Legal

Privacy Policy

What information Proception collects, why we collect it, who we share it with, and the choices you have.

Effective
August 2, 2026
Last updated
August 2, 2026

Proception, Inc. (“Proception”, “we”, “us”) builds humanoid robotic hands and the software that runs them. This policy explains what we collect when you visit our website, buy or operate our products, use our developer tools, apply for a job, or contact us — and what you can ask us to do about it.

We have written it to be read, not skimmed past. If anything here is unclear, or if you want to know specifically what we hold about you, email us and ask.

1. Who we are and what this covers#

Proception, Inc. is a Delaware corporation with offices in Mountain View, California. We are the party responsible for the information described here.

This policy applies to:

  • our public website and online store at proception.ai
  • accounts you create with us, including customer, developer, and applicant accounts
  • our developer portal, documentation, SDKs, and APIs
  • the hardware products we sell and the firmware and software that operate them
  • sales enquiries, quotes, orders, support requests, and other correspondence with us

It does not apply to third-party websites or services we link to, which have their own policies.

2. Two different roles: our data and our customers’ data#

It matters which of two things is happening, because your rights run against a different party in each case.

We decide (we are the controller)
Information about visitors to our site, people who buy from us, developers who use our tools, applicants who apply to us, and the operation of the products we sell. This policy governs it.
Our customer decides (we are the processor)
If an organisation deploys our hands in its own facility and its own people or end users generate personal data through that deployment, that organisation decides what is collected and why. We handle it on their instructions and under our agreement with them. Their privacy notice — not this one — is the one that describes it, and requests about that data should go to them. Business customers can request a data processing agreement from us.

3. Information we collect#

Information you give us

Identity and contact details
Name, email address, phone number, company, job title, and postal or shipping address.
Account information
Sign-in credentials (we store a hash of your password, never the password itself), any second-factor enrolment, your role and permission level, profile details, and language and theme preferences.
Purchase and order information
Quotes, orders, invoices, purchase orders, billing and shipping addresses, tax details, the units allocated to your order, and their serial numbers. Card details go directly to our payment processor; see “Payments” below.
Application materials
If you apply for a role: your résumé or CV, cover letter, links you provide, work authorisation answers, and anything else you choose to include.
Agreements and signatures
When you sign an order form, sale terms, or licence electronically, we record your name, title, email, the document version you signed, your signature, the timestamp, and the IP address the signature came from — because that record is what makes the signature provable.
Correspondence and support
Messages, enquiries, feedback, bug reports, and support tickets, including any files or screenshots you attach.

Information we collect automatically

Device and connection data
IP address, approximate location derived from it, browser and operating system, device type, language, and referring page.
Usage data
Pages and documentation you view, files and SDK releases you download, API calls and their volume, features you use, and errors you hit.
Security and audit logs
Sign-in attempts and their outcome, session and token activity, permission changes, and administrative actions. We keep these to detect and investigate abuse, and because some of them we are required to keep.
We do not ask for, and ask you not to send us, government identification numbers, health information, financial account numbers, or other sensitive categories of data unless we have specifically told you it is needed for a transaction.

4. Product and device telemetry#

Our hardware and its software report on themselves. When a unit is connected, it may transmit operational, diagnostic, performance, sensor, calibration, firmware, usage, and error data — what we call telemetry — to us and to services acting for us.

We use telemetry to:

  • operate and support the product, and diagnose faults in a specific unit
  • honour warranty and service obligations, including tracing a failure to a component or build
  • measure reliability and safety across the fleet, and detect a defect pattern before it reaches more units
  • improve and develop our products, firmware, and models

Telemetry is about a machine, not a person, and normally does not identify anyone. Where it can be linked to a person — because a unit is assigned to a named operator, or because a log carries an account identifier — we treat that link as personal information under this policy.

If you deploy our products around your own personnel or end users, you are the one who has to tell them about this collection and obtain any consent the law requires. Our commercial agreements say so as well, and we cannot do it on your behalf because we do not know who they are.

We also produce aggregated and de-identified statistics from telemetry — fleet-wide reliability figures, usage distributions, model training data. Once data is genuinely aggregated or de-identified it is no longer personal information, we own it, and we may use and disclose it without restriction. We do not attempt to re-identify it.

5. Where information comes from#

  • directly from you, when you fill in a form, create an account, place an order, or write to us
  • automatically from your browser, our products, and our systems as described above
  • from your employer or a colleague, when they add you to an order, an account, or a support thread
  • from our service providers — for example a payment confirmation from our payment processor or a delivery scan from a carrier
  • from publicly available sources, when we research a prospective business customer or verify a company

6. How we use information#

  • to provide, operate, secure, and maintain our website, store, accounts, and developer tools
  • to process quotes, orders, payments, shipments, and returns, and to keep the records that go with them
  • to build, allocate, ship, service, and support the specific units you buy, and to administer warranties
  • to deliver firmware and software updates, and to tell you when one matters
  • to answer enquiries and provide support
  • to evaluate job applications and administer hiring
  • to detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms
  • to understand how our site and products are used, and to improve and develop them
  • to send you product, service, and company updates you have asked for, and to tell you about material changes to our terms or this policy
  • to comply with legal obligations, enforce our agreements, and establish or defend legal claims

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

8. Automated processing and AI#

We use automated tools, including large language models, in a few specific places. Where we do, we tell you here:

Job applications
We use an automated tool to read and score submitted résumés against the requirements of the role, which helps us review every application rather than only the first ones to arrive. A score is an input, not a decision: no application is rejected by the tool alone, a person reviews the candidates, and hiring decisions are made by people. You may ask us for the outcome of an automated review of your application and ask a person to reconsider it.
Support and internal operations
We use automated tools to summarise, classify, and route internal work such as tickets, build failures, and documentation. Where these touch your correspondence, they operate on our own systems under contract, and their output is reviewed by our staff.

We do not use these tools to make decisions with legal or similarly significant effects on you without human involvement.

9. Cookies and similar technologies#

We use a small number of cookies and local storage entries:

Strictly necessary
Keeping you signed in, protecting sessions and forms against forgery, enforcing rate limits, and routing requests. These cannot be switched off without breaking the site.
Preferences
Remembering choices such as light or dark theme and language.
Analytics
Understanding aggregate traffic and which documentation is useful. We keep this minimal and do not use it to build advertising profiles.

You can block or delete cookies in your browser, and you can send a Global Privacy Control or “Do Not Track” signal. We honour Global Privacy Control where we are required to. Blocking strictly necessary cookies will stop you signing in.

We do not run third-party advertising networks on our site.

10. When we share information#

We share personal information only in these situations:

Service providers
Companies that run parts of our operation for us, under contracts that limit them to our instructions and require them to protect the data. The categories are listed in the next section.
Your own organisation
If you use our products or services through your employer, we may share account, order, unit, and support information with the people at that organisation who administer the relationship.
Professional advisers
Our lawyers, accountants, auditors, and insurers, where they need it and are bound to confidentiality.
Legal and safety
Where we are legally required to, or where we reasonably believe disclosure is necessary to investigate suspected fraud or abuse, enforce our terms, protect our rights or property, or protect someone’s safety. Where we may lawfully do so, we will tell you first.
Corporate transactions
In connection with financing, a merger, an acquisition, a reorganisation, or a sale of assets. Any acquirer remains bound by this policy for information it receives, or must give you notice before changing it.

11. Service providers we rely on#

We keep this list current rather than vague, so you can see who actually touches the data. All are bound by contract and process only on our instructions.

Website hosting and delivery
Vercel — serves our public website and store.
Databases and authentication
Supabase — accounts, sign-in, and the records behind the website and store.
File storage
Amazon Web Services (S3) — uploaded files, including résumés, documents, media, and software releases.
Payments
Stripe — checkout, cards, and invoicing. Card numbers go to Stripe, not to us.
Email
Microsoft 365 and Amazon Web Services (SES) — transactional and business email.
AI processing
Anthropic — the model behind the automated review described above. Our agreement does not permit our data to be used to train their models.
Work tracking
Linear — support, feedback, and engineering tickets, which may contain your correspondence.
Shipping
Carriers and freight forwarders — the name, address, and contact details needed to deliver an order.

A material part of our internal systems runs on hardware we operate ourselves, reachable only over our private network. Data held there is not exposed to the public internet.

12. How long we keep information#

We keep personal information only as long as we need it for the purpose we collected it, then delete or de-identify it. In practice:

Account information
For as long as your account is active, and for a reasonable period afterwards so we can honour warranties, resolve disputes, and meet our obligations.
Orders, invoices, and signed agreements
For as long as tax, accounting, warranty, and limitation-period requirements demand — typically seven years after the transaction.
Unit and service records
For the life of the unit and afterwards. A hand’s build, allocation, service, and warranty history is a safety and traceability record; we do not delete it while units are in the field.
Application materials
For up to two years after a decision, so we can consider you for future roles and answer questions about the process. Ask us and we will delete them sooner.
Telemetry
Detailed records for an operational window, after which they are archived or reduced to aggregated and de-identified statistics that we keep indefinitely.
Security and audit logs
For a limited period appropriate to investigating incidents, and longer where a specific incident or legal obligation requires it.
Correspondence
For as long as needed to handle the matter and keep a record of what we agreed.

13. How we protect information#

The measures we take include encryption in transit, encryption of stored files, database-level access rules that restrict every record to the people entitled to see it, least-privilege staff access reviewed against role, multi-factor authentication on sensitive functions, private-network-only access to internal systems, audit logging of administrative action, and immediate session revocation when an account is disabled.

You have a part in this too: use a unique password, turn on a second factor where we offer it, keep your API keys and tokens secret, and tell us promptly if you think an account or credential has been compromised.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and any regulator as the law requires.

14. International transfers#

We are based in the United States and our systems and most of our service providers are located there. We also operate an office in China that supports manufacturing and supply chain, and we work with suppliers and carriers in other countries.

If you are outside the United States, using our services means your information will be transferred to and processed in the United States and other countries, whose privacy laws may differ from your own. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission’s standard contractual clauses and the UK addendum. Ask us and we will describe the safeguards that apply to a specific transfer.

15. Your privacy rights#

Depending on where you live, you may have the right to:

  • know what personal information we hold about you and why, and get a copy of it
  • correct information that is inaccurate or incomplete
  • delete information we no longer have a valid reason to keep
  • receive your information in a portable format, or have us send it to someone else
  • object to or restrict certain processing, including processing based on our legitimate interests
  • withdraw consent you previously gave
  • opt out of marketing email at any time, using the unsubscribe link or by writing to us
  • not be discriminated against for exercising any of these rights
  • complain to your data protection authority — and, in the EEA or UK, to do so without contacting us first, though we would rather you gave us the chance to fix it

To exercise a right, email contact@proception.ai and tell us what you want. We will verify your identity — usually by confirming control of the account or email address in question — before we act, and we will respond within the time the applicable law allows, normally within 30 days and within 45 days for requests under California law. If we need longer, we will tell you why. If we refuse a request, we will explain why and how to challenge that decision. Using these rights is free unless a request is manifestly unfounded or excessive.

An authorised agent may make a request for you if they give us written proof of authorisation, and we may still verify your identity directly.

Some information we must keep even if you ask us to delete it — a transaction record we are required to retain, or a unit’s safety and traceability history. Where that applies we will tell you which information we kept and why.

16. Notice for California residents#

This section supplements the rest of this policy for residents of California and serves as our notice at collection.

The categories of personal information we collect are identifiers, customer records, commercial information, internet and network activity, approximate geolocation, professional and employment information, audio and visual information where you send us files, and inferences drawn from the above. The purposes, sources, and disclosure recipients for each are described in sections 3 through 11, and our retention practice in section 12.

We do not sell personal information and we do not share it for cross-context behavioural advertising, including that of anyone under 16. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. We offer no financial incentive in exchange for personal information.

California residents have the rights listed in section 15, including the right to know, delete, correct, and to limit use of sensitive personal information, and the right to appeal a decision we make on a request. To appeal, reply to our response or write to contact@proception.ai with “Privacy appeal” in the subject line.

17. Children’s privacy#

Our website, products, and services are intended for business use by adults. They are not directed to children under 16 and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.

18. Changes to this policy#

We may update this policy as our products and obligations change. When we do, we revise the “Last updated” date at the top of this page. If a change materially affects how we handle your personal information, we will give you notice — by email, or through a prominent notice on our website — before it takes effect where the law requires, and otherwise as soon as we reasonably can. Continuing to use our services after a change takes effect means you accept the updated policy.

Ask us for a copy of a previous version and we will send you one.

19. How to reach us#

Email contact@proception.ai for anything about this policy, a privacy request, or our data practices. By post: Proception, Inc., Mountain View, CA 94043, United States.

Business customers who need a data processing agreement, a sub-processor list for their own compliance file, or details of our security measures should ask us and we will provide them.