Privacy Policy
Effective Date: September 24, 2025
Last Updated: September 12, 2026
TL;DR: We process your prompts to detect threats. Prompts we store are kept for 24 hours, then automatically anonymized. On the free plan we store only the prompts we block. On a paid plan, contribution starts switched on and covers every request you send, safe and blocked, until you switch it off in the dashboard. We never sell your data. For privacy concerns, use our contact form.
1. What We Collect
We collect what we need to provide the service, protect the network, and see how the website is used:
- Account Info: Email address and password (hashed)
- API Usage: Request counts, response times, and the account a request came from
- Payment: Billing info via Stripe (we don't store card numbers)
- Prompts: Processed in memory. On the free plan we store only prompts we blocked. On a paid plan, if Intelligence Sharing is switched on, which is how an account starts, we store every prompt you send, safe or blocked, for 24 hours
- Blocked Prompts (Phase 1A): Prompt text + client IP stored for 24 hours, then automatically anonymized
- Client IP Addresses: Required for network defense, stored for 24 hours then deleted (a hash of it is kept for 90 days)
- Session Data: Multi-turn validation history, deleted after 2 hours of inactivity and never kept longer than 24 hours
- Attack Patterns: Cryptographic hashes of stored prompts and client IPs, kept for 90 days. These are pseudonymous, not anonymous, so we treat them as personal data and your rights in section 6 cover them
- Website analytics: pages visited on safeprompt.dev, approximate location from IP, browser and device type, through Google Analytics. This is the marketing website only. It is separate from the API, and nothing you send to the API appears in it
- Playground: the playground does not store what you type. It records a hash of the text, a hash of your network address, a session identifier, the length of the text, the result, your browser's user-agent string and abuse signals, so that we can enforce the two-checks-a-day limit and spot abuse. Your text is sent to the inference providers in section 5, the same as an API request
2. How We Use Your Data
- Process your API requests
- Bill you for the service
- Send important account notifications
- Improve our threat detection
- Understand how the marketing website is used
- Comply with legal requirements
Legal basis for each purpose:
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Providing the service and billing you | Contract, Article 6(1)(b) |
| Network defence, including collecting blocked prompts | Legitimate interests, Article 6(1)(f) |
| Collecting every request on a paid plan while Intelligence Sharing is on | Legitimate interests, Article 6(1)(f), with the switch in your dashboard and the right to object in section 6 |
| Website analytics | Legitimate interests, Article 6(1)(f) |
| Meeting legal and tax obligations | Legal obligation, Article 6(1)(c) |
Automated decisions. Deciding whether a prompt is an attack is automated, because that is what the product does. It produces a verdict on a single request and does not make any decision about you as a person, so it is not the kind of automated decision Article 22 restricts.
3. Data Security
We use industry-standard security measures:
- TLS for all API traffic. Always call the https:// endpoint
- Database encrypted at rest with AES-256
- API keys stored as hashes, so nobody can read them back, including us
- Regular security updates
- Limited access controls, with your data scoped by API key and no cross-customer access
Note: We do not hold SOC 2 or ISO 27001 ourselves. Our security page states exactly where we stand, and we would rather you read that than a badge. The third-party services we build on (Supabase, Cloudflare, Stripe) hold their own certifications, which are theirs and not ours.
4. Your Prompts & Threat Intelligence (Phase 1A)
Important: Here's what happens to prompts you send us:
Safe Prompts:
- Analyzed in real-time for threats
- On the free plan: processed in memory, never written to storage
- On a paid plan: stored for 24 hours while Intelligence Sharing is switched on, which is how an account starts. Switch it off in Settings, Privacy and Data Controls and we store nothing
- Never used to train models
Blocked Prompts (Threat Intelligence Collection):
- First 24 hours: Full prompt text + client IP stored for analysis
- After 24 hours: Automatic anonymization - prompt text & IP deleted
- After that: Only cryptographic hashes, kept with the record until it is deleted at 90 days
- Purpose: Network defense intelligence to protect all customers
- Free plan: Contributes blocked prompts automatically. It is a condition of the free plan, and section 6a explains the exchange
- Paid plans (Starter and Business): Contribution starts switched on and covers every request, safe and blocked. Switch it off with the Intelligence Sharing control in Settings, Privacy and Data Controls
Legal Basis: Legitimate interest (network security) on every plan. Contribution on a paid plan starts switched on, so we do not describe it as your consent. The table in section 2 sets out the basis for each purpose, and section 6 sets out your right to object. See our full documentation for technical details.
5. Third-Party Services
Services that receive your prompt text. Validating a prompt means sending it to a language model. These are the companies that process prompt content on our behalf:
- OpenRouter: Routes validation requests to the inference providers below, under our account. Receives the full prompt text.
- Groq, Cloudflare, Together AI, DeepInfra: Inference providers. One of these runs the model for any given request. Receives the full prompt text.
This list is complete and enforced in code: requests are pinned to the providers named above, so a prompt cannot be routed to a provider that is not on this list. Before 17 August 2026, routing fallbacks were enabled and a small fraction of requests may have reached other inference providers available through OpenRouter. We do not permit the providers above to train on your prompts.
Services that do not receive prompt text. These operate the rest of the product:
- Stripe: Payment processing
- Supabase: Database and authentication
- Cloudflare: CDN and DDoS protection (separate from its role as an inference provider above)
- Vercel: API hosting
- Resend: Transactional emails
- Google Analytics: website analytics. It sets identifiers in your browser and records which pages you visit on safeprompt.dev. It never receives prompt content, your API key, or anything you send to the API
5a. Where Your Data Goes
SafePrompt is a US company and our infrastructure is in the United States. Validating a prompt sends it to the inference providers named above, which operate globally, and we do not pin the region for a given request.
If you are in the UK, the EEA or Switzerland, that means your prompt content is transferred outside your region. Each provider processes that content under its own published transfer safeguard, the European Commission's Standard Contractual Clauses or EU-US Data Privacy Framework certification, as set out in that provider's data processing terms. Ask us at [email protected] for a copy of the clauses that apply to your account, and for the current list of providers and the safeguard each one sits under.
If you need your prompts confined to a fixed region, tell us before you integrate. We will tell you whether we can do it for your traffic before you commit to anything.
6. Your Rights (GDPR & CCPA)
You have the following rights:
- Right to Access: View all data we have about you via dashboard or API
- Right to Deletion: Delete all identifiable data (<24h old) immediately via API
- Right to Export: Download all your data in JSON format
- Right to Switch Off Contribution (paid plans): turn off Intelligence Sharing in Settings, Privacy and Data Controls, and we stop collecting from your account
- Right to Rectification: Update your account information
- Right to Object: You can object at any time to our processing of blocked prompts for network defence, whatever plan you are on. Write to [email protected]. We will stop unless we can show compelling grounds that override your interests, and we will tell you which it is within 30 days. On a paid plan you can also switch contribution off yourself in Settings, Privacy and Data Controls, with no need to ask
- Right to Complain: if you are in the UK or the EEA you can complain to your local data protection authority. We would rather you told us first at [email protected], but you do not have to
How to Exercise Your Rights:
- • Via Dashboard: Settings → Privacy → Delete Data / Export Data
- • Via API:
DELETE /api/v1/privacy/deleteorGET /api/v1/privacy/export - • Via Email: Contact form
Note on hashes. After 24 hours we keep only a cryptographic hash of the prompt and of the IP address, until the record is deleted at 90 days. These hashes are pseudonymous, not anonymous, so we treat them as personal data and the rights above cover them. Deletion from the dashboard or the API removes records that still hold prompt text or a raw IP. The hashes that are left stay until their record is deleted at 90 days, and we cannot remove them separately on request.
6a. The Free Plan and Your Data
The free plan is free because blocked prompts from free accounts feed the shared network defence that protects every SafePrompt user. That is the exchange, and we would rather state it plainly than bury it.
What we take: the text of prompts we blocked, and the client IP, for 24 hours, then a hash of each until the record is deleted at 90 days. We never take safe prompts on the free plan, we never sell any of it, and we never use it to train models we sell.
What it is worth: we value this contribution at no more than the retail price of the equivalent paid plan, which is $29 a month, calculated as the price of the lowest paid plan that lets you switch contribution off. In practice it is worth less than that to us, because most accounts block few prompts.
You can leave the programme at any time by upgrading to a paid plan and switching contribution off, or by closing your account and asking us to delete your data. We will not give you a worse service, a smaller quota or a different price for asking.
7. Data Retention (Phase 1A Updated)
| Data Type | Retention Period |
|---|---|
| Session Data | 2 hours of inactivity, 24 hours maximum |
| Prompt Text (blocked) | 24 hours (permanently deleted) |
| Client IP Addresses | 24 hours (permanently deleted) |
| API Logs | 30 days |
| Usage Metrics | 90 days |
| Account Data | While active + 90 days |
| Billing Records | 7 years (legal requirement) |
| Prompt and IP Hashes | 90 days |
Automatic deletion: Background jobs run hourly to delete prompt text and raw IP addresses older than 24 hours. This is mandatory and cannot be disabled (GDPR/CCPA compliance).
What we keep after that, and why it still counts as your data. After 24 hours the prompt text and the raw IP address are permanently deleted. We keep a hash of each until the record itself is deleted at 90 days, because that is what lets us recognise a repeated attack or a repeat abusive source. These hashes are pseudonymous, not anonymous: if you give us a prompt or an IP address we can test whether it matches a stored hash. We therefore treat them as personal data, and they are covered by your rights in section 6. Deleting from the dashboard or the API removes records that still hold prompt text or a raw IP. The hashes that are left stay until their record is deleted at 90 days, and we cannot remove them separately on request.
8. Compliance
We work to the GDPR and CCPA standards that apply to us, and we will answer any specific compliance question at [email protected].
California
If you are a California resident, the CCPA as amended by the CPRA gives you the rights in section 6, and these are the details it asks us to state.
| Category we collect | Where it comes from | Why, and who else sees it |
|---|---|---|
| Identifiers: email address, API key, IP address, session and device identifiers | From you, and from your browser or your integration | To run your account and defend the network. Shared with Supabase, Vercel, Cloudflare and Google Analytics as described in section 5 |
| Commercial information: your plan, invoices and payment status | From you and from Stripe | To bill you and meet tax obligations. Shared with Stripe |
| Internet activity: pages visited on safeprompt.dev, API request metadata | From your browser and your integration | To see how the website is used and to run the service. Shared with Google Analytics for the website only |
| Prompt content, which may contain anything you or your users put in it | From your API requests | To validate the request, and for network defence as described in section 4. Shared with the inference providers in section 5 |
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either
- Sensitive personal information: we do not ask for it. A prompt can contain anything. We use prompt content only to validate the request and to defend the network, which are the uses the CCPA allows without a right to limit
- How long we keep things: the table in section 7
- How to ask: write to [email protected] or use our contact form. We answer within 45 days, and tell you if we need another 45
- How we check it is you: we match the request to the email on the account, and for a deletion we ask you to confirm from that address. If you use an authorised agent, send us written permission signed by you
- No penalty for asking: we will not deny you service, change your price, give you a lower quality of service, or charge you differently because you exercised a right. The free plan's data exchange is described in section 6a, including what it is worth and how to leave it
Nevada
Reboot, Inc. is a Nevada company. We do not sell covered information as Nevada law defines it, and we have no plans to. If you want to make a verified opt-out request anyway, our designated request address is [email protected] and we will respond within 60 days.
Links to Other Sites
Our site links to third-party websites, including Google. We do not control those sites and are not responsible for their privacy practices. Review the privacy policy of any site you visit from ours.
9. Children's Privacy
Our service is not for users under 16. If we learn we've collected data from a child, we'll delete it immediately.
10. Changes to This Policy
We may update this policy as we grow. We'll notify you of significant changes via email or dashboard notification.
11. Contact Us
For any privacy questions or to exercise your rights, please use our contact form.
Company:
Reboot, Inc.
930 S 4th St Ste 209-5981
Las Vegas, NV 89101
United States
Transparency Note: If you have specific compliance requirements or questions, reach out through our contact form and we'll work with you.