Legal

Privacy Policy

Last updated: July 16, 2026

This Privacy Policy describes how Prompts By Design (“we,” “us,” or “our”), operated by Orman Beckles, collects, uses, stores, and shares personal information when you use the Prompts By Design website (promptsbydesign.com) and the Prompts By Design Chrome extension (together, the “Service”). By using the Service you agree to this policy.

1. Information we collect

We collect only the information needed to run the Service:

  • Account identity. When you sign in with Google or Apple (OAuth), we receive your email address, a unique user identifier issued by that provider, and — where the provider supplies it — your name and profile picture URL. We never receive or store your Google or Apple password.
  • User-generated content. The prompts you create or save — including titles, descriptions, keywords, prompt bodies, detected variables, app-type labels, optional thumbnail images you upload, sharing preferences, favorites, version history, and usage timestamps.
  • Variable inputs and copy history. When you “use” a prompt and click copy, we save a snapshot of the filled-in prompt to your personal history so you can retrieve it later.
  • App settings and entitlements. Theme preference, welcome-dialog state, prompt limit, lifetime access flag, and — if you purchase lifetime access — the associated Stripe customer and payment references (we never see or store your card number).
  • Authentication tokens. The Chrome extension stores your Supabase session tokens (access token and refresh token) in your browser’s local extension storage (chrome.storage.local) so you stay signed in. These tokens are transmitted only to our backend to authenticate your requests.
  • Basic technical logs. Standard server logs generated by our hosting and backend providers (IP address, timestamps, request paths, error traces) used for security and debugging.

We do not collect browsing history, keystrokes, page content from sites you visit, health or financial information, precise location, or contacts. The Chrome extension does not read or collect the content of the pages you browse. When you explicitly click Insert in the extension, the extension writes the prompt text you selected into the currently focused input field on the active tab using the browser's activeTab and scripting permissions.

2. How we use your information

  • To create and authenticate your account and keep you signed in on the web and in the Chrome extension.
  • To store your prompt library and sync it between the web app and the extension.
  • To provide AI-powered features you explicitly trigger — enhancing a prompt or description, researching a prompt in the Laboratory, suggesting variable values, and applying app-type rules. When you use these features, the relevant prompt text is sent to an AI provider (see Section 4) so it can return a rewritten result.
  • To send transactional emails (account invitations, receipts, security notices) via our email provider.
  • To process one-time lifetime purchases via our payment processor.
  • To secure the Service, prevent abuse, debug errors, and comply with legal obligations.

We do not sell your personal information. We do not use your prompts to train AI models. We do not show third-party advertising and we do not build advertising profiles.

3. How we store your information

  • Account data, prompts, keywords, variables, sharing settings, version history, and copy history are stored in our managed Postgres database hosted on Lovable Cloud (which uses Supabase as its underlying infrastructure).
  • Prompt thumbnail images are stored in a private Supabase Storage bucket and are accessed only through short-lived signed URLs issued to the signed-in owner (or to users the prompt has been shared with).
  • Data is protected by row-level security policies so each user can only read and modify their own records — except for prompts you explicitly share (see Section 5).
  • Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by our infrastructure providers.
  • Session tokens on the Chrome extension are stored locally in chrome.storage.local and are removed when you sign out or uninstall the extension.

4. Who we share information with (sub-processors)

We share information only with the service providers we need to run the Service. Each is bound by its own terms and privacy policy:

  • Lovable Cloud / Supabase — hosts our database, authentication, and file storage. Receives all stored account and prompt data.
  • Google LLC — OAuth sign-in provider. Receives standard OAuth requests; returns your email and user identifier to us.
  • Apple Inc. — OAuth sign-in provider (if you choose Apple). Same scope as Google.
  • Lovable AI Gateway (Google Gemini models) — when you trigger an AI feature (enhance, research, variable suggestion, app-rules cleanup), the relevant prompt text and, where applicable, your title and variable name are sent to the gateway for processing and a rewritten result is returned. The gateway provider states it does not use gateway traffic to train models.
  • Resend — sends transactional emails (invitations, receipts). Receives recipient email address and the message content we generate.
  • Stripe — processes optional one-time lifetime purchases. Receives payment details directly from you; we receive only the resulting customer identifier and payment status.
  • Cloudflare — serves our website and edge functions. Sees standard request metadata (IP, headers).

We may also disclose information if required by law, to protect our rights, or in connection with a corporate transaction (merger, acquisition, or asset sale), in which case we will notify affected users.

5. Prompt sharing

Prompts you create are private by default. If you explicitly set a prompt’s sharing scope to Everyone, its content becomes visible to all signed-in users of the Service. If you choose Specific people, only the users you name can view it. You can change or revoke sharing at any time from your library.

6. Retention and deletion

  • Your prompts, thumbnails, and history are retained until you delete them or delete your account.
  • Each prompt keeps up to the last 5 edited versions; older versions are automatically discarded.
  • To delete your account and all associated data, email ormanbeckles@gmail.com from the address on your account. We will delete your data within 30 days, except where retention is required by law (e.g. payment records).
  • Signing out of the Chrome extension immediately removes stored session tokens from your browser.

7. Your rights

Depending on where you live (including the EEA, UK, and California), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can exercise most of these rights directly in the app (edit or delete any prompt), or by emailing us at the address below. We do not sell personal information and do not engage in “sharing” for cross-context behavioral advertising as defined by the CCPA.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.

9. International transfers

Our providers may process data in the United States and other countries. By using the Service you consent to this transfer.

10. Chrome extension permissions

The extension requests only the permissions it needs: storage (save your session and cached prompts locally), identity (Google/Apple sign-in), alarms (refresh your session in the background), activeTab and scripting (write the prompt you choose into the focused input field on the active tab when you click Insert), and limited host access to our own backend at promptsbydesign.com. We do not read or collect the content of other websites.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the app or by email. The “Last updated” date at the top reflects the latest revision.

12. Contact

Questions or privacy requests: ormanbeckles@gmail.com.