Privacy Policy

Last updated: September 9, 2026

Introduction

PrompTessor ("we," "our," or "us") provides an AI prompt workspace through our website, mobile applications, Chrome Extension, public REST API, remote MCP service, OAuth authorization service, and webhooks. This Privacy Policy explains what data these products collect, how we use and store it, when it is shared, and the choices available to you.

Information We Collect

Depending on the products and features you use, we collect the following categories of information:

  • Account and profile information, including your name, email address, profile image, plan, account status, and preferences.
  • Authentication information, including session cookies or tokens used to keep you signed in. We do not store your password in plain text.
  • Prompt workflow content, including prompts, selected text, active-input text, additional context, feedback, prompt versions, generated outputs, and output-language choices.
  • User-selected website content and references, including URLs, page content, images, uploaded image files, sampled video frames, file names, and related metadata submitted for a PrompTessor workflow.
  • Prompt Library and History data, including titles, descriptions, categories, model tags, visibility, saves, pins, votes, examples, and generated, analyzed, optimized, refined, or reverse-engineered records.
  • Billing and subscription records, including provider customer, subscription, order, transaction, and invoice identifiers; plan, billing interval, subscription status, current-period dates, scheduled-cancellation and plan-change states; invoice number, amount, currency, payment status, and payment dates. Payment providers collect payment instrument details; PrompTessor does not store full card numbers.
  • Support communications and attachments that you choose to send us.
  • Operational data, including feature usage counts, request timestamps, IP address and server logs, browser or device information, error diagnostics, and security events necessary to operate and protect the Service.
  • Website analytics and cookie information, where enabled, as described in the Cookies section below.

Where Data Is Stored

PrompTessor stores different data in different locations according to the feature being used:

  • On your device: the Chrome Extension uses chrome.storage.local for its authentication token, a limited account profile, language choice, output language, appearance, sidebar position, toolbar preferences, and per-site enable or disable settings.
  • On PrompTessor systems: account records, subscription status, usage records, prompts, workflow history, generated versions, library records, and support records are stored in our application database.
  • In object storage: image attachments and other supported workflow or support files are stored in private cloud object storage and accessed through time-limited signed links.
  • Public or community prompts: content you deliberately mark public or submit to a community area may be visible to other users together with displayed author information and engagement data. Private prompts are not made public unless you change their visibility.
  • With payment providers: Polar stores checkout, customer, billing-identity, tax, payment-method, subscription, order, invoice, receipt, and transaction data under its own privacy policy. Former payment providers may retain historical transaction records under their own policies.

How We Use Your Information

  • Authenticate you and synchronize your account, plan, settings, usage limits, and entitlements across PrompTessor products.
  • Provide user-requested prompt generation, analysis, optimization, refinement, reverse prompting, direct insertion, history, and Prompt Library features.
  • Process the text, URLs, images, video frames, attachments, context, and feedback you deliberately submit to a workflow and return the requested output.
  • Create, display, save, organize, version, and reuse prompts and workflow records at your direction.
  • Create checkouts and authenticated Polar Customer Portal sessions using an external customer identifier; reconcile billing webhooks to activate or revoke entitlements, synchronize renewals, payment failures, cancellations, refunds, invoices, upgrades, and downgrades, maintain billing history, and prevent fraud.
  • Send operational and transactional messages from PrompTessor and/or Polar about successful payments, renewals, failed renewals, plan changes, cancellations, invoices, and receipts. These necessary messages may still be sent when you opt out of marketing communications.
  • Measure feature reliability and aggregate usage, enforce usage limits, troubleshoot errors, secure accounts, and prevent fraud or abuse.
  • Comply with applicable law and enforce our agreements.

Contextual Advertising in Public Free Tools

Eligible public Free Tools may display contextual ads through Hola AI during a limited pilot. These ads may appear while a request is processed and after the result is shown. The Chrome Extension and paid account workflows are not included unless the relevant interface clearly says otherwise.

  • For a thinking-time ad request, we may send the current prompt. For a post-answer ad request, we may send the current prompt and the generated response.
  • We use short-lived generation and session identifiers. Hola AI and advertising technology providers participating in the auction may also receive the IP address, browser or device information, page and placement data, auction events, impressions, clicks, and diagnostics normally involved in delivering and measuring an ad.
  • The data is used to select an ad from the immediate workflow context, run the auction, render and refresh placements, measure delivery, prevent fraud or abuse, and troubleshoot. PrompTessor does not use the workflow content to build a PrompTessor profile for personalized, retargeted, or interest-based advertising.
  • Depending on region and configuration, Hola AI and participating providers may use cookies, local storage, pixels, or similar technologies. Where required by law, non-essential advertising technology is used according to the consent choices made available to you.
  • PrompTessor retains its ad eligibility and event records only as reasonably needed for operations, security, measurement, and compliance. Hola AI and participating providers may retain data under their own privacy and retention practices. Available browser or consent controls may be used to decline or withdraw consent where applicable.

Because prompt and generated response content may be processed for this contextual advertising purpose, do not submit sensitive, confidential, or third-party personal information to a public Free Tool unless you are authorized and comfortable with that processing.

Data Sharing and Service Providers

We do not sell personal information. We disclose only the data needed for a provider or recipient to perform the applicable service, and the parties involved depend on the feature, sign-in method, payment method, or sharing choice you select:

  • Google: optional Google account sign-in, reCAPTCHA fraud and abuse protection, and Google Analytics for website analytics where enabled. Browser workflow content is not sent to Google Analytics.
  • Cloudflare R2: private object storage for supported image and file attachments.
  • Polar: PrompTessor’s active web payment provider and Merchant of Record. We send Polar your name, email, internal user ID as an external customer ID, and the plan, period, purchase mode, transaction, discount, or add-on data needed for checkout, subscriptions, payments, invoices, refunds, and payment recovery. Polar directly collects billing identity, address, tax, and payment-instrument details. Apple: for iOS App Store subscriptions and in-app purchases, Apple receives the App Store account, product, transaction, subscription, billing, tax, and payment information needed to process and manage the purchase. PrompTessor receives signed transaction and subscription status data but does not receive full Apple payment-instrument details.
  • Paddle, Midtrans, and NOWPayments: previously processed selected payments but are currently inactive. They may retain historical transaction and billing records under their own policies. If any is re-enabled, the provider will be identified before checkout and this Policy will be updated.
  • Our contracted application hosting, network, database, and security infrastructure providers: hosting PrompTessor, storing application records, serving requests, backups, monitoring, and protecting the Service.
  • Other PrompTessor users and the public: only when you intentionally publish a prompt, choose public or community visibility, or otherwise direct us to share content.
  • Professional advisers, law enforcement, regulators, courts, or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or complete a corporate transaction subject to applicable notice and consent requirements.
  • Any other party when you give us specific consent or direct us to make the disclosure.

For more information about data handled directly by our payment providers, review the Polar Privacy Policy.

Apple Privacy Policy.

Data Retention and Deletion

We retain data only for as long as needed for the purposes described in this Policy, using the following criteria:

  • Chrome Extension settings and locally stored account data remain on your device until you sign out, clear Extension storage, remove the Extension, or the browser removes that storage.
  • Account, prompt, workflow history, library, and attachment records are retained while your account or the related record remains active so you can reopen, version, save, and reuse them. You can delete supported records or request account deletion.
  • When you delete your account, associated application records are deleted or de-identified, except subscription history, invoices, receipts, refund, dispute or chargeback records, provider transactions, and other information we must retain for tax, accounting, fraud-prevention, security, backup, or legal purposes.
  • Authentication, verification, password-reset, and signed file-access links expire according to their configured security periods.
  • Operational, security, billing, subscription, payment, and audit records are retained only for as long as reasonably necessary for security, accounting, tax, dispute resolution, fraud prevention, compliance, and enforcement, then deleted or de-identified.
  • Data held by Polar or a former payment provider is subject to that provider’s own retention policy and is not automatically deleted when a PrompTessor account is deleted. Requests concerning that data may be directed to the relevant provider.

Data Security

PrompTessor transmits user data between its products and our servers over HTTPS. We use authentication safeguards, access controls, private object storage, time-limited attachment links, operational monitoring, and other reasonable administrative and technical measures. No system is completely secure, so we cannot guarantee absolute security.

Developer Platform Data

When you use the REST API, remote MCP, OAuth, or webhooks, we process additional data needed to authenticate, authorize, operate, secure, and troubleshoot those services:

  • Developer credentials and authorization data: API key name and prefix, one-way hash, scopes, expiration and revocation, last-use time and IP address, OAuth client metadata and redirect URIs, requested or granted scopes, consent records, token identifiers or hashes, resource audience, and security timestamps. Raw API keys and newly created or rotated webhook secrets are displayed once and cannot be recovered from PrompTessor.
  • API and MCP operation data: channel, operation type and status, request ID, idempotency and request hashes, IP address, usage, credit and token counts, related history references, errors, and technical metadata. Request bodies are retained only while processing; responses or errors may be retained temporarily for replay and troubleshooting.
  • Unconsumed temporary uploads are retained for up to 24 hours and upload links expire after 15 minutes; files used in a workflow follow the retention of the related prompt or history record. Idempotency responses are replayable for 24 hours, API and MCP operation records are retained for 90 days, and webhook delivery payloads and logs are retained for 30 days, subject to shorter deletion or longer retention required by law, security, disputes, or enforcement.
  • For webhooks, we store the endpoint URL, description, selected events, encrypted signing secret, payload, delivery attempts and status, response code, and timestamps. Event data is sent to the external endpoint you select; you are responsible for the recipient and its privacy and security practices.
  • A third-party MCP or AI client you connect may receive tool results and process them under its own privacy policy. We send workflow content to AI service providers, including OpenAI where used, only as needed to produce the requested output. You can revoke API keys, disconnect OAuth or MCP access, disable or delete webhooks, and rotate webhook secrets from the available account controls.

Your Rights

Depending on your location, you may have the right to:

  • Access, correct, or obtain a copy of your personal information.
  • Delete supported prompt and workflow records or request deletion of your account and associated data.
  • Change a Prompt Library item's visibility or remove content you published, subject to copies already lawfully shared by others.
  • Opt out of marketing communications while continuing to receive necessary service and security messages.
  • Object to or restrict certain processing and request data portability where applicable.
  • Manage locally stored product settings, including disabling browser tools on individual websites, clearing Extension storage, signing out, or uninstalling the Extension.
  • View and manage billing identity, payment methods, subscriptions, invoices, and receipts held by Polar through the Customer Portal, or contact Polar about data it holds. Requests concerning billing records held by PrompTessor may be submitted to us.

Cookies and Tracking Technologies

We use cookies and similar technologies on the PrompTessor website for authentication, security, preferences, analytics, and permitted campaign measurement. Connected PrompTessor products may use our authentication cookies to access your signed-in account.

What Are Cookies

Cookies are small text files placed on your device when you visit a website. They can keep you signed in, remember settings, protect forms and accounts, and help measure website performance.

Types of Cookies We Use

Essential Cookies

These cookies are necessary for the website and account features to function properly:

  • Authentication cookies to keep you signed in
  • Security and fraud-prevention cookies
  • Session and load-balancing cookies

Analytics Cookies

Where enabled, these help us understand and improve the PrompTessor website:

  • Aggregate website usage statistics
  • Performance and reliability measurement
  • Feature interaction measurement

Preference Cookies

These remember your choices and settings:

  • Theme preferences
  • Language settings
  • User interface customizations

Marketing Cookies

Where enabled and permitted, these support campaign measurement and communications for the PrompTessor website. Prompt workflow content is not used for personalized advertising:

  • Campaign and referral attribution cookies
  • Consent-based conversion measurement
  • Email communication preferences

Third-Party Cookies

Third parties used for authentication, analytics, fraud prevention, and payment processing may set cookies on the PrompTessor website according to their own policies. The Chrome Extension reads only PrompTessor authentication cookies to connect the Extension to your signed-in PrompTessor account; it does not read unrelated websites' cookies.

Managing Your Cookie Preferences

You can control cookies through your browser settings:

  • Block all cookies
  • Allow only first-party cookies
  • Delete existing cookies
  • Set notifications for new cookies

Where required by applicable law, non-essential cookies are used according to the consent choices made available to you. You can also adjust cookie controls in your browser.

Impact of Disabling Cookies

If you disable cookies, some website and connected account features may not function properly:

  • You may need to sign in repeatedly
  • Connected PrompTessor products may not be able to access your signed-in account
  • Your website preferences may not be saved
  • Analytics data may be incomplete

Children's Privacy

PrompTessor is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.

International Data Transfers

PrompTessor and its service providers may process data in countries other than your own. Where required, we use appropriate safeguards for international transfers and require providers to protect data consistently with their contractual and legal obligations.

Browser Extension Data

The PrompTessor Chrome Extension provides user-invoked prompt tools on websites you visit. Its page access is used to display the floating avatar, smart toolbars, and overlay sidebar; insert a prompt into the active input; and process content only when you choose a PrompTessor action.

  • The Extension may read selected text, the active input, an image or video you choose, or the current page URL and relevant page content only when you invoke a generation, analysis, optimization, refinement, insertion, or reverse-prompt workflow.
  • The Extension does not continuously collect or store your browsing history, the list of websites you visit, or unrelated page content.
  • Per-site toolbar settings are stored locally so the Extension can remember where you enabled or disabled a browser tool.
  • Content submitted through a workflow is transmitted to PrompTessor over HTTPS and is handled as described in this Policy.
  • PrompTessor does not sell browser data or use Extension data for personalized, retargeted, or interest-based advertising.

Chrome Web Store Limited Use Disclosure

PrompTessor's use and transfer of information received through Chrome Extension permissions complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

  • We use Extension data only to provide or improve the user-facing prompt workspace features described in the Extension interface and Chrome Web Store listing, and for related security, reliability, and support operations.
  • We do not use or transfer Extension data for personalized advertisements, retargeting, interest-based advertising, creditworthiness, lending, or sale to data brokers.
  • We do not allow humans to read submitted Extension content except when you give specific consent for support, when necessary for security or abuse investigation, when required by law, or when data has been aggregated and de-identified for internal operations.
  • We transfer Extension data only when necessary to provide or improve the disclosed features, protect the Service, comply with law, or complete a permitted corporate transaction subject to applicable requirements.

Contact Us

For questions, privacy requests, or account-deletion assistance, contact us at:

Email: [email protected]

Support email: [email protected]

Website: https://promptessor.com