Last Updated: January 6, 2025
Our Commitment: PromptFence is designed with privacy at its core. We only collect the minimum data necessary to provide security oversight. Prompt content logging is disabled by default and requires administrator opt-in with two-factor authentication.
1. Introduction
This Privacy Policy explains how PromptFence ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our AI security monitoring service.
By using PromptFence, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Organization name: Your company or team name
- Email addresses: Account owner and invited team members
- Account credentials: Authentication tokens (hashed for security)
2.2 Event Data
When the browser extension monitors activity, we collect event data based on your organization's settings. Administrators can choose between metadata-only logging or full prompt capture for compliance and audit purposes:
- Timestamp: When the event occurred
- Website: The AI platform where activity was monitored (e.g., "chat.openai.com")
- User identifier: Which team member triggered the event
- Action type: Type of action monitored (paste, file upload, etc.)
- Policy information: Which blocking rule was triggered
What We DO NOT Collect (by default):
- ❌ Files uploaded to AI platforms
- ❌ Browsing history outside of configured AI platforms
- ❌ Any data from non-AI websites
Optional logging (admin-controlled): Organization administrators may choose to enable encrypted prompt and response logging for compliance purposes. This feature requires two-factor authentication to enable and to view logged content.
2.3 Usage Information
We collect basic usage analytics:
- Provisioned seat counts (for billing purposes)
- Feature usage (which dashboard features are accessed)
- Browser extension version and browser type
2.4 Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers or payment details on our servers. We only receive:
- Subscription status (active, cancelled, past due)
- Billing amount and next billing date
- Last 4 digits of payment method (for display purposes)
2.5 Technical Information
We automatically collect:
- IP addresses (for authentication and security)
- Browser type and version
- Operating system
- Session duration
3. How We Use Your Information
3.1 Service Delivery
- Monitor AI platform usage based on your organization's policies
- Block or warn users when sensitive actions are attempted
- Provide audit logs for compliance and security review
- Authenticate users and validate browser extension tokens
3.2 Billing and Account Management
- Calculate provisioned seats for seat-based pricing
- Process payments through Stripe
- Send billing invoices and payment notifications
- Apply volume discounts based on seat count
3.3 Communication
- Send account-related emails (invitations, password resets, billing)
- Provide customer support and respond to inquiries
- Notify you of service updates or policy changes
3.4 Service Improvement
- Analyze usage patterns to improve features
- Monitor service performance and uptime
- Troubleshoot technical issues
4. Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal data under the following legal bases:
- Contract: To provide the Service you subscribed to
- Legitimate Interests: To improve our Service, prevent fraud, and ensure security
- Consent: For marketing communications (you can opt out anytime)
- Legal Obligation: To comply with applicable laws and regulations
5. Data Sharing and Disclosure
5.1 Third-Party Service Providers
We share data with trusted service providers who help us operate:
Data Residency: All data is stored in US data centers.
These providers are contractually obligated to protect your data and only use it for specified purposes.
5.2 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal process (subpoena, court order)
- Government or regulatory requests
- Protection of our rights, property, or safety
- Investigation of fraud or security issues
5.3 Business Transfers
If PromptFence is acquired, merged, or sold, your information may be transferred to the new entity. We will notify you before such transfer.
5.4 No Selling of Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
6. Data Retention
We retain your data only as long as necessary:
- Event logs: 90 days (automatic deletion)
- Account data: Until account deletion + 30 days
- Billing records: 7 years (legal requirement)
- Session tokens: 7 days of inactivity
See our Data Retention Policy for complete details.
7. Data Security
We implement industry-standard security measures:
- Encryption: TLS 1.3 for data in transit, encryption at rest for databases
- Access controls: Role-based access, multi-factor authentication for admins
- Token security: User tokens are cryptographically hashed
- Infrastructure: Hosted on secure, SOC 2 compliant platforms
- Monitoring: Security monitoring and logging enabled
8. Your Privacy Rights
8.1 Access and Portability
You can access and export your data at any time through the dashboard:
- Export event logs as CSV or JSON
- Download user lists and configuration
- Request a copy of all your data via [email protected]
8.2 Correction and Update
You can update your account information through the dashboard or by contacting support.
8.3 Deletion
You can delete your account at any time:
- Self-service deletion through dashboard settings
- Request deletion via [email protected]
- Complete deletion within 30 days (except legally required billing records)
8.4 Opt-Out of Marketing
You can opt out of marketing emails by clicking "unsubscribe" in any marketing email or contacting support.
8.5 GDPR Rights (EU Users)
If you're in the European Union, you have additional rights:
- Right to access: Request a copy of your personal data
- Right to rectification: Correct inaccurate data
- Right to erasure: Request deletion of your data
- Right to restriction: Limit how we process your data
- Right to portability: Receive your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: For processing based on consent
8.6 CCPA Rights (California Users)
California residents have the right to:
- Know what personal information is collected
- Know if personal information is sold or disclosed
- Opt-out of the sale of personal information (we don't sell data)
- Request deletion of personal information
- Non-discrimination for exercising privacy rights
9. Cookies and Tracking
9.1 Essential Cookies
We use cookies necessary for the Service to function:
- Session authentication tokens
- User preferences and settings
9.2 No Third-Party Tracking
We do not use third-party analytics or advertising cookies. Your browsing activity is not tracked for marketing purposes.
10. Children's Privacy
PromptFence is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we discover such data, it will be deleted immediately.
11. International Data Transfers
Your data may be processed in the United States or other countries where our service providers operate. We ensure appropriate safeguards are in place through:
- Standard contractual clauses approved by the European Commission
- Service providers certified under recognized frameworks
- Encryption and security measures during transfer
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via:
- Email notification to account administrators
- Notice in the dashboard
- Updated "Last Updated" date at the top of this page
Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions, requests, or concerns:
Data Protection Officer
For GDPR-related inquiries, you can contact our Data Protection Officer at [email protected]
EU Representative
If you are in the European Union and wish to exercise your rights or raise a concern, you can also contact your local data protection authority.