Last updated: 7 July 2026 | Eight LLC · Kosovo
This Privacy Policy explains how Eight LLC ("we", "us", "our"), operator of PROVEAiBLE, collects, uses, stores, and protects personal data when you use our Products. It applies to both PROVEAiBLE Intake (our AI client intake widget for legal organisations) and PROVEAiBLE Desktop (our case-preparation software for individuals and small businesses).
We are committed to complying with the EU General Data Protection Regulation (GDPR) and equivalent applicable privacy laws. Contact us at support@proveaible.com with any questions.
The data controller for personal data processed through PROVEAiBLE is: Eight LLC, Kosovo — support@proveaible.com. Eight LLC is established outside the EEA. We are evaluating the appointment of an EU representative under GDPR Art. 27 and will update this policy when one is designated.
PROVEAiBLE operates two products with materially different data architectures.
2.1 PROVEAiBLE Desktop — Local-First Architecture. PROVEAiBLE Desktop is installed on your computer. Case files, documents, evidence, and case notes are stored locally on your machine. We do not upload or retain your case files on our servers. When you use AI analysis features, personal identifying information (names, addresses, dates of birth, document IDs) is redacted on your device before any data is transmitted to an AI provider (Anthropic, OpenAI, or Google, per your BYOK configuration). The AI model receives anonymised text only. PROVEAiBLE does not retain a copy of text sent to the AI provider beyond the duration of the API call.
2.2 PROVEAiBLE Intake — How your information is processed by AI (Bring Your Own Key). Each organisation connects its own AI provider account — an Anthropic, OpenAI, or Google API key (the “Bring Your Own Key” model). AI analysis of your intake and documents is performed through the organisation’s own AI account; PROVEAiBLE does not process your matter content through an AI account of its own. The organisation is the data controller for the matter file it receives.
Before your information is sent to the organisation’s AI provider, PROVEAiBLE replaces personal identifiers in your documents (such as names, addresses and reference numbers) with role tags on its secure server — and the client reviews exactly what is hidden before the matter file is built. Uploaded document images are first processed for text extraction (OCR) by Google Cloud Vision, a PROVEAiBLE sub-processor, before redaction and analysis.
Client intake data is processed transiently and permanently deleted the moment the matter file is delivered to the subscribing organisation. Incomplete sessions (where no matter file is delivered) are purged within 90 days — nothing is kept long-term. We do not retain matter files, and no client PII is stored in our database. The only data we store is the organisation’s configuration (widget settings, branding, delivery address), for the duration of the subscription — never the substance of a client’s matter.
3.1 Account and Billing Data. When you purchase a subscription, Whop Inc. (our Merchant of Record) collects and processes payment information. We receive: your name, email address, subscription tier, and transaction ID. We do not receive or store full payment card details.
3.2 Usage Data. Our website analytics is provided by Plausible Analytics, a privacy-friendly, cookieless tool that collects only aggregate data (page views, referrers, browser and operating-system type, and country) and does not store IP addresses or any data that identifies you individually.
3.3 Website chat enquiries. When you start a conversation in the chat widget on proveaible.com to make an enquiry, we record that session's technical metadata — including your IP address, browser user-agent, the page you started from, the language used, and the messages you send — so that we can operate the chat service, respond to your enquiry, and protect against abuse. Our lawful basis is our legitimate interest in running and securing the service and in responding to enquiries you initiate. (This is separate from the law-firm Intake product, where client data is redacted before any AI sees it and not retained — see Section 2.2.)
3.4 Support Communications. When you contact us at support@proveaible.com, we retain the communication for the purpose of providing support and resolving disputes.
3.5 Data Submitted for Processing. Under Desktop, documents submitted for AI analysis are processed as described in Section 2.1 — PII is redacted on-device and we do not retain copies. Under Intake, intake submissions are processed as described in Section 2.2 — we do not retain matter files after delivery, and incomplete sessions are purged within 90 days.
We engage the following sub-processors, each bound by appropriate data processing agreements.
AI sub-processors (under the organisation’s own BYOK account):
PROVEAiBLE platform sub-processors:
Whop Inc. acts as an independent data controller (Merchant of Record) for payment and fraud-prevention purposes; their privacy policy governs data they collect in that capacity. For transfers to sub-processors in the USA, we rely on Standard Contractual Clauses (SCCs) or applicable transfer mechanisms under GDPR Chapter V.
If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights:
To exercise these rights, email support@proveaible.com. We respond within 30 days. You may also lodge a complaint with your local supervisory authority.
proveaible.com uses minimal cookies. Our website analytics (Plausible) is cookieless and sets no cookies, stores no IP addresses, and uses no personal data — so no analytics consent banner is required. We do not use third-party tracking pixels, advertising cookies, or cross-site tracking tools. The chat / intake widget keeps only the transient session state needed to run an active session; it sets no tracking cookies, and you can clear the session at any time.
We implement appropriate technical and organisational measures to protect personal data, including: encryption in transit (TLS), PII redaction before any AI model call (server-side for Intake, on-device for Desktop), and access controls on our infrastructure. In the event of a personal data breach, we will notify affected individuals and relevant authorities as required by applicable law.
We do not sell, rent, or trade your personal data to third parties for commercial purposes. PROVEAiBLE does not use your documents, case data, or intake submissions to train AI models. We do not retain document content for any purpose beyond delivering the service.
PROVEAiBLE is not directed at children under 16. If you believe a child has provided us with personal data, contact us at support@proveaible.com and we will delete it promptly.
We may update this Privacy Policy from time to time. Material changes will be communicated by email 14 days before taking effect. The current version is always published at proveaible.com.