Privacy Policy
Last updated: September 17, 2026
1. Introduction
Welcome to PromptGPT.io. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website and tell you about your privacy rights and how the law protects you.
2. Data We Collect
We may collect, use, store and transfer different kinds of personal and technical data about you which we have grouped together as follows:
- Identity Data: First name, last name, username or similar identifier.
- Contact Data: Email address.
- Technical Data: Internet protocol (IP) address, your login data, browser type and version, time zone setting, operating system, and platform.
- Usage Data: Information about how you use our website, products and services.
- Developer & API Credentials: API secret keys (`pgpt_live_...`), cryptographic SHA-256 key hashes, and key prefixes generated to authenticate programmatic requests.
- API Request Logs & Telemetry: Operational metadata regarding API requests, including timestamps, endpoint paths (`/api/v1/*`), HTTP status codes, credits consumed, and processing latency (ms) for developer dashboard inspection and rate limit enforcement.
- B2B Billing & Tax Information: Registered business name, GSTIN (15-digit Tax Identification Number), and registered business billing address provided voluntarily for automated GST tax invoices.
3. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- To provide and maintain the PromptGPT platform and Developer API Gateway.
- To process programmatic requests, monitor credit balances, and enforce per-minute rate limits.
- To generate valid B2B tax invoices and comply with statutory financial regulations (GST).
- To prevent fraud, automated abuse, and enforce our Terms of Service.
4. Developer API Privacy & Zero-Retention Policy
We understand that developers transmit proprietary code, sensitive business context, and confidential prompts through our API. We adhere to strict enterprise data protection standards:
- Zero Model Training: Neither PromptGPT.io nor our upstream enterprise AI providers (e.g., Google Gemini Enterprise) use your API prompts, code snippets, or generated responses to train, tune, or improve artificial intelligence models.
- Ephemeral Processing: Text and visual payloads transmitted to our API endpoints (such as
/api/v1/prompts/optimize and /api/v1/prompts/image-to-prompt) are processed ephemerally in volatile memory. We do not store, archive, or inspect the content of your API prompts once the response has been returned.
- Private Execution Telemetry: Only statistical execution telemetry (e.g., timestamp, endpoint, latency, credit usage) is recorded in your authenticated developer usage logs.
- API Key Confidentiality: Secret keys authenticate API requests on your behalf. We store secret keys securely, and allow developers to view, copy, or instantly revoke any key at any time from the Developer Portal.
5. AI Models & Upstream Infrastructure
Text and image prompts submitted through our web application or Developer API are processed in real-time by secure enterprise API connections with trusted foundational AI providers (such as Google Cloud Vertex AI / Gemini API). All transmissions occur over encrypted HTTPS connections using industry-standard TLS 1.3 encryption.
6. Data Security
We implement robust technical and organizational security measures, including cryptographic hashing (SHA-256), automated rate limiting, atomic database transactions, and restricted server environments to protect against unauthorized access, data alteration, or loss.
7. Contact Us
If you have questions regarding this privacy policy, API data processing, or your developer data, please contact our Data Protection team at support@promptgpt.io.