Privacy Policy
Last updated: August 22, 2026
Prynt is device-intelligence software for fraud and bot prevention. This policy explains how the Prynt-operated cloud (pryntid.com, app.pryntid.com, api.pryntid.com) handles data. When you self-host Prynt, you are the data controller and no visitor data ever reaches us.
Data we process (managed cloud)
- Account data — your email, organization name, and hashed password, to run your account.
- Device signals — the browser/device signals your integration sends (rendering, hardware, network) which we fuse into a pseudonymous visitor ID and risk signals for you, the customer.
- IP address — used in real time for network intelligence; stored minimized per your configuration (full / truncated / none).
- Usage metadata — API call counts for billing and rate limiting.
How we use it
Solely to provide the service you requested: identifying returning devices and scoring fraud/bot risk for your own site, plus billing, security and support. We do not sell personal data, and we do not use your visitors' data to build a cross-customer profile except through the explicitly opt-in reputation network.
Data minimization & retention
Retention follows your plan and configuration. IP minimization is configurable. Raw signal history is used for accuracy and drift debugging and is deleted on account closure or on request.
Your choices
Prynt honors Global Privacy Control and Do-Not-Track for suppression, supports right-to-erasure, and lets you export or delete your data. Contact [email protected].
Self-hosting
If you run Prynt on your own infrastructure, visitor data never leaves your environment and you are the sole controller. This is the recommended posture for strict data-residency requirements.
Enterprise
A signable Data Processing Agreement (DPA) and subprocessor list are available to enterprise customers on request at [email protected].
This document is provided for transparency and should be reviewed alongside your own counsel before enterprise procurement.