1. Operator, contact, and U.S. availability
Praxis is operated by C13 Software LLC. This notice applies to the public marketing website at thinkinpraxis.com and the Praxis application at app.thinkinpraxis.com.
Praxis plans to limit its first public enrollment to U.S. residents. Self-service signup is currently disabled. Country-of-residence attestation, U.S. billing-location restrictions, and trusted backend enforcement are planned launch controls and are not yet implemented. No geographic block was found for existing users, but login, recovery, export, support, and erasure while traveling have not yet received a dedicated production test.
For privacy questions or requests, email praxis-help@c13.io.
Mailing address: C13 Software LLC, 382 NE 191st St #210508, Miami, FL 33179, United States.
2. Marketing website processing
The marketing website currently has no analytics platform, advertising tracker, or contact form. Contact links open your email application instead of submitting information through the website.
Amazon Web Services processes ordinary delivery and security information when it serves the site, including IP address, browser or user agent, requested route, referrer, time, and response status. We do not use this information to build a marketing or behavioral profile.
3. Local-only workspace and browser storage
A free Praxis workspace remains local to the device. Subscribing does not automatically upload it: Cloud Sync must be enabled separately and explicitly. Local workspace data stays on the device unless you enable Sync or take another network action described in this notice, such as running a Tool, contacting support, or exporting material to another service.
Praxis uses IndexedDB for the encrypted local workspace and account-scoped control records; sessionStorage for a random session-wrapping secret and short-lived security state; and browser storage for account-scoped preferences and migration staging data.
When possible, signing out after Sync removes the account-scoped local database and key wrappers. Forget this device removes this installation’s key material without disabling Sync elsewhere. Clearing browser data, losing a device, or uninstalling the browser can permanently destroy local-only information. Praxis is not a backup guarantee; export important material.
4. Accounts, authentication, cookies, MFA, and passkeys
Praxis processes an immutable account identifier, email and verification status, a Cognito SRP verifier and recovery state, session and refresh tokens, MFA state, Sync generation, recovery/security epoch, and opaque encrypted workspace-key envelopes. For passkeys, Praxis may store credential identifiers, public registrations, user-assigned names, and opaque encrypted recovery material.
Web traffic between your browser and Praxis or its web service providers is protected in transit with HTTPS/TLS. During password sign-in, Cognito uses Secure Remote Password (SRP): your password stays in the browser, Cognito stores a non-reversible verifier, and Praxis APIs receive authentication tokens rather than your password. This protects sign-in, but it is different from zero-knowledge workspace encryption because the account service must still process some account and session data.
Face, fingerprint, device PIN, and other user verification occur within your authenticator or passkey provider. Praxis does not receive biometric data. WebAuthn private keys, client-only PRF results, mnemonic recovery phrases, and plaintext workspace master keys do not reach Praxis Cloud.
The application uses strictly necessary Secure cookies: HttpOnly ID and access-token cookies lasting up to one hour; an HttpOnly refresh-token cookie lasting up to 30 days; and a Secure, script-readable CSRF cookie lasting up to 30 days. We do not use optional analytics or advertising cookies, so we do not display a consent banner for optional tracking.
If you stop Sync while keeping the account open, limited opaque passkey recovery material may remain after cloud content is purged so an authorized credential can establish a newer Sync generation. Revoking that passkey removes its matching envelope; full account erasure removes all passkey envelopes and registrations held by Praxis.
5. Zero-knowledge Cloud Sync and operational metadata
In this notice, zero-knowledge workspace encryption means workspace content is encrypted on your device before it is uploaded, Praxis Cloud does not receive the plaintext encryption key, and Praxis cannot decrypt the synced content.
Notes, Templates, Vault records and provenance, Workflows, attachments and attachment metadata, and local workspace metadata are zero-knowledge encrypted in the browser before Cloud Sync. Praxis Cloud receives ciphertext and cannot read these synced items in plaintext.
HTTPS/TLS also protects web traffic while it is in transit, but transport encryption and zero-knowledge encryption solve different problems. HTTPS/TLS protects data as it travels. Zero-knowledge encryption keeps workspace content unreadable to Praxis after the service receives and stores it.
Zero-knowledge encryption does not make every fact about the service invisible. Praxis processes limited readable metadata needed to authenticate an account, enforce storage and provider limits, synchronize versions, detect abuse, recover from interrupted operations, and delete data safely. This can include account ID, subscription state, ciphertext sizes, checksums, object ownership, counts, versions, timestamps, Sync generation, quarantine deadlines, storage usage, and cleanup state.
Support messages, billing records, Tool queries, account and authentication metadata, operational logs, and readable exports are not protected by zero-knowledge workspace encryption. They still receive the transport and service protections described in this notice where applicable.
Praxis sends a query and selected filters to Brave only after you explicitly run Search, News, or Images. No Praxis account ID is intentionally sent to Brave. Brave receives the query and request metadata needed to return results; Brave’s own terms and privacy practices govern its processing.
Praxis uses Brave's base Search API plan. Brave’s published Search API notice says it keeps a record of queries for no more than 90 days for billing and troubleshooting, subject to legal obligations, and also identifies abuse prevention as a purpose. Brave says it does not receive identifiers that link a query to a particular Praxis user or device. Brave offers a separate Zero Data Retention option for eligible enterprise customers; Praxis does not use or claim that option.
Praxis uses short-lived, shared result caches that are keyed by a normalized-query hash rather than by account. The standard Search cache payload currently contains the query and returned results and is available for one hour by default. News and Images caches are available for 15 minutes by default. Separate account-linked usage and quota counters are retained for 120 days and do not need to contain the query.
News and Images currently place query and filter parameters in request URLs. Those required Tool inputs may therefore appear with IP address, user agent, time, route, and request identifiers in CloudFront access logs retained for 90 days, with noncurrent log versions retained for 7 days. Search uses a POST body, which is not included in standard CloudFront access logs. Standard logs exclude cookies and request bodies.
Some News and Images result cards load previews directly from an external host using no-referrer requests and without Praxis credentials. That host can still receive your IP address, user agent, request time, and the requested image URL. User-authored remote Markdown images are also loaded directly; under the application-wide referrer policy, their host may receive the Praxis origin. Saving a result to the Vault creates zero-knowledge encrypted workspace content, but it does not undo processing that occurred to return or preview the result.
7. Billing and Stripe
Stripe processes payment and billing information, which may include billing contact details, customer and subscription identifiers, invoices, payment methods, tax information, disputes, and fraud-prevention information. Praxis sends Stripe a Praxis account reference in Checkout and subscription metadata so billing events can be matched to the correct entitlement. Praxis stores the identifiers and subscription state needed to provide paid access, but does not store full card details.
Full account erasure instructs Praxis to delete the Stripe customer and stop future billing. Stripe documents that deleting a customer cancels active subscriptions, removes card details, and prevents further operations, while a limited deleted-customer record and transaction history may remain. Stripe may also retain personal information after account closure or a transaction to meet legal, regulatory, fraud-prevention, tax, accounting, financial-reporting, payment-method, dispute, and applicable limitation-period requirements. Stripe does not publish one universal post-deletion period because those obligations vary.
Praxis retains a de-identified Stripe-customer tombstone for up to 400 days so a delayed, validly signed webhook cannot recreate an erased Praxis profile. The tombstone is not an active customer profile and does not contain a Praxis account ID. A user may ask C13 Software LLC to request additional deletion or redaction of eligible Stripe data, but transaction risk periods and legal retention can delay or limit that process.
8. Support and privacy communications
The praxis-help@c13.io mailbox is hosted through Amazon Web Services and owned by C13 Software LLC. Access is limited to C13 Software LLC personnel authorized to respond to email inquiries. When you email support or make a privacy request, C13 Software LLC and Amazon Web Services process your address, message, and any attachments you choose to send.
Support communications are not protected by Praxis zero-knowledge workspace encryption and must remain readable to authorized personnel so they can respond. We retain them for as long as needed to respond and provide the requested services, and longer only where needed for security or legal obligations. Messages are not currently copied into a helpdesk, customer-relationship management system, or separate security system. If C13 Software LLC later uses one of those systems, authorized providers and personnel may receive copies, and we will update this notice and the Subprocessors list as appropriate.
9. Why we process information and limits on use
We process information to provide and secure Praxis; authenticate accounts; synchronize, bill, support, export, and erase data; enforce storage and provider limits; prevent abuse and fraud; diagnose failures; communicate about the service; and comply with legal obligations.
Praxis does not use workspace content for behavioral advertising, cross-site tracking, user-level search-interest profiles, analytics that require decrypting workspace content, or model training. The inspected application and marketing site contain no third-party analytics or advertising SDK. Queries remain only where needed for Tool processing, shared caches, quota processing, operational logs, or encrypted provenance that you save to your own Vault. Any future use that changes these boundaries would require product review, inventory and policy updates, and any consent required by law.
Praxis does not sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising. It also does not offer a financial incentive or different service level in exchange for personal information. Service-provider processing needed to host, authenticate, bill, support, secure, and return requested Tool results is not a sale by Praxis.
10. Service providers and data location
Praxis currently uses Amazon Web Services for hosting, storage, authentication, operational security, and cloud infrastructure; Amazon SES for outbound account email; Stripe for billing; and Brave for Search, News, and Images results. The Subprocessors page describes the data each provider handles.
Praxis plans to offer its initial public enrollment to U.S. residents; enrollment is currently invitation-only. Praxis primarily processes information in the United States, while providers may process limited information in other locations under their own infrastructure and contractual arrangements. Praxis does not currently represent that public enrollment is available in the European Union or United Kingdom.
11. Category-specific retention
Retention depends on what the data is and why it exists. Logical expiry means Praxis stops making a record available even if a service-managed deletion process removes the physical record later. Quarantine is a recoverable period. Full erasure is a separate irreversible process. Legal obligations may require a provider to retain narrowly defined billing, tax, dispute, fraud, or security records longer.
| Category | Current period | What the period means |
|---|
| Search result cache | 1 hour by default | Unavailable after logical expiry; service-managed deletion may occur later |
|---|
| News and Images result caches | 15 minutes by default | Unavailable after logical expiry; service-managed deletion may occur later |
|---|
| Brave Search API query logs | Up to 90 days under Brave's published standard API notice | Billing, troubleshooting, abuse prevention, and legal obligations; an enterprise Zero Data Retention option exists |
|---|
| Account-linked tool usage and quota counters | 120 days | Counters need not contain the query itself |
|---|
| Trash | 30 days | Recoverable during the Trash period, then scheduled for permanent removal |
|---|
| Stopped or subscription-lapsed Sync generation | 30 days | Frozen and recoverable during quarantine; local data remains |
|---|
| Lambda operational logs | 30 days | Automatic log-group expiry |
|---|
| CloudFront application access logs | 90 days current; 7 days noncurrent | Automatic object expiry; URL-based Tool inputs may appear in these logs |
|---|
| Cleanup source queue | Up to 4 days | Retry window for asynchronous cleanup |
|---|
| Cleanup dead-letter queue | 14 days | Restricted failure investigation and retry |
|---|
| Stripe replay records and erased-customer tombstone | Up to 400 days | Prevents delayed signed webhooks from recreating an erased profile |
|---|
| Encrypted attachment noncurrent versions | 30 days | Ordinary version lifecycle; full erasure separately targets all versions |
|---|
| DynamoDB point-in-time recovery | 35 days for production durable tables | Restricted administrative recovery copy; production cache and source-type tables do not use point-in-time recovery |
|---|
12. Trash, Stop Sync, subscription loss, and full erasure
Moving an item to Trash keeps that encrypted item recoverable for 30 days before permanent removal.
Stop Sync freezes the current encrypted cloud generation for 30 days. Local data remains on the device. You may resume the same generation during quarantine after the required unlock and authorization; after purge, re-enrollment creates a newer generation from an eligible surviving local workspace or recovery method.
Losing subscription entitlement stops new cloud mutations and paid Tools and starts the same 30-day frozen-content quarantine. Local data remains. Cancelling a subscription is not an account-deletion request.
Delete my everything is different: after recent authentication and confirmation, Praxis immediately marks the account for erasure, freezes entitlement-dependent cloud and provider activity, and queues irreversible asynchronous cleanup. Sessions are revoked when the cleanup worker begins processing. The process does not use the 30-day recovery period and does not require your mnemonic or plaintext workspace key. Cleanup removes every attachment version, Vault records, Workflows, Notes and Templates, usage records, the Stripe customer, account rows and passkey envelopes, and the Cognito identity in a retry-safe dependency order.
13. Exports, imports, backups, and disaster recovery
A human-readable export is decrypted in your browser and downloaded as plaintext. An encrypted Praxis Workspace Archive uses a separate password that you supply and Praxis does not store. Files downloaded to a device or sent to another service are outside Praxis’s deletion control and should be protected accordingly.
Import validation and staging occur locally and do not authorize a plaintext upload to Praxis Cloud.
Full erasure removes records from normal application tables and explicitly deletes every encrypted attachment version and delete marker, placing that data beyond ordinary application use. Production durable DynamoDB tables use a 35-day point-in-time recovery window; cache and source-type tables do not use point-in-time recovery. Application workloads cannot restore those copies. No automatic erasure ledger replay or completed isolated restore drill currently proves that an administrator-restored table cannot reintroduce an erased account. Backup restoration is not available as a user recovery feature and cannot restore local-only data.
The downloadable deletion receipt confirms that Praxis accepted the request; it does not currently provide server-verifiable proof that every asynchronous step, restricted recovery copy, or provider-controlled record has expired.
14. Privacy choices and requests
Praxis offers all U.S. users a practical baseline of privacy choices even when a particular state law does not apply. You may ask us to confirm whether we process personal information about you; access or obtain a portable copy; correct inaccurate information; delete eligible information; or appeal a request decision. The Dashboard also provides controls to export data, Stop Sync, Forget this device, revoke a passkey, and choose Delete my everything.
Stop Sync and subscription cancellation are not deletion requests. Delete my everything performs full account erasure and does not require the mnemonic or workspace master key. If you cannot sign in, or if your request concerns account, support, billing, or other readable information, email praxis-help@c13.io. We will verify the request in proportion to its sensitivity, respond within the period required by applicable law, explain any lawful denial, and provide appeal instructions where applicable. We may retain information where a lawful exception applies.
An authorized agent may submit a request for you. We may ask for proof of the agent's authority and may ask you to verify your identity or confirm the request directly. We will not discriminate against you for exercising an applicable privacy right, although deleting information may prevent us from continuing to provide features that require it.
15. U.S. state disclosures and browser privacy signals
The data-inventory table and Sections 2 through 10 identify the categories of personal information Praxis collects, the sources from which it is received, the purposes for using it, and the categories of service providers that receive it. Praxis does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use it to make decisions producing legal or similarly significant effects. Because these activities do not occur, there is no separate sale, targeted-advertising, or profiling opt-out required for current Praxis use.
Praxis does not track a person's activity over time across unrelated websites for advertising. Browser Do Not Track signals and Global Privacy Control signals therefore do not change the service's current behavior. If Praxis later begins processing for which applicable law requires recognition of an opt-out preference signal, we will honor legally valid signals and update this notice before that processing begins.
California residents may use the request methods in Section 14. The categories collected and disclosed, purposes, retention approach, and service-provider recipients are described throughout this notice. Praxis has not sold or shared personal information for cross-context behavioral advertising during the period covered by this notice and does not knowingly sell or share personal information of people under 18. Nevada and other U.S. residents may use the same request address, including to direct Praxis not to make a future sale of covered information.
State privacy laws differ in scope and often apply only after revenue, processing-volume, or business-model thresholds are met. Nothing in this section limits a right available under applicable law. If this voluntary baseline conflicts with a more protective applicable requirement, the more protective requirement controls.
Praxis accounts are available only to people who are at least 18 years old. Praxis is not directed to children, and we do not knowingly collect personal information from anyone under 18.
We may update this notice as Praxis changes. Material revisions will receive a new last-updated date, be archived, and be communicated when applicable law or the nature of the change requires notice.
Privacy contact: praxis-help@c13.io. Operator: C13 Software LLC.
Mailing address: 382 NE 191st St #210508, Miami, FL 33179, United States.
Effective date: August 17, 2026. Last updated: September 2, 2026.