose to record a guided video or upload an existing video. Proofling requests camera and microphone access only after the recipient explicitly starts camera setup. Browser and device controls govern that permission, and the recipient may instead choose a written response or supported file upload when available.

A recording contains both video and audio. After the recipient previews the recording, accepts the required website-use consent, and submits it, Proofling uploads the selected recording for processing. Automatic captions may be generated from the spoken audio. Camera and microphone access is stopped when recording finishes, the recipient retakes or leaves the flow, or the page closes, subject to browser behavior.

5. Public Content

Proofling keeps responses private until a workspace user approves them for publication. Once approved, written proof and video playback on proof walls or website embeds are public and may be indexed, shared, embedded, previewed, played, or viewed by others. Public video data includes the playback media, poster, duration, aspect ratio, approved attribution, and captions where available; private upload identifiers and internal processing errors are not intended for public display.

Customer logos discovered through Stripe and public business websites remain private drafts until the customer grants the stated customer-logo-public-use permission and a workspace Owner or Admin publishes them. Permission covers public customer walls, website embeds, downloadable feeds, API/MCP access, and AI-assisted creation of those customer displays; it excludes ads, invented endorsements, resale, and material alteration. Withdrawal or subscription ineligibility removes the logo from Proofling public results, although third-party caches or prior authorized copies may take time to update.

Guided video requires base consent for use on Proofling walls and website embeds. Paid or social advertising is excluded from that base consent and requires a separate optional consent choice that is unchecked by default. Withdrawing advertising consent alone does not remove a wall publication; withdrawing base website-use consent removes public eligibility and starts deletion processing.

Workspace users must not publish testimonial content unless they have the right consent and the content is accurate and not misleading.

6. Customer Recipients

If a business uses Proofling to contact you, we process your contact details and response on behalf of that business. You may use the opt-out or unsubscribe options in Proofling emails where available, or contact the business that sent the request.

After submitting feedback, you may optionally answer whether you would recommend the product. That structured answer does not change your testimonial consent, hide mixed feedback from the business, or control any external-review handoff. If you choose to share, Proofling may provide a tracked referral link and record link activity, an attribution code, and whether the business later marks the referral converted. An optional “maybe” note stays private to the workspace, and this step does not collect the referred person’s contact details.

Referral event payloads do not include the referred person’s contact details. Opportunity and reward records remain associated internally with the original referral and may include link creation, sharing, clicks, expiry, conversion state, a configured reward promise, hold and lifecycle timestamps, and an opaque external fulfillment reference. A connected system may report a conversion or manage reward state through an authenticated project API or MCP connection. The short display attribution code is not used as an API credential.

A connected system may optionally supply a referred email address for self-referral detection. Proofling normalizes that value ephemerally and persists only a project-scoped SHA-256 fingerprint in referral records. Reward qualification, cap, and terms-version outcomes may also be retained for audit and dispute handling.

Authenticated reward responses omit respondent names, emails, testimonial content, private recommendation notes, and referred-person contact details. Proofling records fulfillment only after the workspace or integration confirms an external action already completed; Proofling does not execute the payment or benefit and does not send reward fulfillment webhooks.

Eligible older email-introduction or copy actions may be backfilled only where an explicit opt-in can be matched safely to an active configured project. A legacy backfill does not infer recommendation intent or add referred-person contact details.

You can also contact support@proofling.com if you need help locating or removing a Proofling request or published testimonial.

7. Third-Party Services

We use trusted service providers to operate Proofling. These providers may process information only as needed to provide their services to us.

  • Supabase for authentication, database, and storage infrastructure.
  • Vercel for website and application hosting.
  • Stripe for billing, checkout, subscriptions, and optional Stripe automation metadata.
  • Public customer business websites when a workspace enables logo detection. Proofling requests public page and image assets only and stores a normalized copy rather than hotlinking the detected logo.
  • Mux for direct video uploads, video and audio processing, storage, automatic captions, public playback, and deletion processing.
  • Resend or other email infrastructure for sending product and testimonial request emails.
  • Google and GitHub for OAuth login when you choose those sign-in methods.
  • Google Business Profile APIs and Google Cloud Pub/Sub when an authorized workspace connects eligible profiles to Review Watch. Proofling does not scrape Google reviews.
  • Error monitoring, logging, analytics, or support tools where enabled to operate and improve the Service.

8. Cross-Border Disclosure

Proofling is operated from Australia, but service providers may process information in Australia, the United States, the European Union, and other locations where they or their infrastructure operate.

We take reasonable steps to use providers that maintain appropriate security and privacy protections.

9. Security

We use technical and organizational safeguards such as HTTPS, authentication, access controls, encryption at rest where supported, encrypted integration secrets, and provider security controls.

No internet service is perfectly secure. You are responsible for keeping your account credentials safe and for limiting workspace access to trusted people.

10. Data Retention

We retain account, workspace, customer, campaign, testimonial, billing, and integration records while needed to provide Proofling, comply with legal obligations, resolve disputes, prevent abuse, and maintain business records. Ready videos are retained while the workspace keeps them in Proofling and remains entitled to the relevant service.

When a video response is permanently deleted or its base website-use consent is withdrawn, Proofling removes its public eligibility and queues the associated Mux upload or asset for deletion. Provider deletion is asynchronous and may be retried if it fails; the product may show the item as pending deletion until Mux confirms cleanup. Backups, logs, security records, or cached copies may remain for a limited period where technically necessary or legally required.

External-review content is retained only as permitted by the connected provider. Google Business Profile content used by Review Watch is scheduled for deletion at 29 days and is not retained as a permanent archive. Unchanged refetches do not extend that deadline. Provider-derived content is removed after disconnect under the same policy. Provider-independent workflow facts or irreversible deduplication records are retained only where the provider expressly permits them.

Customer-logo permission requests and immutable decision events may remain as private audit history after a subscription becomes inactive or the current logo record is removed. Public logo access stops after withdrawal, unpublishing, or a completed sync marks the subscription ineligible. Workspace deletion removes associated records and normalized assets, subject to legal, audit, security, backup, log, or cache retention needs.

New referral opportunities use the project’s configured link lifetime, which defaults to 30 days and may be set to no expiry. Existing opportunities created before configurable expiry and eligible legacy backfills may remain no-expiry. Extending a link retains the same signed URL. Referral opportunities, event history, conversions, reward promises, and fulfillment state may be retained for workspace history, security, attribution, disputes, tax, and audit purposes until deleted or no longer needed.

You may request deletion of account or workspace data by contacting support@proofling.com. Some records may be retained where required for security, billing, legal, tax, or audit reasons.

11. Cookies and Similar Technologies

Proofling uses cookies and similar technologies for authentication, security, preferences, CSRF protection, and product operation. Some third-party services may also use cookies as part of authentication, billing, or abuse prevention.

12. Your Rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to the processing of your personal information.

A testimonial recipient may ask the workspace that requested the testimonial, or Proofling support, to withdraw applicable publication consent. Advertising consent and base wall or website-embed consent are administered separately.

To exercise privacy rights, contact support@proofling.com. We may need to verify your identity and, for customer recipient data, may direct you to the business that controls the campaign.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. Material changes may also be notified through the Service or by email.

14. Contact

Questions should be directed to support@proofling.com or Jake Baden North trading as Donkeh Labs (ABN 87 636 703 254), Adelaide, SA 5157, Australia.