← Back to PromptFast

Privacy Policy

Last updated: 25 February 2026

1. Who we are

PromptFast (“we”, “us”, “our”) operates the website promptfast.dev. We are the data controller for personal data collected through this service. If you have questions about this policy, contact us at info@whiz.hu.

2. What data we collect

Account data (via Google OAuth)

When you sign in with Google, we receive your name, email address, and Google profile picture. We store this in our database to identify your account and personalise your experience.

Usage data

We use Google Analytics 4 to collect anonymised usage statistics — pages visited, session duration, approximate location (country/city level), and device type. IP addresses are anonymised before storage. You can opt out via your browser's privacy settings or a browser extension such as the Google Analytics Opt-out Add-on.

Payment data

Payments are processed by Lemon Squeezy (the Merchant of Record). We never see or store your card details. Lemon Squeezy provides us with your email address and subscription status only.

API keys

API keys you enter (OpenAI, Anthropic, Google) are never sent to our servers. If you choose “Remember on this device”, they are encrypted with AES-GCM using a key derived from your login token and stored in your browser's localStorage. They exist only on your device and are never transmitted to us.

3. How we use your data

  • To authenticate you and maintain your account
  • To track your usage quota (free tier vs. paid subscription)
  • To manage your subscription status via Lemon Squeezy
  • To improve the product through anonymised analytics
  • To send transactional emails (payment receipts, subscription updates) via Lemon Squeezy

We do not sell your personal data. We do not use your data for targeted advertising.

4. Legal basis (GDPR)

Where GDPR applies, we process your data under the following bases:

  • Contract — to provide the service you signed up for
  • Legitimate interests — for anonymised analytics and product improvement
  • Legal obligation — to comply with applicable laws

5. Data retention

We retain your account data for as long as your account is active. You can delete your account at any time from the account settings panel, which permanently removes your data from our systems. Analytics data is retained by Google Analytics per their standard retention policy (default 14 months).

6. Your rights

If you are in the EU or UK, you have the right to access, rectify, erase, or port your personal data, and to object to or restrict processing. To exercise these rights, email us at info@whiz.hu. You also have the right to lodge a complaint with your national data protection authority.

7. Cookies

We do not set first-party cookies beyond what is strictly necessary for authentication. Google Analytics sets cookies for analytics purposes. reCAPTCHA sets cookies for abuse-prevention purposes.

8. Third-party services

9. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects when changes were last made. Continued use of the service after changes constitutes acceptance of the updated policy.