Proception, Inc. (“Proception”, “we”, “us”) builds humanoid robotic hands and the software that runs them. This policy explains what we collect when you visit our website, buy or operate our products, use our developer tools, apply for a job, or contact us — and what you can ask us to do about it.
We have written it to be read, not skimmed past. If anything here is unclear, or if you want to know specifically what we hold about you, email us and ask.
1. Who we are and what this covers#
Proception, Inc. is a Delaware corporation with offices in Mountain View, California. We are the party responsible for the information described here.
This policy applies to:
- our public website and online store at proception.ai
- accounts you create with us, including customer, developer, and applicant accounts
- our developer portal, documentation, SDKs, and APIs
- the hardware products we sell and the firmware and software that operate them
- sales enquiries, quotes, orders, support requests, and other correspondence with us
It does not apply to third-party websites or services we link to, which have their own policies.
2. Two different roles: our data and our customers’ data#
It matters which of two things is happening, because your rights run against a different party in each case.
- We decide (we are the controller)
- Information about visitors to our site, people who buy from us, developers who use our tools, applicants who apply to us, and the operation of the products we sell. This policy governs it.
- Our customer decides (we are the processor)
- If an organisation deploys our hands in its own facility and its own people or end users generate personal data through that deployment, that organisation decides what is collected and why. We handle it on their instructions and under our agreement with them. Their privacy notice — not this one — is the one that describes it, and requests about that data should go to them. Business customers can request a data processing agreement from us.
3. Information we collect#
Information you give us
- Identity and contact details
- Name, email address, phone number, company, job title, and postal or shipping address.
- Account information
- Sign-in credentials (we store a hash of your password, never the password itself), any second-factor enrolment, your role and permission level, profile details, and language and theme preferences.
- Purchase and order information
- Quotes, orders, invoices, purchase orders, billing and shipping addresses, tax details, the units allocated to your order, and their serial numbers. Card details go directly to our payment processor; see “Payments” below.
- Application materials
- If you apply for a role: your résumé or CV, cover letter, links you provide, work authorisation answers, and anything else you choose to include.
- Agreements and signatures
- When you sign an order form, sale terms, or licence electronically, we record your name, title, email, the document version you signed, your signature, the timestamp, and the IP address the signature came from — because that record is what makes the signature provable.
- Correspondence and support
- Messages, enquiries, feedback, bug reports, and support tickets, including any files or screenshots you attach.
Information we collect automatically
- Device and connection data
- IP address, approximate location derived from it, browser and operating system, device type, language, and referring page.
- Usage data
- Pages and documentation you view, files and SDK releases you download, API calls and their volume, features you use, and errors you hit.
- Security and audit logs
- Sign-in attempts and their outcome, session and token activity, permission changes, and administrative actions. We keep these to detect and investigate abuse, and because some of them we are required to keep.
4. Product and device telemetry#
Our hardware and its software report on themselves. When a unit is connected, it may transmit operational, diagnostic, performance, sensor, calibration, firmware, usage, and error data — what we call telemetry — to us and to services acting for us.
We use telemetry to:
- operate and support the product, and diagnose faults in a specific unit
- honour warranty and service obligations, including tracing a failure to a component or build
- measure reliability and safety across the fleet, and detect a defect pattern before it reaches more units
- improve and develop our products, firmware, and models
Telemetry is about a machine, not a person, and normally does not identify anyone. Where it can be linked to a person — because a unit is assigned to a named operator, or because a log carries an account identifier — we treat that link as personal information under this policy.
We also produce aggregated and de-identified statistics from telemetry — fleet-wide reliability figures, usage distributions, model training data. Once data is genuinely aggregated or de-identified it is no longer personal information, we own it, and we may use and disclose it without restriction. We do not attempt to re-identify it.
5. Where information comes from#
- directly from you, when you fill in a form, create an account, place an order, or write to us
- automatically from your browser, our products, and our systems as described above
- from your employer or a colleague, when they add you to an order, an account, or a support thread
- from our service providers — for example a payment confirmation from our payment processor or a delivery scan from a carrier
- from publicly available sources, when we research a prospective business customer or verify a company
6. How we use information#
- to provide, operate, secure, and maintain our website, store, accounts, and developer tools
- to process quotes, orders, payments, shipments, and returns, and to keep the records that go with them
- to build, allocate, ship, service, and support the specific units you buy, and to administer warranties
- to deliver firmware and software updates, and to tell you when one matters
- to answer enquiries and provide support
- to evaluate job applications and administer hiring
- to detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms
- to understand how our site and products are used, and to improve and develop them
- to send you product, service, and company updates you have asked for, and to tell you about material changes to our terms or this policy
- to comply with legal obligations, enforce our agreements, and establish or defend legal claims
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
7. Legal bases (EEA, UK, and Switzerland)#
If data protection law in your country requires us to name a legal basis, ours are:
- Performance of a contract
- Creating and running your account, fulfilling an order, providing support, and honouring a warranty.
- Legitimate interests
- Securing our systems, preventing fraud and abuse, understanding and improving our products, product telemetry, and business correspondence — balanced against your interests and rights.
- Consent
- Marketing email where consent is required, and non-essential cookies. You can withdraw consent at any time; it does not affect processing already carried out.
- Legal obligation
- Tax, accounting, export control, and other records we are required to create or keep.
8. Automated processing and AI#
We use automated tools, including large language models, in a few specific places. Where we do, we tell you here:
- Job applications
- We use an automated tool to read and score submitted résumés against the requirements of the role, which helps us review every application rather than only the first ones to arrive. A score is an input, not a decision: no application is rejected by the tool alone, a person reviews the candidates, and hiring decisions are made by people. You may ask us for the outcome of an automated review of your application and ask a person to reconsider it.
- Support and internal operations
- We use automated tools to summarise, classify, and route internal work such as tickets, build failures, and documentation. Where these touch your correspondence, they operate on our own systems under contract, and their output is reviewed by our staff.
We do not use these tools to make decisions with legal or similarly significant effects on you without human involvement.
11. Service providers we rely on#
We keep this list current rather than vague, so you can see who actually touches the data. All are bound by contract and process only on our instructions.
- Website hosting and delivery
- Vercel — serves our public website and store.
- Databases and authentication
- Supabase — accounts, sign-in, and the records behind the website and store.
- File storage
- Amazon Web Services (S3) — uploaded files, including résumés, documents, media, and software releases.
- Payments
- Stripe — checkout, cards, and invoicing. Card numbers go to Stripe, not to us.
- Microsoft 365 and Amazon Web Services (SES) — transactional and business email.
- AI processing
- Anthropic — the model behind the automated review described above. Our agreement does not permit our data to be used to train their models.
- Work tracking
- Linear — support, feedback, and engineering tickets, which may contain your correspondence.
- Shipping
- Carriers and freight forwarders — the name, address, and contact details needed to deliver an order.
A material part of our internal systems runs on hardware we operate ourselves, reachable only over our private network. Data held there is not exposed to the public internet.
12. How long we keep information#
We keep personal information only as long as we need it for the purpose we collected it, then delete or de-identify it. In practice:
- Account information
- For as long as your account is active, and for a reasonable period afterwards so we can honour warranties, resolve disputes, and meet our obligations.
- Orders, invoices, and signed agreements
- For as long as tax, accounting, warranty, and limitation-period requirements demand — typically seven years after the transaction.
- Unit and service records
- For the life of the unit and afterwards. A hand’s build, allocation, service, and warranty history is a safety and traceability record; we do not delete it while units are in the field.
- Application materials
- For up to two years after a decision, so we can consider you for future roles and answer questions about the process. Ask us and we will delete them sooner.
- Telemetry
- Detailed records for an operational window, after which they are archived or reduced to aggregated and de-identified statistics that we keep indefinitely.
- Security and audit logs
- For a limited period appropriate to investigating incidents, and longer where a specific incident or legal obligation requires it.
- Correspondence
- For as long as needed to handle the matter and keep a record of what we agreed.
13. How we protect information#
The measures we take include encryption in transit, encryption of stored files, database-level access rules that restrict every record to the people entitled to see it, least-privilege staff access reviewed against role, multi-factor authentication on sensitive functions, private-network-only access to internal systems, audit logging of administrative action, and immediate session revocation when an account is disabled.
You have a part in this too: use a unique password, turn on a second factor where we offer it, keep your API keys and tokens secret, and tell us promptly if you think an account or credential has been compromised.
14. International transfers#
We are based in the United States and our systems and most of our service providers are located there. We also operate an office in China that supports manufacturing and supply chain, and we work with suppliers and carriers in other countries.
If you are outside the United States, using our services means your information will be transferred to and processed in the United States and other countries, whose privacy laws may differ from your own. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, including the European Commission’s standard contractual clauses and the UK addendum. Ask us and we will describe the safeguards that apply to a specific transfer.
15. Your privacy rights#
Depending on where you live, you may have the right to:
- know what personal information we hold about you and why, and get a copy of it
- correct information that is inaccurate or incomplete
- delete information we no longer have a valid reason to keep
- receive your information in a portable format, or have us send it to someone else
- object to or restrict certain processing, including processing based on our legitimate interests
- withdraw consent you previously gave
- opt out of marketing email at any time, using the unsubscribe link or by writing to us
- not be discriminated against for exercising any of these rights
- complain to your data protection authority — and, in the EEA or UK, to do so without contacting us first, though we would rather you gave us the chance to fix it
To exercise a right, email contact@proception.ai and tell us what you want. We will verify your identity — usually by confirming control of the account or email address in question — before we act, and we will respond within the time the applicable law allows, normally within 30 days and within 45 days for requests under California law. If we need longer, we will tell you why. If we refuse a request, we will explain why and how to challenge that decision. Using these rights is free unless a request is manifestly unfounded or excessive.
An authorised agent may make a request for you if they give us written proof of authorisation, and we may still verify your identity directly.
Some information we must keep even if you ask us to delete it — a transaction record we are required to retain, or a unit’s safety and traceability history. Where that applies we will tell you which information we kept and why.
16. Notice for California residents#
This section supplements the rest of this policy for residents of California and serves as our notice at collection.
The categories of personal information we collect are identifiers, customer records, commercial information, internet and network activity, approximate geolocation, professional and employment information, audio and visual information where you send us files, and inferences drawn from the above. The purposes, sources, and disclosure recipients for each are described in sections 3 through 11, and our retention practice in section 12.
We do not sell personal information and we do not share it for cross-context behavioural advertising, including that of anyone under 16. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. We offer no financial incentive in exchange for personal information.
California residents have the rights listed in section 15, including the right to know, delete, correct, and to limit use of sensitive personal information, and the right to appeal a decision we make on a request. To appeal, reply to our response or write to contact@proception.ai with “Privacy appeal” in the subject line.
17. Children’s privacy#
Our website, products, and services are intended for business use by adults. They are not directed to children under 16 and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
18. Changes to this policy#
We may update this policy as our products and obligations change. When we do, we revise the “Last updated” date at the top of this page. If a change materially affects how we handle your personal information, we will give you notice — by email, or through a prominent notice on our website — before it takes effect where the law requires, and otherwise as soon as we reasonably can. Continuing to use our services after a change takes effect means you accept the updated policy.
Ask us for a copy of a previous version and we will send you one.
19. How to reach us#
Email contact@proception.ai for anything about this policy, a privacy request, or our data practices. By post: Proception, Inc., Mountain View, CA 94043, United States.
Business customers who need a data processing agreement, a sub-processor list for their own compliance file, or details of our security measures should ask us and we will provide them.