Save My Prompts is a place to keep the prompts you use with AI tools, fill in their blanks, and share the good ones. This policy explains what we do with the information that passes through the website, the Chrome extension and the mobile app. We've tried to write it so you can check it against what the product actually does.
- We store what you give us: your account, your prompts and boards, and the things you do with them.
- Private prompts stay private. They never appear in the public feed, search results, sitemaps, link previews or next to ads.
- We don't sell your personal information, and we never store your conversations with AI tools. The extension reads a chat page only when you click a capture button, and only the prompt you choose to save is stored.
- Public pages on the website may carry Google ads once we're approved. In the EEA, UK and Switzerland, ad cookies are only used if you agree. The extension and the app have no ads.
- You can export everything or delete your account from Settings at any time.
1. Who we are#
Save My Prompts is run by [PLACEHOLDER: Legal entity name (company or sole proprietor)], [PLACEHOLDER: Registered postal address] (“we”, “us”). For the EU and UK GDPR we are the controller of your personal data, and under India's Digital Personal Data Protection Act, 2023 (DPDP Act) we are the data fiduciary.
Privacy questions and requests: [PLACEHOLDER: Privacy email, e.g. privacy@savemyprompts.net]. Complaints in India can also go to our Grievance Officer. Our representative in the EU and UK, where one is required: [PLACEHOLDER: EU and UK representative (GDPR Article 27), if one is appointed].
2. What this policy covers#
The website at savemyprompts.net, the API at api.savemyprompts.net that the website, extension and app talk to, the Save My Prompts Chrome extension, the mobile app once it's released, and the emails we send.
It doesn't cover the AI tools you paste or insert prompts into (ChatGPT, Claude, Gemini, Perplexity, Copilot and others). What you type there is governed by their own policies. It also doesn't cover websites that prompts link to.
3. What we collect#
We only collect what the product needs to work. Here is all of it.
| What | Details | Where it comes from |
|---|---|---|
| Account | Your name, email address, whether the email is verified, and when you joined. If you sign up with a password we store only a salted, slow hash of it, never the password itself. | You, at sign-up |
| Google sign-in | If you choose “Continue with Google”: your Google account ID, name, email address, profile picture address, and the sign-in tokens Google issues to us. We don't get your Google password or access to your Gmail, Drive or contacts. | Google, with your permission |
| Sessions | A session token for each device you're signed in on, the IP address and browser or device description (user agent) at sign-in, and when the session expires. | Your browser, extension or app |
| Profile | Your @handle, display name, short bio, one website link and one support link, if you add them. Avatars are generated from your initials; we don't ask for a photo. | You |
| Prompts | Title, text, tags, the AI tools it works with, card colour, visibility, whether it's a favourite, when it was created, edited and last used, how many times you used it, earlier versions, which prompt it was remixed from, and the address of the page you saved it from (when you save selected text with the extension). | You |
| Boards and sharing | Board names, descriptions, items and notes, members and their roles, join links, and the invites you send: the invitee's email address, the role and when the invite expires. | You |
| Likes, saves and reports | Which prompts you liked or saved, and reports you file with the reason you chose. | You |
| Use counts on public prompts | Daily totals of how many different people copied, filled in, inserted or opened each public prompt in an AI tool. See “How we count” below for how we keep these anonymous. | Everyone who uses a public prompt |
| Views on public prompts | How many times a public prompt's page was opened each day, the referring website's domain and whether it was opened on the web, in the extension or in the app. Only the prompt's author sees these. | Everyone who opens a public prompt |
| Messages | What you send us through the contact form or by email, including copyright and grievance notices. | You |
How we count uses without tracking you
Each public prompt shows how many different people used it. To count each person once a day, we record a short key alongside the prompt and the date. If you're signed in, the key is your account ID. If you're signed out, it's a one-way hash of your IP address and browser description, mixed with a secret that changes every day and is then thrown away. That hash can't be turned back into your IP address, and it can't be matched across days. These keys are deleted after two days; only the daily totals stay. None of this uses cookies, so it works the same whatever you choose in Privacy choices.
Page views are counted by Cloudflare Workers Analytics Engine, a counting service inside our hosting provider. It stores the prompt, the date, the referring domain and the surface (web, extension or app), not who you are.
What we don't collect
- Your date of birth. Sign-up asks you to confirm your age instead.
- Your phone number, address or government ID.
- Card or bank details. If we launch Pro, a payment provider will handle payments and we'll update this policy first.
- Your browsing history, or the content of your conversations with AI tools, beyond a prompt you choose to save.
Stored only on your device
The website keeps a few small things in your browser's local storage: your theme (light, dark or system), your privacy choices, whether you've dismissed the welcome band, and the values you type into a prompt's blanks. Blank values are never sent to us. The cookie policy lists every key.
4. The Chrome extension#
The extension is a side panel and a quick-search popup for your library. It is built to act only when you ask it to. The extension page explains each permission Chrome shows you.
- On your computer, it keeps your sign-in token, an offline copy of your library (prompts, tags and settings) so search is instant and works offline, and, for a moment, the text you just chose to save. That draft is held in temporary storage and removed as soon as the editor opens it. It also remembers, on this device only, which prompts it has already asked “Did it work?” about today.
- When you choose “Save as prompt” on selected text, it reads that selection and the page's address, and nothing else on the page.
- When you click Insert on ChatGPT, Claude, Gemini, Perplexity or Copilot, it finds the chat box on that page and places the prompt in it. It doesn't read your conversation or send anything from the page to us. (Reading a chat happens only when you click a capture button, described below.)
- The floating “Save prompt” button is off by default. If you turn it on, Chrome asks you to allow access to all sites so the button can appear when you select text. The button does nothing until you click it. Turning it off removes that access.
- It sends your library changes to our API so your devices stay in sync. It contains no ads and no analytics or tracking code.
Capture from ChatGPT, Claude and Gemini
- Capture: when you click Save last prompt, Save + Improve or Create from conversation on ChatGPT, Claude or Gemini, the extension reads that tab's messages to find your last prompt or the reply to its request. Nothing is read until you click, and we don't store the conversation. Only the prompt you choose to save is stored, together with the text you started from and the address of the page it came from.
- Requests in your chat: Save + Improve and Create from conversation type a request into your chat box. You see it and press Send yourself. It's sent by you, to that AI service, under that service's terms. We don't send anything to it.
- On-device AI: when your computer has Chrome's built-in AI, the title, description, category and tags may be suggested on your device, and the editor's Improve button rewrites the prompt on your device. That text never leaves your computer for these steps.
- “Did it work?”: your yes and no answers are stored as counts on your own prompts.
5. Why we use it, and our legal bases#
The GDPR asks us to name a legal basis for each use. Under the DPDP Act, we rely on your consent or on the legitimate uses the Act allows.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Running your account and syncing your library | Account, sessions, prompts, boards | Contract: it's the service you signed up for |
| Publishing what you choose to make public or share | Profile, prompts, boards, public counts | Contract |
| Emails about your account: verification, password reset, email change | Email address | Contract |
| Sending an invite you asked us to send | The invitee's email address, your display name, the board or prompt title | Legitimate interests (yours and the invitee's). One email per invite, and the invitee can stop all future invites. |
| Counting uses and views, and ranking Trending | Daily keys, totals, Analytics Engine counts | Legitimate interests, with the safeguards above |
| Keeping the service safe: spam and abuse limits, reports, moderation, checks for personal data and secret keys before you publish | Account, sessions, prompts, reports | Legitimate interests; legal obligation where the law requires action |
| Personalised ads on public website pages | Cookies and identifiers set by Google | Consent (EEA, UK, Switzerland; and India while we ask there) |
| Non-personalised or limited ads | Limited data for frequency capping, fraud prevention and reporting | Legitimate interests, or consent where required |
| Answering your messages and legal requests | Messages, account | Legitimate interests; legal obligation |
We don't use your prompts to train AI models, and we don't let anyone else do so. We don't make automated decisions about you that have legal or similarly significant effects. Automatic holds on reported prompts are always reviewed by a person.
6. What's public#
Only what you choose. Each prompt and board has one of four visibility levels:
- Only me: visible to you. If you place it in an invite-only board, members of that board can see it too.
- People I invite: visible to you and the signed-in people you invite.
- Anyone with the link: visible to anyone who has the link. It isn't listed anywhere or indexed by search engines.
- Public: listed in the feed, search, tag pages and your profile, and indexed by search engines.
Your @handle, display name, bio and links are public once you set up a profile. Public prompts show their use, save, like and remix counts.
Once something is public, other people can copy it, remix it and save it, and search engines may keep a copy for a while. If you make a prompt private again, it leaves our feed, search and sitemap within about five minutes, but we can't recall copies other people already made. Remixes made while it was public stay with their authors. That's the licence described in our terms.
Please don't put personal information in public prompts. Before you publish, we check for email addresses, phone numbers, Aadhaar and PAN numbers and card numbers and warn you, and we block publishing anything that looks like an API key.
7. Analytics and tags (Google Tag Manager)#
Pages of the website, including the pages you see when signed in, load Google Tag Manager (a container we manage, which loads other tags such as Google Analytics if we turn them on). Tag Manager itself doesn't collect anything for us. It runs the tags inside it, and those are listed here once they are live. It isn't loaded in the Chrome extension or the mobile app, or on admin pages and the password-reset page.
- Denied until you choose. Using Google Consent Mode, the tags start in a denied state: they set no advertising or analytics cookies and keep no identifiers for you. Google tags may send cookieless pings (a page view without cookies or a user ID) so Google can model overall traffic.
- Your choice. If you accept Measurement or Personalised ads in Privacy choices, the matching tags may then set cookies and measure how pages are used, with the page address, a cookie or device identifier, your browser and device type and a rough location from your IP address. Reject all, and they stay denied. Your choice is stored on this device and read before the tags run.
- Cookies. [PLACEHOLDER: Cookie names and lifetimes set by Google Tag Manager and Google Analytics, from Google's current documentation and a live check after launch] The cookie policy lists them.
- Google acts as our processor for measurement and uses the data under its own terms; see how Google uses information from sites that use its services (opens in a new tab). Opt out of Google Analytics everywhere with the browser add-on (opens in a new tab).
8. Advertising (Google AdSense)#
We plan to show Google AdSense ads on public pages of the website: the feed, public prompt pages, tag and tool pages, public boards and profiles, and help articles. At the time of writing, ads are not switched on. We will apply to AdSense only after launch.
Ads never appear on sign-in and sign-up pages, settings, the editor, your library, invite-only or link-only pages, legal pages, error pages, in the Chrome extension or in the app.
- Google, as a third-party vendor, uses cookies to serve ads on our site. Google's advertising cookies let it and its partners serve ads to you based on your visits to this and other websites.
- You can opt out of personalised advertising in Google's My Ad Center (opens in a new tab), or opt out of some other vendors' use of cookies at aboutads.info (opens in a new tab) and youronlinechoices.eu (opens in a new tab).
- Read how Google uses information from sites that use its services (opens in a new tab).
- We use Google's own certified consent tool (Privacy & messaging) with Consent Mode. In the EEA, the UK and Switzerland we ask before any ad cookie is used. If you say no, Google may show limited or non-personalised ads, which aren't based on your past browsing.
- Change your mind at any time with Privacy choices in the footer of every page.
- Google is the only ad vendor we work with. We don't sell or pass your account details, prompts or email address to advertisers.
9. Who helps us run the service#
These companies process personal data for us, under contracts that limit them to doing what we ask:
| Provider | What they do for us | Data involved |
|---|---|---|
| Cloudflare, Inc. | Hosting for the website and API, our database (Cloudflare D1, primary location in the Asia-Pacific region), file storage, security, bot protection and view counting | Everything stored in the service, plus IP addresses and request details while serving pages |
| Resend | Sending account emails and invites | Recipient email address and the email's content |
| “Continue with Google” sign-in, if you use it; Tag Manager and Analytics on website pages (after your choice); ads and the consent message on public website pages | See the sections above |
If we launch Pro, payments will go through a payment provider acting as merchant of record (such as Paddle or Lemon Squeezy). We'll add them here before anyone can pay.
We share information with others only when the law requires it (for example a valid court order), to protect people from serious harm, or as part of a merger or sale of the service, in which case we'll tell you first and this policy will keep applying to your data. We don't sell personal data.
10. Where your data is stored#
Our database's primary location is in Cloudflare's Asia-Pacific region. Cloudflare serves pages from data centres around the world, so requests can be handled in the country you're in. Resend sends email from the United States.
For transfers out of the EEA, the UK and Switzerland we rely on the European Commission's standard contractual clauses (and the UK addendum), or on the EU-US Data Privacy Framework where a provider is certified under it. Under the DPDP Act, we transfer data only to countries the Government of India hasn't restricted.
11. How long we keep it#
| Data | Kept for |
|---|---|
| Your account, prompts and boards | Until you delete them or your account |
| A prompt you delete | Restorable for 30 days, then erased by a daily clean-up job |
| Sessions | Until you sign out or the session expires |
| Daily keys used to count each person once | 2 days |
| Daily use totals for public prompts | 90 days on the free plan (longer on Pro, when it exists) |
| View counts in Analytics Engine | About 3 months |
| Invites | 30 days after they expire, are revoked or are used |
| An old @handle redirect after you rename | 30 days |
| Reports and moderation records | 12 months |
| Messages to us | Up to 2 years, longer only if needed for a legal claim |
| Database backups | Roll off within 30 days, so deleted data disappears from them too |
When you delete your account, we delete your profile, prompts, boards, likes, saves and pending invites straight away. Your public prompts are removed, not left behind without an author. Remixes other people made of your public prompts stay with them, marked “original removed”. Our logs never contain your prompt text, passwords or sign-in tokens.
12. Your rights#
Wherever you live, you can:
- Get a copy of your data: Settings → Privacy → Export downloads everything as a file. See Your data.
- Correct it: edit your profile and account details in Settings.
- Delete it: delete prompts one by one, or your whole account from Settings → Account.
- Withdraw consent for ads or measurement with Privacy choices in the footer.
- Ask us anything about how your data is used: [PLACEHOLDER: Privacy email, e.g. privacy@savemyprompts.net].
We answer within 30 days, and may ask you to confirm the request from your account's email address so we know it's you.
India (DPDP Act, 2023)
You have the right to a summary of the personal data we process and what we do with it, and the names of anyone we've shared it with; to have it corrected, completed, updated or erased; to withdraw consent as easily as you gave it; to have your grievances addressed by our Grievance Officer; and to nominate someone to exercise these rights if you die or become unable to. If you're not satisfied with our answer, you can complain to the Data Protection Board of India. The Act also asks you not to file false or frivolous complaints.
EEA, UK and Switzerland (GDPR)
You also have the right to restrict our use of your data, to object to uses based on legitimate interests, to receive your data in a portable format, and to complain to your local data protection authority.
California and other US states (CCPA/CPRA)
In the last 12 months we've collected identifiers (name, email, IP address), the content you create, and activity on our own service, for the purposes in this policy. We don't sell personal information for money. Personalised ads from Google may count as “sharing” for cross-context behavioural advertising under California law. To opt out, choose Privacy choices in the footer and turn off personalised ads (shown to US visitors as “Do not sell or share my personal information”). We treat a Global Privacy Control signal from your browser as the same opt-out. We don't use sensitive personal information to infer things about you. You have the right to know, delete and correct, and to use these rights through an authorised agent. We won't treat you differently for using them.
13. Age requirement#
You must be at least 16 to use Save My Prompts, or at least 18 if you're in India. Sign-up asks you to confirm this; we don't ask for your date of birth. Under the DPDP Act, anyone under 18 needs verifiable consent from a parent, which we can't collect yet, so we don't offer accounts to under-18s in India.
We don't knowingly collect data from younger people, and we don't show ads to people who've told us they're under 18. If you believe a child has an account, write to [PLACEHOLDER: Privacy email, e.g. privacy@savemyprompts.net] and we'll delete it.
14. Security#
Everything travels over HTTPS. Passwords are stored as salted, slow hashes. Invite and share tokens are random and stored only as hashes, so a leaked database copy couldn't be used to open them. Private and invite-only content is never written to public caches. Only the people who run the service can access stored data, and only to investigate a report, fix a problem, or when the law requires it.
No system is perfectly secure. If a breach affects your personal data, we'll tell you and the authorities the law requires us to tell (in India, the Data Protection Board; in Europe, the relevant authority within 72 hours) without undue delay. Found a vulnerability? See security.txt.
15. Changes to this policy#
If we change this policy in a way that matters, we'll email account holders and show a notice on the site at least 14 days before the change takes effect, unless the law requires a faster change. The date at the top always shows the latest version.
16. Contact#
Privacy: [PLACEHOLDER: Privacy email, e.g. privacy@savemyprompts.net]. Post: [PLACEHOLDER: Legal entity name (company or sole proprietor)], [PLACEHOLDER: Registered postal address]. India grievances: Grievance Officer. Or use the contact form and choose “Privacy request”.