Privacy Policy
Last updated: September 2025
1. Who we are
HPrompts ("we", "us", or "our") provides the HPrompts browser extension and web dashboard (collectively, the "Service"). This notice explains how we collect, use, and safeguard personal data when you access the Service. Questions? Email privacy@hprompts.com.
2. Data we collect
Account & authentication
When you sign in with Google we receive your email address, display name, profile image, and Google account identifier so we can create and manage your HPrompts account.
Prompt content & history
Enhanced prompts, selected phrases, and associated metadata (platform, timestamps) are stored in your account so you can revisit them. You can download or delete this information from the dashboard at any time.
Usage & telemetry
We log daily enhancement counts, plan usage, device information (browser, version), and error diagnostics to operate the Service, prevent abuse, and plan capacity. Usage metrics are tied to your account ID.
Subscription & billing
Payments are handled by our commerce partner. We receive transaction confirmations, plan identifiers, and billing status; card numbers and sensitive payment data never reach our servers.
Support communications
If you contact us, we keep the message, email address, and any attachments so we can respond and improve the Service.
3. How we use your data
- Provide, secure, and troubleshoot the Service
- Store enhanced prompts and usage history so you can revisit them
- Process subscriptions, invoices, and account upgrades
- Send important notices about changes, incidents, or outages
- Measure feature adoption and plan product improvements
- Comply with legal obligations and enforce our Terms of Service
4. Legal bases for processing (GDPR)
- Contract: delivering the Service, retaining prompts, billing, and support.
- Legitimate interest: preventing abuse, maintaining security, and improving functionality.
- Consent: optional analytics/marketing cookies and storing prompts when you explicitly agree during sign-in.
- Legal obligation: record keeping and responding to lawful requests.
5. Who we share data with
We only share data with service providers who help us deliver the Service:
- Authentication: Google Identity Services (OAuth).
- AI processing: OpenRouter (proxying requests to supported models).
- Infrastructure: hosting, database, and email providers.
- Payments: our payment processor for subscription billing.
Each provider is bound by a data-processing agreement and only processes data on our instructions. We never sell personal information.
6. International transfers
We operate from the United States and may process data in other countries where our providers are located. When personal data is transferred outside the EU/EEA or UK, we rely on Standard Contractual Clauses (SCCs) or other lawful safeguards. Details are available on request.
7. Retention
We apply the following retention periods unless you request deletion sooner:
- Account profile and authentication data – kept while your account is active.
- Prompt history – kept until you delete it or close your account.
- Usage records – retained for up to 18 months for analytics and abuse prevention.
- Billing records – kept for at least 7 years to meet tax and accounting obligations.
- Support correspondence – retained for up to 24 months.
8. Your rights and choices
You can manage your privacy from the dashboard or by emailing privacy@hprompts.com.
- Access and download your data.
- Delete your account and prompt history instantly.
- Update profile information and subscription settings.
- Withdraw consent to prompt storage (using the sign-in consent checkbox).
- Opt out of non-essential cookies via the cookie banner.
- Lodge a complaint with your local supervisory authority.
9. Cookies and local storage
We use essential cookies and local storage to keep you signed in and remember your preferences. Non-essential analytics or marketing cookies are disabled by default and only load if you consent via the cookie banner. You can update your choice at any time.
10. Security
We apply administrative, technical, and physical safeguards such as HTTPS-only transport, access controls, and routine monitoring. No security measure is perfect, so we maintain an incident-response plan to notify you and regulators if a breach occurs.
11. Contact & representatives
Reach our privacy team at privacy@hprompts.com. If we appoint an EU/UK representative or data protection officer, their details will appear here.