Effective Date: January 8, 2026 | Last Updated: January 8, 2026
At Proompi, we transform your ideas into expert AI prompts while maintaining the highest standards of privacy protection. This Privacy Policy explains how we collect, use, protect, and share your information in compliance with global privacy regulations including GDPR and CCPA.
What we collect and why
Access, correct, delete your data
How we protect your information
Reach our privacy team
We collect information to provide our AI prompt enhancement services effectively while maintaining transparency about our data practices.
Email addresses, usernames, and account information necessary for service delivery and account management.
GDPR Article 13Text inputs, generated prompts, and improvement suggestions to enhance our AI models and provide personalized experiences.
Business DataSession data, feature interactions, and performance metrics to optimize user experience and platform functionality.
Legitimate InterestIP addresses, browser data, device information, and cookies for security, analytics, and service optimization.
CCPA CategoriesGDPR emphasizes data transparency and requires clear information regarding data practices. We process your data based on:
| Purpose | Legal Basis (GDPR) | CCPA Category |
|---|---|---|
| Service Delivery - Prompt enhancement, account management | Contract Performance | Commercial Information |
| AI Model Improvement - Training and optimization | Legitimate Interest | Inferences |
| Security & Fraud Prevention - Platform protection | Legitimate Interest | Identifiers |
| Analytics & Optimization - Performance analysis | Legitimate Interest | Internet Activity |
AI Processing Transparency: CCPA 2025 includes identifiers, commercial information, internet activity, and inferences drawn from personal data, with sensitive personal information requiring separate disclosure.
Global Privacy Rights Protection
Enhanced right-to-know provisions extend data access windows, allowing consumers to request historical data back to January 2022
Request corrections to personal information we maintain about you
Request businesses delete personal information they collected from you, with some exceptions if legally required to keep the information
Businesses must implement means for consumers to confirm opt-out status, including displaying that Global Privacy Control signals are being honored
Receive your data in a structured, machine-readable format for transfer
Exercise Your Rights: Businesses must confirm receipt within 10 business days and respond within 45 calendar days (extendable to 90 days). Email us at hi@proompi.com or use our data request portal.
Account Data
Retained while account is active plus 3 years for legal compliance
Prompt Content
2 years for AI model training and service improvement
Analytics Data
26 months for performance optimization and insights
Security Logs
1 year for fraud prevention and system security
GDPR requires organizations to notify authorities within 72 hours of a data breach and maintain comprehensive incident response plans.
Encryption
AES-256 encryption for data at rest and TLS 1.3 for data in transit
Access Controls
Role-based permissions with multi-factor authentication
Infrastructure
SOC 2 Type II certified cloud providers with EU data centers
Monitoring
24/7 security monitoring with automated threat detection
Cookies that collect personal data are subject to GDPR and require explicit consent with clear information about purposes and opt-in/out options.
| Cookie Type | Purpose | Duration | Legal Basis |
|---|---|---|---|
| Essential | Authentication, security, basic functionality | Session | Necessity |
| Analytics | Usage patterns, performance optimization | 24 months | Consent |
| Preferences | User settings, language, customization | 12 months | Consent |
Cookie Management: You can manage cookie preferences through your browser settings or our cookie preference center. Essential cookies cannot be disabled as they're necessary for service functionality.
Updated CCPA regulations require disclosure of personal information categories disclosed to service providers and contractors in the preceding 12 months.
Cloud Infrastructure
AWS (EU regions) - Hosting and data processing
AI Services
Anthropic & OpenAI (USA) - AI prompt enhancement and image generation (with SCC)
Analytics
Privacy-focused analytics tools - Usage insights
Payment Processing
Stripe - Subscription and payment handling
International Data Transfers: GDPR imposes strict requirements for international transfers, requiring Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). We ensure adequate protection through EU Standard Contractual Clauses for non-EU transfers, adequacy decisions where available, and additional safeguards including encryption and access controls.
No Data Sales: We do not sell personal information to third parties. We may share data with service providers under strict contractual obligations for business purposes only.
CCPA 2025 revisions include personal information of consumers under age 16 as sensitive personal information. Our services are not directed to individuals under 16 years of age.
When you use the image generation feature:
CCPA revisions take effect with new obligations for automated decision-making technology, cybersecurity audits, and risk assessments.
For questions about data processing or to exercise your rights:
Mailing Address:
ENGIT Sp. z o.o.
ul. Stefana Jaracza 39
33-100 Tarnow, Poland
KRS: 0001109234
NIP: 8733296963
REGON: 528839231
Supervisory Authority: You have the right to lodge a complaint with UODO (Polish Data Protection Authority) or your local supervisory authority.
Last Updated: January 8, 2026 | Version 2.1