Privacy Policy

Last updated: July 25, 2026

This Privacy Policy explains how [Legal entity name](“Promptic”, “we”, “us”) collects, uses, shares, and protects personal data in connection with the Promptic platform. Our registered address is [registered address]. For any privacy request or question, contact us at [data-requests contact email].

This document contains placeholders in [brackets] that must be completed with your legal entity, address, contact, and hosting region before publication, and reviewed by legal counsel.

1. Our two roles

Promptic processes personal data in two distinct capacities:

  • As a controller — for the personal data of our account holders (the people who sign up to build and manage agents): the account and workspace data we need to provide the service.
  • As a processor— for the personal data that an account holder’s own end-users (site visitors) submit to an agent, such as chat messages and captured contact details. For that data the account holder is the controller and decides why and how it is processed; we process it under their instructions to operate the agent.

2. Data we collect

Account holders

  • Email address and (optionally) name, provided at signup.
  • Workspace details you create (workspace name, agent configuration).
  • Usage and billing metering (message counts, token usage, and cost per workspace).

End-user (visitor) data, on behalf of customers

  • The content of chat messages exchanged with an agent.
  • Any identity a customer’s website asserts about a visitor (e.g. name or email), which we store but do not independently verify.
  • Leads and escalation contact details captured by an agent’s configured actions.
  • Documents a customer uploads to train an agent.

Technical data

  • Aggregate, cookieless analytics via Vercel Web Analytics and Speed Insights. These do not use cookies and do not store data that directly identifies you.
  • We do not store visitor IP addresses or device fingerprints in the application.

3. How we use data and our lawful bases

  • To provide the service (performance of a contract) — authenticating you, running your agents, and metering usage.
  • To operate and secure the platform (legitimate interests) — preventing abuse, debugging, and enforcing usage limits.
  • End-user data is processed on the instructions of the customer who deployed the agent, under the lawful basis that customer relies on.

4. Cookies and local storage

  • Session cookies — strictly necessary cookies set by our authentication provider (Supabase) to keep you signed in.
  • Analytics — Vercel Web Analytics and Speed Insights are cookieless.
  • Widget local storage— the embeddable chat widget stores a conversation identifier in the browser’s localStorageso a visitor’s conversation persists across page loads. This is not a cookie and is not used for cross-site tracking.

5. Sub-processors

We use the third-party sub-processors below to provide the service. Each processes only the data needed for its function.

Sub-processorPurposeData categoriesLocation
SupabasePrimary database, authentication, and file storageAccount profile, workspace data, chat content, uploaded documents[hosting region — confirm in Supabase dashboard]
VercelApplication hosting and cookieless product analyticsAll data in transit; aggregate, cookieless usage metricsUnited States / global edge
Vercel AI GatewayRouting model and embedding requests to providersChat messages and document content sent for processingUnited States / global
OpenAIText embeddings and (optionally selected) chat modelChat message content, document contentUnited States
AnthropicChat model (Claude)Chat message contentUnited States
FirecrawlFetching content from customer-provided URLs for trainingPublicly reachable content at URLs the customer suppliesUnited States
ResendTransactional email delivery (e.g. escalation notifications)Escalation contact details and message contentUnited States

In addition, a customer may configure their agent to send escalation data to a webhook endpoint they control. That endpoint is the customer’s own integration, not a Promptic sub-processor, and the customer is responsible for it.

6. Your rights

Depending on your location, you may have rights to access, correct, export, delete, or object to the processing of your personal data. Account holders can exercise the core rights directly:

  • Access & portability — download a machine- readable copy of your account and workspace data from Workspace settings → Your data.
  • Erasure — permanently delete your account and the workspaces you own from the same settings page. This cannot be undone.
  • Other requests (rectification, objection, or requests from an end-user) — contact us at [data-requests contact email]. Where you are an end-user of an agent, please also contact the operator of the site you used, who is the controller of that data.

7. Data retention

We retain account and workspace data for as long as your account is active. When you delete your account, the account and the workspaces you solely own — including agents, uploaded documents, conversations, messages, leads, and escalations — are erased. Backups, if any, are cycled out on their normal schedule.

8. International transfers

Some sub-processors listed above are located in the United States. Where personal data is transferred outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses. [Confirm the transfer mechanism and data-processing agreements in place with each sub-processor.]

9. Security

Data is encrypted in transit. Access to workspace data is enforced at the database level by row-level security so each workspace can only reach its own data, and privileged operations are isolated to trusted server-side code.

10. Children

Promptic is not directed to children and is not intended for use by anyone under the age required to consent to processing in their jurisdiction.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “last updated” date above.

12. Contact

Questions or requests: [data-requests contact email], [Legal entity name], [registered address].