§ privacy

Privacy Policy

Last updated June 26, 2026

PromptFloe is operated from India. This policy explains what data we collect when you build, verify, and deploy applications with us, how we use and share it, where it is processed, and the rights you have under India's Digital Personal Data Protection Act, 2023 and the GDPR.

01 Who we are

PromptFloe ("PromptFloe", "we") is the data fiduciary / controller responsible for personal data processed through the service. For questions or to exercise your rights, contact support@promptfloe.com.

Where you use PromptFloe to process personal data on behalf of your own organization, you are the controller / data fiduciary and we act as your processor under our Data Processing Addendum (DPA), available at /trust.

02 Information we collect

Account data you provide - name, email, and authentication identifiers from GitHub or Google when you sign in with them.

Build data - the prompts, design references, and files involved in generating your applications, along with the verification records (gate results and certificates) each build produces.

Payment data - billing identity and transaction records processed by our payment providers (Razorpay for India, Stripe internationally). We do not store full card numbers.

Usage and device data - pages visited, features used, and standard technical information such as browser type and IP address, used to operate and secure the service.

Optional inputs - voice audio if you use voice features, and messages exchanged through Slack or Telegram if you connect those integrations.

03 How we use your data

To run the product: generate, verify, and deploy the applications you ask for, and to maintain your workspace and build history.

To process payments, prevent fraud and abuse, and meet legal and tax obligations.

To improve quality and safety: aggregate, de-identified signals help us measure and improve generation quality and catch abuse. We do not sell your personal data.

To communicate: transactional messages about your builds, account, and security. You can opt out of non-essential email at any time.

04 AI processing

Generating an application sends the relevant prompt and context to large language model providers (Anthropic, OpenAI, and Google) under their respective data-processing terms. We pass only what a given step needs.

AI processing is limited to Anthropic, OpenAI, and Google. We recommend not submitting personal or sensitive data in prompts.

Your build inputs and outputs are stored so you can revisit, edit, and deploy them. You can delete a build at any time.

05 Sharing and sub-processors

We share personal data with vetted service providers that process it on our behalf - including cloud hosting and storage (AWS), our database and cache providers, AI model providers, payment processors, email delivery (Resend), analytics and error monitoring (PostHog, Sentry), and the deployment targets you choose (Vercel, Netlify).

A current, categorized list of these sub-processors, with the data they handle and their regions, is published at /trust. We also disclose data where required by law or to protect rights and safety.

06 Where your data is processed

Primary application data is stored in India (AWS ap-south-1). AI generation and several supporting services operate in the United States, so using PromptFloe involves international transfers of personal data.

For transfers from the EEA/UK, we rely on Standard Contractual Clauses together with a Transfer Impact Assessment and additional safeguards, available on request via support@promptfloe.com.

07 Data retention and deletion

We retain account and build data for as long as your account is active. Deleting a build removes its files; deleting your account removes your personal data, subject to limited records we must keep for legal, tax, or security reasons.

08 Security

We use encryption in transit, encryption at rest for sensitive credentials, scoped role-based access controls, rate limiting, and audited internal operations. Secrets you provide for deployment are encrypted and never exposed in generated code.

No system is perfectly secure. To report a vulnerability, contact support@promptfloe.com.

09 Your rights

Under the DPDP Act, 2023 and the GDPR you may have rights to access, correct, update, export, and erase your personal data, to withdraw consent, and to nominate another person to exercise your rights in the event of death or incapacity.

To exercise any right, contact support@promptfloe.com and we will respond within the timeframe the law requires. If you are unsatisfied, you may escalate to our Grievance Officer or lodge a complaint with the Data Protection Board of India or your local supervisory authority.

10 Grievance Officer

In accordance with the DPDP Act, 2023, PromptFloe has designated a Grievance Officer to address concerns about the processing of your personal data. Contact details are available on request at support@promptfloe.com.

11 Changes to this policy

We may update this policy as the product and the law evolve. Material changes will be communicated through the service or by email, and the "last updated" date above will change.

Questions? Reach us at support@promptfloe.com.