Legal
Privacy Policy
Last updated September 17, 2026
1. Who we are
IterPrompt LLC ("IterPrompt", "we", "us") operates IterPrompt and is the data controller for the personal data described here. You can reach us at daiki@iterprompt.com — put "Privacy" in the subject line and it gets handled as a privacy request.
This policy covers the IterPrompt website and its account features. It does not cover the third-party sites we link to, including every AI tool in our directory, which have their own policies.
2. What we collect
Things you give us
- Account details — your email address, a display name if you set one, and a one-way hash of your password. We never store your password itself and cannot read it.
- Content you create — prompts you save or write, folders and tags, task templates, workflows, workspaces, and the job descriptions you enter to generate a personal prompt library. If you describe your job in your own words, whatever you type there is stored with your account.
- Prompt runs — when you run a prompt, we store the prompt, the values you filled in, the model output, the model and provider used, token counts, duration, and credits spent, so you can see your history and so we can bill credits accurately.
- Your own provider API keys — if you bring your own key for an AI provider, we store it encrypted and use it only to run the prompts you ask us to run. You can delete it at any time.
- Community contributions — if you submit a prompt, skill, or template, we store what you submit plus the name and email you optionally provide. Ratings are stored without an identifier.
- Messages you send us — support email and its contents.
Payment details
Payments are processed by Stripe. Card numbers go straight to Stripe and never touch our servers. We store the Stripe customer and subscription identifiers, your plan, your credit balance, and your auto-reload settings — not your card.
Things collected automatically
- Request data — IP address, user agent, requested URL and timestamp, processed at the edge to rate-limit abuse and block scrapers. This is held in memory for minutes, not written to a long-term store by us, and used for no other purpose.
- Hosting logs — our hosting provider keeps standard server logs on our behalf.
- Analytics — with your consent (see Cookie Policy), we record which pages and features are used. The events we send are limited to a fixed list of non-identifying fields: page type, content slug, whether a visitor is signed in, coarse device type, and the length of a search term. The text of your prompts, your variable values, and your search terms are never sent to an analytics service.
We do not use tracking pixels for advertising, we run no ad network, and we do not build advertising profiles.
3. Why we use it, and our legal basis
If you are in the EEA, the UK or Switzerland, the GDPR requires us to name a legal basis for each purpose:
- Running your account and the features you ask for — saving prompts, running models, showing your history. Basis: performance of a contract.
- Taking payment, granting credits, preventing chargeback fraud. Basis: performance of a contract; legal obligation for tax and accounting records.
- Keeping the service up and abuse out — rate limiting, bot protection, security investigation. Basis: legitimate interests in a service that stays online and is not scraped or brute-forced.
- Understanding which content is useful — analytics. Basis: your consent, which you can withdraw at any time.
- Replying to you — support, contributions, moderation. Basis: legitimate interests, or contract where you are a customer.
- Complying with the law — responding to valid legal requests, handling copyright notices. Basis: legal obligation.
4. AI model providers — read this one
When you run a prompt, its content, your filled-in values, and any file or context you attach are sent to the AI provider you selected, so that the provider can generate a response. This is the core function of the feature and it cannot be done without that transfer.
Each provider processes that data under its own terms and privacy policy. We do not control their retention or training practices. Do not put anything into a prompt that you are not allowed to disclose to a third-party processor — that includes other people's personal data, health or financial records, credentials, and trade secrets you are contractually bound to protect.
The providers a run may be sent to, and their privacy policies:
If you use your own API key, the run goes to that provider under your own account and agreement with them.
5. Who else we share data with
We share personal data only with service providers who process it on our instructions, and only as far as they need it. The current list — what each one does and where it operates — is on our subprocessors page.
Beyond those processors, we disclose personal data only:
- when the law requires it, or to respond to a valid legal process — and we will tell you unless we are legally barred from doing so;
- to establish, exercise or defend a legal claim, or to investigate fraud, abuse or a security incident;
- to an acquirer, as part of a merger, acquisition or sale of assets — in which case this policy continues to apply until you are told otherwise, and you will be notified before any new policy takes effect;
- with your direction — for example, when you publish a submission.
We do not sell personal data, and we never have. We do not share it for cross-context behavioural advertising. We do not use your prompts, your saved content, or your run history to train any AI model.
6. Content you publish
If you submit a prompt, skill or template to the public library, the content you submit — and the author name you choose, if any — becomes publicly visible and may be copied by anyone. Do not include personal data you want kept private. Your email address on a submission is used only to contact you about it and is not published.
7. Cookies
We use a small number of strictly necessary cookies to keep you signed in and to remember your language and your cookie choice. Analytics cookies are set only where you have consented. Every cookie, what it does and how long it lasts is listed in the Cookie Policy, where you can also change your choice at any time.
8. International transfers
We operate in the United States, and our processors may operate elsewhere. If you use the service from outside the United States, your data will be transferred there. For transfers of data about people in the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) in our agreements with processors, together with the safeguards described in their own policies.
9. How long we keep things
- Account data — while your account exists, and for up to 30 days after you delete it, to allow for accidental deletion and to complete any pending payment obligations.
- Saved prompts, tasks, workflows, job libraries — until you delete them or delete your account.
- Run history — until you delete it or delete your account.
- Payment and credit records — up to 7 years, because tax and accounting law requires it. This is limited to the transaction record, not your content.
- Public submissions — indefinitely, since the library is a published work; the author name can be removed on request.
- Analytics — per the retention setting of each analytics provider, listed on the subprocessors page.
- Abuse-prevention data — minutes to hours.
10. Security
Passwords are stored as salted one-way hashes. Provider API keys are encrypted at rest. Traffic is served over HTTPS with hardened security headers, and abusive traffic is rate-limited and blocked at the edge. Access to production data is limited to the people who need it.
No service can promise perfect security. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant supervisory authority within the deadlines the law sets (72 hours to the authority under the GDPR).
11. Your rights
If you are in the EEA, the UK or Switzerland
You have the right to:
- access the personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format, and have it sent to another controller where technically feasible;
- withdraw consent at any time, without affecting past processing;
- lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office; in the EEA, your national data protection authority.
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
If you are in California
Under the CCPA/CPRA you may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclose to; request deletion; request correction; and limit the use of sensitive personal information. We do not collect sensitive personal information as the CPRA defines it beyond your account credentials, and we use it only to provide the service.
We do not sell or share personal information, and we have not in the preceding 12 months — including personal information of anyone under 16. There is therefore no "Do Not Sell or Share" process to run; you can still switch analytics off entirely from the Cookie Policy. We will not discriminate against you for exercising any privacy right.
The categories we collect map to the CCPA list as: identifiers (email, account ID, IP address); commercial information (plan, credits, transaction history); internet activity (pages viewed, features used); and your own content. We collect no biometric, geolocation-precise, genetic, or government-ID data.
If you are elsewhere in the United States
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have comparable rights of access, correction, deletion, portability, and appeal. If we decline a request, you may appeal by replying to our decision; we will respond to the appeal within 45 days and tell you how to contact your state attorney general.
How to exercise any of these rights
Email daiki@iterprompt.com from the address on your account, or tell us enough to verify you own it. We answer within 30 days and will tell you if we need longer (and why). Using these rights is free unless a request is manifestly unfounded or excessive. An authorised agent may act for you with written permission we can verify.
12. Global Privacy Control and Do Not Track
Our analytics respect the browser Do-Not-Track signal. We treat a Global Privacy Control (GPC) signal as a valid opt-out of analytics where your law gives it that effect. Because we do not sell or share personal information, there is nothing further for a GPC signal to stop.
13. Children
IterPrompt is not directed to children. You must be at least 16 — or 13 with verifiable permission from a parent or guardian, where your country allows it — to create an account. We do not knowingly collect personal data from children under 13. If you believe a child has given us data, email us and we will delete it.
14. Changes to this policy
We update this policy when our practices change. The "last updated" date at the top always reflects the current version. If a change materially affects your rights, we will give notice — by email to account holders, or a notice on the site — before it takes effect.
15. Contact
Privacy questions, requests and complaints: daiki@iterprompt.com. Other ways to reach us are on the contact page.