Privacy Policy
PromptForge — AI Prompt Enhancer
Last updated: May 10, 2026 · Effective: May 10, 2026
Summary: PromptForge does not sell your data, does not show ads, and does not share your personal information with third parties for marketing. Your prompt text is sent to our server solely to enhance it and is never stored on our servers.
1. Who We Are
PromptForge ("we", "our", "us") is a Chrome browser extension developed by Gajanand Kumawat. We can be reached at info.kumawatgajanand890@gmail.com.
This privacy policy explains what data we collect, how we use it, how we store it, and your rights regarding your data when you use the PromptForge Chrome extension.
2. What Data We Collect
2.1 Data you provide directly:
- Email address and password — collected when you create an account or sign in. Stored securely in Supabase (our authentication provider).
- Prompt text — the text you type into ChatGPT and choose to enhance. This is sent to our backend server to process and is returned enhanced. We do not permanently store your prompt text on our servers.
2.2 Data collected automatically:
- Anonymous install ID — a randomly generated ID (e.g., "pf_abc123") stored locally in your browser to track your daily usage count. This does not identify you personally.
- Usage count — the number of prompt enhancements you perform per day, tracked server-side and linked to your account to enforce usage limits.
- Prompt enhancement history — stored locally in your browser's storage (not on our servers). This includes your original prompt, the enhanced version, detected category, and quality scores.
2.3 Data we do NOT collect:
- We do not collect your ChatGPT conversation history
- We do not collect your browsing history
- We do not collect payment information (no payments in current version)
- We do not collect your device information or IP address for tracking purposes
- We do not use cookies for tracking
3. How We Use Your Data
We use the data we collect solely to:
- Authenticate your account and maintain your login session
- Process your prompt text through our AI enhancement pipeline (Google Gemini API) and return the improved version
- Enforce daily usage limits (free plan: 5 enhancements/day)
- Send account-related emails (email verification, password reset) via Resend
- Improve the quality and accuracy of our prompt enhancement service
We do not use your data for advertising, profiling, or selling to third parties.
4. How We Store Your Data
4.1 Local browser storage:
- Your prompt enhancement history (last 50 entries) is stored in Chrome's local storage on your device only
- Your login session token is stored locally in Chrome storage
- Your anonymous install ID is stored locally in Chrome storage
- This data never leaves your device except as described in this policy
4.2 Server-side storage (Supabase):
- Your email address and hashed password are stored securely in Supabase's authentication system
- Your daily usage count is stored server-side to enforce plan limits
- Supabase is hosted on AWS infrastructure with encryption at rest and in transit
- Supabase's privacy policy: https://supabase.com/privacy
4.3 Data retention:
- Account data is retained as long as your account is active
- Local history data is retained until you clear it via the extension's Settings → Clear History option
- You may request deletion of your account and all associated data at any time by emailing us
5. Data Sharing and Third Parties
We share data with the following third-party services, solely to provide the extension's functionality:
We do not sell, rent, or trade your personal information to any third party for commercial purposes.
We may disclose your information if required by law, court order, or to protect the safety and rights of our users.
6. Permissions We Request and Why
PromptForge requests the following Chrome permissions:
- storage — To save your login session, prompt history, and usage data locally in your browser
- host_permissions for chatgpt.com — To inject the sparkle button into the ChatGPT interface and read the text from the input box you want to enhance
- host_permissions for api.promptforge.website — To communicate with our backend API server
- host_permissions for supabase.co — To authenticate your account directly from the extension
We do not request any permissions beyond what is strictly necessary for the extension's functionality.
7. Children's Privacy
PromptForge is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately and we will delete it.
8. Your Rights
You have the right to:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate personal data
- Deletion — Request deletion of your account and all associated data
- Portability — Request your data in a portable format
- Opt-out — Uninstall the extension at any time to stop all data collection
To exercise any of these rights, contact us at info.kumawatgajanand890@gmail.com. We will respond within 30 days.
9. Security
We take reasonable measures to protect your data:
- All data transmission between the extension and our servers uses HTTPS/TLS encryption
- Passwords are hashed and never stored in plaintext (handled by Supabase)
- Authentication tokens are stored locally and expire automatically
- We do not log or store your prompt text on our servers after processing
No method of transmission over the internet is 100% secure. We strive to protect your data but cannot guarantee absolute security.
10. Changes to This Policy
We may update this privacy policy from time to time. When we make significant changes, we will update the "Last updated" date at the top. Continued use of the extension after changes constitutes acceptance of the updated policy.