Privacy Policy

Built to keep your creative work in your hands.

Last updated: July 26, 2026

HyperPrompt runs in your browser. Provider API keys are stored only on your device and used directly to authenticate requests to the AI provider you configure. A model request can include the content you choose, the active rule and model settings. Signing in is optional and is used for account, Pro license and cloud sync features.

1. Data flow at a glance

Where What is handled there Why
Your device Provider keys, local history, personal rules and extension settings. To run HyperPrompt. Provider keys are stored in local Chrome extension storage and are never uploaded to HyperPrompt.
Chrome Sync Selected non-sensitive extension preferences, when you enable Chrome Sync. To preserve compatible browser preferences across your Chrome profile. Provider keys are excluded.
Your AI provider The content you choose to process, the active rule, model settings and the provider API key used to authenticate that request. To create reverse prompts, expansions, translations or other requested results. Your provider's terms and privacy policy apply.
Supabase Account email, basic profile information when Google sign-in is used, license status, device record, and—only for Pro users—synced history, rules and system settings. To provide sign-in, Pro entitlement and cloud sync. Free accounts do not upload creative content for HyperPrompt cloud sync.
Creem Checkout and payment information when purchases become available. Creem processes the payment as merchant of record. HyperPrompt does not receive or store card details.

2. Data stored on your device

3. Content you choose to process

4. Account and cloud-sync data

5. Payments

When checkout is live, Creem processes purchases as merchant of record and sends purchase event data to our backend. That event can include order, customer, product and metadata fields. We process and retain only the fields needed to activate, maintain or revoke a Pro entitlement. We do not receive or store your payment-card details.

6. What we do not do

7. Retention, export and deletion

8. Security and Google user data

9. Children

HyperPrompt is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data, contact support@hyperprompt.dev so we can investigate and delete it where required.

10. Changes and contact

We will update this policy and its date when material practices change. For privacy questions, contact support@hyperprompt.dev.