PRIVACY POLICY
Your prompt is yours.
This policy explains what Promptr stores, why it is stored, and the choices available to you.
Effective August 10, 2026At a glance
You can use Promptr without an account. Anonymous drafts, private modules, favorites, and browser-saved configurations stay in your browser and are not uploaded by Promptr. If you sign in and choose to save a configuration to your profile, that cloud copy is stored so it can be opened on your other devices.
Promptr does not sell personal information or use prompt configurations for advertising.
Information we collect
Browser-only use
Promptr uses browser local storage for drafts, private custom modules, favorites, preferences, and configurations you save locally. This information remains on that device unless you copy it, clear the site’s storage, or save a configuration to a signed-in profile.
Signed-in profiles
When you sign in with Google, Promptr receives the account details needed to create and operate your profile, such as your name, email address, profile image, provider account identifier, and authentication tokens. OAuth tokens are encrypted in storage.
Cloud-saved prompts
Cloud saves can include the name, description, tags, shell type, generated configuration text, selected modules, private module definitions, colors, and automated safety-scan results. Do not place passwords, access tokens, private keys, or other secrets in a prompt configuration.
Votes and suggestions
Promptr stores votes on official modules and module suggestions submitted from signed-in profiles. Suggestions may include a tool name, your description of the desired module, and an optional documentation link.
Privacy requests and feedback
If you use the privacy and feedback form, Promptr stores the category, subject, message, optional name and contact email, request status, and Promptr’s response. An account is not required. A random secret lets you privately check the request; Promptr stores only a one-way hash of that secret.
Operational information
Hosting and authentication providers may process limited technical information such as IP address, browser type, request time, error details, and security events to operate and protect the service.
How information is used
- Provide account sign-in and cross-device configuration sync.
- Save, display, update, and delete the configurations you request.
- Count votes and review suggestions for official modules.
- Receive, review, respond to, and retain privacy requests and feedback.
- Detect abuse, troubleshoot failures, and protect the availability of the service.
- Comply with legal obligations and enforce applicable service rules.
Service providers
Promptr relies on service providers that process information only as needed to provide their services. These currently include Vercel for application hosting, Neon for managed PostgreSQL storage, and Google for OAuth sign-in. Their handling of information is also governed by their respective terms and privacy policies.
Retention and deletion
Browser-only information remains until you delete it, clear browser storage, or the browser removes it. Cloud configurations remain until you delete them or delete your account. Votes are deleted with the account.
Module suggestions may remain after account deletion because they can still help improve Promptr, but the association with the deleted profile is removed. Operational and security records are retained only as reasonably needed for reliability, fraud prevention, dispute resolution, or legal compliance and may also be subject to provider retention settings.
Open privacy requests remain while they are being reviewed. Resolved and closed privacy requests are scheduled for deletion after 90 days unless longer retention is reasonably required to establish compliance, resolve a dispute, prevent abuse, or meet a legal obligation. Expired records are removed during routine privacy and administrative activity.
You can delete individual cloud configurations from your profile. You can also permanently delete your Promptr account from the profile page. Account deletion removes the profile, sessions, linked OAuth account, cloud configurations, and votes. It does not erase browser-only data on your devices; you control that data through Promptr or your browser settings.
Security
Promptr uses access controls, encrypted OAuth-token storage, private-by-default configurations, isolated validation when explicitly enabled, and transport security. No system is perfectly secure, so review generated shell code before installing it and never store credentials in a prompt.
Your choices and rights
You may use Promptr anonymously, keep configurations only in your browser, delete cloud saves, remove your account, or stop using the service. Depending on where you live, you may also have rights to request access, correction, deletion, restriction, or a copy of personal information.
To ask a privacy question, submit feedback, or exercise a data right, use the Promptr privacy request form. No account or email address is required, and the form provides a secret link for checking Promptr’s response. Promptr may need to verify your identity before completing requests involving account data.
Children
Promptr is not directed to children under 13, and Promptr does not knowingly collect personal information from children under 13.
International processing and policy changes
Promptr and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws from your location.
This policy may be updated as Promptr changes. Material changes will be identified by updating the effective date and, when appropriate, by providing an in-product notice.