Privacy Policy
Last updated 10 September 2026
The short version
We store your account details and the prompts you enhance so you can find them again. Your prompts are private to your account, we do not sell data, and we do not train models on your content. You can delete any prompt at any time, or delete your whole account from Settings without asking us.
What we collect
- Account data — your email address, an optional display name, and your plan. Authentication is handled by Supabase.
- Sign-up questionnaire — when you create an account we ask for your name, the area you work in, your role title (optional), how you work with AI, which features would be most useful to you, and how you heard about us. We use this to decide what to build. It is never published or sold.
- Prompt data — the text you submit, the enhanced result, the options you chose (category, target model, detail level, tone), and any answers you give to the follow-up questions in “Improve further”.
- Usage data — timestamps, which AI provider served the request, token counts and response times. We use this to keep the service running and to spot abuse.
- A hashed IP — for logged-out visitors only, so the daily free allowance and anti-spam limits can be enforced. It is salted and one-way hashed; we cannot recover the original address from it.
- Support messages — if you contact us through the support form, we keep your name, email, category and message so we can reply and refer back to it.
- Payment data — handled entirely by Stripe. We store only your Stripe customer and subscription identifiers, never card details.
- Analytics — pages visited, roughly where in the world you are, and what referred you, collected by Google Analytics. It never includes your prompts. See Cookies and analytics below.
Who your prompts are shared with
To enhance a prompt we send its text, plus our system instructions, to the AI provider currently in use — Groq, Google (Gemini), OpenAI or Anthropic (Claude). Using “Improve further” sends the same text again so the model can suggest what is missing. They process these requests under their own API terms. We do not enable any training-on-input option offered by these providers.
Your stored prompts are protected by Postgres row-level security, so no other Prompt Mate account can read them. Our staff access production data only when necessary to investigate a fault you have reported.
If you are on a team, two things become visible to the people on it: any template you explicitly choose to share, and how many prompts you have enhanced, on the team's usage page. That page shows counts and dates only — the text of your prompts is never visible to anyone else, including the person who pays for the team. Leaving the team ends both immediately; nothing you wrote is transferred to anyone.
Browser extension
The Prompt Mate Chrome extension adds an Enhance button beside the prompt box on claude.ai, chatgpt.com and gemini.google.com, and on any other site you explicitly enable it for. It reads nothing on its own. When you click Enhance or press the shortcut, the text in that one input — and only that text — is sent to promptmate.cloud and handled exactly as a prompt entered on the website: same providers, same storage rules above.
If you connect the extension to your account, it stores a revocable token on your device and sends it with each request so the prompt counts against your plan and appears in your history. Revoke it at any time from Settings → Connected browsers. Without an account, the extension uses the same daily allowance as a logged-out visitor to the site.
The extension does not track browsing, does not read other pages or other inputs, does not inject advertising, and contains no remotely loaded code.
Sub-processors
- Supabase — database, authentication and storage
- Vercel — hosting and content delivery
- Stripe — payment processing
- Google Analytics — traffic measurement on the public site
- Groq, Google, OpenAI, Anthropic — AI inference (whichever is active)
How long we keep things
- Prompts and templates — until you delete them, or until you delete your account.
- Usage logs — twelve months, then removed by a scheduled job.
- Anonymous IP hashes — seven days, then removed by a scheduled job.
- Support messages — kept while we may still need them to help you; ask us and we will delete a specific thread.
Deleting your account
Settings → Delete account removes your profile, sign-in, every prompt, every template and your questionnaire answers immediately. If you have an active subscription it is cancelled as part of the same action.
Two things deliberately survive, with the link back to you removed: anonymised usage counts, which we need for capacity planning and cannot tie to a person once the account is gone, and any blog post authored from an admin account, which stays published without an author. Deletion cannot be undone.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Deletion is self-serve in Settings. For anything else — including a copy of your data — use the support form and we will respond within 30 days.
Cookies and analytics
We set cookies that keep you signed in. Google Analytics sets its own first-party cookies, which hold a randomly generated identifier so it can tell a returning visit from a new one and show us which pages people arrive on and leave from.
That is measurement, not advertising: we do not run ads on Prompt Mate, and we do not sell what analytics collects. Google processes this data on our behalf — their privacy policy covers what they do with it.
Where we ask before setting them, you will see a notice offering Accept or Reject on your first visit. Reject means the analytics cookies are never set and Google Analytics is never loaded — nothing else about the site changes, and we do not ask again. You can change your mind whenever you like:
reopens that choice. It is also in the footer of every page. A tracker blocker, or Google’s own opt-out add-on, stops the collection too.
Contact
Questions about this policy, or a data request: use the support form. Dedicated privacy and support mailboxes are not live yet, so the form is the reliable route to us.
