CONFIDENTIAL

DOC-PRIVACY-001 | Updated Sep 2025
REFERENCE

Privacy Policy

Effective Date: September 6, 2025

1. Introduction

PersonaGen Ltd ("we", "us", or "our") operates the PersonaGen API service. This Privacy Policy explains how we collect, use, and protect information when you use our synthetic persona generation service.

Important: PersonaGen generates entirely synthetic personas. We do not collect, store, or process personal data of real individuals. All generated personas are fictional statistical combinations.

2. Information We Collect

Account Information:

  • Email address (for API key generation and service communications)
  • API usage statistics (request counts, error rates, timestamps)
  • Account creation and last access dates

Technical Information:

  • IP addresses (for rate limiting and abuse prevention)
  • User agent strings (for API compatibility)
  • Request metadata (endpoints accessed, response times)

What We Do NOT Collect:

  • Personal information about real individuals
  • Generated persona data (deleted after response)
  • Content of your applications using our API
  • Behavioral tracking or advertising data

3. How We Use Your Information

We use collected information for:

  • Service Provision: Processing API requests and generating synthetic personas
  • Rate Limiting: Enforcing usage limits and preventing abuse
  • Service Improvement: Analyzing usage patterns to improve API performance
  • Communication: Sending service updates and technical notifications
  • Security: Detecting and preventing unauthorized access or abuse
  • Compliance: Meeting legal obligations and responding to valid legal requests

4. Synthetic Data Policy

No Real Personal Data: All personas generated by our API are entirely synthetic. They represent statistical combinations of demographic attributes and do not correspond to real individuals.

Data Sources: Our probability models are derived from publicly available demographic research, census data, and academic studies. No private or personal data is used in model training.

No Data Retention: Generated persona data is not stored after the API response is delivered. Each request generates fresh synthetic data.

5. Information Sharing

We do not sell, trade, or rent your personal information. We may share information in these limited circumstances:

  • Service Providers: Third-party services that help us operate (hosting, analytics, email delivery)
  • Legal Requirements: When required by law, court order, or regulatory request
  • Business Transfer: In the event of a merger, acquisition, or sale of assets
  • Consent: When you provide explicit permission

All service providers are bound by confidentiality agreements and data protection requirements.

6. Data Security

We implement industry-standard security measures:

  • HTTPS encryption for all API communications
  • Secure API key authentication
  • Regular security audits and updates
  • Limited data retention policies
  • Access controls and monitoring

While we take security seriously, no method of transmission over the Internet is 100% secure.

7. Data Retention

We retain information for the following periods:

  • Account Data: Until account deletion or 2 years of inactivity
  • Usage Logs: 12 months for service improvement and security
  • Generated Personas: Not stored - deleted immediately after response
  • Error Logs: 30 days for debugging purposes

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request information about data we hold about you
  • Correction: Update or correct your account information
  • Deletion: Request deletion of your account and associated data
  • Portability: Receive your data in a structured format
  • Objection: Object to certain uses of your information

To exercise these rights, contact us at privacy@personagen.dev.

9. International Data Transfers

Our services are hosted in the United States. If you access our service from outside the US, your information may be transferred to, stored, and processed in the US.

We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses and security measures.

10. Children's Privacy

PersonaGen is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18.

If we become aware that we have collected information from a child under 18, we will delete such information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.

Significant changes will be communicated via email to registered users. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact Information

For questions about this Privacy Policy or our privacy practices, contact us at:

PersonaGen Ltd

Privacy Officer

Email: privacy@personagen.dev

Website: https://personagen.dev

Address: [Company Address - To be updated]