Promptation

Legal

Privacy Policy

Last updated: April 20, 2026

This Privacy Policy describes how Promptation (“we”, “us”, or “our”) collects, uses, and protects information when you use our website (promptation.ai), desktop application, and API services (collectively, the “Services”).

1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address, display name, and a securely hashed password. We never store plaintext passwords.

1.2 Usage Data

We automatically collect information about how you interact with the Services, including:

  • Pages visited and features used
  • Device type, operating system, and browser
  • IP address and approximate location (country/region)
  • Timestamps of access and session duration

1.3 Content Data

Prompt templates, project names, workspace settings, and other content you create within the Services are stored to provide and improve the product.

1.4 Communication Data

If you contact us via the contact form or email, we collect your name, email address, and message content.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Services
  • Authenticate your identity and manage your account
  • Respond to support requests and communications
  • Monitor for security threats, abuse, and fraud
  • Generate aggregated, anonymized analytics to improve the product
  • Comply with legal obligations

3. Data Sharing

We do not sell your personal data. We may share data with:

  • Service providers — hosting, analytics, and email delivery services that process data on our behalf under strict agreements.
  • Legal authorities — when required by law, subpoena, or to protect our rights.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice to affected users.

4. AI Provider Data

When you use Promptation to interact with third-party AI providers (e.g., OpenAI, Anthropic, Google), prompt content is sent to those providers to generate responses. We do not control how third-party providers process that data. Please review their respective privacy policies.

We never use your prompts or outputs to train our own models or any third-party models.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., transaction records, audit logs).

6. Security

We implement industry-standard security measures including:

  • TLS encryption for all data in transit
  • Bcrypt password hashing with configurable cost factor
  • Token-based authentication with short-lived access tokens and rotatable refresh tokens
  • Role-based access controls and audit logging
  • Regular security reviews and dependency scanning

7. Cookies

We use essential cookies for authentication and session management. We may use analytics cookies to understand usage patterns. You can control cookie preferences in your browser settings.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access and receive a copy of your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Data portability (receive your data in a structured format)

To exercise any of these rights, contact us using the information below.

9. Children’s Privacy

The Services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal data, please contact us so we can delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Continued use of the Services after changes constitutes acceptance.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please: