Prompted OS

Privacy Policy

Last updated: November 21, 2025

Prompted OS ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered marketing platform for Shopify store owners at promptedos.com.

1. Information We Collect

Account Information

  • Email address
  • Name (if provided)
  • Profile information from authentication provider (Clerk)
  • Subscription and billing information

Connected Platform Data

When you connect third-party platforms, we access:

  • Facebook: Ad account information, page data, and campaign management access
  • Google: Calendar, Docs, Sheets, and Drive access for integrations
  • Shopify: Store data, product information, and blog content

Usage Data

  • AI tool usage and generated content
  • Uploaded files and media
  • Feature usage patterns
  • API usage metrics

2. How We Use Your Information

  • To provide and maintain our AI-powered marketing services
  • To process your transactions and manage your subscription
  • To connect and interact with your authorized third-party platforms
  • To generate personalized marketing content using AI models
  • To improve our services and develop new features
  • To communicate with you about your account and our services
  • To comply with legal obligations

3. Data Storage & Security

We take data security seriously and implement industry-standard measures to protect your information:

  • Encrypted Storage: API keys and OAuth tokens are stored using Supabase Vault with encryption at rest
  • Secure Transmission: All data is transmitted over HTTPS/TLS
  • Access Controls: Row-level security (RLS) ensures users can only access their own data
  • Authentication: Clerk provides secure user authentication with industry-standard protocols

4. Third-Party Services

We integrate with and share data with the following third-party services:

  • AI Providers: OpenAI and Anthropic for AI content generation
  • Authentication: Clerk for secure user authentication
  • Payments: Stripe for subscription and payment processing
  • Database: Supabase for data storage and file hosting
  • Platform Integrations: Facebook, Google, and Shopify APIs
  • Web Scraping: FireCrawl for URL content extraction

5. Data Retention

  • Account Data: Retained while your account is active
  • Generated Content: Stored for 48 hours in browser cache, permanently in files if saved
  • URL Extractions: Cached for 6 hours to reduce API costs
  • Usage Logs: Retained for 90 days for analytics and billing purposes
  • Connected Platform Tokens: Deleted immediately when you disconnect a platform

6. Your Rights

Depending on your location, you may have the following rights under GDPR, CCPA, and other privacy laws:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Request your data in a portable format
  • Restriction: Request limitation of data processing
  • Objection: Object to certain data processing activities
  • Withdraw Consent: Withdraw previously given consent

To exercise these rights, please use the contact form on our website.

7. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information held by businesses
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising your CCPA rights

We do not sell your personal information.

8. Children's Privacy

Our services are not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

10. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us through our website at promptedos.com