Privacy Policy
Last Updated: August 8, 2026
This Privacy Policy explains how Prompt Sloth ("we," "our," or "us") handles your data when you use our browser extension, desktop app and website.
1. Prompts you improve
To provide prompt history and memory, we store the prompts you improve. For each improvement we keep:
- The original text you wrote
- The improved version we returned
- The version that was submitted, where we detect it
- Which AI site you were on (for example chatgpt.com), the improvement mode, and timestamps
This is what powers your prompt history and the memory that keeps improvements consistent with how you work. It is stored against your account, transmitted over TLS, held in an access-controlled database, and never sold, rented, or shared with advertisers.
We do not use your prompts to train any AI model, ours or anyone else's, and neither does our AI provider.
2. Memory and derived context
To make improvements more relevant, an automated process reads your recent prompts and extracts short factual statements about you and your work — for example your role, your product's name, or a format you reuse. These facts are stored against your account and used to improve future results. You stay in control of them:
- View, edit and delete any stored fact in the Context tab of the extension, or on your dashboard
- Turn memory off entirely with a single switch, which stops both the storage and the use of these facts
- Turning memory off does not delete facts already stored — use the delete controls for that
3. What we do NOT collect
- We do not read the pages you visit. The extension activates around text fields; it does not scrape page content, and it does not read your AI conversations.
- We do not collect your browsing history.
- We do not store the contents of files you attach to an AI chat. We never receive them.
- We do not sell personal data, and we do not use your content for advertising.
4. Account and billing data
Authentication: Google OAuth. We store your email, display name and account identifier.
Billing: handled by Stripe. Card details go to Stripe directly and are never stored on our servers. We keep your subscription status and customer identifier.
Credits: your balance and reset schedule.
5. Custom templates
Templates you save are encrypted with AES-GCM (256-bit) in your browser before they are sent to us, and are stored encrypted at rest.
As with any service-managed encryption, our systems can decrypt this data in order to serve it back to you, so please don't store passwords, API keys or other credentials in templates.
6. Analytics
We record an event when you improve a prompt, including the AI site, input length, language, timing, token counts and cost. We use these to understand which features are used and to keep the service running. Product analytics are processed by PostHog on EU infrastructure.
7. Third-party services
OpenAI — generates the improved prompt. Receives your prompt text and relevant memory facts. Per OpenAI's API policy, data sent through their API is not used to train their models.
Google (Firebase) — sign-in and authentication. Receives your email and profile basics.
Stripe — payments. Receives the billing details you enter with Stripe.
Turso — our database. Stores everything described in this policy.
PostHog (EU) — product analytics. Receives usage events, not prompt text.
Vercel — hosting. Standard request logs.
8. Retention and your rights
We keep prompt history and derived context for as long as your account exists.
You can:
- Read and delete individual memory facts at any time
- Delete your prompt history from the dashboard
- Request deletion of your account and all associated data by emailing us
- Export your custom templates
- Stop all collection by uninstalling the extension
To exercise any of these, email [email protected] and we will action it within 30 days.
9. Security
- All data is transmitted over TLS
- Custom templates are encrypted with AES-GCM before storage
- Authentication is handled by Google OAuth; we never see or store your password
- Card details are handled by Stripe and never reach our servers
- Access to production data is restricted and audited
10. Changes to this policy
If we begin collecting a materially new category of data, we will update this policy and say so clearly here rather than quietly widening a paragraph.
11. Contact
For questions about this privacy policy: [email protected]