Privacy Policy
Effective September 21, 2026
1. Who operates Produrate
Produrate is a product-validation service offered under the SolutAI brand. Produrate is operated by JDJ Invest s.r.o. References to "Produrate," "SolutAI," "we," "us," or "our" in this Privacy Policy mean JDJ Invest s.r.o. Our full operator identity and contact details are at the bottom of this page.
2. Scope
This Privacy Policy explains what information Produrate processes when a company creates an account and submits a product for evaluation, when someone participates in an evaluation as a respondent, and when either interacts with the public parts of the service. It covers the SolutAI homepage, the Produrate landing page, the company dashboard, the product submission and payment flow, and the public evaluation flow at /evaluate.
3. Company-account data
When a company creates an account, we collect an account/company name, an email address, and a password. Your password is handled by our authentication provider and is never visible to us in plain text. We also keep basic account timestamps and the products, bids, and payment-related records associated with your account, described further below.
4. Respondent/evaluation data
When you participate in a product evaluation as a respondent, we process:
- Your response — whether you're interested, unsure, or not interested, and, where applicable, the price you say you'd be willing to pay.
- A random browser identifier — when you first open an evaluation, your browser generates a random identifier and stores it in your browser's local storage. This identifier is not derived from your device, browser, or hardware in any way — it's a random value your browser can reset at any time (for example, by clearing site data or using a private/incognito window). We use it to recognize repeat visits from the same browser and to help prevent the same browser from responding to the same product more than once.
- A privacy-preserving signal derived from your IP address — while your response is being submitted, we briefly process your IP address to compute a one-way cryptographic transformation of it. We do not store your raw IP address; only this transformed value is kept, and it cannot practically be reversed back into your original IP address without a secret key we control.
- A signal derived from your browser's User-Agent — we briefly check your browser's User-Agent to help identify clearly automated or non-browser traffic. We do not store the raw User-Agent string, only a derived signal.
- Referral information — if you arrived via a shared link, we may record which link (and any campaign information attached to it) brought you to the evaluation, so the company can see in aggregate where their responses came from.
None of this identifies you in the ordinary sense — we don't ask for or knowingly collect your name, email address, or other directly identifying information as a respondent, and we don't use canvas, font, WebGL, or other device-fingerprinting techniques. We do treat the browser identifier and the IP-derived signal as personal data for the purposes of this policy, since they're pseudonymous identifiers tied to your browser and activity.
5. Product/content data
When a company submits a product, we collect the product's title, description, an image, a planned selling price and currency, and the company's chosen bid amount. See "Public product information" below for what becomes visible once a product is active.
6. Payment processing
Payments (bids and top-ups) are processed through Stripe, a third-party payment processor, using Stripe's own hosted checkout page. When you pay, you're redirected to a page hosted by Stripe — your card details are entered there and are never sent to or stored on Produrate's own servers.
To set up a payment, we send Stripe the amount and currency of the payment, a short description of what it's for, and opaque internal identifiers that let us match the payment back to the right record once it completes. We do not currently send Stripe your billing email address, and we do not currently create a saved Stripe customer profile for your company.
Once a payment completes or is refunded, we store Stripe's own transaction and refund reference identifiers so we can reconcile and, if needed, look into a specific payment. We never see or store your card number or other card details.
7. Anti-abuse/integrity processing
We use the signals described in "Respondent/evaluation data" above — together — as automated integrity checks intended to help keep response counts meaningful, by limiting duplicate, abusive, or clearly automated activity. Passing these checks may determine whether a given response counts toward a product's target number of validated responses. We don't publish the exact thresholds or scoring logic behind this processing, since doing so would make it easier to defeat.
8. Public product information
Once a product is approved and becomes active, some of the information a company submitted becomes publicly visible through Produrate — specifically the product's title, description, image, planned/declared price and currency, and aggregate validation information such as how many validated responses it has received and, on our leaderboards, how it ranks relative to other active products.
We do not make the following public: the company's identity or internal account/company identifier, the exact bid or top-up amount paid for priority, or any respondent's browser identifier, IP-derived signal, or other anti-abuse data.
9. Cookies and local browser storage
Produrate does not use advertising cookies, third-party tracking pixels, or analytics/marketing tracking software. We do use a small number of strictly functional browser-storage mechanisms:
- The evaluation flow stores the random browser identifier described above in your browser's local storage, used only for duplicate-response prevention.
- Our authentication provider stores session information in your browser so you can stay signed in to your company account.
- The company dashboard sets a small, non-tracking cookie to remember a display preference (such as whether a sidebar is expanded), and nothing else.
- Pages on this site load webfonts directly from Google Fonts. Loading these fonts causes your browser to make a direct request to Google's servers, which — as with any request to a third-party server — exposes your IP address to Google as a normal part of that request.
We do not use cookies or local storage for advertising or cross-site tracking.
10. Service providers
We use a small number of service providers to operate Produrate:
- Stripe — payment processing, described above.
- Supabase — provides our authentication, database, and file-storage infrastructure, including the emails our authentication provider sends for account confirmation and password resets.
We do not use any analytics, advertising, or marketing-technology providers, and we do not sell or rent personal data to anyone.
11. Retention
We currently retain account, product, payment, and evaluation-related records for as long as needed to operate Produrate — including maintaining transaction and moderation records, protecting the integrity of evaluation results, and meeting our own legal and accounting obligations. Produrate does not yet have an automated, time-based deletion system, so data isn't automatically deleted after a fixed period today. If you'd like us to review or delete specific information about you, contact us (see "Data-subject and privacy requests" below) and we'll handle your request manually.
12. Security
We apply a number of technical measures intended to limit who can access what: product images are stored in a private file-storage location rather than a publicly listable one; the browser-identifier and IP-derived anti-abuse signals described above are never exposed to the companies whose products are being evaluated; and server-side credentials are kept out of the code that runs in your browser. No system is perfectly secure, and we can't guarantee absolute security.
13. Data-subject and privacy requests
If you'd like to ask what information we hold about you, request a correction, or ask us to delete it, contact us at helpdesk@solutai.io. Because Produrate is currently in a small, controlled beta, we handle these requests manually rather than through an automated self-service tool. We'll do our best to respond promptly, though we can't yet commit to a specific processing timeframe.
14. International and data-location considerations
Produrate is operated from the Czech Republic. Our database, authentication, and file-storage infrastructure is hosted within the European Union. Some of our other service providers, including our payment processor, operate international infrastructure and may process data outside the European Economic Area as part of their own standard global operations.
15. Contact
JDJ Invest s.r.o.
IČO 25405128
Na Luhách 1559/14
400 01 Ústí nad Labem, Czech Republic
helpdesk@solutai.io
16. Changes to this policy
We may update this Privacy Policy from time to time, for example as Produrate's features change. We'll update the effective date above when we do. If a change is significant, we'll make a reasonable effort to bring it to your attention.
Also see our Terms of Service.