PROVEAiBLE
Community Legal Centres University Clinics Compliance Library
Intake Pricing
Request a demo
Community Legal Centres University Clinics Compliance Library
For Lawyers
IntakePricing
Request a demo

PROVEAiBLE Privacy Policy

Last updated: 7 July 2026  |  Eight LLC · Kosovo

This Privacy Policy explains how Eight LLC ("we", "us", "our"), operator of PROVEAiBLE, collects, uses, stores, and protects personal data when you use our Products. It applies to both PROVEAiBLE Intake (our AI client intake widget for legal organisations) and PROVEAiBLE Desktop (our case-preparation software for individuals and small businesses).

We are committed to complying with the EU General Data Protection Regulation (GDPR) and equivalent applicable privacy laws. Contact us at support@proveaible.com with any questions.

Section 1

Data Controller

The data controller for personal data processed through PROVEAiBLE is: Eight LLC, Kosovo — support@proveaible.com. Eight LLC is established outside the EEA. We are evaluating the appointment of an EU representative under GDPR Art. 27 and will update this policy when one is designated.

Section 2

Our Two Products and Their Different Data Models

PROVEAiBLE operates two products with materially different data architectures.

2.1 PROVEAiBLE Desktop — Local-First Architecture. PROVEAiBLE Desktop is installed on your computer. Case files, documents, evidence, and case notes are stored locally on your machine. We do not upload or retain your case files on our servers. When you use AI analysis features, personal identifying information (names, addresses, dates of birth, document IDs) is redacted on your device before any data is transmitted to an AI provider (Anthropic, OpenAI, or Google, per your BYOK configuration). The AI model receives anonymised text only. PROVEAiBLE does not retain a copy of text sent to the AI provider beyond the duration of the API call.

2.2 PROVEAiBLE Intake — How your information is processed by AI (Bring Your Own Key). Each organisation connects its own AI provider account — an Anthropic, OpenAI, or Google API key (the “Bring Your Own Key” model). AI analysis of your intake and documents is performed through the organisation’s own AI account; PROVEAiBLE does not process your matter content through an AI account of its own. The organisation is the data controller for the matter file it receives.

Before your information is sent to the organisation’s AI provider, PROVEAiBLE replaces personal identifiers in your documents (such as names, addresses and reference numbers) with role tags on its secure server — and the client reviews exactly what is hidden before the matter file is built. Uploaded document images are first processed for text extraction (OCR) by Google Cloud Vision, a PROVEAiBLE sub-processor, before redaction and analysis.

Client intake data is processed transiently and permanently deleted the moment the matter file is delivered to the subscribing organisation. Incomplete sessions (where no matter file is delivered) are purged within 90 days — nothing is kept long-term. We do not retain matter files, and no client PII is stored in our database. The only data we store is the organisation’s configuration (widget settings, branding, delivery address), for the duration of the subscription — never the substance of a client’s matter.

Section 3

Personal Data We Collect

3.1 Account and Billing Data. When you purchase a subscription, Whop Inc. (our Merchant of Record) collects and processes payment information. We receive: your name, email address, subscription tier, and transaction ID. We do not receive or store full payment card details.

3.2 Usage Data. Our website analytics is provided by Plausible Analytics, a privacy-friendly, cookieless tool that collects only aggregate data (page views, referrers, browser and operating-system type, and country) and does not store IP addresses or any data that identifies you individually.

3.3 Website chat enquiries. When you start a conversation in the chat widget on proveaible.com to make an enquiry, we record that session's technical metadata — including your IP address, browser user-agent, the page you started from, the language used, and the messages you send — so that we can operate the chat service, respond to your enquiry, and protect against abuse. Our lawful basis is our legitimate interest in running and securing the service and in responding to enquiries you initiate. (This is separate from the law-firm Intake product, where client data is redacted before any AI sees it and not retained — see Section 2.2.)

3.4 Support Communications. When you contact us at support@proveaible.com, we retain the communication for the purpose of providing support and resolving disputes.

3.5 Data Submitted for Processing. Under Desktop, documents submitted for AI analysis are processed as described in Section 2.1 — PII is redacted on-device and we do not retain copies. Under Intake, intake submissions are processed as described in Section 2.2 — we do not retain matter files after delivery, and incomplete sessions are purged within 90 days.

Section 4

Legal Bases for Processing (GDPR)

  • Contract performance — to deliver the Products you have subscribed to.
  • Legitimate interests — to operate, maintain, and improve the Products and ensure security.
  • Legal obligation — to comply with applicable laws.
  • Consent — where we rely on consent (e.g. marketing communications), you may withdraw at any time.
Section 5

Sub-Processors and Third Parties

We engage the following sub-processors, each bound by appropriate data processing agreements.

AI sub-processors (under the organisation’s own BYOK account):

  • Anthropic (Claude API) — AI text analysis
  • OpenAI (GPT API) — AI text analysis (optional)
  • Google (Gemini API) — AI text analysis (optional)

PROVEAiBLE platform sub-processors:

  • Google Cloud Vision — OCR for document images
  • Render — hosting (US region)
  • Supabase — organisation configuration (eu-west-1, Ireland) — no client matter content
  • Resend — transactional email

Whop Inc. acts as an independent data controller (Merchant of Record) for payment and fraud-prevention purposes; their privacy policy governs data they collect in that capacity. For transfers to sub-processors in the USA, we rely on Standard Contractual Clauses (SCCs) or applicable transfer mechanisms under GDPR Chapter V.

Section 6

Data Retention

  • Account and billing data: retained for the duration of subscription plus 7 years for tax and accounting compliance.
  • Desktop case files: stored locally on your machine only. We hold no copies.
  • Intake matter files: delivered to firm inbox and not retained on PROVEAiBLE servers.
  • Firm configuration data (Intake): retained for the duration of subscription plus 90 days, then deleted.
  • Support communications: retained for 3 years.
  • Usage logs: retained for 90 days then aggregated or deleted.
Section 7

Your Rights Under GDPR

If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights:

  • Right of access — to obtain a copy of the personal data we hold about you.
  • Right to rectification — to have inaccurate data corrected.
  • Right to erasure — to request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction — to request restriction of processing.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is consent-based, to withdraw at any time.

To exercise these rights, email support@proveaible.com. We respond within 30 days. You may also lodge a complaint with your local supervisory authority.

Section 8

Cookies and Tracking

proveaible.com uses minimal cookies. Our website analytics (Plausible) is cookieless and sets no cookies, stores no IP addresses, and uses no personal data — so no analytics consent banner is required. We do not use third-party tracking pixels, advertising cookies, or cross-site tracking tools. The chat / intake widget keeps only the transient session state needed to run an active session; it sets no tracking cookies, and you can clear the session at any time.

Section 9

Security

We implement appropriate technical and organisational measures to protect personal data, including: encryption in transit (TLS), PII redaction before any AI model call (server-side for Intake, on-device for Desktop), and access controls on our infrastructure. In the event of a personal data breach, we will notify affected individuals and relevant authorities as required by applicable law.

Section 10

No Sale of Data and No Training on Customer Data

We do not sell, rent, or trade your personal data to third parties for commercial purposes. PROVEAiBLE does not use your documents, case data, or intake submissions to train AI models. We do not retain document content for any purpose beyond delivering the service.

Section 11

Children's Privacy

PROVEAiBLE is not directed at children under 16. If you believe a child has provided us with personal data, contact us at support@proveaible.com and we will delete it promptly.

Section 12

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email 14 days before taking effect. The current version is always published at proveaible.com.

Section 13

Contact

Data protection enquiries: support@proveaible.com — Eight LLC, Kosovo.

This Privacy Policy is effective as of 7 July 2026.
PROVEAiBLE

AI client intake for community legal centres, university clinics and law firms. Every matter arrives structured, redacted and ready — so the first appointment is about advice, not data entry.

For Community Legal Centres

  • Client Intake
  • See it work
  • Pricing
  • Book a setup call

More from PROVEAiBLE

  • University Clinics
  • For Law Firms
  • Compliance

Company

  • About
  • FAQ

Legal

  • Privacy Policy
  • Terms of Service
  • Refunds
  • Cookies
© 2026 PROVEAiBLE (Eight LLC). All rights reserved. AI can make mistakes. PROVEAiBLE is intake and case-preparation software — not a law firm. It does not provide legal advice and creates no lawyer-client relationship. All output must be reviewed by a qualified person before it is relied on or filed; responsibility for legal decisions rests with you and your legal team.