Proximae Privacy Policy
Effective date: August 14, 2026
This Privacy Policy explains how Proximae, the operator of Proximae (“Proximae,” “we,” “us,” or “our”), collects, uses, shares, and protects personal information when you use our website, applications, workspaces, Share Links, and related services (together, the “Service”).
We have tried to keep this policy practical and readable. If you have questions about your information or this policy, contact us at privacy@proximae.io.
1. The short version
We collect the information needed to operate Proximae, including account details, workspace and review activity, technical and security information, billing records, and information you choose to submit.
We also process files, comments, annotations, approvals, and other content that customers place in Proximae so that we can provide the review and collaboration service.
We use service providers for infrastructure, storage, email, and payments. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or use it for targeted advertising.
We keep information only for as long as reasonably needed for the purposes described here, subject to legal, security, billing, backup, and recordkeeping requirements.
2. When this policy applies
This policy applies when you:
- visit a Proximae website where this policy is linked;
- create or use a Proximae account;
- join or manage a workspace or project;
- receive or accept an invitation;
- access content through a Proximae Share Link;
- comment on, annotate, approve, or download shared work;
- contact support or submit product feedback; or
- purchase or manage a subscription.
A Proximae customer may also upload files or other Customer Content that contains personal information about other people. In that situation, the customer generally decides why that information is placed in Proximae, while we process it to provide the Service. See Section 6: Customer Content and customer-controlled data.
3. Information we collect
Account and profile information
When you create or use an account, we may collect information such as:
- your name;
- email address;
- profile image or avatar;
- account and authentication identifiers;
- sign-in and account-security information; and
- information associated with supported third-party sign-in methods, if you choose to use one.
Passwords and authentication secrets are handled through our authentication systems and are not intended to be stored as readable passwords.
If you upload a profile image, it may be hosted at a publicly accessible image URL so it can be displayed to people who interact with you through Proximae. The URL is not intended to expose private project content.
Workspace, membership, and collaboration information
We process information needed to manage collaboration, such as:
- workspaces and projects you belong to;
- your role, permissions, and project access;
- invitations you send or receive;
- comments, replies, annotations, and attachments;
- approvals and other review actions;
- notification preferences and subscriptions; and
- activity needed to show or operate collaborative features.
Customer Content
Customers may upload or create content such as:
- 3D models and related source files;
- images and videos;
- documents and other supported files;
- asset names, metadata, versions, thumbnails, and derived files;
- comments and annotations;
- review attachments;
- saved camera or viewing information; and
- other material submitted through the Service.
Some Customer Content may contain personal, confidential, commercially sensitive, or proprietary information. The customer controls what it chooses to place in the Service and who it authorizes to access it.
We do not require sensitive personal information as part of ordinary account setup. Customers should avoid placing sensitive personal information in Customer Content unless it is appropriate and lawful for their use of the Service.
Share Link and guest reviewer information
If you access a Share Link without a normal workspace account, we may process information such as:
- the reviewer name you provide;
- your email address if it is required for a feature or if you choose to subscribe to permitted notifications;
- comments, replies, approvals, and other actions you take;
- the Share Link and assets you access;
- scoped session or reviewer-grant information used to keep the review secure; and
- technical or security information related to that access.
Billing and subscription information
If you purchase a paid plan, we may process:
- your plan and subscription status;
- billing period and renewal information;
- organization or workspace associated with the subscription;
- paid-seat or similar subscription quantities;
- payment-provider customer and subscription identifiers;
- invoice, payment status, and transaction metadata; and
- billing contact information you provide.
Payment card details are handled by our payment processor rather than being stored by Proximae as full payment-card numbers.
Technical, security, and usage information
When you use the Service, we may automatically process information such as:
- IP address and similar connection information;
- browser, device, and operating-system information;
- request identifiers, timestamps, routes, and response information;
- sign-in, security, and rate-limit events;
- error messages, diagnostics, and service logs;
- upload, processing, job, and queue status; and
- basic usage information needed to operate, secure, troubleshoot, and improve product performance.
Where practical, we reduce or transform information used for abuse prevention. For example, some anti-abuse records use a salted hash derived from an IP address instead of storing the raw address in that record.
Feedback and support information
If you contact us or submit feedback, we may collect:
- the message you send;
- your account and contact information;
- the page or feature you were using;
- a request or error identifier; and
- technical context that helps us investigate the issue.
4. How we use personal information
We use personal information to:
- create and secure accounts;
- provide authentication and session management;
- create and manage workspaces, projects, memberships, and invitations;
- store, process, convert, optimize, display, and deliver Customer Content;
- operate comments, annotations, approvals, downloads, and Share Links;
- send invitations, account messages, review notifications, security notices, and other transactional communications;
- process subscriptions, payments, renewals, and billing administration;
- enforce plan limits and permissions;
- prevent fraud, abuse, unauthorized access, and attacks;
- troubleshoot errors and maintain reliability;
- respond to support requests and feedback;
- understand and improve how the Service performs;
- comply with legal obligations and valid legal requests; and
- establish, exercise, or defend legal rights when necessary.
We do not use Customer Content simply because it is commercially valuable to our customers. Our processing of Customer Content is tied to providing, securing, maintaining, supporting, and operating the Service.
We do not use personal information for targeted advertising or for automated profiling that produces legal or similarly significant effects about individuals.
5. Consent and legal bases where required
Different privacy laws use different legal frameworks. Where a law requires consent, we seek consent in a form appropriate to the information and purpose. Where a law requires another legal basis for processing, the basis depends on the context and may include:
- providing the Service or taking steps you request before entering into a contract;
- our legitimate interests in operating, securing, troubleshooting, and improving the Service where that basis is recognized and appropriate;
- complying with legal obligations;
- consent where we specifically ask for it; or
- protecting important interests or establishing, exercising, or defending legal rights where applicable law permits the processing.
The fact that you use Proximae does not mean every processing activity is based on consent.
6. Customer Content and customer-controlled data
Proximae is often used by studios, businesses, teams, and other organizations to review their own work.
When a customer uploads personal information about another person as part of Customer Content, the customer is responsible for deciding whether it is lawful and appropriate to place that information in Proximae and for providing any notices or obtaining any permissions required by law.
For personal information contained in Customer Content that we process on a customer’s behalf, Proximae generally acts as a service provider or processor rather than deciding the customer’s underlying purpose for collecting that information.
If you want to exercise a privacy right relating to information a Proximae customer placed in its workspace, you may need to contact that customer directly. We will support customers with appropriate requests where required by applicable law and our agreement with them.
If a business customer is subject to a law that requires specific data-processing terms, it should contact us before using Proximae to process regulated personal information that requires those terms. We can enter into appropriate additional terms where legally required and mutually applicable.
7. Service providers
We use third parties to help provide the Service. Depending on the feature and deployment, these may include providers for:
- application hosting and background processing, such as Railway;
- database infrastructure, such as Neon;
- object storage, content delivery, and network services, such as Cloudflare;
- transactional email delivery, such as Resend; and
- payment processing and subscription billing, such as Stripe.
These providers process information for the services they provide to us, subject to their contracts and applicable law.
Our providers and infrastructure may change as Proximae develops. We will update this policy when a change materially affects how personal information is handled.
8. When we share information
We may disclose personal information in the following situations:
With people you or your organization authorize
Information may be visible to workspace owners, administrators, project members, reviewers, or Share Link recipients according to the permissions and sharing choices configured in the Service.
For example, a comment may show the commenter’s display identity to other people who can access the same review context.
With service providers
We provide information to infrastructure, storage, email, payment, security, and other vendors where needed for them to perform services for us.
For legal and safety reasons
We may disclose information when we reasonably believe disclosure is required by law or valid legal process, or when reasonably necessary to protect the rights, safety, and security of Proximae, our users, or others.
Where legally permitted, we may challenge requests that we believe are invalid, overly broad, or inappropriate.
During a business transaction
If Proximae is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, information may be disclosed as part of evaluating or completing that transaction, subject to appropriate confidentiality and legal requirements.
At your direction
We may disclose information when you ask us to do so or intentionally use a feature designed to share it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising.
9. International processing
Proximae is operated from Canada, but our infrastructure and service providers may process or store information in Canada, the United States, or other countries where they operate.
As a result, personal information may be subject to the laws of those jurisdictions and may be lawfully accessible to courts, law-enforcement bodies, or other authorities there.
Where applicable law requires safeguards for an international transfer, we will use an appropriate legal mechanism or contractual protection when that law applies to our processing.
10. Cookies and similar local technologies
Proximae uses cookies or similar browser technologies where needed to operate the Service. These can include:
- authentication and session cookies;
- security and anti-abuse information;
- scoped Share Link or reviewer access grants; and
- settings needed to maintain your session or preferences.
These technologies are primarily used to provide requested functionality and keep access secure.
We do not currently use cookies for third-party behavioral advertising. If we later introduce non-essential analytics, advertising, or similar tracking that requires additional notice or consent, we will update our practices and provide controls where required by law.
11. Email and notifications
We may send service-related communications such as:
- account verification and security messages;
- workspace or project invitations;
- password and authentication messages;
- billing and subscription notices;
- comments, approvals, and review notifications you are entitled or subscribed to receive; and
- important changes affecting the Service or our legal terms.
Some notification categories can be controlled through product preferences where available.
If we send marketing communications, we will provide any opt-out mechanism required by applicable law. Opting out of marketing does not prevent us from sending necessary transactional or security communications.
12. How long we keep information
We keep personal information only as long as reasonably necessary for the purpose for which it was collected, including providing the Service, maintaining security and reliability, satisfying legal or accounting requirements, resolving disputes, and enforcing agreements.
Retention periods vary by type of information. For example:
- account and workspace information is generally kept while the relevant account or workspace remains active and for a reasonable period afterward;
- Customer Content is generally kept until it is deleted through the applicable workspace, asset, project, or account lifecycle;
- if an individual leaves an organization-controlled workspace, comments, approvals, activity records, and other workspace business records may remain with that workspace even after the individual loses access or closes a personal account;
- temporary upload and processing information may be removed after it is no longer needed;
- billing and transaction records may be retained to meet tax, accounting, fraud-prevention, and legal requirements;
- security and operational records are kept according to limited retention schedules appropriate to their purpose; and
- backups may retain deleted information for a limited period before being overwritten or removed.
Deleting content from the user interface may start an asynchronous deletion process rather than removing every copy instantly.
We may retain limited information after deletion where required by law or reasonably necessary for security, fraud prevention, dispute resolution, or enforcement of our agreements.
13. How we protect information
We use administrative, technical, and organizational measures intended to protect personal information and Customer Content. Depending on the data and feature, these measures include access controls, authentication, private storage, scoped permissions, short-lived or limited-access links, service authentication, logging controls, and other security practices.
Proximae is designed so that normal private project files are not made publicly available simply by being uploaded. Access to private stored files is mediated through the Service and time-limited access mechanisms.
No system can guarantee perfect security. You are also responsible for protecting your credentials and for using workspace permissions and Share Links appropriately.
If a security incident affects personal information, we will provide notices to affected people or authorities where applicable law requires us to do so.
14. Your privacy choices and rights
Depending on where you live, whether the applicable law applies to Proximae, and the circumstances of the request, you may have rights to:
- know how your personal information is collected and used;
- request access to personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- request deletion of information in circumstances where the law provides that right;
- withdraw consent where processing is based on consent;
- receive certain information in a portable format;
- object to or restrict certain processing where applicable law provides that right;
- appeal our response to a privacy request where applicable law provides an appeal right;
- complain to an applicable privacy or data-protection authority; and
- challenge our compliance with applicable privacy law.
These rights are not absolute, and exceptions may apply. For example, we may need to verify your identity, retain information required by law, protect another person’s rights, preserve an organization’s legitimate business records, or decline a request that the law does not require us to fulfill.
To make a privacy request, contact privacy@proximae.io. Please provide enough information for us to identify the relevant account or data without sending unnecessary sensitive information.
If the information is controlled by a Proximae customer rather than by Proximae itself, we may direct you to that customer and assist it as appropriate.
US state privacy rights
Some US states provide additional privacy rights when a business meets the law’s applicability thresholds. If such a law applies to Proximae and to your information, we will honor the rights required by that law.
Proximae does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use it for automated profiling that produces legal or similarly significant effects. If those practices change, we will update this policy and provide any required choices or opt-outs.
15. Children
Proximae is a professional collaboration service and is not directed to children. You must be at least 18 years old to create a Proximae account.
If you believe a child has provided personal information to us improperly, contact privacy@proximae.io.
16. Changes to this policy
We may update this Privacy Policy as the Service, our providers, or legal requirements change.
If a change materially affects how we collect, use, or disclose personal information, we will provide an appropriate notice and obtain consent where applicable law requires it.
The effective date at the top tells you when this version became effective.
17. Contact and privacy questions
For privacy questions, requests, or complaints, contact:
Privacy contact Email: privacy@proximae.io
For general product or account support, contact support@proximae.io.
If you are not satisfied with our response, you may also have the right to contact the privacy or data-protection authority that applies where you live.