HyperPrompt runs in your browser. Provider API keys are stored only on your device and used directly to authenticate requests to the AI provider you configure. A model request can include the content you choose, the active rule and model settings. Signing in is optional and is used for account, Pro license and cloud sync features.
1. Data flow at a glance
| Where | What is handled there | Why |
|---|---|---|
| Your device | Provider keys, local history, personal rules and extension settings. | To run HyperPrompt. Provider keys are stored in local Chrome extension storage and are never uploaded to HyperPrompt. |
| Chrome Sync | Selected non-sensitive extension preferences, when you enable Chrome Sync. | To preserve compatible browser preferences across your Chrome profile. Provider keys are excluded. |
| Your AI provider | The content you choose to process, the active rule, model settings and the provider API key used to authenticate that request. | To create reverse prompts, expansions, translations or other requested results. Your provider's terms and privacy policy apply. |
| Supabase | Account email, basic profile information when Google sign-in is used, license status, device record, and—only for Pro users—synced history, rules and system settings. | To provide sign-in, Pro entitlement and cloud sync. Free accounts do not upload creative content for HyperPrompt cloud sync. |
| Creem | Checkout and payment information when purchases become available. | Creem processes the payment as merchant of record. HyperPrompt does not receive or store card details. |
2. Data stored on your device
- API keys and provider credentials you configure are stored locally in Chrome extension storage. They are sent only to the provider you choose for a request.
- Your local prompt history and personal rules stay on your device unless you choose to sign in and use Pro cloud sync.
- Some non-sensitive preferences may use Chrome Sync when it is enabled. Provider keys are not included.
3. Content you choose to process
- HyperPrompt detects supported image and video elements on pages where the extension runs so it can offer its controls. It does not automatically send page content to HyperPrompt or to a model provider; provider requests occur only when you invoke a feature.
- A model request can also include the active rule, model settings and your provider API key for authentication.
- When you save a result, its history item can include the reference thumbnail, prompt, page title and source URL or path needed to help you recognise and reuse that reference later.
- That request goes directly from your browser to the AI provider you configured. We do not proxy provider requests through HyperPrompt servers.
4. Account and cloud-sync data
- You can sign in with Google or an email code. Google sign-in provides your email address and basic profile; email sign-in uses the address you enter and a one-time code. Both methods create a Supabase session so we can identify your account and Pro entitlement.
- For Pro users, cloud sync can store history items, rules, system settings, a random device identifier and last-seen information. This keeps up to five signed-in devices consistent.
- Cloud history is provided at fair use: up to 150 MiB or 7,500 active history items per Pro account, whichever comes first. Local history is not counted against that cloud allowance.
5. Payments
When checkout is live, Creem processes purchases as merchant of record and sends purchase event data to our backend. That event can include order, customer, product and metadata fields. We process and retain only the fields needed to activate, maintain or revoke a Pro entitlement. We do not receive or store your payment-card details.
6. What we do not do
- No advertising, tracking pixels, analytics SDKs or sale of personal data.
- No human review of your synced creative content unless you explicitly ask us to inspect it for support, or disclosure is required for security or by law.
- No upload of your provider API keys to HyperPrompt.
7. Retention, export and deletion
- You can manage local data in the extension and export your data from settings.
- Signed-in users can delete their account and cloud account data directly in the extension (Settings → Account → Delete account, with double confirmation). You can also request deletion by emailing support@hyperprompt.dev from your account email; we target completion within 30 days unless retention is required by law or for a legitimate security or fraud-prevention need.
8. Security and Google user data
- Communication with our backend and payment provider uses HTTPS. Remote image fetching is validated for protocol, content type and size, and is sent without cookies or credentials. An image address on a non-loopback private network is refused, and if a redirect ends on one its content is discarded rather than read; loopback addresses such as localhost are allowed to support configured local services.
- HyperPrompt's use of information received from Google APIs follows the Chrome Web Store User Data Policy, including its Limited Use requirements. Google account information is used only for the account and license features described here.
9. Children
HyperPrompt is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data, contact support@hyperprompt.dev so we can investigate and delete it where required.
10. Changes and contact
We will update this policy and its date when material practices change. For privacy questions, contact support@hyperprompt.dev.