AI Prompt Safe Logo

Privacy Policy

Effective date: 9 July 2026

This policy explains what personal data AI Prompt Safe collects, why we collect it, who we share it with, and the rights you have over it.

AI Prompt Safe is a web application, also installable as a PWA, that lets you store, organise, test, and share AI prompts. The app is available at https://app.aipromptsafe.com.

We aim our service at professionals and businesses. It is not intended for children.

1. Who we are

The service is operated by Pyxage ("we", "us", "our").

We are the data controller for the personal data described in this policy, except where stated otherwise (see Client Management data in section 2).

For any privacy question or to exercise your rights, contact us at privacy@hq.pyxage.com.

2. Data we collect

Account data

When you sign up and use your account, we hold:

  • Your full name.
  • Your email address.
  • Your password, stored only as a hash by our authentication provider. We never see or store it in plain text.
  • A marketing consent flag (emails about news and offers), set at signup and changeable anytime in profile settings.
  • An automated-contact consent flag (automated messages and phone calls about offers, including calls made by AI voice agents), set at signup and changeable anytime in profile settings.
  • Your account status.
  • Your subscription plan.

User content

The app stores the content you create:

  • Prompts, including title and full text.
  • Categories, tags, and folders.
  • AI provider, model, and source labels.
  • Favourites and usage counts.

Client Management data

If you use the optional Client Management feature, you may store client names and project names. This data can identify your own customers.

For that data you are the data controller and we act as your data processor. We process it only to provide the feature to you.

Public sharing

You can mark any prompt "Public". When you do, its title and content are published at a public URL. Anyone with the link can view it. This stays public until you unshare it.

Bring your own API keys (BYOK)

You may save Google AI, OpenAI, Anthropic, OpenRouter, Vercel AI Gateway, and Ollama Cloud API keys. These keys:

  • Are stored encrypted in a secrets vault.
  • Are decrypted only on our servers, to call the provider you selected.
  • Are never returned to your browser after saving.
  • Can be removed by you at any time.

AI usage metering

We keep a per-account monthly counter of app-paid AI runs used for the current billing period.

Audit and event logs

We keep internal webhook and event logs for billing and marketing-event delivery. These include your email address and the event type, for example "plan upgraded".

Server logs

Our hosting provider records server logs that may include your IP address.

3. Purposes and legal bases

We rely on the following legal bases under UK GDPR and EU GDPR.

PurposeData usedLegal basis
Create and run your accountAccount data, user contentContract
Provide the Client Management featureClient and project namesContract (we act as your processor)
Publish prompts you choose to sharePrompt title and contentConsent (your choice to make it public)
Store and use your BYOK keysAPI keysContract
Enforce free-plan limitsAI usage counterContract and legitimate interest
Take payment and manage subscriptionsEmail, name, plan, Stripe IDsContract
Send service notices, for example payment failureEmail, plan, statusContract and legitimate interest
Send marketing emailsEmail, name, consent flagConsent
Send automated messages and phone calls about offers (including AI voice agents)Contact details, consent flagConsent
Prevent bots and abuse at signupIP address, browser signalsLegitimate interest
Keep billing and event audit logsEmail, event typeLegitimate interest and legal obligation
Run the app and keep it secureServer logs, IP addressLegitimate interest

You can withdraw consent for marketing emails and for automated messages and calls at any time in profile settings, independently of each other. Withdrawal does not affect processing carried out before you withdrew.

4. Third parties and subprocessors

We share data with the providers below to run the service. Each acts under a contract that limits their use of the data.

ProviderPurposeData sharedLocation
SupabaseDatabase, authentication, file and secret storage, serverless functions, transactional auth emails such as password reset and account setupAll application data, email addresseu-west-2, London, United Kingdom
VercelHosting, cookieless Web Analytics, and BotID bot protectionServer logs including IP address and browser signals. Analytics is anonymised with no cross-site tracking and no advertising IDsUnited States and global edge network
StripePayments and billing portalCard details entered on Stripe pages, never on our servers. We store only the Stripe customer ID, subscription ID, plan, and statusGlobal
GoHighLevelCRM, lifecycle email, and automated contactEmail, name, plan, previous plan, subscription status, registration origin, marketing and automated-contact consent flagsUnited States
Google, OpenAI, AnthropicAI model processing for Playground, Prompt Creator, and Help assistantThe text you submit to the selected modelGlobal
OpenRouterRoutes Playground and Prompt Creator requests made with your OpenRouter key to the model provider you selectThe text you submit, the selected model, and request metadataGlobal
Vercel AI GatewayRoutes included app-paid and Help assistant requests, and requests made with your own Gateway key, to AI providersThe text you submit, the selected model, and request metadataGlobal
Ollama CloudRuns hosted Ollama models for Playground and Prompt Creator requests made with your Ollama Cloud keyThe text you submit, the selected model, and request metadataGlobal
Google FontsLoads the Inter font from Google's CDNYour IP addressGlobal

We may update this list as our providers change. The current list always reflects who we use.

5. How AI inputs are handled

When you run a prompt in the AI Playground, generate a prompt with the AI Prompt Creator, or ask the in-app Help assistant a question, the text you submit is sent to the AI service used for that request.

There are four routes:

  • Included app-paid generations and the Help assistant. Requests pass through the Vercel AI Gateway using our credentials. The Gateway is configured for zero data retention.
  • Direct-provider BYOK usage. Requests using a Google AI, OpenAI, or Anthropic key go directly to that provider under your account and are governed by its terms.
  • OpenRouter BYOK usage. Requests using an OpenRouter key pass through OpenRouter to the upstream model provider you select. Processing is governed by OpenRouter's terms and privacy policy as well as the upstream provider's applicable terms.
  • Vercel AI Gateway and Ollama Cloud BYOK usage. Requests using your Gateway key pass through Vercel to the selected model provider. Requests using your Ollama Cloud key run on Ollama's hosted service. Each is governed by that service's terms and the selected upstream provider's terms where applicable.

You should review the privacy terms of any AI provider whose model you use.

6. International transfers

Your application data is stored in the United Kingdom, in Supabase's eu-west-2 (London) region.

Some providers in section 4, such as Stripe, GoHighLevel, the AI providers, Vercel, and Google, may process data outside the UK and the EEA.

Where data leaves the UK or EEA, we rely on a lawful transfer mechanism. This includes UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, and the EU Standard Contractual Clauses, as applicable.

You can ask us for more detail on the safeguards used by contacting privacy@hq.pyxage.com.

7. Cookies and local storage

We use only essential cookies.

  • Authentication session cookie. This keeps you signed in.

Theme and other UI preferences are kept in your browser's local storage, not in cookies.

We do not use advertising or cross-site tracking cookies. Our analytics, provided by Vercel, is cookieless.

8. Retention

We keep your data while your account exists.

When you delete your account, we permanently delete the account and all associated data.

Any database backups we keep for disaster recovery are encrypted and automatically deleted after no more than 30 days.

Stripe retains billing records for as long as the law requires.

Audit and event logs are kept only for as long as necessary for billing and security purposes.

9. Your rights

Under UK GDPR and EU GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Erase your data.
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent for marketing at any time.
  • Complain to a supervisory authority.

The product gives you direct control over much of this:

  • Export. Export all prompts to CSV at any time.
  • Update. Change your name and your communication preferences (marketing emails, and automated calls and messages) in profile settings.
  • API keys. Remove stored API keys at any time.
  • Public prompts. Unshare any public prompt at any time.
  • Delete account. The "Danger Zone" option permanently and irreversibly deletes your account and all associated data. It requires you to re-enter your password.
  • Subscription. Cancel your subscription through the Stripe billing portal.

To exercise any right not covered by these controls, contact privacy@hq.pyxage.com.

If you are unhappy with how we handle your data, you can complain to your local supervisory authority. In the UK this is the Information Commissioner's Office. In the EEA it is the authority in your country.

10. California privacy rights (CCPA and CPRA)

If you live in California, you have extra rights over your personal information.

You can ask us to:

  • Tell you what categories of personal information we collect and the purposes for collecting it.
  • Give you a copy of the personal information we hold about you.
  • Delete your personal information, subject to legal exceptions.
  • Correct inaccurate personal information.

We do not sell your personal information. We do not share it for cross-context behavioural advertising.

We will not discriminate against you for exercising these rights.

To make a request, contact privacy@hq.pyxage.com. We may need to verify your identity before we act.

11. Children

Our service is for professionals and businesses. It is not intended for children, and we do not knowingly collect data from children.

If you believe a child has given us personal data, contact privacy@hq.pyxage.com and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the effective date at the top and, where appropriate, notify you.

13. Contact

For any question about this policy or your data, contact Pyxage at privacy@hq.pyxage.com.