Your prompts. Your data.
Last updated · 21 September 2026
Promptaide is built to be a tool, not a data business. There is no account, no login, and no advertising. We collect as little as possible, we never sell your information, and we explain exactly what we keep below.
The short version
- No account required. The app works without sign-up, and so does this site. There is no login anywhere and we never ask for your name or your contacts. The only detail that names or reaches you is one you typed in yourself: an email you sent us, or an address you gave this site for the launch notice. Online requests also give our servers your IP address. We use it to limit repeated requests, store scrambled forms for the purposes below, and may record it in service error logs. The sections below explain what is kept and for how long.
- Copy events and counts. When a prompt is copied in the app, the app sends us that prompt's identifier — never the text it just put on your clipboard — and we increment the aggregate counter that powers the live leaderboard, and we log one row for that copy holding a keyed, copy-specific hash of the IP address it came from when our server key is configured, so a flood of fake copies can be spotted. Without that key we store no IP hash. Those rows are deleted automatically after 31 days. These records include the prompt identifier and time, and can group copies from the same network address within this period. They contain no account or device identifier.
- Fending off floods. Our server uses the real IP address of a copy, a submission, a report or a launch-notice signup to limit repeated requests — five submissions a day, one report per prompt, and so on. These rate-limit records stay in server memory, not our application database. They can remain after the limit expires, until the same record is reused, the memory store is cleaned up at capacity, or the server process restarts. The scrambled IP values described elsewhere are separate database records. Service error logs may also contain real IP addresses, as explained below.
- Prompts you submit. If you submit a prompt for the library, we store its text so we can moderate and (if approved) publish it. Automated checks may approve or reject a submission; uncertain results are held for human review. If automated classification is unavailable, submissions that pass the local checks are held for a person. We keep the moderation decision and its review history.
- Reports you send. We store the reported prompt's identifier, your selected reason, any note you provide, the time, and a scrambled form of your IP address — or nothing at all in that field, as explained below. These records help us review complaints and detect repeated or abusive reports. The scheduled review job clears report IP hashes after 30 days; report content remains for moderation and removal requests. Please leave personal or sensitive information out of prompts, handles and report notes.
- Your handle, if you give one. The handle on a submission is optional. If you provide one and we publish your prompt, that handle is shown next to it — that is the whole point of it. Leave it blank and the prompt is published with no name attached. Beyond the handle, a submission asks you for nothing: no email, no account. The app does send one more thing with it, described next.
- A random submitter identifier, so people can block you. The first time you submit a prompt, the app creates a random identifier on your device and sends it with each submission. It is not derived from your device, your Apple ID or anything about you, and nothing else the app does sends it. We store a one-way scrambled form of it — never the identifier itself — and publish that scrambled value with your prompt, so that a person who finds a submission abusive can block everything from the same submitter without learning who you are. Deleting the app discards the identifier; a reinstall gets a fresh one. The scrambling uses the same server-side key as our IP addresses when that key is set up, and a plain one-way hash otherwise; either is irreversible, because the identifier is random rather than something that could be guessed.
- Your email, only if you ask for the launch notice. Before launch this site may show a box for one thing: telling you when the app reaches the App Store. Use it and we store your address, the time it arrived, a scrambled form of your IP address — or nothing at all in that field, explained below — and, if the form that sent it says so, which part of the site the box was on. Our form does not send that, so that last field stays empty. One email at launch, then we delete the row by hand. Full detail below.
- Basic diagnostics. Crash and performance data may be collected through Apple's standard, opt-in App Store mechanisms to keep the app stable.
The one email
Before launch, this site may show a box that takes an email address for exactly one purpose: telling you, once, on the day it lands. If no box is configured, launch-notice links open your own mail app instead. Once the app is available, download buttons point to the App Store and the launch-notice form is no longer shown. Giving an address is optional and nothing here depends on it — the prompts, the leaderboard and the copy button behave identically whether you give an address or not. Any such box is on this website only. The iOS app has no launch-notice box and never asks you for an address for one. The app can help you compose a prompt submission, a report or a support message; you choose whether to send it through your own email account.
What we store. If you use it: the address you typed, the time it arrived, a scrambled form of your IP address — or nothing at all in that field, which the next paragraph explains — and, if the form that sent it says so, which part of the site the box was on. Our form does not send that, so that field stays empty. Alongside it we keep a row number and a marker recording whether your one email has gone out yet. That is the whole row: no name, no device identifier, nothing else attached to it.
About that scrambled IP. It is there for one job: if a flood of signups arrives, we can tell afterwards whether they all came from one place. It is not how the form is rate-limited — that check happens in memory, against your real IP address. The signup limit has a one-day window, but its memory record can remain longer, as described under “Fending off floods.” We don't keep your real IP address on the signup row, and the scrambled value is specific to this list: it is deliberately different from the one we log for a prompt copy or a report, so the two cannot be matched up. The scrambling is done with a key that lives on our server and is never written into the database, so the value sitting on the row cannot be turned back into an address by anyone holding a copy of that database. If that key is not set up on the server, we do not quietly fall back to a weaker scramble: the field is left empty. Our servers still receive the real IP address and use it as described above. Either way the value goes when the row goes (see below) rather than being kept around.
No confirmation email. We promise one email, so we don't send a second one asking you to confirm the first. Your address goes straight onto the list — we lower-case it and trim any stray spaces, so a capital letter can't put you on there twice — and the next thing you hear from us is the launch notice itself. If you mistype it, that notice goes to the typo — write to us and we will fix or remove it. Entering the same address twice does not add a second row, and the page says the same thing either way: we don't tell anyone whether an address is already on the list.
What it is never used for. One email at launch, then nothing. No newsletter, no list, no drip sequence, no product updates, no marketing of any kind. We do not sell it, rent it, or hand it to an advertising network, and the only system outside our own database that ever sees it is the one that delivers that single email. It is not a login and it cannot become one.
Getting removed. Email hello@promptaide.app and we delete the row. No questions, no waiting period. Once the launch email has gone out the list has done its only job and we delete it — that is a step we run by hand after launch, not an automatic timer, and we would rather tell you that than let you assume the code does it for us.
How copy works
Promptaide writes a prompt to your clipboard when you tap copy. It does not read your clipboard contents, and copied text never leaves your device through us: the copy count is sent as that prompt's identifier and nothing else. Submitting a prompt is a separate action that sends the text you choose to submit.
Your purchase
The one-time purchase is processed entirely by Apple through the App Store. The U.S. base price is $2.99; local App Store prices may vary. We never see your card details. We receive only the anonymized transaction confirmation Apple provides.
No ads. No selling.
We do not run third-party advertising, we do not sell or rent your data, and we do not build advertising profiles. We do not run a mailing list: the launch notice above is a single send, so there is no sequence to unsubscribe from. What we do use is the handful of service providers described below to run Promptaide, and we may also disclose information where the law requires it.
Where online data goes
Hostinger hosts our website and API, and Neon stores the online library, copy events, submissions, reports and moderation records. Online requests pass through our hosting infrastructure, which receives the request's IP address.
Service error logs may include your real IP address and the requested web address, including search terms in its query string. Our server logs rotate when they reach a size limit, rather than being deleted after a fixed number of days. We do not store a separate search history in our application database.
When automated classification is enabled, we send a submission's title, body, category, selected AI models and optional handle to our automated-moderation provider — Anthropic, or Google Gemini via OpenRouter when that provider is the one configured. This checks community submissions; it does not generate an AI answer for you. When it is not enabled or cannot return a usable result, submissions that pass local checks wait for human review.
We keep weekly moderation summaries for the owner to review. When email delivery is configured, our SMTP email provider delivers a summary containing prompt excerpts, optional handles and moderation information to the designated moderator. That same email provider is the one that delivers the single launch notice, and it is the only system outside our own database that ever sees the address you gave for it. If you contact us by email, our email provider also handles your message and email address.
How long records remain
Scheduled database cleanup removes individual copy events older than 31 days while keeping aggregate copy totals. Weekly cleanup removes rejected prompts older than 90 days and moderation summaries older than 180 days. Deleting a prompt also deletes its associated reports, copy events and moderation log. Used moderation-link records are removed seven days after their links expire.
These deletions depend on the scheduled jobs running. Published, held and hidden prompts, and their associated reports, do not have a fixed automatic deletion period. Database cleanup does not delete delivered emails or records held separately by hosting and email providers. Contact us below to request deletion of a submission or report; include enough information for us to identify it.
The launch-notice list has no automatic deletion timer: we delete it by hand once the single email has gone out, as the launch-email section above says.
Control & deletion
You can request a copy of, or deletion of, any prompt you submitted, ask us to delete the address you gave for the launch notice, or ask any question about your data, by emailing hello@promptaide.app. Because there is no account anywhere, the only things that carry your name or your words are the ones you typed in yourself: a prompt submission, a report, or that email address. There is no account for us to look up either, so include the prompt, report or address details that will help us find the record. We also hold the IP records described above, including raw addresses in server memory and potentially in service error logs. The scrambled IP value on the launch list is deliberately different from the values stored for copies and reports, so those values cannot be matched across those records.
Updates to this policy
If this policy changes materially, we'll update the date above and note the change. Continued use after an update means you accept the revised policy.
21 September 2026. Submissions now require a random submitter identifier, so each new API submission receives a blockable author ID.
20 September 2026. Corrected how long raw IP addresses can remain in rate-limit memory and clarified that service error logs may contain IP addresses and requested web addresses, including search queries. Clarified that leaving an IP-hash field empty does not prevent our servers from receiving the real IP address. These corrections describe existing behavior; they do not add data collection.
14 September 2026. Clarified that the launch-notice form is available before launch, and that email you choose to send from the app may be a submission, report or support message. No change to data collection.
11 September 2026. Added the random submitter identifier the app sends with a submission so that other people can block a submitter, and the one-way scrambled form of it we store and publish. Nothing else changed.
8 September 2026. Clarified that copy events can group activity from the same network address, use a separate keyed hash, and store no IP hash without the server key. Added the 30-day clearing period for report IP hashes.
7 September 2026. No new collection: every addition here describes something the code was already doing. The launch-email section covers the address this site takes when it is showing the launch-notice box. The copy-counts point now says the thing it always should have: a copy is logged with a scrambled form of the IP address it came from, and the row is deleted after 31 days. The submissions point no longer says a person reads everything first — automated checks can publish or reject a submission, and only the uncertain ones wait for a human. And there are new sections for the reports we keep, the service providers involved, and how long each kind of record lasts.
Questions · hello@promptaide.app