1. Who controls your data
Experir di Evandro Beqaj, established at Via Trieste 721, 21042 Caronno Pertusella (VA), Italy, VAT number 04101440123, is the controller for personal data processed to operate Prototir. Prototir is an in-house product and platform of Experir. Contact prototir@experir.com for privacy questions or rights requests.
The operator's complete public business identifiers are available in the legal notice.
2. Data we process
- Account and identity: email address, display name, handle, profile image, bio, linked OAuth provider identifiers, account settings, organization membership, and authentication records.
- Published and community content: prototypes and their files, descriptions, tags, comments, Likes, tips made with points, reports, appeals, jam entries, event applications and application notes, invitations, judging activity, and remix or template lineage.
- Event information: format, visibility, admission method, schedule, venue name and address, organizer participation link, prize description, prize provider, official rules URL, and the organizer's compliance confirmation.
- Use and reliability: prototype sessions, active duration, SDK events, completion or score when a prototype sends it, device identifier, truncated or salted IP-derived security data, browser diagnostics, timestamps, and service logs.
- Payments: tier, subscription state, seat quantity, and Stripe customer and subscription identifiers. Stripe and Link collect the contact, billing, payment, location, and tax information needed to act as merchant of record. They may share order and transaction details with Prototir so we can provide access and support. Prototir does not store full card numbers.
- AI features: prompts, generated responses, safety results, usage totals, and the internal provider and model used to operate and account for the managed service.
- Messages: notification preferences, transactional email delivery information, and correspondence sent to us.
We receive data from you, your browser and prototype sessions, GitHub, Google, or Apple when you choose those sign-in methods, Stripe and Link for Managed Payments transactions, other users who interact with or report content, and service providers that operate the platform.
3. Why we use it
- Contract: create accounts, host and deliver prototypes, provide feedback tools, teams, events, billing, downloads, templates, and support.
- Legitimate interests: secure the service, prevent manipulation and abuse, moderate content, diagnose failures, measure genuine use, rank and recommend public content, and improve Prototir. We balance these interests against your rights.
- Legal obligations: respond to lawful requests, handle accounting and payment records, and protect rights and safety.
- Consent: where the law requires it. You may withdraw consent without affecting earlier lawful processing.
Prototir does not sell personal data and does not use personal data for targeted advertising.
4. What becomes public
Your public profile, creator identity, public prototypes, comments, Likes, feedback tags, public point tips, badges, and event participation can be seen by others. Private and unlisted prototypes are excluded from public discovery, but anyone with an unlisted link may be able to open it. Public events are listed; unlisted jams can be opened by anyone with their link; private events are limited to authorized accounts. Venue details, organizer links, prize disclosures, and official rules are visible to everyone who can view the event. Do not publish secrets, private residential addresses, or personal information you do not want disclosed.
5. Event hosts and participant information
For an approval-gated jam, the host can see an applicant's display name, handle, optional note, status, and application time. Prototir does not disclose the applicant's account email, billing information, or private account settings to the host. Invite and application decisions create in-product notifications linked to the event.
A user-hosted event organizer may be an independent controller for information they collect outside Prototir, for example through an organizer website, venue registration, or winner-delivery form. That host must provide its own privacy notice and lawful basis. Information submitted to an external organizer leaves Prototir and is governed by the organizer's practices. Participants should not put postal addresses, identity documents, tax information, or other sensitive delivery data in public descriptions, application notes, comments, or prototypes.
6. Providers and international processing
Prototir uses Cloudflare for the web edge and content delivery, Microsoft Azure for APIs, databases, storage, moderation, email, and operational telemetry, Stripe and Link for Managed Payments checkout, merchant-of-record tax handling, receipts, order management, and transaction support, and GitHub infrastructure for deployment. If you choose them, GitHub, Google, and Apple process sign-in data. When a prototype invokes managed AI, prompt and response data may be sent to an AI subprocesser selected by Prototir. Creators and players do not provide provider API keys or choose the provider through the prototype.
Some providers may process data outside the European Economic Area. Where required, transfers must rely on an adequacy decision, contractual safeguards, or another lawful transfer mechanism. The current subprocesser list and applicable transfer safeguards must be kept in Prototir's public subprocesser documentation.
7. Retention
Account data and content are generally kept while the account is active. Authentication tokens are short-lived. Security, session, moderation, and operational records are kept only as long as reasonably needed to preserve integrity, investigate abuse, resolve disputes, and meet legal duties. Billing records may be retained for statutory accounting periods. Backups and caches may take a limited period to expire after deletion.
When you delete your account, Prototir removes the profile, authentication identities, owned prototypes and stored bundles, hosted events, private API keys, and personal activity covered by the deletion workflow. We may retain narrowly required records where law, fraud prevention, dispute resolution, or the rights of others require it.
Deleting a Prototir account does not itself delete a Link account or Link transaction records. Active paid subscriptions must first be canceled through Link. Link handles its own data-rights requests and retention under its privacy notice; deleting a Link account can cancel subscriptions that were sold through Link.
Event applications, invitations, entries, votes, organizer disclosures, and review records are generally retained with the event while needed to administer it and preserve result integrity. A host must set its own retention period for information collected outside Prototir and must not use Prototir application data for unrelated marketing.
Operational retention schedule
- Magic-link verification records: expired records are removed after a 30-day operational buffer; the sign-in token itself expires much sooner and only its hash is stored.
- Stripe webhook idempotency and completed upload-job records: 90 days, unless a failure, dispute, or security investigation requires a longer hold.
- Session-level creator analytics and AI usage metering: up to 400 days. Published aggregates or account-level totals that no longer identify a session may remain longer. The Prototir usage ledger records provider, model, and token totals, not prompt or response text; the selected AI subprocesser applies its own documented request retention.
- In-product notifications: up to two years.
- Reports, moderation decisions, and appeals: retained while needed to enforce the Terms, establish repeat behavior, resolve disputes, or meet legal duties; normally reviewed after three years, with longer preservation for an active matter.
- Billing, refund, and withdrawal records: retained for the applicable Italian accounting and legal limitation periods even after account deletion. They are restricted to what is needed for those purposes.
A daily cleanup job enforces the stated 30-, 90-, 400-, and 730-day limits in Prototir's primary database. Provider backups, caches, and security logs expire on their own restricted cycles. A legal hold for a dispute, fraud investigation, safety issue, or binding request temporarily overrides routine deletion only for the records needed for that matter.
8. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection. You may also withdraw consent and complain to a supervisory authority. In Italy, this is the Garante per la protezione dei dati personali.
Update your profile or permanently delete the account from Account settings. For access, portability, objections, or anything the controls do not cover, email prototir@experir.com. We may need to verify identity before acting and normally respond within one month.
9. Security and automated systems
We use access controls, sandboxing, encryption in transit, protected platform AI credentials, rate limits, content safety checks, and moderation. No online system can guarantee absolute security. Feed ranking, abuse checks, and content-safety tools assist platform decisions, but users can report mistakes and appeal moderation outcomes. Prototir does not make solely automated decisions that produce legal or similarly significant effects.
10. Children and changes
Accounts are not offered to children under 16. See the minors policy. We will update this notice when processing materially changes and will provide a prominent notice when appropriate.
For Digital Services Act contacts, illegal-content notices, moderation reasons, and appeals, see the Platform rules.