1. Data controller
Angelo Pampaluna, operator of the Prompt.Lab project.
Contact for information and privacy requests: prompt.labassistance@gmail.com.
2. Data we process
Prompt and selected platform
The text you enter and the platform you select are sent to the OpenAI API only to generate the optimized prompt. Prompt.Lab does not store the original or generated prompt in its database.
Account
To register and sign in, we process your email address, account identifier, and technical session data. Authentication is managed by Supabase. Prompt.Lab does not receive or store your password in plain text.
Technical data for the free limit
To provide one trial without an account and count it correctly after registration, the browser receives a random technical identifier. The server may also use the IP address and user agent to transfer any previous use to the new identifier. These details are not stored in plain text. After sign-in, the account identifier is also converted into a daily cryptographic code. These codes allow one use without an account and an overall maximum of three optimizations per day. Individual usage counts are deleted when the day changes.
Aggregate statistics
We retain aggregate daily totals for requests, successes, failures, and limit hits. They contain no prompts or visitor identifiers and are kept for up to 24 months to evaluate how the beta performs.
Traffic and performance analytics
Cloudflare Web Analytics provides aggregate page-view, visit, and performance measurements. According to Cloudflare, it does not use analytics cookies or collect visitors’ personal data. These statistics help us understand whether the beta is useful and keep the site fast and reliable.
Email communications
If you contact us, we process your email address, message content, and any information you choose to provide so we can respond and handle your request.
Subscription and payment data
If you choose Prompt.Lab Pro, Stripe processes your payment details. Prompt.Lab does not receive or store your complete card number. We store the account identifier, Stripe customer and subscription identifiers, selected price, subscription status, renewal date, cancellation state, and monthly usage count so we can provide and manage Pro access.
3. Purposes and legal bases
- provide the requested optimization and operate the beta, based on performance of the requested service;
- process and administer a Pro subscription, provide paid features, and maintain transaction records, based on performance of the contract and applicable legal obligations;
- apply the daily limit, prevent abuse, and protect the service, based on the legitimate interest in the platform’s security and sustainability;
- respond to communications and comply with legal obligations where applicable.
4. Providers and international transfers
Data may be processed by technical providers required to deliver the service: OpenAI for text generation and Sites hosting, Cloudflare for infrastructure, the usage-count database, and privacy-first web analytics, Supabase for registration and authentication, Stripe for checkout, recurring billing, invoices, and subscription management, and Google if you email the contact address. These providers operate under their own terms and privacy policies and may process data outside the European Economic Area using mechanisms permitted by applicable law.
According to OpenAI’s documentation, data sent through the API is not used to train models unless the customer explicitly opts in. Prompts and responses may appear in abuse-monitoring logs, normally retained for up to 30 days, subject to legal or security exceptions.
OpenAI data controls ↗Cloudflare Privacy ↗Supabase Privacy ↗Stripe Privacy ↗Google Privacy ↗
5. Cookies and tracking
Prompt.Lab does not use advertising cookies, profiling, or marketing analytics. Cloudflare Web Analytics measures aggregate visits and performance without analytics cookies. Prompt.Lab uses one strictly necessary technical cookie to keep the free-trial count stable and connect it to the account after registration. The cookie contains only a random identifier, not the prompt. The browser also stores the Supabase session data needed to keep you signed in. The infrastructure may use additional technical mechanisms required for security, operation, and site delivery.
6. Automated decisions
The counter automatically blocks further requests after the applicable Free daily limit or Pro monthly limit. Stripe and payment providers may apply automated fraud-prevention checks to transactions. AI-generated content is a suggestion and must be reviewed by the user.
7. Your rights
You may request access, correction, deletion, restriction, or objection where provided by Articles 15–22 GDPR by writing to prompt.labassistance@gmail.com. For account-related requests, write from the associated email address. The daily usage codes cannot by themselves be used to reconstruct an IP address, email address, or user identifier.
You may also lodge a complaint with the Italian Data Protection Authority.
8. Security and changes
We use reasonable data-minimization and security measures, but no online system can guarantee absolute protection. This policy may be updated if features, providers, or applicable rules change. The date shown above identifies the current revision.