This policy describes how Sisigestate, LLC (“we”), operating BreezyPrompt at breezyprompt.com, handles personal data. We are the data controller for that data. Questions go to contact@breezyprompt.com, or by post to 1111b South Governors Ave STE 28437, Dover, DE 19904, United States.
The short version
- Your prompts are never used to train AI models by us, and we do not give them to anybody else. We do not sell data, and we run no advertising.
- We run no analytics and set no tracking cookies. The only cookie is the one that keeps you signed in.
- You can export everything you have written, at any time, as JSON, without asking us.
What we collect
| Data | Why |
|---|---|
| Name, email address, hashed password | To create your account and let you sign in. Passwords are stored hashed and are not recoverable by us. |
| Session records, including IP address and browser user agent | To keep you signed in, and to detect and stop abuse of the service. |
| Your content: prompts, titles, descriptions, tags, and their edit history | This is the service. We store it so you can retrieve it. |
| Teams you belong to and your role in them | To decide what you are allowed to see and change. |
| Invitation records: the email address invited, by whom, and to which team | To deliver the invitation and let the sender withdraw it. If you were invited and never signed up, this is the only data we hold about you, and it is deleted when the invitation expires or is withdrawn. |
| Counts of how often a prompt has been copied | So your library can be sorted by what you actually use. It is a number on the prompt, not a log of when you did it. |
| Server request logs | Kept briefly by our hosting provider for reliability, security and debugging. |
When payments are available, our payment provider will collect what it needs to take a payment. We never see or store your card details.
What we do not do
- We do not train AI models on your prompts, and we do not sell or hand them to anybody who might. Your prompts are never on a publicly crawlable page: everything in a library sits behind a sign-in, and share links are unlisted and excluded from search.
- We do not sell, rent or trade personal data.
- We do not use advertising, analytics or tracking cookies.
- We do not read your prompts, except where you have explicitly asked us for support and shared them with us, or where we are legally compelled to.
About IP addresses and browser details
We list these separately because people ask. Every session record keeps the IP address and browser user agent it was created from. This is ordinary for any service with a login, and we use it for exactly two things: keeping you signed in, and telling a person apart from a script so we can throttle abuse.
We do not use it to build a profile of you, to locate you, or to advertise. It is deleted with the session record when you sign out or the session expires, which is 30 days at the latest. Under the GDPR an IP address is personal data and our basis for it is legitimate interests, specifically security and fraud prevention.
Legal bases, where the GDPR applies
We are a United States company, and the GDPR still applies to us in respect of people in the EEA and the UK. For them we rely on: contract, for running an account and storing its content; legitimate interests, for security, abuse prevention and keeping the service working; and legal obligation, for tax and accounting records relating to payments.
Where your data is held
Sisigestate is based in the United States, and our providers operate globally, so data about you is transferred to and stored in the United States and elsewhere. Where data moves out of the EEA or the UK, our providers use Standard Contractual Clauses or an equivalent approved transfer mechanism.
If you are in the United States
State privacy laws, including the California Consumer Privacy Act, give residents of several states rights to know what is collected, to have it deleted, to correct it, and to opt out of its sale or of targeted advertising. Two of those need no request here:
- We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of, and no “Do Not Sell” mechanism is needed because the answer is already no.
- We do not use it for targeted advertising, or for automated decisions with a legal effect on you.
The rights described in Your rights below are offered to everyone, wherever you live, rather than only where a statute compels it. We will not discriminate against you for exercising them.
Who else processes your data
We use a small number of providers to run the service. Each is bound by contract to process data only on our instructions.
| Provider | What for | Where |
|---|---|---|
| Cloudflare | Application hosting, CDN, DDoS and abuse protection, request logs | Global edge network |
| Supabase | Managed PostgreSQL database holding accounts, prompts and teams | Region selected for the project |
| Resend | Transactional email: password resets, team invitations, account notices | United States and European Union |
| Creem | Merchant of record: payment processing, tax handling, invoicing, refunds | European Union (Estonia) |
Sharing you choose
Some sharing is under your control, and it is worth being precise about what it means:
- Team prompts are visible to every member of that team. Your personal prompts are not, unless you share them into a team deliberately.
- Public links are unlisted rather than published: anyone holding the link can read that prompt without signing in, and the link cannot be guessed. Unpublishing kills it immediately, and resetting the link revokes the old one.
- Invitations reveal your name and the team name to the address you invite.
How long we keep things
- Deleting a prompt moves it to your trash, where it stays until you empty it. This is deliberate, so a mistake is recoverable, but it does mean a deleted prompt still exists until you purge it.
- Edit history keeps up to 30 previous versions of each prompt. Rewriting a prompt does not erase what it said before; permanently deleting the prompt removes its history with it.
- You can delete your account yourself, from Settings, and it happens immediately. Your prompts, your sessions, your login records and any teams you are the only member of go with it.
- Work inside a team you share with other people stays with that team. Those prompts belong to everybody in it, so your leaving cannot remove them. If you are the only owner of such a team, we ask you to hand it over before deleting, rather than quietly taking it down with you.
- Payment and invoice records are kept as long as tax law requires, typically several years, even after an account is deleted.
Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your data, and to object to it. Three of those need no request at all, and are in Settings: export is a button, deletion is a button, and correction is editing your own prompts.
For anything else, write to contact@breezyprompt.com. We answer within 30 days. If you are in the EEA or the UK and are not satisfied, you may complain to your national data protection authority.
Security
Traffic is encrypted in transit. Passwords are hashed. Access to a prompt is denied by default and granted only by an explicit rule, and a prompt you may not see answers as though it does not exist, so its existence is not revealed. No service can promise perfect security, and we will not pretend otherwise, but we will tell you promptly if something happens that affects you.
Children
BreezyPrompt is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
Changes
We will update the date at the top when this policy changes. If a change materially affects how we handle your data, we will email you before it takes effect rather than relying on you to notice.
Who we are
Sisigestate, LLC
1111b South Governors Ave STE 28437, Dover, DE 19904, United States
contact@breezyprompt.com