Privacy Policy
Last updated: July 17, 2026
The short version
- We store only the prompts you write. Never AI responses, system prompts, or other page content.
- No analytics or ad trackers. No telemetry in the extension. We never sell your data and never use your prompts to train AI models.
- TLS in transit, encryption at rest, device tokens stored only as SHA-256 hashes, strict per-account isolation.
- Delete any prompt anytime, or delete your whole account from Settings → Danger Zone — a 48-hour recovery period lets you undo it, otherwise your account is permanently deleted before 96 hours.
1. What PromptCase does
PromptCase captures the prompts you write in supported AI tools — through our browser extension and our command-line tool (CLI) — and syncs them to your PromptCase account so you can search, tag, organize, and reuse them. Capture happens only in the tools you install, only on the sites and apps we support, and you can turn it off per site or globally at any time.
2. Data we collect
- Account data. Your email address, name, and authentication identifiers, created through our authentication service when you sign up (including via Google or GitHub if you choose to sign in with them).
- Your prompts. The prompt text you author and submit on supported sites (browser extension) or in Claude Code sessions (CLI), with the source name and capture time. We capture only user-authored prompt text — never AI responses, system prompts, or any page content beyond your prompt.
- Device metadata. A name and type for each connected extension or CLI (so you can manage and revoke them), the client version, and access tokens stored only as cryptographic hashes.
- Usage counters. Prompt counts per account, used solely to enforce plan limits.
Signing in with Google or GitHub. If you choose one of those options, the provider shares only your email address, basic profile (your name), and profile picture, which we use solely to create and identify your account. We request no other scopes and never access your Google or GitHub content. Our handling of data received from Google — including Sign in with Google — adheres to the Google API Services User Data Policy and the Chrome Web Store User Data Policy, including their Limited Use requirements. You can revoke access at any time from your Google or GitHub account settings.
That is the whole list. We run no analytics or advertising trackers on the site, and the extension contains no telemetry.
3. How we use it
We use your data to provide and sync the service, enforce plan limits, and answer your support requests. Nothing else. Specifically, we do not:
- sell your data or share it with third parties for advertising,
- use your prompts to train AI models,
- show ads.
4. Where your data lives
We use a small set of processors (sub-processors) to run PromptCase, each receiving only what it needs:
- Supabase — authentication and our database (your account and sign-in credentials, plus your prompts, tags, folders, and device records). Hosted in the Asia-Pacific (Singapore) region.
- Vercel — hosting for the web app and API.
- Cloudflare Turnstile — bot protection on our sign-in and sign-up forms. It processes limited technical signals (such as your IP address) to tell humans from bots. It is not an advertising tracker.
- Paddle(paddle.com) — our payment provider and Merchant of Record for paid plans. When you buy a paid plan, Paddle collects and processes your payment and billing details directly, and handles invoicing and tax. We never see or store your full card or bank details. See Paddle's own privacy policy for how it handles that data.
Because Supabase hosts your data in Singapore, your data may be processed outside your country. Data is encrypted in transit (TLS) and encrypted at rest by our database provider. Device tokens are stored only as SHA-256 hashes — we cannot read them back, and neither can anyone else. Every query is scoped to your account with strict per-account isolation.
Cookies. We use only essential cookies needed to keep you signed in and to run the site securely. We do not use advertising or cross-site tracking cookies.
5. Browser extension & CLI specifics
Browser extension.The extension runs only on the 13 supported AI chat sites listed in its manifest and reads only the prompt you submit in the composer — not your browsing history, not the AI's replies, not the rest of the page. Each site has its own on/off toggle in the extension settings. Disconnecting the extension wipes its locally stored data and tokens.
The 13 supported sites
ChatGPT · Claude · Gemini · Microsoft Copilot · Perplexity · Mistral Le Chat · HuggingChat · You.com · Poe · Grok · Bolt · Lovable · Replit
On Firefox, the add-on's built-in data-collection consent declares exactly two categories: website content (the prompt text you author) and authentication information (the device token used to sync to your account). Both are required for the extension to work; no other category is collected.
CLI. The CLI reads only your local Claude Code transcript files on your machine, and extracts only the prompts you typed. AI responses, system messages, and tool output in those files are never uploaded.
6. Retention & deletion
- We keep your data for as long as your account is active.
- Prompts beyond your plan's visible window are not deleted — they remain securely stored and become visible again if you upgrade. Everything is permanently removed when you delete your account.
- You can delete any prompt at any time from the dashboard.
- You can revoke any connected device from the dashboard; its tokens stop working immediately.
- You can delete your entire account yourself at any time from Settings → Danger Zone. It schedules deletion with a 48-hour recovery period: log back in within 48 hours to cancel; otherwise your profile, prompts, folders, tags, devices, tokens, and any uploaded avatar are permanently deleted before 96 hours.
- Prefer that we do it for you? Email support@promptcase.dev. For deletion requests made by email, we complete deletion within 30 days.
7. Your rights
You can access, export, correct, or delete your data at any time — directly in the dashboard, or by emailing support@promptcase.dev. We reply within 1–2 business days.
8. Children
PromptCase is not directed at children under 13, and we do not knowingly collect data from them.
9. Changes to this policy
If this policy changes, we will post the update here with a new "Last updated" date. Material changes will be called out clearly at the top of the page.
10. Contact
Questions, deletion requests, anything else: support@promptcase.dev or our contact page.