Probily Public beta

Privacy Policy

Version 2.0 · effective 2026-05-23. GDPR-aligned. Written to be understood without a lawyer; if anything is unclear, email support@probily.tech — we will explain in normal language.

1. Who we are

Probily («we», «us», «the Operator») — the brand and website at probily.tech — is the data controller for personal data processed by the Service. Contact: support@probily.tech.

We have not appointed a separate Data Protection Officer because we do not meet the GDPR Article 37 thresholds. The Operator handles all DPO functions personally. If you would prefer to escalate a privacy concern, you may also lodge a complaint with your national data-protection authority.

2. What we collect

The Service collects data in the categories below. We collect only what we need to run the Service; we do not collect anything for marketing or for sale.

2.1. Account data

2.2. Inputs & reports you generate

2.3. Project data

2.4. Contribution data

2.5. Public profile data (opt-in)

2.6. Operational telemetry

2.7. Billing data (when paid tiers launch)

We do not collect: location, contacts, device fingerprints, browsing history outside the Service, any analytics from third-party trackers (we do not use Google Analytics, Facebook Pixel, or any similar service).

2.5. Personal data about people named in reports (third parties)

A report may contain personal data about individuals and organisations named in the article you submit. This data is not obtained from those individuals — it comes from the news article you provide and from public, open-source records (Wikipedia / Wikidata, official sanctions and watch-lists, court and regulatory dockets, corporate registries). Where such an individual is an EU/UK data subject, this is personal data obtained from a source other than the data subject within the meaning of GDPR Article 14.

We process it under our legitimate interests (Art. 6(1)(f)) in supporting journalism, research, fact-checking and due diligence; and, for data revealing criminal offences or special categories, under the substantial-public-interest condition (Art. 9(2)(g) / Art. 10 GDPR and the corresponding national provisions). We surface only information already in the public record, always linked to its original public source. Because reports are generated on demand from public sources and may concern a large, unbounded number of people, individually notifying every data subject would involve disproportionate effort; the Article 14 exemption for disproportionate effort therefore applies, and this Policy serves as the public notice of that processing. A named person may still exercise the rights in §6 (including objection and erasure) by contacting us.

3. Legal basis for processing

Under GDPR Article 6 we rely on the following lawful bases:

4. Who we share data with

Probily does NOT sell your data, ever. We share with:

We do not share with marketing partners, analytics vendors, advertising networks, or data brokers.

5. Cookies

Probily uses one essential cookie set by SuperTokens to keep you signed in. We do not use tracking, advertising, or analytics cookies. We do not display a cookie banner because GDPR does not require consent for strictly-necessary cookies.

6. Your rights

Under GDPR you have the right to:

To exercise any right, email support@probily.tech. We respond within 30 days (Art. 12(3)).

7. Data retention

Data Retention
Account email + auth hashKept while your account is active; deleted on request
Private reports + projects + notesKept while your account is active; projects deletable in your workspace, otherwise deleted on request
Public reports + approved contributionsIndefinite (historical record). You may request retraction; we evaluate per case
Captured-source snapshotsWayback's retention (independent of us)
HTTP access logs30 days; aggregated metrics longer
Billing records (when launched)10 years (tax/audit requirement)
Backup snapshots90 days rolling; deleted data clears on next rotation

8. Children

The Service is not directed at children under 16 and we do not knowingly collect personal data from anyone under 16. If you become aware that a child has provided us with personal data, please contact support@probily.tech and we will delete it.

9. International transfers

Probily's servers are hosted in the EU. The processors we use (Anthropic, Paddle) are based in the United States / United Kingdom and rely on the EU Standard Contractual Clauses or equivalent safeguards for any EU-to-US data transfer. Internet Archive is based in the US and operates as a non-profit information service; the URL you submit is the only transferred information.

10. Security

We protect data in transit with TLS (Let's Encrypt) and at rest with database encryption (PostgreSQL with disk-level encryption). Passwords are bcrypt-hashed by SuperTokens. Session cookies are HTTP-only, Secure, SameSite=Lax. Backups are encrypted. We log security events and review them weekly.

If we become aware of a personal-data breach affecting your data, we will notify you within 72 hours (GDPR Art. 34) and describe what happened, what data was affected, and what steps we are taking.

11. Changes to this Policy

Material changes will be posted here with a new effective date and a changelog. We will email active accounts at least 30 days before changes take effect. Continued use of the Service after a change constitutes acceptance.

12. Contact

Data controller: Probily. Privacy questions: support@probily.tech. Postal address available on request.


Changelog