Privacy Policy
Last updated: September 4, 2026
Cyber Eccentric Pty Ltd ("Cyber Eccentric", "we", "us", or "our") operates ProcureMind.io, including the web application, Chrome Extension, and Outlook Add-in (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, your rights under the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs), and our obligations under the Notifiable Data Breaches (NDB) scheme.
1. Data We Collect
Account Information
When you sign in with Google, we receive your name, email address, and Google profile ID via OAuth. We store your email address and a hashed identifier to manage your account. We do not store your Google password.
Email Content
The Chrome Extension reads the content of Gmail emails you are currently viewing, but only when you click "Extract RFQ". Email content is read directly from the Gmail webpage (DOM access). It is transmitted to our servers solely to perform AI extraction. Raw email content is processed to fulfil your request and is not stored in our database. Only the structured result is saved.
Uploaded Files
When you upload a file through the web dashboard (PDF, Excel, CSV, Word document, or an image such as PNG or JPG), the file is transmitted to our servers for text extraction and AI processing. Text and document images extracted from PDF files and images are processed in memory and not stored. Text extracted from Excel and CSV files is retained with the extraction record so you can review what was processed. You can permanently purge it at any time from your dashboard.
Extracted Data
The structured data extracted by AI (vendor name, quote numbers, line items, amounts, etc.) is stored in our database and linked to your account. This is the core output of the Service. You can view and delete this data at any time from your dashboard.
Customer & Quote Data
When you use the quote follow-up features, we store the quotes you track and the customer contact details you enter or that are extracted from those quotes (names, email addresses, phone numbers). When a customer replies, you can paste their reply text into the dashboard; it is stored with the quote and classified by AI (intent detection) to recommend a next step. A reply consisting only of an opt-out request (e.g. "STOP") automatically opts that customer out of further follow-ups. You can edit or delete this data at any time from your dashboard.
AI-Generated Follow-Up Drafts
The Service generates follow-up email drafts with AI, constrained to the facts in your quote and customer data. Drafts are validated against anti-fabrication rules and rejected if they invent details such as discounts or amounts you never quoted. Drafts are prepared for your review only; you send them yourself from your own mailbox.
Usage Data
We track how many extractions you perform each month to enforce plan limits. We also collect basic usage metrics (number of extractions, source type, confidence scores) to improve the Service. When product analytics is enabled, pageviews and product usage events are collected via PostHog under an anonymous identifier; analytics collection is disabled entirely when not configured.
Payment Information
Payments are processed by Stripe. We never store your credit card number, CVV, or full payment details. We store only a Stripe Customer ID and subscription status to manage your plan.
Google Sheets Access
If you connect Google Sheets, we store OAuth access and refresh tokens server-side to write extracted data to your chosen spreadsheet. These tokens are encrypted at rest and never exposed to the Chrome Extension. You can revoke access at any time from your Google Account settings or from our Settings page.
Microsoft 365 Access
If you connect a Microsoft 365 account (Outlook or Excel Online), we store OAuth access and refresh tokens server-side, encrypted at rest, to read supplier emails you choose to extract and to write extracted data to your chosen workbook. You can disconnect at any time from our Settings page or from your Microsoft account permissions.
2. How We Use Your Data
- To provide and operate the Service (AI extraction, Sheets sync, extraction history, quote follow-up drafts)
- To enforce plan limits and process subscription payments
- To improve extraction accuracy and product quality
- To classify pasted customer replies (AI intent detection) and recommend next steps
- To send transactional and notification emails (usage warnings, payment notifications, quote activity alerts such as follow-up ready, customer responded, or recovery won). No marketing without consent
- To analyse product usage via PostHog, when analytics is enabled
- To monitor errors and diagnose technical issues (via Sentry)
3. Third-Party Processors
We share data with the following third-party services, each under their own privacy policies:
| Processor | Purpose | Data Shared |
|---|---|---|
| AI processing providers | AI text and vision extraction, follow-up drafting & reply classification | Email/file content you choose to extract (including document page images); pasted customer replies; quote & customer data used in drafts |
| Supabase | Database & authentication hosting | All account and extraction data |
| OAuth login & Sheets API | Account identity; extracted rows written to your sheet | |
| Stripe | Payment processing & subscriptions | Email address, billing details |
| Sentry | Error monitoring | Error stack traces (no email content) |
| Vercel | Web application hosting | Server logs (IP, user agent) |
| Resend | Transactional & notification email delivery | Your email address; quote activity notifications (follow-up ready, customer responded, recovery won) |
| PostHog | Product analytics (only when enabled) | Pageviews & product usage events under an anonymous identifier; hosted on PostHog US cloud |
Important: Email and file content (including document page images) is transmitted to third-party AI processing providers solely to perform the extraction or classification you request. Pasted customer reply text and the quote/customer data needed to generate follow-up drafts are processed under the same terms. These providers process content under their standard API terms; we do not control their retention practices. Their servers may be located outside Australia, and by using the Service you consent to this international transfer.
4. Data Retention
- Raw email and PDF content: Not retained. Processed in memory during extraction only
- Text extracted from Excel/CSV uploads: Retained with the extraction record until you purge or delete it
- Extracted data: Retained while your account is active; deleted on account deletion
- Customer, quote, reply & follow-up data: Retained while your account is active; deleted on account deletion
- Usage logs: Retained for 13 months for billing and analytics purposes
- Sheets OAuth tokens: Retained until you disconnect Google Sheets from Settings
5. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Delete your account and all associated data via Settings → "Delete my data"
- Portability: Export your extraction history as CSV or a branded Excel file from the dashboard
- Objection: Object to processing where we rely on legitimate interests
- Withdrawal of consent: Disconnect Google Sheets or revoke Google OAuth at any time
To exercise any of these rights, email us at support@procuremind.io. We respond within 30 days.
6. Cookies & Tracking
We use cookies solely for authentication (session management via Supabase). If product analytics is enabled, PostHog additionally stores an anonymous identifier in your browser to measure product usage. We do not use third-party advertising cookies or tracking pixels. We do not sell your data.
7. Security
We use industry-standard security practices: TLS encryption in transit, encrypted storage at rest via Supabase, row-level security (users can only access their own data), and AES-256-GCM encryption for stored OAuth tokens. The Chrome Extension stores only your ProcureMind session in Chrome's extension storage. The access token is session-scoped and cleared when the browser closes; tokens for connected services such as Google Sheets are stored server-side only. See our Security page for details.
8. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us immediately at support@procuremind.io.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or by posting a notice on the Service. The "Last updated" date at the top indicates when this policy was last revised.
10. Australian Privacy Act & Your Rights
We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). Under Australian law you have the right to:
- Access personal information we hold about you (APP 12)
- Correct inaccurate or out-of-date information (APP 13)
- Delete your account and associated data via Settings → "Delete my data"
- Complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have breached the APPs
We will respond to privacy requests within 30 days. In the event of an eligible data breach we will notify affected individuals and the OAIC as required by the NDB scheme.
11. International Users & GDPR
The Service is offered worldwide. For users in the European Economic Area or the United Kingdom, Cyber Eccentric Pty Ltd is the data controller of your personal data under the General Data Protection Regulation (GDPR).
We process personal data on these lawful bases: performance of our contract with you (providing the Service), our legitimate interests (improving and securing the Service), and your consent (for optional connections such as Google Sheets or Microsoft 365, which you can withdraw at any time).
In addition to the rights in Section 5, you have the right to restrict or object to processing, the right to lodge a complaint with your local supervisory authority, and the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. International transfers of your data are covered by the safeguards described in Section 3.
12. Contact Us
For privacy enquiries, data requests, or complaints:
Cyber Eccentric Pty Ltd
Sydney, New South Wales, Australia
Email: support@procuremind.io
Website: procuremind.io