Privacy Policy
Last updated: 2026-03-30
1. Data Controller
This Privacy Policy applies to ProposalAI, operated by Kerr & Company LLC DBA Outlier ("Company", "we", "us"). We are the data controller for personal information collected through this Service.
2. What We Collect
- Account information: email address, name, company name, and password (hashed)
- Proposal content: job descriptions, client details, and pricing you enter
- Usage analytics: pages visited, features used, session duration
- Payment information: billing details processed by Stripe (we do not store card numbers)
- Communications: support requests, feedback, and email correspondence
3. How We Use Your Data
- Service delivery: generating proposals, managing your account, processing payments
- Service improvement: analyzing usage patterns to improve features
- Communication: sending service updates, receipts, and support responses
- Security: detecting and preventing fraud and unauthorized access
4. Third-Party Services
We share data with the following third-party providers as necessary to operate the Service:
We do not sell your personal information to third parties.
5. Data Retention
Account data is retained while your account is active. Upon deletion request, we will remove your personal data within 30 days, except where retention is required by law. Anonymized analytics data may be retained longer.
6. CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it
- Delete your personal information (subject to legal exceptions)
- Opt-out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
7. GDPR Rights (EU/EEA Residents)
If you are located in the EU or EEA, you have the following rights under the General Data Protection Regulation:
- Access: request a copy of your personal data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your personal data ("right to be forgotten")
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Restriction: request we restrict processing of your data
Our legal basis for processing is primarily contract performance (delivering the Service you subscribed to) and legitimate interests (security, fraud prevention, service improvement).
8. EU AI Act Disclosure
ProposalAI uses artificial intelligence to generate proposal content. In compliance with the EU AI Act:
- AI-generated content is clearly labeled within the application
- Human review is available — you review all proposals before sending
- The AI system does not make binding decisions on your behalf
- You retain full control over the final content sent to your clients
9. Cookies and Tracking
We use session cookies for authentication and analytics cookies (PostHog) for product improvement. You may disable cookies in your browser settings; this may affect Service functionality.
10. Security
We implement industry-standard security measures including TLS encryption in transit, hashed passwords, and access controls. No system is completely secure; please contact us immediately if you suspect unauthorized access to your account.
11. Contact Us
For privacy requests, questions, or to exercise your rights, contact us at:
Kerr & Company LLC DBA Outlier
Email: admin@kerrandcompanyholdings.com