Legal
Privacy Policy
Effective August 26, 2026
PromptShield reviews prompts in supported AI chats (ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek, and Meta AI) and can also optimize prompts on this website at /try. Cloud optimization requires a signed-in account. Prompt text is processed on our servers when you request optimization but is not stored as optimization history. Guard, Library, History, and personalization are Chrome extension features. Payments go through Stripe.
Overview
This policy describes how PromptShield ("PromptShield," "we," "us") handles information when you use the PromptShield browser extension, the website optimizer at /try, our API, and this marketing website.
The Chrome extension requests host access only for the PromptShield production API and these standalone web chats: ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek (chat.deepseek.com), and Meta AI (meta.ai and www.meta.ai). Host access is used to detect the active prompt composer, read the draft you intentionally ask PromptShield to check, write an improved draft when you choose Use this version, and intercept send only for the existing Guard flow. Use this version does not automatically submit the prompt. PromptShield does not scrape complete conversations. Product analytics do not include prompt text. PromptShield is not affiliated with or endorsed by OpenAI, Anthropic, Google, Perplexity, xAI, DeepSeek, or Meta.
Information you provide
- Email address for account sign-in and verification.
- Feedback you submit (message, optional reply email, extension version).
- Support emails you send to support@usepromptshield.com.
Website analytics
This marketing website uses first-party, anonymous analytics so we can understand how people find PromptShield, whether they click install-intent buttons (for example “Add to Chrome — Free”), copy the Chrome Web Store install link on a phone, or use the website optimizer at /try. This is not advertising measurement, and a website click is not an extension installation. We do not collect an email address for the phone copy-link action or for /try funnel events.
We may record:
- A random anonymous visitor identifier in a first-party cookie (
ps_vid), not derived from a fingerprint. - A first-party first-touch cookie (
ps_ft) that stores only source, medium, campaign, referring hostname, and landing pathname so later page views do not overwrite how you first arrived. - Page pathnames you visit on this website (for example
/,/pricing, or/try), without unrelated query strings. - Clicks on install-intent calls to action, including whether the button pointed at our download page or the Chrome Web Store listing. On phones, we may also record that you copied the install link. That event does not include an email address or other personal information.
- Anonymous
/tryfunnel events such as opening/try, tapping Optimize a prompt now, starting or completing website sign-in, requesting an optimization, success or failure, reaching the Free daily limit, copying the result, or opening ChatGPT. These events do not include prompt text, optimized prompt text, email addresses, verification codes, or authentication tokens. - UTM source, medium, and campaign when those parameters are present in the link you used.
- The referring website’s hostname only (for example
reddit.com), never the full referring URL. - The landing pathname of your first visit.
We do not collect the following for website acquisition analytics:
- Prompt text, optimized prompt text, ChatGPT conversations, or other product content from the extension or
/try. - Email addresses or names (those are only collected if you create an account or contact us separately).
- Browser fingerprints, advertising IDs, or third-party analytics / advertising pixels.
We do not sell this analytics data. IP addresses may be hashed and stored temporarily in rate-limit records to stop abuse across servers; they are not stored in marketing analytics records. User-agent strings may be inspected in memory to ignore obvious bots and are not stored. Analytics event records are kept for about 24 months, then may be deleted or reduced to aggregates.
You can clear site cookies in your browser to reset the anonymous identifier. Contact support@usepromptshield.com if you have questions about this data.
Extension product analytics
PromptShield may collect first-party product-usage events from the browser extension so we can understand feature usage, reliability, and activation, and improve the product. This is first-party product analytics, not advertising measurement. These anonymous product-usage events use a randomly generated, pseudonymous product analytics identifier.
We may record:
- A randomly generated, pseudonymous product analytics identifier stored only on your device (
promptshield:product-anon-id.v1). It is generated locally, is not derived from a fingerprint, and is not the same as your account install id or the website visitor cookie. PromptShield does not link this identifier to your email, account identity, Stripe/customer identity, or the website visitor identifierps_vid. - Event names such as starting onboarding, opening Quick Check, a successful optimized result being shown, applying an optimized prompt into the composer, opening the Pro page, starting checkout, and Pro becoming active on this install.
- The extension version and, when applicable, a short allowlisted site identifier such as chatgpt.
We do not collect the following for extension product analytics:
- Original prompt text, optimized prompt text, prompt previews, or prompt hashes.
- Email addresses, account IDs, authentication tokens, or Stripe / customer IDs.
- The website visitor identifier (
ps_vid), UTM parameters, or full page URLs. - Keystrokes, Library, History, or other prompt content stored on your device.
PromptShield does not link this randomly generated, pseudonymous product analytics identifier to email, account identity, Stripe/customer identity, or website ps_vid. We do not use product analytics for advertising. We do not sell this analytics data. IP addresses may be used briefly in memory to rate-limit abuse; they are not stored in product analytics records. User-agent strings may be inspected in memory to ignore obvious bots and are not stored. We intend to retain product analytics event records for about 24 months. There is no automated purge that deletes records at a fixed 24-month date, so records may be kept longer until they are deleted or reduced to aggregates.
Prompt processing
A PromptShield account with verified sign-in is required to use cloud prompt optimization, including from the Chrome extension and from this website at /try. The website and the extension use the same PromptShield cloud optimizer. Free accounts receive 3 successful optimizations per local day in total across the website and the extension for the same account; PromptShield Pro is $7.99/month for unlimited optimizations under the existing account entitlement.
When you request cloud optimization, PromptShield sends the prompt to our API over HTTPS so our configured AI provider can generate an optimized prompt. The browser does not call model providers directly — provider credentials remain on PromptShield servers.
On the Chrome extension, that request is made after you are signed in. On the website /try page, an optimization is sent only after you authenticate with an email sign-in code. Website /try does not run the extension's local Guard preflight. Prompts submitted through /try are sent to PromptShield's backend and AI provider for optimization; they do not stay entirely on your device.
Prompt text is processed to fulfill your request and is not stored on PromptShield servers as optimization history under our current database schema. If the cloud optimizer is unavailable, PromptShield shows an unavailable or error state. It does not silently rewrite your prompt locally.
Guard & attachments
Guard is a Chrome extension feature. On supported AI chats, Guard may inspect image attachments locally on your device using OCR to flag potentially sensitive text before you send. Attached images are not uploaded to PromptShield servers for OCR. OCR stays on your device.
The website optimizer at /try does not run Guard, does not inspect chat attachments, and does not provide Guard protection. Do not treat a /try optimization as a privacy scan of what you later paste into an AI chat.
Data on your device
By default, the following stay in your browser unless you choose to share them in support or feedback:
- Saved prompts (Library)
- Optimization History
- Personalization preferences
- Settings and onboarding progress
- A randomly generated, pseudonymous product analytics identifier used only for anonymous usage events
- Free-plan usage counts
- Signed-in session tokens for account features
Accounts
Sign-in is required for cloud prompt optimization on Free and Pro, whether you use the Chrome extension or the website /try page. We link your verified email to an account so usage limits, Pro access, and entitlements can be restored after reinstall. Authentication uses verification codes and rotating session tokens stored securely on our servers. Website /try sign-in uses first-party cookies on this site; it does not create a Chrome extension installation.
Billing
Stripe processes subscriptions and payment cards. We store subscription status and Stripe references — not full card numbers.
Retention
Local usage records may be trimmed over time on your device. We intend to retain anonymous website acquisition events and anonymous extension product-usage events for about 24 months. We do not currently run an automated job that deletes these records at a fixed 24-month date. Account and billing records may be kept for reconciliation, fraud prevention, and legal obligations. Deletion requests are handled per our support process.
Your choices
Email support@usepromptshield.com to ask about your data or request account deletion. Uninstalling the extension removes local data from that browser profile.
Contact
PromptShield — support@usepromptshield.com
Local browser storage (Chrome extension) may include:
promptshield:optimization-quota.v1— daily usage and plan snapshotpromptshield:account-session.v1— account session for billing sync- Library, History, personalization, and settings keys as described in extension documentation
Server-side records may include users, installations, Stripe customer ids, subscription state, webhook event ids, verification tokens, anonymous website acquisition events (visitor id, event type, pathname, UTM fields, referring hostname, landing path, and CTA destination, including anonymous /try funnel event names), website /try session records, and anonymous extension product-usage events (a separate randomly generated, pseudonymous product analytics identifier, event type, extension version, and allowlisted site identifier). Marketing and product analytics do not store IP addresses, user-agents, emails, prompt text, optimized prompt text, or prompt hashes. See the Security page for a plain-language overview.
Questions? Contact support · support@usepromptshield.com