Privacy Policy - CuriousBox AI Inc.
Effective Date: March 6th, 2026CuriousBox AI Inc. ("CuriousBox AI," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our websites, including www.prode.ai, and related services (collectively, the "Service").
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
IMPORTANT: BY ACCESSING OR USING THE SERVICE, YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT YOUR CONTINUED USE OF THE SERVICE CONSTITUTES YOUR ONGOING CONSENT TO THE COLLECTION, PROCESSING, USE, AND SHARING OF YOUR INFORMATION IN ACCORDANCE WITH THIS PRIVACY POLICY.
Legal Bases for Processing
We rely on various legal bases to process your information lawfully, including:
Performance of Contract
Processing necessary to provide the Service and fulfill our obligations under our Terms of Service or other agreements with you.
Legitimate Interests
Processing necessary for our legitimate interests or those of third parties, provided these interests are not overridden by your rights and freedoms. These legitimate interests include providing, improving, and personalizing the Service, marketing, and research.
Compliance with Legal Obligations
Processing necessary to comply with applicable laws, regulations, court orders, or other legal requirements.
Consent
Processing based on your specific consent, such as for certain marketing communications or where otherwise required by law.
Vital Interests
In rare circumstances, processing may be necessary to protect someone's vital interests.
Where we rely on consent, you have the right to withdraw consent at any time, though this will not affect the lawfulness of processing based on consent before its withdrawal.
Information We Collect
Personal Information
We may collect the following categories of personal information.
Account Information
When you register for an account, we collect your name, email address, and account credentials.
Billing Information
For paid subscriptions, payment information is processed by our trusted third-party payment processor. We receive limited transaction data but do not directly collect or store your credit card details.
Profile Information
Information you provide in your user profile, such as job title, employer, professional background, and profile picture.
Usage Information
Information about how you use our Service, including features accessed, time spent, and actions taken.
Communication Data
Records of your communications with us, including support requests, feedback, and survey responses.
Technical Information
Device Information
Information about your device, including IP address, device type, operating system, and browser type.
Log Data
Information that your browser automatically sends whenever you visit our website or use our Service, including access times, pages viewed, and referring websites.
Cookies and Similar Technologies
Information collected through cookies, web beacons, and similar tracking technologies. For more information, please see our Cookie Policy.
Code and Content Information
User Content
We collect code, text, and other materials you input, upload, or otherwise submit to the Service.
Interactions
We collect information about your interactions with our AI features, including prompts, queries, and selections you make.
Project Information
Data about your projects, repositories, and codebase structure as necessary to provide our Service.
Important Codebase Protections
- We never train any AI models using your codebase or repository content.
- We never share your codebase with any third parties, partners, or external entities.
- We only require read-only access to your repositories through secure OAuth tokens.
- Repository connections are explicitly authorized and can be revoked at any time.
How We Use Your Information
To Provide Our Service
- Creating and managing your account
- Delivering our AI-powered codebase intelligence and knowledge layer services
- Processing transactions and managing subscriptions
- Providing customer support
- Sending service-related communications
To Improve Our Service
Analyzing usage patterns to enhance functionality. Debugging and fixing issues. Developing new features and capabilities. Training and improving our AI models (we never use your codebase or repository content for training).
For Legal and Security Purposes
- Enforcing our Terms of Service
- Protecting against malicious, deceptive, or fraudulent activity
- Complying with legal obligations
- Establishing, exercising, or defending legal claims
Codebase Security and Access
Repository Access
When you connect repositories to our knowledge layer service, we only request and maintain read-only access permissions. Any repository connection must be explicitly authorized by an administrator within your organization.
No Training on Your Code
We never use your codebase, repository content, or any proprietary code you provide to train our AI models or any machine learning systems. Your code remains exclusively yours.
No Third-Party Sharing
We never share, sell, license, or otherwise distribute your codebase or repository content to any third parties, including other customers, partners, or service providers.
Analysis vs. Training
While we analyze your codebase to create contextual understanding for our knowledge layer service, this analysis is used solely to enhance your codebase intelligence experience and is never used for model training.
For Marketing and Communication
- Sending promotional communications (subject to your preferences)
- Informing you about new features, updates, and offers
- Conducting surveys and collecting feedback
Marketing Communications
We may send you marketing communications about our products and services that we believe may interest you. The legal basis for this processing is either consent or our legitimate interests, depending on your jurisdiction.
In regions where express opt-in consent is required by law (such as the European Economic Area, United Kingdom, and certain other jurisdictions), we will only send marketing communications when you have explicitly opted in.
You can opt out of receiving marketing communications at any time by:
- Clicking the "unsubscribe" link in marketing emails
- Adjusting your communication preferences in your account settings
- Contacting us at contact@prode.ai
Please note that even if you opt out of marketing communications, we may still send you service-related communications that are necessary for the administration of your account or to fulfill our contractual obligations.
Disclosure of Your Information
We may share your personal information with the following categories of recipients:
Service Providers
We may share your information with third-party vendors, consultants, and other service providers who need access to such information to carry out work on our behalf, such as:
- Cloud hosting providers
- Payment processors
- Analytics services
- Customer support services
All service providers are contractually obligated to use your information solely as necessary to provide their services to us and in compliance with applicable privacy laws.
Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your information may be transferred as part of that transaction. We will notify you of any such change.
Legal Requirements
We may disclose your information where required by law or if we reasonably believe that such action is necessary to:
- Comply with legal obligations or valid legal process
- Protect the rights, property, or safety of CuriousBox AI, our users, or others
- Prevent or investigate possible wrongdoing
- Enforce our Terms of Service
With Your Consent
We may share your information with third parties when you have given us your consent to do so.
Data Security
We implement commercially reasonable technical and organizational measures designed to protect your information. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your information, we cannot guarantee its absolute security.
We aim to maintain information security by protecting data against:
- Unauthorized access
- Improper disclosure
- Alteration or destruction
However, due to the inherent nature of the Internet and data transmission, we cannot guarantee that unauthorized access, hacking, data loss, or other breaches will never occur. We encourage you to take steps to protect your own personal information, such as choosing strong passwords and keeping them confidential.
If we become aware of a data breach that is reasonably likely to result in a risk to your rights and freedoms, we will take measures to notify affected users as may be appropriate under the circumstances and as may be required under applicable law. Our notification may include email notification, prominent website notices, or other appropriate means.
Data Retention
We retain different categories of information for different periods based on our business needs and legal requirements:
Account Information
We typically retain your account information for up to 7 years after account closure to comply with tax, accounting, and other legal requirements.
Usage Data
We typically retain usage data for up to 2 years to improve and optimize our Service.
Technical Logs
We typically retain logs and technical information for up to 90 days for security and troubleshooting purposes.
Marketing Data
We retain marketing preferences until you opt out or after 3 years of account inactivity.
Billing Information
We retain billing records for up to 7 years to comply with tax and accounting requirements.
These retention periods may be extended if:
- We are required to retain the information for legal reasons (such as tax or accounting regulations)
- There is an outstanding issue, claim, or dispute requiring us to keep the relevant information
- The information is needed for legitimate business purposes, such as fraud prevention
When we no longer need the information, we will securely delete or anonymize it.
International Data Transfers
Your information may be transferred to, stored, and processed in countries other than the one in which you reside. In particular, our servers are located in the United States, and our service providers may be located in various countries worldwide.
When we transfer personal information outside of your jurisdiction, we implement appropriate safeguards to protect your information, which may include:
- Standard contractual clauses approved by relevant regulatory authorities
- Binding corporate rules
- Adequacy decisions (where transfers are to countries that have been deemed to provide an adequate level of protection)
- Derogations for specific situations as permitted by applicable law
- Any other legally approved mechanisms that are recognized as providing adequate protection
We maintain flexibility in our data transfer mechanisms to adapt to changing regulatory landscapes and to ensure ongoing compliance. By using our Service, you consent to these transfers in accordance with this Privacy Policy.
Specific Privacy Provisions for India
For users located in India, we comply with applicable provisions of India's data protection laws, including the Digital Personal Data Protection Act, 2023 ("DPDPA") and related regulations. Your personal information is processed in accordance with these laws.
Data Localization and Cross-Border Transfers
In accordance with Indian law, we may store certain categories of personal data on servers within India and/or implement approved mechanisms for cross-border transfers of Indian users' personal data. These mechanisms comply with requirements established by relevant Indian authorities.
Consent Requirements
Where required by Indian law, we obtain specific, clear consent for collecting and processing certain categories of personal data. You have the right to withdraw this consent at any time, subject to legal requirements.
Data Principal Rights
As a "data principal" under Indian law, you have certain rights regarding your personal data, including the right to:
- Confirm whether we process your personal data
- Access your personal data
- Correct inaccurate personal data
- Erase your personal data in certain circumstances
- Nominate another person to exercise your rights in case of incapacity or death
To exercise these rights, please contact us at contact@prode.ai.
Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
Access and Portability
You have the right to request a copy of the personal information we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.
Correction
You have the right to request that we correct any inaccurate or incomplete information we hold about you.
Deletion
You have the right to request the deletion of your personal information in certain circumstances. Please note that we may need to retain certain information for record-keeping purposes, to complete transactions, or to comply with our legal obligations.
Restriction and Objection
You have the right to request that we restrict the processing of your personal information. You also have the right to object to the processing of your personal information in certain circumstances.
Consent Withdrawal
Where we rely on your consent to process your personal information, you have the right to withdraw your consent at any time.
Exercise Your Rights
To exercise these rights, please contact us at contact@prode.ai.
Do Not Track Signals
Some browsers feature a "Do Not Track" (DNT) setting that requests that websites not track your browsing activity. While we strive to honor your privacy preferences, there is currently no industry standard for responding to DNT signals. As such, we do not currently respond to DNT signals.
Children's Privacy
Our Service is not directed to children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us at contact@prode.ai so that we can take appropriate action.
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to:
- Know what personal information is being collected about you
- Know whether your personal information is sold or disclosed and to whom
- Opt-out of the sale of your personal information
- Access your personal information
- Request deletion of your personal information
- Non-discrimination for exercising your privacy rights
To exercise these rights, please contact us at contact@prode.ai.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time in response to changing legal, technical, or business developments. When we update our Privacy Policy, we will post the updated version and change the Effective Date above. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated terms.
For significant changes, we will provide additional notice, such as adding a statement to our website's homepage or sending you an email notification.
Force Majeure
We will not be liable for any failure to perform our obligations under this Privacy Policy where such failure results from any cause beyond our reasonable control, including but not limited to, natural disasters, pandemics, cyber-attacks, mechanical, electronic, or communications failure or degradation.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
CuriousBox AI Inc.
Attn: Privacy Team
Email: contact@prode.ai
For data subjects in the European Union, CuriousBox AI Inc. is the data controller responsible for your personal information. If you have any concerns about how we process your personal information, you also have the right to lodge a complaint with your local data protection authority.