Privacy Policy

Last updated: May 20, 2026

1. Information We Collect

We collect personal information that you voluntarily provide to us when you register on our Services, subscribe to plans, or contact us. This includes:

A. Personal Information Disclosed by You

  • Profile Data: Names, usernames, email addresses, and passwords when creating an account.
  • Billing & Payment Data: Payment processing is handled securely by Stripe. All transaction records, billing details, and payment information are securely transmitted to and stored by Stripe in compliance with their privacy policy (https://stripe.com/privacy). We do not store or process card numbers on our servers.
  • Social Authentication Data: If you sign up using third-party login services (such as Google or Github), we receive limited profile details (name, email) from your provider via Supabase secure authorization.

B. Information Automatically Collected

Like most native desktop applications, we automatically log specific technical parameters necessary for licenses, device locking, and diagnostics:

  • Machine Identifier: To enforce licensing quotas and single-device subscription limits, our application reads a unique hardware identifier (machine UUID) of your device.
  • Diagnostics and Performance Data: Crash logs, error reports, and general performance analytics related to your use of the application.
  • System Characteristics: Operating system, version details, and basic network parameters (such as approximate region deduced from IP address) to maintain session security.

Google API Services User Data Policy: Our application integrates with Google API Services. Any personal data accessed through Google APIs is handled locally by your web browser and is subject to Google's Limited Use requirements.

2. How We Process Your Information

We process your personal information only when we have a valid legal reason to do so. Our processing activities focus on providing a secure and reliable desktop automation experience:

  • Account Provisioning: Allowing you to register, log in, manage preferences, and retain your local library of configurations.
  • Subscription and Quota Management: Enforcing plan limits and subscription states securely hosted in our Supabase backend.
  • Device Verification: Matching your hardware ID during startup to ensure account security and prevent multiple concurrent sessions on different desktops.
  • Software Maintenance: Reviewing version configurations to prompt automatic updates and ensure compatibility with third-party web interfaces.

3. When and With Whom We Share Your Information

We only share data in specific situations with trusted partners required to run our cloud backend and billing services:

  • Stripe: Processing payments, validating subscription states, and managing checkouts.
  • Supabase: For user authentication, identity management, and secure database hosting.
  • Legal Obligations: We may disclose information if required by law to comply with judicial processes, court orders, or administrative requests.

We do not sell, rent, or distribute your email addresses or personal statistics to any third-party marketing companies.

4. Cookies and Similar Technologies

Our website uses basic cookies to facilitate user authentication and monitor landing page traffic. The desktop application does not load traditional website tracking pixels.

However, the application uses local browser cookies stored exclusively in your local machine's session folder to maintain persistent sessions with third-party web platforms during automation. This data remains 100% on your local machine and is never transmitted to our servers.

5. Third-Party Integrations

Our desktop application operates on a local browser automation architecture. When you execute an automation queue, the application utilizes a persistent local browser profile on your device to interact directly with third-party platforms on your behalf.

All inputs, prompts, credentials, and session cookies are transmitted securely over HTTPS directly to these third-party servers. We do not inspect, intercept, capture, or store your prompts, generative inputs, or output files on our backend servers.

6. Social Logins and Third-Party Authentication

If you choose to authenticate with a third-party social identity provider, we receive specific profile elements (name, email address, and profile picture URL). We store this data securely inside our user database solely to personalize and authenticate your account profile.

7. Data Retention

We retain your personal profiles and transaction records only for as long as necessary to fulfill the purposes highlighted in this policy, or to satisfy legal, tax, or auditing requirements. Upon account deletion, your profile data, hardware UUID associations, and related records are permanently removed from our active database hosts.

8. Security of Your Information

We deploy secure cloud infrastructure hosted by Supabase to protect your account profile. However, because our desktop application stores session credentials and automation logs locally in your user data directory, you are responsible for maintaining the physical and digital security of your device against unauthorized access.

9. Your Privacy Rights

Depending on your geographic location (such as the European Union under GDPR, or California under CCPA), you may possess specific rights regarding your personal information:

  • Access and Rectification: You can request a summary of the data we hold, or ask for adjustments.
  • Data Erasure: You can request that we delete your account profiles and associated Stripe records.
  • Withdraw Consent: Since we process data with your direct consent (such as checking update histories or device lock telemetry), you can object or terminate sessions.

To exercise any data rights, please submit a request to our data contact at phanphuc1100@gmail.com. We will address all valid requests in accordance with local regulations within 30 days.

10. Updates to This Policy

We may update this Privacy Policy from time to time. The updated date will be stated in the "Last updated" header at the top of this document. Any material changes will be communicated either via an update banner in the desktop application or by updating this policy page directly.

11. How to Contact Us

If you have any questions or security concerns regarding our application, data processing practices, or third-party integrations, please email the developer directly at:

Email: phanphuc1100@gmail.com
Developer: Phuc Phan
Project: PrompCut Developer Group