Privacy Policy
Effective 12 September 2026
Who we are
Prompto is operated by Cypher AI (ABN 84 678 167 443). This policy explains what we collect, why, and who else sees it. We handle personal information in line with the Australian Privacy Principles.
What we collect
- Account details — your email address, and a display name if you give one. Passwords are stored only as a cryptographic hash; we never see them.
- Usage counts — how many prompts you have scored in the current period, so we can apply plan limits.
- Your saved prompt library. Prompts you choose to save are stored against your account, so they follow you from one browser to another. Deleting your account deletes them with it. If you use Prompto without an account they stay in your browser and never reach us, and either way you can export a copy at any time.
- An anonymous identifier — a random value in a cookie so visitors without an account get their free runs. It is a random token, not a fingerprint: we collect no device or browser characteristics to build it.
- Billing details — held by Stripe, not by us. We store only a customer reference and your subscription status. We never see your card number.
- Prompt content, in transit — see below.
What we deliberately don’t hold
- Your provider API key. If you use your own key it stays in your browser and is sent with each request. It is never written to our database or logs.
- The prompts you score. We don’t retain them after returning your result.
Prompt content and AI providers
Scoring a prompt necessarily sends its text to a third-party AI provider. That is the one place your content leaves us.
The included model runs on a provider’s free tier, and free tiers commonly reserve the right to use submitted content to improve their services, including human review. Treat anything you put in that lane as disclosed to that provider. For confidential material, use your own API key — that request goes to your own account under your own agreement with that provider.
Who else processes your data
- AI providers (Groq, Anthropic) — prompt text, for scoring
- Neon — database hosting for accounts and subscriptions
- Upstash — sessions and usage counters
- Stripe — payments and billing
- Resend — verification and password-reset emails
- Netlify — hosting
Some are outside Australia, so your information may be processed overseas. We don’t sell your personal information, and we don’t share it for advertising.
Cookies
We use two, both strictly functional: one to keep you signed in, and one carrying the anonymous identifier that tracks free-run usage. No advertising or analytics cookies.
How long we keep things
Account details and your saved prompt library for as long as your account exists; both go when you delete it. Usage counters expire automatically — anonymous ones within a day, account ones after the billing period. Records of terms acceptance and billing history are kept while required for legal and tax purposes.
Security
Passwords are hashed, sessions can be revoked, and two-factor authentication is available from your account page. Changing your password signs out every other session. No system is perfectly secure, but we’ve tried to limit what a breach could expose — which is why your prompt library and API key never reach us in the first place.
Your rights
You can ask what personal information we hold about you, ask us to correct it, or ask us to delete your account and its data. Email support@prompto.biz and we will respond within a reasonable time.
If you’re unhappy with how we’ve handled your information, contact us first. If we don’t resolve it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
If we make a material change to this policy we’ll give reasonable notice by email before it takes effect.
Contact
Cypher AI (ABN 84 678 167 443) — support@prompto.biz