Privacy Policy
Last updated: July 25, 2026
This Privacy Policy explains how [Legal entity name](“Promptic”, “we”, “us”) collects, uses, shares, and protects personal data in connection with the Promptic platform. Our registered address is [registered address]. For any privacy request or question, contact us at [data-requests contact email].
This document contains placeholders in [brackets] that must be completed with your legal entity, address, contact, and hosting region before publication, and reviewed by legal counsel.
1. Our two roles
Promptic processes personal data in two distinct capacities:
- As a controller — for the personal data of our account holders (the people who sign up to build and manage agents): the account and workspace data we need to provide the service.
- As a processor— for the personal data that an account holder’s own end-users (site visitors) submit to an agent, such as chat messages and captured contact details. For that data the account holder is the controller and decides why and how it is processed; we process it under their instructions to operate the agent.
2. Data we collect
Account holders
- Email address and (optionally) name, provided at signup.
- Workspace details you create (workspace name, agent configuration).
- Usage and billing metering (message counts, token usage, and cost per workspace).
End-user (visitor) data, on behalf of customers
- The content of chat messages exchanged with an agent.
- Any identity a customer’s website asserts about a visitor (e.g. name or email), which we store but do not independently verify.
- Leads and escalation contact details captured by an agent’s configured actions.
- Documents a customer uploads to train an agent.
Technical data
- Aggregate, cookieless analytics via Vercel Web Analytics and Speed Insights. These do not use cookies and do not store data that directly identifies you.
- We do not store visitor IP addresses or device fingerprints in the application.
3. How we use data and our lawful bases
- To provide the service (performance of a contract) — authenticating you, running your agents, and metering usage.
- To operate and secure the platform (legitimate interests) — preventing abuse, debugging, and enforcing usage limits.
- End-user data is processed on the instructions of the customer who deployed the agent, under the lawful basis that customer relies on.
4. Cookies and local storage
- Session cookies — strictly necessary cookies set by our authentication provider (Supabase) to keep you signed in.
- Analytics — Vercel Web Analytics and Speed Insights are cookieless.
- Widget local storage— the embeddable chat widget stores a conversation identifier in the browser’s
localStorageso a visitor’s conversation persists across page loads. This is not a cookie and is not used for cross-site tracking.
5. Sub-processors
We use the third-party sub-processors below to provide the service. Each processes only the data needed for its function.
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Supabase | Primary database, authentication, and file storage | Account profile, workspace data, chat content, uploaded documents | [hosting region — confirm in Supabase dashboard] |
| Vercel | Application hosting and cookieless product analytics | All data in transit; aggregate, cookieless usage metrics | United States / global edge |
| Vercel AI Gateway | Routing model and embedding requests to providers | Chat messages and document content sent for processing | United States / global |
| OpenAI | Text embeddings and (optionally selected) chat model | Chat message content, document content | United States |
| Anthropic | Chat model (Claude) | Chat message content | United States |
| Firecrawl | Fetching content from customer-provided URLs for training | Publicly reachable content at URLs the customer supplies | United States |
| Resend | Transactional email delivery (e.g. escalation notifications) | Escalation contact details and message content | United States |
In addition, a customer may configure their agent to send escalation data to a webhook endpoint they control. That endpoint is the customer’s own integration, not a Promptic sub-processor, and the customer is responsible for it.
6. Your rights
Depending on your location, you may have rights to access, correct, export, delete, or object to the processing of your personal data. Account holders can exercise the core rights directly:
- Access & portability — download a machine- readable copy of your account and workspace data from Workspace settings → Your data.
- Erasure — permanently delete your account and the workspaces you own from the same settings page. This cannot be undone.
- Other requests (rectification, objection, or requests from an end-user) — contact us at [data-requests contact email]. Where you are an end-user of an agent, please also contact the operator of the site you used, who is the controller of that data.
7. Data retention
We retain account and workspace data for as long as your account is active. When you delete your account, the account and the workspaces you solely own — including agents, uploaded documents, conversations, messages, leads, and escalations — are erased. Backups, if any, are cycled out on their normal schedule.
8. International transfers
Some sub-processors listed above are located in the United States. Where personal data is transferred outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm the transfer mechanism and data-processing agreements in place with each sub-processor.]
9. Security
Data is encrypted in transit. Access to workspace data is enforced at the database level by row-level security so each workspace can only reach its own data, and privileged operations are isolated to trusted server-side code.
10. Children
Promptic is not directed to children and is not intended for use by anyone under the age required to consent to processing in their jurisdiction.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “last updated” date above.
12. Contact
Questions or requests: [data-requests contact email], [Legal entity name], [registered address].