Privacy Policy
Effective August 1, 2026
This Privacy Policy explains what information NexPrompt ("we," "us," or "our") collects, how we use it, and the choices you have. It applies to our website and application (together, the "Service").
1. Information we collect
Account information. If you create an account, we collect your email address, the display name you provide, and a hashed password (we never store your password in plain text — password hashing and authentication are handled by our authentication provider, Supabase).
Your content. The prompts, prompt bodies, titles, folders, tags, and collections you create — the actual content of your workspace.
Usage & device information. Basic technical information such as browser type, general region (derived from IP address, not stored precisely), and pages visited, used for security, debugging, and understanding aggregate product usage.
Local/device storage. If you use NexPrompt without an account (demo mode), your data is stored only in your browser's local storage and a session cookie, and is never transmitted to our servers.
2. How we use your information
- To provide, maintain, and secure the Service, including syncing your workspace across your devices;
- To authenticate you and protect your account from unauthorized access;
- To operate AI assist features, which send the specific prompt text you act on to our AI provider to generate a suggestion (see Section 4);
- To communicate with you about your account, such as password resets or security notices;
- To understand aggregate usage patterns so we can improve the Service;
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use the content of your prompts to train AI models.
3. Where your data is stored
When you create an account, your workspace (prompts, folders, tags, collections) and account information are stored in a hosted Postgres database provided by Supabase, protected by row-level security policies that scope every record to your own account — no other user can query or read your data through the application. Backups you create locally within the app are stored in your browser and are not uploaded to our servers.
4. AI providers
When you run an AI assist action (Improve, Rewrite, Expand, Shorten), the text of the specific prompt you're acting on is sent to our AI provider (Anthropic) to generate a suggested result, then discarded — we don't direct the provider to retain it for training. Refer to Anthropic's own privacy policy for how they handle API data. No AI action runs automatically; it only runs when you click an AI action button.
5. Sharing your information
We share information only in the following circumstances:
- Service providers who host our infrastructure or process data on our behalf (e.g. Supabase for authentication and database hosting, Anthropic for AI assist requests), under contractual obligations to protect it;
- Public share links you explicitly create — anyone with the link can view that specific prompt or collection;
- Legal requirements, if we're required to disclose information to comply with a law, regulation, or valid legal process;
- Business transfers, if NexPrompt is involved in a merger, acquisition, or asset sale, subject to standard confidentiality protections.
6. Your choices and rights
- Access & export. Export your entire workspace as JSON at any time from Settings → Data.
- Correction. Update your display name and account email from Settings → Account.
- Deletion. Delete individual prompts, folders, tags, or collections at any time; contact us via the contact page to request deletion of your account and associated data.
- Unsharing. Revoke a public share link at any time by turning off "Public" for that prompt or collection.
Depending on where you live, you may have additional rights under applicable law (such as the GDPR or CCPA), including the right to object to or restrict certain processing. Contact us to exercise these rights.
7. Data retention
We retain your account and workspace data for as long as your account is active. If you delete your account, we delete your workspace data and personal information within a reasonable period, except where we're required to retain certain records for legal, security, or fraud-prevention purposes.
8. Security
We use industry-standard measures to protect your data, including encryption in transit (TLS), row-level security on all database access, and hashed password storage. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
9. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can remove it.
10. International data transfers
Our service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll provide reasonable notice (for example, by email or an in-app notice) before they take effect.
12. Contact us
Questions about this policy or your data? Reach out via the contact page.