Privacy Policy
Last updated: February 16, 2026 • Promptory v1.7.0
1. Overview
Promptory ("the Extension") is a browser extension for managing AI prompts. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your data.
TL;DR: We store only what's necessary for the extension to work: your email (for auth), your prompts, and your folders. We do NOT sell, share, or transfer your data to third parties. No analytics or tracking.
2. Data We Collect
2.1 Account Data (optional — only if you sign in)
- Email address — received from Google OAuth, used to identify your account
- Display name & avatar URL — from Google profile, for display in the extension UI
2.2 User Content
- Prompts — titles, text, descriptions, tags, variables, usage counts
- Folders — names and organization structure
- Settings — theme preference, hotkey assignments, language
- Images — optional cover images for shared prompts (stored in Supabase Storage)
2.3 Data We Do NOT Collect
- Browsing history or page content
- Keystrokes or form inputs on websites
- Passwords or financial information
- Device identifiers or fingerprints
- IP addresses (not logged by the extension; Supabase may log IPs per their own policy)
3. How Data Is Stored
3.1 Local Storage
All prompts, folders, and settings are stored locally in your browser using chrome.storage.local. This data never leaves your device unless you choose to sign in and enable cloud sync.
3.2 Cloud Storage (Supabase) Optional
If you sign in with Google, your data is synced to Supabase (an open-source backend platform). Data is stored in a PostgreSQL database with Row-Level Security (RLS), ensuring only you can access your own data.
Technical note: The extension uses a Supabase "anon key" in its source code. This is a public API key by design (per Supabase's architecture) and does not grant access to any user data. All data access is protected by authentication tokens and RLS policies.
4. How We Use Your Data
- Prompt management — to save, organize, search, and insert your prompts
- Cloud sync — to keep your prompts available across devices (optional)
- Public library — if you explicitly choose to share a prompt, it becomes visible to other signed-in users
- Usage statistics — displayed only to you in the Stats tab; we do not share or aggregate usage data
5. Data Sharing
We do NOT sell, rent, trade, or transfer your personal data to any third parties. Your data is used solely for the functionality of the Extension.
The only exception: if you explicitly share a prompt to the Public Library, the prompt title, text, description, author name, and tags will be visible to other authenticated users.
5a. Payment Processing
Premium subscriptions are processed through LemonSqueezy, a Merchant of Record. When you purchase a subscription:
- Your payment information (credit card, billing address) is handled entirely by LemonSqueezy — we never see or store it
- LemonSqueezy may collect data necessary for payment processing per their Privacy Policy
- We receive only your email, subscription status, and customer ID from LemonSqueezy
- Voluntary donations via DonationAlerts are processed separately per DonationAlerts Privacy Policy
6. Third-Party Services
7. Content Scripts
Promptory injects content scripts only into supported AI platforms (ChatGPT, Claude, Gemini, Perplexity, Poe, etc.) to enable the "Insert prompt" feature. The content script:
- Finds the chat input field and inserts your prompt text
- Shows a search overlay when triggered via keyboard shortcut
- Does NOT read, collect, or transmit any page content
8. Data Retention & Deletion
- Your local data is stored until you uninstall the extension or clear browser data
- Cloud data persists as long as your Supabase account exists
- You can export all your data at any time via Settings → Export
- To delete cloud data: sign out, or contact us to request full account deletion
8a. Your Rights (GDPR / CCPA)
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access — You can request a copy of all personal data we hold about you. Use Settings → Export to download your data instantly.
- Right to Rectification — You can correct inaccurate personal data directly in the Extension (profile, prompts, folders).
- Right to Erasure ("Right to be Forgotten") — You can request complete deletion of your account and all associated data. Contact us via Telegram (@user_Alexander) with your email address, and we will delete your data within 30 days.
- Right to Data Portability — You can export all your data in JSON format via Settings → Export.
- Right to Object — You can object to data processing by signing out and using the Extension locally (offline mode).
- Right to Withdraw Consent — You can withdraw consent at any time by signing out, which stops all cloud data processing.
To exercise your rights: Contact us via
Telegram (@user_Alexander) with your registered email address. We will respond within 30 days as required by GDPR/CCPA.
9. Security
- All communication with Supabase uses HTTPS encryption
- Authentication uses OAuth 2.0 with JWT tokens
- Database access is protected by Row-Level Security (RLS)
- Tokens are refreshed automatically; expired tokens are cleared
10. Children's Privacy
Promptory is not directed at children under 13. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date at the top. Continued use of the Extension after changes constitutes acceptance.
12. Contact
If you have questions about this Privacy Policy or want to request data deletion: