← Back to home

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Binnash.com.bd ("Binnash", "we", "us", or "our"), the data controller and operator of Progga, collects, uses, shares, and protects your information.

1. Information We Collect

1.1 Account Information

When you register, we collect your name, email address, and a password (stored as a salted hash). You may optionally enable two-factor authentication, which generates a secret key stored in encrypted form.

1.2 Chat Data

We store the content of conversations you have through the Service, including messages, AI responses, thinking blocks, and tool call outputs. This data is processed to provide the Service and may be sent to third-party LLM providers for inference.

1.3 API Usage Data

We record API requests including the model used, number of tokens consumed, request timestamps, and error status. This data is used for billing, monitoring, and improving the Service.

1.4 Payment Data

Payments use the hosted checkout provided by Binnash.com.bd. We retain the amount, Progga and Binnash references, status, consent time, and accounting effects needed to credit or refund your account. When available, the Progga application provides your existing name, email, verified phone number, IP address, and browser user agent to the hosted checkout to open and secure it. Card, bank, or mobile-banking credentials are entered directly in the hosted checkout and are not received or stored by the Progga application.

1.5 User Memory Data

If enabled, we may extract facts and preferences from your conversations to personalize your experience. This data is stored with semantic embeddings and can be managed or deleted by you at any time.

1.6 Technical Data

We collect IP addresses, browser/user-agent information, and session activity logs for security and operational purposes.

1.7 Analytics and Advertising Data

We use Google Analytics to understand traffic sources, campaign performance, device characteristics, and how pages perform. We use Meta Pixel and the Meta Conversions API to measure advertising attribution, optimize campaigns, and build advertising audiences. These services may use cookies or similar browser storage and receive page, campaign, device, and interaction data.

When Meta measurement is enabled, the browser Pixel may send page views and a verified-signup event (CompleteRegistration with only method=email|google) with a random deduplication identifier. Our server may also send the same verified-signup event and, when a payment is marked paid, a server-only Purchase event (with value in BDT and currency=BDT) to Meta for measurement. Server events may include hashed identifiers and attribution data: a SHA-256 hash of your lowercased email, a SHA-256 hash of your verified phone number in E.164 format when available, an HMAC of your internal user id, the Meta click identifier fbclid and browser identifiers _fbp/_fbc, UTM parameters from your first landing, truncated IP address, and user agent. Meta may use the fbtrace_id for debugging.

We do not include chat content, prompts, API request payloads, passwords, payment proofs, names, or unhashed email addresses in our analytics events.

Meta processes this measurement data under the Meta Business Tools Terms. You can review Meta's data uses in its privacy policy and limit processing via your browser cookie controls and the privacy/advertising controls in your Google and Meta accounts.

2. How We Use Your Data

We use collected data for the following purposes:

  • Providing, maintaining, and improving the Service
  • Processing AI inference requests through third-party LLM providers
  • Monitoring usage, detecting abuse, and ensuring security
  • Communicating with you about your account (verification, security notices)
  • Personalizing your experience through the memory system
  • Measuring traffic and advertising campaign performance
  • Complying with legal obligations

3. Data Sharing

3.1 LLM Providers

To generate AI responses, your chat messages are sent to third-party LLM providers (e.g., DeepSeek, Crof, Ollama). Each provider processes data according to its own privacy policy. When running autonomous agents in isolated environments, the agent's LLM requests are routed through our internal proxy.

3.2 Service Infrastructure

We use Redis for caching and real-time streaming, SQLite/MySQL for storage, and may use cloud infrastructure providers for hosting. These providers have access to the minimum data necessary to operate.

3.3 Legal Requirements

We may disclose your data if required by law, court order, or to protect our rights and the safety of our users.

3.4 No Sale of Data

We do not sell your personal data or submitted identifiers to third parties.

4. Data Retention

We retain your account data for as long as your account is active. Chat data is retained indefinitely to provide continuous service. You may delete your chats or your entire account at any time. Usage records may be retained for longer periods for billing and audit purposes. Backup copies may persist temporarily after deletion.

5. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent at any time

6. Security

We implement reasonable security measures including encryption at rest for sensitive fields (API tokens, 2FA secrets), password hashing, and HTTPS in transit. API keys are stored as SHA-256 hashes. However, no system is completely secure, and we cannot guarantee absolute security.

7. Cookies

We use essential cookies for session management, authentication, and storing preferences such as theme appearance and sidebar state. When analytics integrations are configured, Google Analytics and Meta Pixel may also use cookies or similar browser storage for traffic measurement, advertising attribution, campaign optimization, and audience measurement.

You can limit or remove these technologies through your browser's cookie controls and the privacy or advertising controls provided by Google and Meta. Blocking them does not prevent you from using Progga's core services.

8. Third-Party Services

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with your data.

9. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect data from children. If we become aware that a child under 13 has provided us with data, we will take steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or through the Service. Your continued use after changes constitutes acceptance of the updated policy.

11. Contact

If you have questions about this Privacy Policy, please open a support ticket or contact Binnash.com.bd through the channels listed on our website.