Profusia

Privacy

What Profusia stores, where it lives, how long it is kept, and how each data-protection right maps to something you can actually do in the product. The security half of this picture is at /trust.

What we store, where, and for how long

DataWhere it livesHow long
Documents you publish, and every prior version of themCloudflare R2 (bytes) and D1 (metadata, plus a derived text index so search can read inside documents)Kept until you delete them. Deleting moves them to your workspace trash; nothing is erased until you explicitly purge, or the workspace itself is deleted. The search index follows the document: it leaves search when the document is trashed and is erased when the document is erased.
Datasets behind live pagesCloudflare D1Kept until you delete them (same trash-then-purge rule).
Accounts: email, optional name, salted password hashCloudflare D1Kept while the account has a workspace membership. Erasable on request by a workspace admin (see “Erasure” below).
Sign-in sessions, share links, access keys, connector tokensCloudflare D1 — stored only as hashesUntil they expire or are revoked. The secret itself is never stored.
Audit log (who did what, when)Cloudflare D1400 days, then swept by a daily job.
AI per-call ledger (who asked, which document, tokens, cost)Cloudflare D190 days, then swept. Daily spend aggregates (no personal detail) are kept longer for billing honesty.
Page-view countsCloudflare D1Counted per document per day. Visitors are never identified — no IP addresses or identifiers are stored with views.
Portal visitors: the display name a visitor typed, and their session (as a hash)Cloudflare D1Until the visitor or their portal is revoked, the session expires (90 days), or the workspace is erased. The name is self-reported and unverified; portal opens are counted per day with no IP address or fingerprint.
A deleted workspaceDeletion makes the workspace unreachable immediately, and is reversible by an owner for 30 days. After that, a daily job permanently erases its database rows and stored files.

All of it is hosted on Cloudflare (Workers, R2, D1) — Cloudflare is our infrastructure subprocessor. We run no other datastore.

Subprocessors

That is the whole list. Profusia runs no analytics or advertising service. The Google sync above is the only case in which Profusia authenticates to another platform at all, it happens only if you turn it on, and it only ever writes — Profusia never reads another platform’s data on your behalf.

Your rights, as product actions

Anything a product act doesn't cover: contact us at the address in /.well-known/security.txt — the same contact handles privacy requests until a dedicated privacy address exists, and we say so here rather than inventing one.

California (CCPA/CPRA)

Profusia does not sell personal information and does not share it for cross-context behavioural advertising. There is no “Do Not Sell or Share” mechanism because there is no sale or sharing to opt out of.

Cookies

There is no cookie banner because there is nothing a banner would be consenting to: Profusia sets first-party cookies only, and only to make the page in front of you work — signing you in, remembering where you were working, keeping a password-protected link open once you have answered it, and remembering which version of a shared document your browser last opened so the page can say what changed since. None of them identifies you. No third-party cookies, no trackers, no analytics beacons. Anonymous page views are counted as numbers per document per day; visitors are never identified.

Where processing happens

Cloudflare's network is global; data is stored in Cloudflare's R2 and D1 services under our account. We do not currently offer a regional-pinning guarantee, and this page will say so until we do rather than implying one.

Last reviewed 2026-08-28 Security & trust Report a vulnerability