Legal
Effective date: 30 March 2026
itisaprompt is a community platform where users discover, share, vote on, and save AI prompts. We are committed to protecting your privacy and handling your data transparently. This policy covers data collected through our website, authentication system, user-generated content features, email communications, and in-app prompt execution tools.
We act as both a data controller (for data we collect directly from you) and a data processor (for content you submit and store through our service).
If you sign in using Google or GitHub, we receive your email address, name, and profile photo URL from that provider. We do not receive your OAuth provider password. The scope of data shared is governed by the respective provider's OAuth policy.
We use the information we collect to:
We do not sell your personal data. We do not use your data for advertising targeting. We do not use AI/ML to make automated decisions that produce legal or similarly significant effects about you.
We use the following third-party services. Their privacy policies govern their handling of any data shared with them:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Authentication, database, file storage | Email, hashed password, profile data, all content |
| PostHog | Product analytics | Pseudonymised user ID, page views, feature events |
| Vercel | Hosting & CDN | Server logs, IP address (transient) |
| Resend / Email provider | Transactional & digest emails | Email address, first name |
| OpenAI / Anthropic | Prompt Studio execution (only if you use Studio) | Prompt text you choose to run; your API key is used server-side for your request only |
We implement industry-standard safeguards to protect your data:
No system is 100% secure. In the event of a data breach that affects your personal information, we will notify you and relevant supervisory authorities within 72 hours of becoming aware, as required by GDPR Article 33.
Depending on your location, you have the following rights regarding your personal data. To exercise any of these rights, email us at privacy@itisaprompt.com. We will respond within 30 days.
To delete your account, go to Settings or contact us at privacy@itisaprompt.com.
The Service is not directed at children under the age of 13 (or 16 in the EU / UK where a higher age of digital consent applies). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@itisaprompt.com and we will delete that data without delay.
itisaprompt is operated from and primarily stores data in the United States and/or the European Union via our sub-processors. If you access the Service from outside those regions, your data may be transferred to, stored in, and processed in a country with different data protection laws than your own.
For transfers from the EEA/UK to third countries, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent transfer mechanisms provided by our sub-processors to ensure your data receives an adequate level of protection.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
Your continued use of the Service after the effective date of any update constitutes your acceptance of the revised policy. If you do not agree, you may delete your account before the changes take effect.
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact our privacy team:
If you are in the EU and have an unresolved privacy concern, you also have the right to contact your local data protection authority.