Legal

Privacy Policy

This policy describes what Propel collects, why, and what happens to it. It reflects how the product actually works today and will be updated when the product changes.

Last updated: 11 September 2026

Information we collect

Propel collects information you provide directly when you create an account and use the product, plus a limited amount of technical information generated automatically when the service runs. We do not buy personal information from third parties and we do not build advertising profiles.

Account information

To create an account we collect your email address and a password, which is handled by our authentication provider and stored as a hash rather than as readable text. If you sign in with Google, we receive the basic profile information that Google returns for the account you choose — typically your email address and name. During onboarding you may also add a display name, company name, company description, website, services, portfolio case studies, testimonials, and brand details such as colours, fonts, and a logo. All of that is optional; the product works with less of it, though generated proposals will be more generic.

Proposal information

Proposals you create are stored in our database, along with the client records, project briefs, scope, deliverables, timelines, and pricing you enter. Proposals are saved as structured content, and earlier versions may be retained so that edits can be reviewed. If you generate a public share link, the proposal at that link can be opened by anyone who has the link — treat share links as semi-public and only send them to people who should see the proposal. If a client accepts a proposal through a share link, the acceptance details they submit, including a typed signature and name, are stored with the proposal.

Contact information

When you submit the contact form we store the name, email address, subject, and message you provide so we can read and reply. Do not include passwords, payment card details, or confidential client documents in a contact message.

Usage data

Our infrastructure providers process standard technical information required to deliver a web application, including IP address, browser and device type, and timestamps of requests. Within the product we record AI usage events — which operation ran, when, and how many credits it consumed — so that credit balances are accurate. Where a proposal has been shared by link, views of that link are recorded and shown to the proposal owner.

Cookies

Propel uses browser storage and cookies that are necessary for the service to function, principally to keep you signed in between page loads and to remember unsaved input in the proposal maker on your own device. We do not use advertising cookies or cross-site tracking cookies. Clearing your browser storage will sign you out and discard any locally saved draft.

Analytics

Propel does not currently run a third-party web analytics or advertising script on this website. The engagement figures shown inside the product relate only to your own shared proposals and are generated by Propel itself. If we add third-party analytics in future, this policy will be updated before it is deployed.

AI and API processing

Generating, scoring, or rewriting a proposal sends the relevant content — your project details, company information, and the current proposal text — to an AI model provider through the Lovable AI gateway so the response can be produced. That processing happens on our servers using server-side credentials; model credentials are never exposed in your browser. AI output is generated text and can contain mistakes or statements that are not true of your business, so you are responsible for reviewing a proposal before sending it to a client. Do not paste information into the product that you are not permitted to share with a processor.

Third-party services

Propel is built on third-party infrastructure and cannot operate without it. We use a managed backend platform for database storage, authentication, and file storage; a hosting and edge platform to serve the application; and an AI gateway that routes requests to model providers. These providers process data on our behalf under their own terms. Because of this, we cannot claim that information is never shared with anyone — it is shared with the processors required to run the service, and not sold.

How information is used

We use the information described above to authenticate you, to store and display your proposals and company knowledge, to generate and edit proposal content when you ask for it, to meter AI credit usage, to show you engagement on proposals you have shared, to respond to contact messages, to maintain security and investigate abuse, and to keep the service working. We do not sell personal information and we do not use your proposal content to market to your clients.

Data retention

Account and proposal information is retained while your account exists, so that your work remains available to you. Proposal versions, view records, and AI usage records are retained alongside the proposal they belong to. Contact messages are retained while they remain useful for support and record-keeping. Provider logs are retained according to those providers' own retention periods, which are outside our direct control.

Data deletion

You can delete individual proposals, clients, portfolio items, and testimonials from inside the product at any time, and deleting a proposal removes its stored content. To have your account and its associated data deleted, send a request through the contact form from the email address on the account. Deletion may not immediately remove copies held in routine encrypted backups, which age out over time.

Security

Traffic to Propel is served over HTTPS, passwords are stored hashed by the authentication provider, and database access is restricted by row-level security rules so that account holders can read and write their own records rather than other people's. Server-side credentials, including AI provider keys, are held as environment variables on the server and are not shipped to the browser. We do not claim end-to-end encryption: proposal content is stored in a form our servers and processors can read, which is what makes generation, editing, and sharing possible. No system is perfectly secure, and you should not store information in Propel that would be seriously harmful if disclosed.

User rights

Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. Much of this is available directly in the product: you can view and edit your profile, company knowledge, and proposals at any time. For anything the interface does not cover, contact us and we will respond within a reasonable period. If you believe we have handled your information improperly, you may also complain to your local data protection authority.

Children's privacy

Propel is a business tool intended for adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete the account and its content.

Changes to this policy

We will update this page when the product changes in a way that affects what is collected or how it is handled, and we will revise the date at the top. Continuing to use Propel after an update means the updated policy applies to your use of the service.

Contact

Questions about this policy, or a request relating to your information, can be sent through the contact page. We do not publish a separate postal address or support email address at this time.