The Short Version
PromptBud is designed with privacy first. We don't track you, we don't sell your data, and your prompts are only processed to provide the service. Memory features use encryption and automatic PII redaction.
1. What Data We Collect
When you use PromptBud, we process:
- Prompt text: The content you ask us to clarify or check. This is sent to our API for processing and is not stored after the response is returned.
- Memory data (optional, Pro feature): If you enable the Memory feature, we store anonymized, summarized versions of your conversations to personalize future interactions. See "Memory Feature" below for details.
- Settings: Your preferences (domain mode, API key if using BYOK) are stored locally in your browser using Chrome's storage API.
We do NOT collect:
- Analytics or tracking data
- Browsing history
- Personal identification information (unless you provide it in prompts)
- Payment information (handled by Stripe)
2. Memory Feature (Pro)
The Memory feature allows PromptBud to learn your preferences over time. Here's how it works:
- Automatic PII Redaction: Before any conversation data is stored, we automatically detect and remove personal identifiable information (names, emails, phone numbers, addresses, etc.)
- Summarization: We don't store raw conversations. Instead, we store short, anonymized summaries of preferences and patterns.
- Encryption: Memory data is encrypted at rest.
- User Control: You can view, export, and delete your memory data at any time from the extension settings.
- Portability: Your memory works across ChatGPT and Claude — it's tied to your account, not a specific AI platform.
3. How We Use Your Data
Your data is used exclusively to:
- Process your prompt clarification and QA requests
- Personalize responses based on your stored preferences (if Memory is enabled)
- Improve the service (aggregate, anonymized statistics only)
We never sell, rent, or share your data with third parties for marketing purposes.
4. Third-Party Services
PromptBud uses the following third-party services:
- Anthropic Claude API: To process prompt clarification requests. Subject to Anthropic's Privacy Policy.
- OpenAI API: For embeddings in the Memory feature. Subject to OpenAI's Privacy Policy.
- Stripe: For payment processing. Subject to Stripe's Privacy Policy.
- Cloudflare: For hosting and API infrastructure. Subject to Cloudflare's Privacy Policy.
- Supabase: For secure data storage. Subject to Supabase's Privacy Policy.
5. BYOK (Bring Your Own Key) Mode
If you use your own API key:
- Your API key is stored locally in your browser and never sent to our servers
- API requests go directly from your browser to the AI provider
- We have no visibility into your usage or conversations in BYOK mode
6. Data Retention
- Prompt processing: Not retained. Data is discarded after the response is generated.
- Memory data: Retained until you delete it or close your account.
- Local settings: Stored in your browser until you uninstall the extension or clear browser data.
7. Your Rights
You have the right to:
- Access: View all data we have about you (available in extension settings)
- Export: Download your memory data in a portable format
- Delete: Remove all your data at any time
- Opt-out: Disable Memory features while continuing to use clarity features
7a. For EU/EEA Users (GDPR)
If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation:
- Right of Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your data ("right to be forgotten").
- Right to Data Portability: Receive your data in a machine-readable format.
- Right to Object: Object to processing of your data for certain purposes.
- Right to Restrict Processing: Request limited use of your data.
Our legal basis for processing your data is: (a) your consent when you enable Memory features, (b) performance of a contract when you purchase credits, and (c) our legitimate interests in providing and improving the Service. To exercise any of these rights, contact [email protected]. We will respond within 30 days.
7b. For California Users (CCPA)
If you are a California resident, the California Consumer Privacy Act gives you the right to:
- Know: What personal information we collect and how it is used.
- Delete: Request deletion of your personal information.
- Opt-out of Sale: We do not sell personal information. We never have and never will.
- Non-Discrimination: We will not discriminate against you for exercising your rights.
To make a verifiable request, contact [email protected].
7c. Medical Mode Disclaimer
The Medical research mode is designed for academic research prompts only. PromptBud is not a medical device, does not provide medical advice, and is not HIPAA-compliant. Do not enter protected health information (PHI) into PromptBud. If you work in healthcare, use PromptBud only for general research queries, not for patient-specific data.
8. Security
We implement industry-standard security measures:
- All data transmission uses HTTPS/TLS encryption
- Memory data is encrypted at rest
- We use secure, audited cloud infrastructure (Cloudflare, Supabase)
- Regular security reviews and updates
9. Children's Privacy
PromptBud is not intended for use by children under 13. We do not knowingly collect data from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes through the extension or via email (if provided).
11. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: [email protected]