← Back to PromptUI

Privacy Policy

Last updated: August 6, 2026

PromptUI operates this service. For privacy and data requests, use the contact channel listed on this site.

This Privacy Policy applies to PromptUI and PromptUI Growth Agent. PromptUI Growth Agent is the social publishing and GTM workspace inside PromptUI.

TL;DR — Plain English Summary

  • ✅ We collect your email, prompts, and generated code to run the service.
  • ✅ We never sell your data to third parties.
  • ✅ Payments go through Stripe — we never see your card details.
  • ✅ Projects are private by default. You control what you share.
  • ✅ We use analytics, advertising, and referral technologies. In the EU/UK/Switzerland you choose via the cookie banner — reject and only essential technologies load.
  • ✅ You can request deletion of your data at any time.

1. Information We Collect

Account Information

When you sign up via Clerk authentication, we collect your email address, name, and profile information provided by your authentication provider (Google, GitHub, or email).

Usage Data

  • Prompts and instructions you provide to the AI builder
  • Brand profiles, campaign briefs, and publishing settings you save in PromptUI Growth Agent
  • Generated code and project files created by the Service
  • Session metadata (timestamps, status, model used)
  • Credit balance and transaction history

Connected Services

If you connect GitHub or a supported social account, we process the account and installation identifiers, selected-repository or connected-account metadata, and the content needed to perform the import, export, synchronization, or publishing action you request. GitHub repository contents are accessed only for repositories you authorize.

Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers or payment details on our servers. We receive transaction confirmations and subscription status from Stripe.

2. How We Use Your Information

  • Service Delivery: Your prompts and relevant project context are sent through OpenRouter or to selected AI model providers to generate and refine code and content. These providers may process that data under their own privacy policies.
  • Build and Verification: Generated project files and the related build output are processed in isolated E2B environments, while Trigger.dev runs background jobs needed for builder and media workflows.
  • GitHub Integration: If you connect GitHub, we use the access you grant to list selected repositories and perform the import, export, or synchronization action you request.
  • Social Publishing: If you use PromptUI Growth Agent, we process your connected-account metadata, draft content, and publishing preferences to support social posting workflows.
  • Account Management: To manage your account, credits, and session history.
  • Service Improvement: Aggregated, anonymized usage data may be used to improve the Service.
  • Communication: To send service, account, purchase, and consented marketing emails through Resend.

3. Data Sharing

We share your data with the following third-party service providers, each operating under their own privacy policies:

  • OpenRouter and selected AI model providers: Receive prompts and relevant project context to generate AI responses
  • GitHub: Provides authentication and, when you connect it, repository import, export, and synchronization for the repositories you authorize
  • Clerk: Handles authentication and user identity
  • Stripe: Processes payments and manages billing
  • Vercel: Hosts the application and may process request logs
  • Supabase: Hosts the database containing your projects and account data
  • E2B: Provides isolated build, preview, and verification environments that process generated project files, configuration, and build or runtime output
  • Trigger.dev: Runs background jobs and processes the job payloads, status, and logs needed for builder and media workflows
  • Resend: Delivers service, account, purchase, and consented marketing emails using recipient addresses and message content or delivery metadata
  • PostHog: Product analytics — records manual product events and, for signed-in users, account identifiers and basic profile details so we can understand reliability and product use
  • Sentry: Browser and server error monitoring. Consented browser monitoring can include sampled performance traces and masked session replay; prompt text, code, and media are masked or excluded from replay.
  • Meta & Google: Advertising measurement — we send conversion and audience signals so our ads can be measured and optimized (subject to your consent, see §9)
  • Tolt: Affiliate/referral tracking — attributes a subscription to the partner who referred you, so they can be credited
  • Connected social, media, and research providers: Process only the account data, content, assets, or queries needed when you connect or request their optional features

We do not sell your personal information to third parties.

4. Data Storage & Security

  • Your data is stored in a PostgreSQL database hosted on Supabase with encryption at rest.
  • GitHub and supported social-account credentials are encrypted before storage, and connected access can be revoked through the relevant provider.
  • All communication is encrypted in transit via HTTPS/TLS.
  • API keys and secrets are stored as environment variables, never in source code.
  • We implement reasonable security measures but cannot guarantee absolute security.

5. Your Projects

  • Projects you create are private by default and accessible only to you.
  • Completed projects can be shared via public links. Only projects with a "done" status are accessible to others via share links.
  • You can export your projects to GitHub at any time, giving you full ownership and portability.

6. Data Retention

We retain your account and project data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., payment records).

7. International Data Transfers

PromptUI and the providers listed above may store or process data in the United Kingdom, European Economic Area, United States, and other countries where those providers operate. Where data-protection law requires it, transfers are supported by appropriate safeguards such as contractual data-protection terms or Standard Contractual Clauses.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to or restrict certain processing of your data

To exercise these rights, contact us at the email provided on our website.

9. Cookies, Analytics & Advertising

We use these cookies and similar technologies:

  • Essential — required for the Service to work: authentication and session management (via Clerk), and your cookie-consent choice. These always load.
  • Referral attribution (Tolt) — if you arrive through an affiliate/referral link, this records which partner referred you so they can be credited when you subscribe. It follows the same regional consent choice as analytics and advertising technologies.
  • Analytics & advertising — non-essential:
    • PostHog — product analytics using manual events; signed-in events can be associated with your PromptUI account
    • Sentry — browser error and performance monitoring with masked session replay sampling
    • Meta Pixel and Google Ads tag — to measure and optimize our advertising (including conversions and remarketing audiences)

Your choice. If you visit from the EU, UK, or Switzerland, PostHog, Sentry browser monitoring, Meta, Google advertising tags, and Tolt do not load until you accept them in the cookie banner shown on your first visit. Choose Reject and only essential technologies are used. Outside these regions, these technologies load by default, but an explicit rejection is respected. You can change your choice at any time using Cookie settings.

Server-side operational events and error logs may still be processed without browser analytics cookies when needed to deliver, secure, troubleshoot, and measure the reliability of the Service. These can include account, session, build, request, and error metadata.

Each provider processes data under its own privacy policy. We never sell your personal information.

10. Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page.

12. Contact Us

For privacy-related questions or to exercise your data rights, contact us at the email provided on our website. PromptUI handles privacy requests for PromptUI and PromptUI Growth Agent.