Last Updated: March 18, 2026
IMPORTANT NOTICE: This Privacy Policy explains how PR Bot collects, uses, and protects your personal information. Since our service involves AI processing of your professional profile to automate media outreach, we recommend reading this policy carefully.
StartupBros LLC d/b/a PR Bot ("us", "we", or "our") operates the https://prbot.ai/ website (the "Service").
Your privacy is important to us. It is StartupBros LLC d/b/a PR Bot policy to respect your privacy regarding any information we may collect from you across our website, https://prbot.ai/, and other sites we own and operate.
We use your data to provide and improve the Service. This Privacy Policy describes our data practices and the legal bases under which we process your personal information. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, accessible from https://prbot.ai/.
We collect several different types of information for various purposes to provide and improve our Service to you.
When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your computer's Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details.
We may also collect data about the device you're using to access our website. This data may include the device type, operating system, unique device identifiers, device settings, and geo-location data. What we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Information”). Personally identifiable information may include, but is not limited to:
As part of our AI-powered PR outreach services, we collect information about your professional expertise, previous work, and communication style to train our AI systems to accurately represent you when responding to media opportunities.
This information is used solely for the purpose of generating personalized responses to journalist queries on your behalf. We implement strict security measures to protect this sensitive professional data and will never use it for purposes other than providing our services to you.
The processing of your professional profile data to generate AI-powered media responses is performed under GDPR Article 6(1)(b) (contractual necessity), as this processing is the core service you contracted us to deliver. You can review and manage your profile data at any time through your account settings.
We may also collect information on how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as your computer's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.
Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
We participate in affiliate marketing programs. When you visit our website through an affiliate link, we may use cookies to:
The affiliate tracking cookies contain:
This tracking helps us compensate our partners who refer customers to our service. You may opt out of affiliate tracking by clearing your browser cookies or using private/incognito browsing mode.
Under the EU General Data Protection Regulation (GDPR), we are required to have a lawful basis for each type of processing we perform on your personal data. The table below sets out the legal basis we rely on for each processing activity.
| Processing Activity | Data Categories | Legal Basis |
|---|---|---|
| Account registration and management | Name, email, password | Contractual necessity — Art. 6(1)(b). Necessary to create and maintain your account per our Terms of Service. |
| Subscription billing | Payment information, billing address, transaction history | Contractual necessity — Art. 6(1)(b). Necessary to process payments for services you subscribed to. |
| AI-powered PR outreach (profile processing, journalist response generation) | Professional profile, credentials, expertise, communication style | Contractual necessity — Art. 6(1)(b). This is the core service you contracted us to deliver. |
| AI content generation via sub-processors (OpenAI, Anthropic, Google AI) | Profile data, journalist queries, generated responses | Contractual necessity — Art. 6(1)(b). Necessary to deliver the AI-powered outreach service. |
| Media outreach via Featured.com (pitch submission to journalists) | Name, professional credentials, expertise, AI-generated pitch content | Contractual necessity — Art. 6(1)(b). Necessary to deliver the media outreach service by submitting expert pitches to journalists through Featured.com's network. |
| Essential cookies (session, authentication) | Session identifiers, authentication tokens | Contractual necessity — Art. 6(1)(b). Strictly necessary for the Service to function. |
| Product analytics (PostHog) | Usage patterns, feature interactions, anonymized session data | Legitimate interests — Art. 6(1)(f). Improving service quality, identifying bugs, and understanding usage patterns. |
| Analytics and marketing cookies (Google Analytics, non-essential) | Browsing behavior, page views, click patterns, device information | Consent — Art. 6(1)(a), also required under the ePrivacy Directive (Directive 2002/58/EC). Obtained via our cookie consent banner before non-essential cookies are set. |
| Marketing communications | Email address, name, communication preferences | Consent — Art. 6(1)(a). Explicit opt-in at signup or via your preferences panel. |
| Live chat and CRM (GoHighLevel) | Name, email address, chat messages, browsing context | Legitimate interests — Art. 6(1)(f). Pre-sale support, lead management, and responding to inquiries submitted through our chat widget. |
| Affiliate program tracking | Affiliate ID, referral source, conversion data | Consent — Art. 6(1)(a), also required under the ePrivacy Directive (Directive 2002/58/EC). Obtained via our cookie consent banner before the affiliate tracking cookie is set. |
| Tax and financial records | Payment records, tax identification information | Legal obligation — Art. 6(1)(c). Required by applicable tax and accounting legislation. |
| Fraud prevention and security | IP addresses, device identifiers, login patterns | Legitimate interests — Art. 6(1)(f). Protecting the Service and our users from unauthorized access and abuse. |
| Responding to legal requests | Any data as required by valid legal process | Legal obligation — Art. 6(1)(c). Compliance with court orders, law enforcement, and regulatory requests. |
Where we rely on legitimate interests as our legal basis, we have conducted a balancing assessment to ensure our interests do not override your fundamental rights and freedoms. Our legitimate interests include:
You have the right to object to any processing based on legitimate interests at any time. See the Data Protection Rights section below for details.
Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal:
StartupBros LLC d/b/a PR Bot uses the collected data for various purposes:
The primary purpose of PR Bot is to facilitate communications between you and journalists/media outlets. We do this by submitting expert responses on your behalf through Featured.com (operated by Terkel Inc.), a third-party platform that connects subject-matter experts with publishers and journalists. By using our service, you expressly authorize us to:
Important: Once your data is transmitted to Featured.com, it is processed under Featured.com's own Privacy Policy and Terms of Service. Featured.com may retain and use your submitted content in accordance with their policies, including a perpetual license to published expert responses. We encourage you to review their policies.
We will only share the minimum information necessary to effectively respond to media opportunities on your behalf.
If you choose to participate in our affiliate program, we collect additional information to manage your affiliate account:
This information is used solely for:
Stripe Connect handles all sensitive financial information according to PCI compliance standards. We do not store your banking details on our servers.
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
StartupBros LLC d/b/a PR Bot will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
To provide and improve our Service, we work with trusted third-party service providers who process your personal information on our behalf. Below is a list of our key sub-processors and the categories of data they process:
| Service Provider | Purpose | Data Categories | Location |
|---|---|---|---|
| Supabase | Database, authentication, storage | All user data, profile data, account information | United States |
| OpenAI | AI content generation | Profile data, journalist queries, generated responses | United States |
| Anthropic | AI content generation | Profile data, journalist queries, generated responses | United States |
| Google AI | AI content generation | Profile data, journalist queries, generated responses | United States |
| Stripe | Payment processing, subscriptions | Payment information, billing details, transaction history | United States |
| Stripe Connect | Affiliate payouts, tax reporting | Banking details, tax IDs, commission data (affiliates only) | United States |
| PostHog | Product analytics, session replay | Usage data, feature interactions, anonymized session data | United States |
| Google LLC (Google Analytics) | Website analytics, traffic reporting | IP addresses (anonymized), browsing behavior, page views, device information | United States |
| Vercel | Application hosting, CDN | Log data, IP addresses, usage data | Global (CDN) |
| HighLevel Inc. (GoHighLevel) | CRM, live chat widget, marketing automation | Name, email address, chat messages, browsing context | United States |
| Featured.com (Terkel Inc.) | Media outreach and expert content placement | Name, professional credentials, expertise, AI-generated pitch content | United States |
Important Notice for EU/UK Residents: Data transfers to the United States and other countries are conducted under appropriate safeguards. Many of our sub-processors are certified under the EU-U.S. Data Privacy Framework (DPF), and where applicable we also rely on Standard Contractual Clauses (SCCs) as approved by the European Commission. Each sub-processor has committed to protecting your data in accordance with applicable data protection laws.
For detailed information about data processing safeguards and retention policies, please see our Data Processing Information page.
AI Vendor Data Retention: Profile data sent to AI service providers (OpenAI, Anthropic, Google AI) is processed to generate responses on your behalf. These vendors may retain data according to their own privacy policies. For complete details about how we use AI and your rights, see our AI Transparency & Policy page. You can review vendor privacy policies at:
This list is current as of the last update date shown above. We may add, remove, or change sub-processors as needed to provide and improve our Service. We will update this list accordingly.
StartupBros LLC d/b/a PR Bot may disclose your Personal Data in the good faith belief that such action is necessary to:
Depending on your location, you may have certain rights regarding your personal information, including:
Right to Object to Legitimate Interests Processing (GDPR Article 21): Where we process your data on the basis of legitimate interests (Article 6(1)(f)), you have the right to object at any time. Upon receiving your objection, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection supervisory authority. If you are in the EU, you can find your local authority at edpb.europa.eu. If you are in the UK, you may contact the Information Commissioner's Office (ICO).
To exercise any of these rights, please contact us at privacy@prbot.ai.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you may direct privacy inquiries to our dedicated international privacy contact at privacy@prbot.ai. We are committed to cooperating with the guidance and decisions of the relevant data protection supervisory authorities regarding any complaints or concerns that cannot be resolved directly with us.
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Florida, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, or another state with a comprehensive consumer privacy law, you have specific rights over your personal information, including the right to access, delete, correct, and opt out of certain processing activities.
We do not sell your personal information for monetary consideration. However, certain analytics and advertising-related cookies may constitute “sharing” under the CCPA/CPRA or “targeted advertising” under other state laws. For complete details about our data sharing practices, your opt-out rights, a state-by-state rights breakdown, and how to exercise your choices, please visit our standalone Your Privacy Choices page.
We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of the sale and sharing of personal information, as required by the CCPA/CPRA, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, and other applicable state laws. When we detect a GPC signal, we automatically treat it as an opt-out request for your browser.
To exercise any of these rights, please contact us at privacy@prbot.ai with the subject line “Privacy Rights Request.” We will verify your identity before processing your request and respond within 45 days. For opt-out requests and detailed state-by-state information, visit our Your Privacy Choices page.
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law:
We honor the Global Privacy Control (GPC) opt-out preference signal. If your browser or device sends a GPC signal (via the Sec-GPC HTTP header or the navigator.globalPrivacyControl JavaScript API), we will treat that signal as a valid request to opt out of the sale or sharing of your personal information, as required by the California Consumer Privacy Act (CCPA/CPRA), the Colorado Privacy Act (CPA), and other applicable state privacy laws.
When we detect a GPC signal:
If you have previously accepted cookies on our site and subsequently enable GPC in your browser, we will honor the GPC signal as your most recent privacy preference and treat it as a new opt-out request.
We do not respond to the deprecated Do Not Track (DNT) browser signal, as it lacks a legal framework or technical standard requiring compliance.
To enable GPC, visit your browser's privacy settings or install a browser that supports GPC, such as Firefox, Brave, or DuckDuckGo. For more information, see our Your Privacy Choices page.
In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law:
If the Company is involved in a merger, acquisition, asset sale, or bankruptcy, your personal data may be transferred as part of that transaction. We will notify you before your personal data is transferred and becomes subject to a different privacy policy.
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
We implement a variety of security measures to help protect your information:
For comprehensive details about our security controls, infrastructure, encryption standards, and vulnerability disclosure program, please see our Security Policy.
Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Our Service does not address anyone under the age of 18 (“Children”).
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy, please contact us:
StartupBros LLC d/b/a PR Bot
100 1st Ave N, #2706
St. Petersburg, FL 33701, USA
Email: privacy@prbot.ai
This Privacy Policy explains how we process your personal data. Where we rely on consent as a legal basis, we obtain your explicit consent through a clear affirmative action before processing begins. For all other processing, our legal bases are set out in the table above.
Related Legal Documents:
Questions about this document? Contact us at privacy@prbot.ai
Ready to build your media presence?
Most customers get their first backlink within 7 days. 30-day money-back guarantee on every plan.
See Plans