← Prompt Prober

Privacy Policy

Effective date: 27 August 2026 · Last updated: 24 September 2026

This policy explains what data Prompt Prober (“we”, “us”) collects, why, who we share it with, and how your privacy is protected. Prompt Prober is an AI Prompt Engineering and Context Intelligence Workspace consisting of a browser extension and web dashboard.

1. Who is responsible for your data

Prompt Prober is the data controller for account and subscription information described here. For any privacy-related questions or data deletion requests, contact us directly at support@promptprober.com.

2. What we collect and why

We adhere to strict data minimization:

  • Account credentials & email — used for passwordless OTP authentication, account management, and subscription checkout and servicing. Legal basis: performance of contract.
  • Transient prompt & context inputs — when you request AI prompt enhancement, Snapcopy visual analysis, or Response Grounding, prompt text, response/reference text, targeted public-source queries, retrieved public-source excerpts, and ephemeral image snips pass transiently through our stateless API to the applicable processor (see sections 3 and 4). Legal basis: performance of contract.
  • Usage metering and abuse prevention — introductory and monthly action counts are recorded to enforce the first 10 Premium Enhancements and the shared 300 Premium-Enhancement and Snapcopy-analysis allowance. Limited request timestamps, random non-content identifiers, and short-lived capacity leases enforce managed-call rate and concurrency limits, including Response Grounding. A one-way hash of the request IP is retained for up to 30 days to limit introductory allocations to five distinct accounts per IP/day. Legal basis: performance of contract and legitimate interest in preventing abuse.
  • Subscription & billing status — subscription IDs, plan tier, and renewal timestamps managed via our payment processors (see section 5). Legal basis: performance of contract.
  • Local client data — account-isolated prompt history (including full original prompts, analyses, and enhancements), pinned research notes, and harvested page text are stored on your device in browser local storage. If you opt into “Remember across sessions,” text-only Snapcopy context is also stored locally for up to 24 hours within a bounded ring. Extracted tables stay only in the current side-panel session unless you copy them or explicitly include them in a prompt. These items leave the device only when you choose to include them in a managed AI request; Prompt Prober does not save that request content on its servers.
  • Required webpage access — the browser asks you to allow Prompt Prober to read and change data on ordinary webpages (often described by the browser as access to “all sites”). This standing access makes side-panel capture, harvesting, pinning, and table extraction available on the page you choose, but access alone performs none of those actions. Each capture or extraction starts only when you select its side-panel button or Prompt Prober right-click command. Prompt insertion is limited to the exact active chatbot document currently connected to Prompt Prober. Outside supported chatbot composers, Prompt Prober does not passively observe ordinary webpages. On the three built-in supported chatbot origins, the extension observes text in the visible chat composer for local scoring and coaching. Any additional chatbot origin is not observed until you explicitly choose Enable Prompt Prober on this chatbot. Composer observation does not read unrelated fields or browsing history, and observation alone does not transmit drafts.

3. How prompt enhancement and context intelligence work

Local 6-dimension prompt diagnosis and scoring happen entirely on your machine in the browser extension without making network requests. When you trigger AI enhancement or multimodal context synthesis:

  • The input text and/or visual viewport snip is transmitted over TLS to our secure Next.js API hub.
  • Our backend forwards the payload to a configured AI sub-processor to generate the enhanced prompt or structured breakdown. Prompt Prober does not display or promise a particular model.
  • The synthesized result is returned to your browser. Prompt Prober does not store, log, or persist your prompt content or image bytes on our servers.
  • When Snapcopy attaches a captured image, it does so only to the exact active chatbot tab that is currently connected to Prompt Prober. The extension re-checks that destination before attachment; it does not attach to a background, disconnected, or different chatbot tab.
  • Prompt Prober does not use your content to train models. AI providers process requests under their applicable API data-use and retention terms, which may vary by provider and account configuration.

4. AI & Infrastructure Sub-processors

We use service providers only to operate the user-requested features described in this policy:

  • Managed AI inference sub-processors — a provider-neutral pool processes prompt text, response/reference text, public source excerpts, or visual snips transiently when you explicitly request a managed enhancement, Response Grounding check, or Snapcopy analysis. Provider and model selection may change for reliability; Prompt Prober does not promise a particular provider or model.
  • Public-source search and retrieval services — process targeted queries and return public URLs or page content transiently for a Response Grounding check. Prompt Prober does not store those queries or source bodies; the service's applicable API data-use and retention terms still apply.
  • Neon, Inc. — serverless PostgreSQL database hosting account records, OTP tokens, and usage quotas.
  • Vercel, Inc. — web dashboard hosting and secure serverless API execution.

Chrome Web Store Limited Use

Prompt Prober's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that information only to provide or improve Prompt Prober's single-purpose, user-facing features. We do not use it for advertising, credit decisions, or unrelated profiling, and we do not sell it.

We transfer data only when necessary to provide a feature you requested, for security or legal compliance, or with your affirmative consent. Human access is prohibited except when required for security, legal compliance, or support that you explicitly request.

5. Payment processor: Polar.sh

Polar.sh (Polar Software Inc.) is our Merchant of Record for subscriptions, handling billing, invoicing, and applicable tax compliance.

When you start checkout, we send Polar your account identifier and email to link the purchase to your Prompt Prober account.

Your payment card and financial details are submitted directly to Polar during checkout. Prompt Prober systems never receive or store your raw credit card information.

6. Data retention and client-side isolation

We do not maintain server-side prompt logs. Account data (email, subscription plan, and usage counts) is retained for as long as your account remains active.

Client-side history is stored locally per account with an approximately 1 MB rolling cap and oldest-first eviction. Pinned notes and harvested page text are also account-isolated locally. Optional text-only Snapcopy context is limited to 10 entries, 50 KB total, and a 24-hour lifetime. Signing out ends the session but does not erase that account's on-device history; you can clear locally stored data in the extension or by removing extension data. Snapcopy images are held ephemerally, sent for analysis, attached only to the exact active connected chatbot when possible, and then discarded by Prompt Prober; the destination chatbot may retain the attachment under its own terms. If you choose Save, your browser downloads a copy to your device for manual upload, under your control.

7. Your rights

Under GDPR and international privacy regulations, you have the right to access, export, correct, or permanently delete your personal data.

You can request account deletion from the Account page in your dashboard. Account deletion first attempts to cancel any recurring subscription and stops if cancellation cannot be confirmed or a checkout still needs billing review. After successful processing it permanently removes your email, authentication records, and quota history. Locally stored extension data remains under your browser's control and can be cleared from the extension or by removing its data. You may also contact support@promptprober.com for data portability or privacy assistance.

8. International transfers and age requirement

Our infrastructure and sub-processors may process data in countries outside your own. Their locations and transfer safeguards are governed by their current service and privacy terms.

Prompt Prober is intended for professional and adult users. You must be at least 18 years old to create an account or subscribe. We do not knowingly collect personal data from anyone under 18.

9. Governing law

This Privacy Policy and all associated data handling practices are governed by applicable privacy laws and our commitment to user transparency. Any updates to this policy will be reflected on this page with a revised effective date.