Terms of ServicePrivacy PolicyRefund Policy
Legal

Privacy Policy

Effective [Effective date]

This policy explains what personal data Prompt Build collects when you use Prompt Build, why we collect it, and the choices you have. We are the controller of that data.

01What we collect

Account details: your name, email address, and password (stored only as a hash). If you sign in with Google we receive your name, email address, and profile picture from Google instead of a password.

Your content: the prompts you write, files you attach, the source code generated for you, your conversations with the assistant, and your project settings.

Billing details: your plan, credit balance, and credit history. Card details are entered directly with our payment provider and never reach our servers.

Technical data: request logs containing a request identifier, account identifier, route, response status, and timing. We use these to operate and debug the service.

02Why we use it, and our legal basis

To provide the service you asked for, including generating and running your apps and saving your work. Basis: performance of our contract with you.

To take payment, meter credit usage, and prevent abuse of them. Basis: performance of our contract, and our legitimate interest in protecting the service.

To keep the service secure, reliable, and free from misuse. Basis: our legitimate interest.

To meet legal obligations such as tax and accounting record-keeping. Basis: legal obligation.

We do not sell your personal data, we do not use your data to build advertising profiles, and we do not run advertising trackers.

03Your content and AI processing

To generate and edit your app, your prompts and the relevant parts of your project source are sent to our model provider. We instruct providers not to use this content to train their models. We do not use your project content to train models either.

Project environment variables you enter are encrypted before storage and are never shown back to you or included in prompts.

04Who processes data for us

We use a small number of processors, each under a data processing agreement, and each only for the purpose listed:

  • Supabase — database, authentication, and file storage;
  • Google (Gemini API) — generating and editing your application code;
  • E2B — the temporary sandbox that runs your app preview;
  • Stripe — subscription and payment processing;
  • Sentry — error monitoring, with request contents, cookies, and anything you typed removed before an error is sent;
  • Mixpanel — product analytics, measured on our servers and limited to which pages and features are used.

Some of these providers process data outside your country. Where that happens we rely on the transfer safeguards those providers offer, such as standard contractual clauses.

05How long we keep it

We keep your account, projects, and conversations until you delete them or close your account. Preview environments are temporary and are discarded when they expire.

We keep billing and tax records for as long as the law requires. Operational logs are kept for a limited period for security and debugging.

06Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent where we rely on it.

You can download any project’s source from the builder at any time. For any other request, contact [contact@promptbuild.dev] and we will respond within the time the law allows.

You may also complain to your local data protection authority.

07Cookies

We set a small number of strictly necessary cookies to keep you signed in and to protect the service. We do not use advertising or analytics cookies, so we do not show a consent banner.

We do measure how the service is used, but we do it on our servers rather than in your browser, and without storing anything on your device. Visitors who are not signed in are counted using a temporary identifier that is rebuilt each day and cannot be traced back to you. We record which page was opened, not what you typed into it.

08Security

Access is scoped to your workspace and enforced in the database. Secrets are encrypted at rest, session cookies are HTTP-only, and requests are rate limited. No service can promise perfect security, so please use a strong, unique password.

09Children

Prompt Build is not intended for children. We do not knowingly collect data from anyone under 16, or under the age of digital consent where that is higher.

10Changes and contact

We will post any update here and, if the change is material, tell you before it takes effect.

Prompt Build, 10 Anson Road. Privacy questions and data requests: [contact@promptbuild.dev].

Terms of ServiceRefund Policy

Turn plain-language ideas into working web apps.

Terms of ServicePrivacy PolicyRefund Policy
promptbuild.dev