Privacy Policy
Last updated: August 4, 2026
This policy is provided for transparency about what Fromptly collects today. It has not yet been reviewed by qualified legal counsel — treat it as a good-faith draft, not a final legal instrument, until that review is complete.
1. Who we are
Fromptly (“we”, “us”, “our”) is a Chrome browser extension that helps you write better prompts for AI tools like ChatGPT, Claude, and Gemini. This policy explains what data Fromptly collects, why, and how you can control it.
Contact: support@fromptly.dev
2. What Fromptly does NOT do
- We do not read, log, or transmit anything you type unless you explicitly select text and choose to optimize it, or explicitly enable an opt-in feature described below.
- We do not sell your data to anyone, ever.
- We do not use your prompts to train any AI model.
3. Data we collect
3.1 Data you explicitly send for optimization
When you select text and choose “Optimize Prompt,” that text is sent to the AI provider you’ve configured (e.g. OpenAI, Anthropic, Google) using your own API key or account, subject to that provider’s own privacy policy and terms. Fromptly does not store this text on our servers.
Before sending, Fromptly automatically scans the text for common sensitive-data patterns (passwords, credit card numbers, CVV codes, one-time passcodes, bank account numbers, private key blocks, JWTs, API tokens, and government ID numbers) and blocks the request if any are detected, unless you’ve disabled this protection in Settings → Security.
3.2 Local data (stays on your device)
- Your settings and preferences
- Prompt history and clipboard history (if enabled)
- A local security audit log (permission grants, sign-ins, subscription changes — metadata only, never prompt content)
This data is stored using Chrome’s local extension storage and never leaves your device unless you enable cloud sync (see 3.3).
3.3 Account & cloud sync data (only if you sign in)
If you create an account and sign in, we store, via our backend provider (Supabase):
- Your email address and authentication credentials (or OAuth identity, if you sign in with Google/GitHub)
- Your prompt history, favorites, folders, tags, and collections, if cloud sync is enabled
- Your subscription/billing status (see 3.4)
Your session (login) tokens are encrypted at rest using AES-256-GCM before being stored, even locally on your device.
3.4 Payment data
If you subscribe to a paid plan, payment processing is handled entirely by Stripe. We do not receive, process, or store your credit card number or other payment instrument details — Stripe provides us only with your subscription status (active, trialing, past due, canceled) and a customer/subscription identifier.
3.5 Analytics & error monitoring (opt-in, off by default)
Fromptly can optionally report anonymized usage analytics and crash/error reports to help us improve the product. This is disabled by default. When enabled, analytics events never include prompt text, passwords, or clipboard content, and error reports never include prompt content or stack traces containing user input.
4. How we use your data
- To provide the core optimization feature
- To sync your prompt library across your devices (if you enable it)
- To manage your subscription and billing
- To detect and prevent abuse (rate limiting, fraud prevention)
- To improve the product (only if you’ve opted into analytics)
5. Data sharing
We share data only with the service providers necessary to operate Fromptly:
- Supabase (authentication, database, cloud sync)
- Stripe (payment processing)
- Your chosen AI provider (only the specific text you choose to optimize)
- An analytics/error-monitoring provider, only if you’ve explicitly enabled one
We do not sell, rent, or otherwise share your data with advertisers or data brokers.
6. Data retention
- Local data persists until you clear it (Settings → Security → “Delete your data”) or uninstall the extension.
- Cloud-synced data persists until you delete it or close your account.
- The security audit log is automatically bounded to the most recent 500 entries.
- Backups of cloud data, if any, are retained for 90 days after deletion, for disaster-recovery purposes only.
7. Your rights & choices
- Export your prompt library at any time from the Workspace settings.
- Settings → Security → “Delete your data” clears all local device data and signs you out immediately.
- Full account deletion currently requires contacting support@fromptly.dev.
- Opt out of analytics/error monitoring anytime in Settings → Privacy.
- If GDPR/CCPA applies to you, you have the right to access, correct, delete, or port your data, and to object to processing — contact us to exercise these rights.
8. Cookies & similar technologies
Fromptly is a browser extension, not a website — it does not use third-party advertising cookies. This website may use standard analytics cookies.
9. Children’s privacy
Fromptly is not directed at children under 13 (or the relevant age of digital consent in your jurisdiction) and we do not knowingly collect data from them.
10. Changes to this policy
We’ll update the “Last updated” date above and, for material changes, notify users via the extension or this website.
11. Contact
Questions about this policy: support@fromptly.dev