BreezyPrompt

Privacy Policy

What BreezyPrompt collects, why, and what it never does with it.

Last updated 30 August 2026

This policy describes how Sisigestate, LLC (“we”), operating BreezyPrompt at breezyprompt.com, handles personal data. We are the data controller for that data. Questions go to contact@breezyprompt.com, or by post to 1111b South Governors Ave STE 28437, Dover, DE 19904, United States.

The short version

What we collect

DataWhy
Name, email address, hashed passwordTo create your account and let you sign in. Passwords are stored hashed and are not recoverable by us.
Session records, including IP address and browser user agentTo keep you signed in, and to detect and stop abuse of the service.
Your content: prompts, titles, descriptions, tags, and their edit historyThis is the service. We store it so you can retrieve it.
Teams you belong to and your role in themTo decide what you are allowed to see and change.
Invitation records: the email address invited, by whom, and to which teamTo deliver the invitation and let the sender withdraw it. If you were invited and never signed up, this is the only data we hold about you, and it is deleted when the invitation expires or is withdrawn.
Counts of how often a prompt has been copiedSo your library can be sorted by what you actually use. It is a number on the prompt, not a log of when you did it.
Server request logsKept briefly by our hosting provider for reliability, security and debugging.

When payments are available, our payment provider will collect what it needs to take a payment. We never see or store your card details.

What we do not do

About IP addresses and browser details

We list these separately because people ask. Every session record keeps the IP address and browser user agent it was created from. This is ordinary for any service with a login, and we use it for exactly two things: keeping you signed in, and telling a person apart from a script so we can throttle abuse.

We do not use it to build a profile of you, to locate you, or to advertise. It is deleted with the session record when you sign out or the session expires, which is 30 days at the latest. Under the GDPR an IP address is personal data and our basis for it is legitimate interests, specifically security and fraud prevention.

Legal bases, where the GDPR applies

We are a United States company, and the GDPR still applies to us in respect of people in the EEA and the UK. For them we rely on: contract, for running an account and storing its content; legitimate interests, for security, abuse prevention and keeping the service working; and legal obligation, for tax and accounting records relating to payments.

Where your data is held

Sisigestate is based in the United States, and our providers operate globally, so data about you is transferred to and stored in the United States and elsewhere. Where data moves out of the EEA or the UK, our providers use Standard Contractual Clauses or an equivalent approved transfer mechanism.

If you are in the United States

State privacy laws, including the California Consumer Privacy Act, give residents of several states rights to know what is collected, to have it deleted, to correct it, and to opt out of its sale or of targeted advertising. Two of those need no request here:

The rights described in Your rights below are offered to everyone, wherever you live, rather than only where a statute compels it. We will not discriminate against you for exercising them.

Who else processes your data

We use a small number of providers to run the service. Each is bound by contract to process data only on our instructions.

ProviderWhat forWhere
CloudflareApplication hosting, CDN, DDoS and abuse protection, request logsGlobal edge network
SupabaseManaged PostgreSQL database holding accounts, prompts and teamsRegion selected for the project
ResendTransactional email: password resets, team invitations, account noticesUnited States and European Union
CreemMerchant of record: payment processing, tax handling, invoicing, refundsEuropean Union (Estonia)

Sharing you choose

Some sharing is under your control, and it is worth being precise about what it means:

How long we keep things

Your rights

Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your data, and to object to it. Three of those need no request at all, and are in Settings: export is a button, deletion is a button, and correction is editing your own prompts.

For anything else, write to contact@breezyprompt.com. We answer within 30 days. If you are in the EEA or the UK and are not satisfied, you may complain to your national data protection authority.

Security

Traffic is encrypted in transit. Passwords are hashed. Access to a prompt is denied by default and granted only by an explicit rule, and a prompt you may not see answers as though it does not exist, so its existence is not revealed. No service can promise perfect security, and we will not pretend otherwise, but we will tell you promptly if something happens that affects you.

Children

BreezyPrompt is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.

Changes

We will update the date at the top when this policy changes. If a change materially affects how we handle your data, we will email you before it takes effect rather than relying on you to notice.

Who we are

Sisigestate, LLC
1111b South Governors Ave STE 28437, Dover, DE 19904, United States
contact@breezyprompt.com