Privacy Policy

Last updated: March 24, 2026

Darwin & Rose, LLC (“Company,” “we,” “us,” or “our”) operates the MyPros+ platform (“Service”). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use the Service.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, do not use the Service.

1. Information We Collect

1.1. Information You Provide

Account Information: Name, email address, phone number, company name, ZIP code, business type, and trade categories when you create an account or complete onboarding.

Payment Information: Billing details are collected and processed by our third-party payment processor (Stripe, Inc.). We do not store complete credit card numbers, CVVs, or full payment account numbers on our servers. We may store the last four digits of your card number and expiration date for display in your account settings.

Communications: Information you provide when contacting us via our contact form, submitting feedback, or requesting support.

User Content: Diagnostic queries, annotations, notes, and other content you voluntarily submit through the Service.

1.2. Information Collected Automatically

Usage Data: Features used, searches performed, diagnostic queries submitted, pages viewed, documents accessed, and interactions with the Service.

Device Information: Browser type and version, operating system, device type, screen resolution, and device identifiers.

Log Data: IP address, access times, referring URLs, and pages visited.

Location Data: Approximate location based on your IP address. We do not collect precise GPS location.

Cookies and Similar Technologies: See Section 8 (Cookies and Tracking) below.

Camera and Image Data: If you use the camera feature to photograph model tags, wiring diagrams, or other appliance documentation, these images are transmitted to our AI provider for processing. Images are processed in real-time and are not permanently stored on our servers after the diagnostic response is generated.

2. How We Use Your Information

We use your information to:

  • Provide, operate, maintain, and improve the Service
  • Process subscriptions and payments
  • Verify your account via email and SMS
  • Send transactional communications (account confirmations, billing receipts, trial notifications, service updates, security alerts)
  • Respond to your inquiries and support requests
  • Monitor and analyze usage patterns to improve the Service
  • Detect, prevent, and address fraud, abuse, or security issues
  • Enforce our Terms of Service
  • Comply with legal obligations

We do NOT use your personal information to:

  • Sell or rent your data to third parties
  • Serve targeted or behavioral advertising
  • Build advertising profiles
  • Share your diagnostic queries or repair history with third parties for their independent use
  • Send unsolicited marketing emails (unless you opt in)

3. How We Share Your Information

We may share your information only in the following circumstances:

3.1. Service Providers

We use the following third-party services to operate the platform:

  • Stripe — Payment processing. Stripe collects and processes your payment information directly. See Stripe's Privacy Policy.
  • Supabase — Database hosting and authentication. Your account data and usage data are stored on Supabase infrastructure.
  • Anthropic — AI processing. Your diagnostic queries, uploaded images (model tags, wiring diagrams), and relevant model context are sent to Anthropic's Claude API to generate diagnostic responses. This data is used solely for generating your response and is not used to train AI models. See Anthropic's Privacy Policy.
  • Vercel — Application hosting and content delivery.
  • Resend — Transactional email delivery (account confirmations, billing receipts, trial notifications).
  • Microsoft Clarity — Session recording, heatmaps, and behavioral analytics to improve the Service. See the Microsoft Privacy Statement.

These providers access your data only as necessary to perform their services and are bound by contractual obligations to protect your information.

3.2. Team Accounts

If you are part of a team account, your team administrator may have access to limited aggregate usage statistics (such as number of searches performed). Your specific diagnostic queries and chat content are not shared with team administrators.

3.3. Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or enforceable governmental request, or if we believe in good faith that such disclosure is necessary to: (a) comply with a legal obligation; (b) protect the rights, safety, or property of the Company, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect against legal liability.

3.4. Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service of any change in ownership or uses of your personal information.

3.5. With Your Consent

We may share information with your explicit consent for purposes not described in this policy.

3.6. AI-Specific Data Processing

When you use AI diagnostic features, the following data may be transmitted to our AI provider (Anthropic):

  • Your diagnostic query or symptom description
  • Images you upload (model tags, wiring diagrams, data plates)
  • The model number and appliance information for your current session
  • Relevant excerpts from service documentation used to generate the response

This data is processed in real-time to generate your diagnostic response. We do not send your name, email address, phone number, or payment information to our AI provider. Your diagnostic queries and uploaded images are not used by Anthropic to train their AI models, per our contractual agreement.

We do not sell, share, or disclose your personal information to any third party for their own marketing, advertising, or commercial purposes.

4. SMS & Phone Number Policy

MyPros+ collects your phone number during account registration for identity verification purposes only. When you tap “Send Code” during signup, we send a one-time SMS verification code to the phone number you provided. We do not send marketing, promotional, or recurring messages via SMS. Your mobile phone number and SMS opt-in data will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. Message and data rates may apply. You may opt out of SMS messages at any time by replying STOP. For assistance, reply HELP or contact us at hello@mypros.plus.

5. Data Security

We implement commercially reasonable technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of sensitive data at rest
  • Row-level security on database access
  • Secure authentication with hashed passwords
  • Access controls limiting employee access to personal data
  • Regular security assessments

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law (including California Civil Code § 1798.82, which requires notification without unreasonable delay, and in no event later than required by law).

6. Data Retention

We retain your personal information as follows:

  • Account information (name, email, phone): Retained while your account is active and for 30 days after account deletion to allow for account recovery.
  • Diagnostic chat history: Retained while your account is active. Deleted within 30 days of account deletion.
  • Uploaded images (model tags, wiring diagrams): Processed in real-time for AI diagnostics and not permanently stored after the response is generated.
  • Payment records: Retained for 7 years after the transaction date to comply with tax and accounting requirements.
  • Usage analytics: Anonymized and aggregated after 12 months. Anonymized data may be retained indefinitely to improve the Service.
  • Server logs (IP addresses, access times): Retained for 90 days for security and abuse prevention purposes.

After the applicable retention period, personal information is securely deleted or anonymized.

7. Your Rights

Depending on your location, you may have the following rights:

7.1. Access and Portability

You may request a copy of the personal information we hold about you in a commonly used, machine-readable format.

7.2. Correction

You may update your account information at any time through your account settings or by contacting us.

7.3. Deletion

You may request deletion of your account and personal information through your account settings or by contacting us. We will comply with deletion requests within 30 days, subject to legal retention requirements.

7.4. Opt-Out of Non-Essential Communications

You may opt out of non-essential communications at any time by using the unsubscribe link in any email or by contacting us.

7.5. Data Processing Objection

Where applicable, you may object to the processing of your personal data on grounds relating to your particular situation.

8. Cookies and Tracking Technologies

8.1. Essential Cookies

We use cookies that are strictly necessary for the operation of the Service, including session management and authentication. These cookies cannot be disabled without breaking core functionality.

8.2. Analytics

We use Google Analytics 4 (GA4) to analyze usage patterns and improve the Service. GA4 collects anonymized usage data including pages visited, session duration, device information, and general geographic location. GA4 does not collect personally identifiable information. Google's privacy policy is available at https://policies.google.com/privacy.

8.3. Analytics and Session Recording

We partner with Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve our products and services. Website usage data is captured using first and third-party cookies and other tracking technologies. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

8.4. No Advertising Cookies

We do not use third-party advertising cookies, retargeting pixels, or cross-site behavioral tracking technologies.

8.5. Do Not Track

We do not currently respond to “Do Not Track” (DNT) browser signals, as there is no industry-standard technology for recognizing and implementing DNT signals. However, we do not engage in cross-site tracking.

9. State Privacy Rights

9.1. California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond what is necessary to provide the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Global Privacy Control: We honor Global Privacy Control (GPC) signals. When we detect a GPC signal from your browser, we treat it as a valid opt-out request.

To exercise these rights, contact us at hello@mypros.com or at the address below. We will verify your identity before processing any request. We will respond to verifiable requests within 45 days.

9.2. Other U.S. State Residents

If you are a resident of Virginia, Colorado, Connecticut, Texas, Oregon, Indiana, Kentucky, Tennessee, Montana, Iowa, or any other state with applicable consumer privacy legislation, you may have similar rights to access, correct, delete, and opt out of certain processing of your personal information. To exercise these rights, contact us at hello@mypros.com. We will process your request in accordance with applicable state law.

9.3. Do Not Sell or Share

We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising. Because we do not engage in these practices, there is no need to submit an opt-out request, but you may contact us at any time to confirm.

10. European Economic Area (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

10.1. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance: Processing necessary to provide the Service you requested (account management, diagnostics, document access).
  • Legitimate interest: Processing for analytics, security, fraud prevention, and service improvement, where our interests do not override your data protection rights.
  • Consent: Processing based on your explicit consent, which you may withdraw at any time (e.g., optional communications).
  • Legal obligation: Processing required to comply with applicable laws.

10.2. Your Rights Under GDPR

In addition to the rights described in Section 7, you have the right to:

  • Access: Request a copy of your personal data.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data (“right to be forgotten”).
  • Data portability: Receive your data in a structured, machine-readable format.
  • Restriction: Request restriction of processing in certain circumstances.
  • Objection: Object to processing based on legitimate interest.

10.3. International Data Transfers

Your personal data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for such transfers, ensuring that your data receives an adequate level of protection.

10.4. Contact for Data Protection Inquiries

For questions about GDPR compliance or to exercise your rights, contact us at hello@mypros.com or at the postal address in Section 15 below. You also have the right to lodge a complaint with your local data protection supervisory authority.

11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a person under 18, please contact us immediately and we will take steps to delete such information.

12. International Users

The Service is operated from the United States. If you access the Service from outside the United States, you acknowledge and consent to the transfer of your information to the United States for processing and storage. The data protection laws of the United States may differ from those of your jurisdiction.

13. Third-Party Links

The Service may contain links to third-party websites or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect. The “Last updated” date at the top reflects the most recent revision. Your continued use of the Service after changes take effect constitutes acceptance.

15. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint about our data practices, contact us at:

Darwin & Rose, LLC

2801 Ocean Park Blvd, Suite 1140

Santa Monica, CA 90405

Email: hello@mypros.com

Phone: 1-424-322-1712