Privacy Policy
Last updated: June 5, 2026
This Privacy Policy explains how PromptLab (“we”, “us”) collects, uses, and protects information when you use our website and services (the “Service”). By using the Service you agree to this policy.
1. Information we collect
- Account information. When you sign up we collect your email address, name, and (if you sign in with Google) your Google account profile picture and unique identifier.
- Billing information. Payments are processed by Stripe. We do not store your full card details; we only retain a Stripe customer ID, the status of your subscription, and the plan tier.
- Content you create. Prompts, saved templates, folder names, onboarding answers, and any text you enter into the Service are stored so we can display them back to you.
- Usage data. Standard server logs (IP, user agent, request paths, timestamps) and anonymous product analytics (page views, feature use) via Umami.
2. How we use information
- To provide, maintain, and improve the Service.
- To authenticate you and protect against fraud and abuse.
- To process payments and manage your subscription.
- To send transactional email (account, billing, password reset).
- To respond to support requests.
We do not sell your personal information, and we do not use the content of your prompts to train third-party AI models.
3. Third-party processors
We rely on a small number of vendors to run the Service. Each processes data only as needed to provide their function:
- Stripe — payments and subscription billing.
- Google — optional OAuth sign-in.
- Resend — transactional email delivery.
- Neon — managed PostgreSQL database hosting.
- Vercel — application hosting and CDN.
- OpenRouter / model providers — when you generate a prompt, your input is sent to an AI model provider for completion.
4. Cookies
We use a single session cookie to keep you signed in. We use Umami for product analytics, which is cookie-free.
5. Data retention
We retain your account and content for as long as your account is active. You can request deletion of your account and associated data at any time by emailing us.
6. Security
We use industry-standard practices (TLS in transit, encrypted database storage, scoped access tokens) to protect your data. No system is perfectly secure; we will notify affected users of any breach involving personal data, as required by applicable law.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete personal information we hold about you. To exercise any of these rights, email us at the contact address below.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them.
9. Changes
We may update this policy from time to time. Material changes will be announced in the app or by email.
10. Contact
Questions or requests: support@promptlab.space.