HomeLegal
Security Policy
How we safeguard your prompts and personal data.
Last Updated: March 27, 2026
At PromptifyApp, protecting your data is our highest priority. This policy outlines our technical and organizational security measures.
1. Data Encryption
- In Transit: All communications are encrypted using TLS 1.2 or higher.
- At Rest: User data and account information are encrypted using AES-256 encryption on our cloud infrastructure.
2. AI API and Processing Security
- No Public Model Training: We use enterprise APIs and ensure your prompts are not used to train public AI models.
- Ephemeral Processing: Prompts are discarded after processing unless you explicitly save them to your history.
- Secure Key Management: API keys are managed securely in our backend vault.
3. Infrastructure and Hosting
Our backend is hosted on secure cloud providers with strict physical security and multi-factor authentication for administrative access.
4. Payment Security
Payments are processed by Paddle, our secure Merchant of Record. We do not store credit card details.
5. Browser Extension Security
The extension requests minimal permissions and utilizes your browser's secure Local Storage. Our code is reviewed by the Chrome and Edge web stores.
6. Vulnerability Management
We proactively monitor dependencies, perform regular updates, and conduct peer code reviews to address security threats.
7. Incident Response
We have a protocol in place to notify users within 72 hours of a confirmed data breach and take immediate containment steps.
8. Compliance & Certifications
We deliberately partner with enterprise-tier infrastructure providers. Our core sub-processors maintain rigorous industry security certifications, including SOC 2 Type II and ISO 27001 compliance.
9. Vulnerability Reporting & Responsible Disclosure
We take security seriously. If you believe you have found a vulnerability in PromptifyApp, please report it to us directly. We request that you do not publicly disclose the issue until we have had a reasonable timeframe to investigate and patch it.
10. Contact Us
To report security vulnerabilities, please contact us via our contact form.
