Privacy Statement & Data Protection

PromptHub Privacy Statement

Effective: 2026-08-09 | Last revised: 2026-08-09 | Version: v3.1.0

1. Introduction and Scope

Welcome to PromptHub. The PromptHub platform, including the PromptHub desktop app, website, PromptHub Studio, and PromptHub Cloud API (collectively, the “Platform” or “Service”), is operated by 运营主体待确认 (“we”, “us”, or “PromptHub”).

We follow local-first and data-minimization principles. This Privacy Statement (the “Statement”) explains how we process personal information when you visit, register for, or use the Service. We comply with the PIPL, GDPR, CCPA, and other privacy laws only where each law applies; mentioning a law here does not expand its territorial or material scope.

Please read this Statement carefully. Before creating an account or using a feature that requires personal information, review this Statement. Where processing requires consent, we will request an appropriate affirmative consent separately. Using necessary features that rely on another lawful basis is not blanket consent to optional processing.

2. Local and Cloud Data

3. Information, Purposes, and Lawful Bases

We process information for the activities below. The specific lawful basis depends on your location and the context and may include performance of a contract, your consent, compliance with law, and, after an appropriate balancing assessment, our legitimate interests in securing the Service, preventing fraud, and improving core operations.

Activity Main information Purpose Whether required and consequence of refusal
Account and authentication Email, display name, avatar; profile ID and authorization data from GitHub, Google, or LINUX DO Account creation, sign-in, recovery, and necessary service notices Required for account features; without it, we cannot create or maintain an account
Cloud sync, storage, and teams Prompt and skill content and versions, attachments, workspace metadata, team membership, and roles Sync, backup, recovery, collaboration, and access control Required only for the relevant cloud feature; refusal does not prevent available local features but prevents that cloud feature
Payment and subscriptions Stripe customer identifier, plan, subscription status, billing period, and transaction identifier Payment, reconciliation, entitlements, fraud prevention, and legally required billing records Required to purchase; Stripe processes full card and bank-account details, which we do not store
Community publishing and governance Published assets, publishing and moderation records, reports, and evidence Public display, review of unlawful or infringing content, appeals, and disputes Required only to publish or report content; refusal prevents the relevant action
Security and operations IP address, user-agent, timestamps, request paths, stable error codes, and necessary diagnostic data Sessions, abuse prevention, troubleshooting, audit, and capacity planning Required to provide a secure network service; without it, access may not be safely available
Official AI, when offered Inputs, model and parameters, outputs, and usage metadata Send a request to an upstream model provider, return results, meter usage, and prevent abuse Required only for official AI; refusal prevents that feature

Sensitive personal information

We do not actively request sensitive personal information to provide the core Service. However, prompts, skills, attachments, official AI inputs, or report evidence that you submit may contain it. Do not upload sensitive information unless necessary. If a feature needs to process sensitive personal information, we will provide the notices required by applicable law, including necessity and impact where required, and request separate consent where applicable.

4. AI Data Processing

  1. Local BYOK path. When the desktop app uses an API key you configure to contact a third-party model directly, that provider processes data under its own terms and privacy policy. Avoid sending unnecessary sensitive information.
  2. Official AI path. When we offer official AI, inputs, necessary parameters, and outputs may pass through PromptHub systems and be provided to an upstream model provider to complete your request. Before enabling the feature, or in a related notice, we will identify the actual provider, retention approach, and applicable limitations.
  3. PromptHub training purposes. We do not use private cloud content or official AI inputs and outputs to train, fine-tune, or improve a PromptHub foundation model unless we clearly disclose a new purpose and obtain any consent required by applicable law. Upstream providers’ processing remains governed by the contracts and policies applicable to them.
  4. Public publishing. Community assets become public only after you publish them. Remove personal information, credentials, and material that should remain private before publishing.

5. Cookies and Similar Technologies

We use authentication cookies required to maintain secure sessions. We currently do not use third-party advertising-tracking cookies, and we do not sell personal information or “share” it for cross-context behavioral advertising. Rejecting necessary cookies may prevent you from staying signed in. If we introduce non-essential cookies, we will provide applicable choices before using them.

6. Disclosure, Public Content, and Sub-processors

We do not sell personal information. We disclose only what is necessary to provide a feature you select, comply with law, protect users or the Platform, or act on an appropriate authorization. If you publish a community asset, the asset, displayed author information, and related interactions become visible according to your publishing choices.

Depending on enabled features and actual production configuration, we may use the following sub-processors or independent service providers. A listed provider does not receive data merely because it appears here if the relevant service is not enabled.

Provider/category Service Information that may be processed
Railway and the actual PostgreSQL hosting provider Web/API hosting, database, deployments, and infrastructure logs Account and cloud primary data, requests, and operations metadata
Cloudflare, when CDN or R2 is enabled Edge network, security, and object storage IP/request metadata, cloud attachments, and export packages
Resend, when email is enabled Verification, security, and necessary service email Recipient email, template content, delivery and bounce metadata
Stripe, when paid services are enabled Checkout, subscriptions, customer portal, and payment risk controls Order, billing, and payment information
GitHub / Google / LINUX DO, when selected OAuth sign-in Profile ID, email, display name, avatar, and authorization metadata
Official AI upstream provider, identified when enabled Text or image model inference Inputs, parameters, outputs, and safety or usage metadata
Actual logging and monitoring provider Availability, security, and diagnostics Request, error, device/network metadata, and alert information

The providers, processing regions, and data scopes applicable to you are those identified in this Statement or the notice shown for the relevant feature. We will update this Statement or provide a separate notice for changes that materially affect you.

7. Storage, Cross-border Transfers, and Security

  1. Storage and transfers. Cloud services may be deployed outside your country or region. When you use a cloud feature, personal information may be transferred to and processed where the actual hosting, storage, email, payment, OAuth, or AI provider operates.
  2. Users in mainland China. Where applicable law requires it, before a cross-border disclosure we will identify the overseas recipient, contact details, purpose, method, information categories, and how you may exercise rights, request separate consent where required, and complete the applicable transfer mechanism. If you do not provide a required authorization, we will not transfer that information overseas, and the relevant cloud feature may be unavailable.
  3. EEA and UK users. Where the GDPR or UK GDPR applies, we will use an applicable adequacy decision, standard contractual clauses, or another lawful safeguard based on the actual processing chain, and provide relevant information upon request.
  4. Security. We use technical and organizational measures appropriate to risk, including HTTPS/TLS in transit, session and access controls, private object access and short-lived signed URLs, audit records, and least-privilege administration. Unless we explicitly state otherwise for a specific feature, cloud sync is not end-to-end encrypted. Authorized personnel may have restricted access for support, security investigations, abuse response, or legal requirements.

8. Retention, Deletion, and Account Closure

We retain information for the period needed for the purposes in this Statement, the duration of the contract, security needs, and applicable legal obligations. We consider the data type, amount, sensitivity, purpose, security and fraud risk, and legal requirements when setting a period.

When you close an account or request deletion, we verify identity and use the current account process to remove authentication information and terminate active sessions, then delete, de-identify, or restrict retained records as appropriate. The following may remain for their respective necessary periods:

Contact us under Section 11 to ask about the current retention approach for a category of information.

9. Your Rights

Subject to applicable law, you may request access, a copy, correction, supplementation, erasure, restriction, or objection, and data portability where available. You may also:

Rights may be limited by identity verification, request scope, others’ rights, and statutory exceptions. Submit a request under Section 11. We will respond within the applicable statutory period and explain a denial and available appeal where required.

10. Protection of Minors and Updates

The Service is intended only for users 16 or above and is not directed to minors under 16. If you are under 16, do not register or use account-based features. If we learn that we collected information contrary to this age requirement, we will take reasonable steps to delete or restrict it. Contact us under Section 11 to report a concern involving minors.

We may revise this Statement. For material changes to purposes, methods, disclosures, or your rights, we will provide reasonable notice through the website, console, or registered email. If new processing requires consent, we will request new consent rather than relying only on continued use.

11. Contact Us

For questions, complaints, or rights requests about this Statement or personal-information processing, contact: