Privacy Policy
Last updated September 7, 2026
This policy explains what personal data Prompt Patent (“we”) collects when you use the site, why we collect it, who we share it with, and what you can do about it. We do not sell personal data, and we do not run advertising or third-party analytics trackers.
1. What we collect
Account data
You sign in with GitHub or Google. We receive from them, and store: your name, email address, whether that email is verified, your profile image URL, and the identifier that provider uses for you. We do not receive or store your password. We generate a public username for you at signup, which you can change in Settings.
Content you publish
The prompts you publish — title, description, body, category and optional model hint — along with the timestamps of creation and edits, and their attribution to your account. Published prompts and your profile page are public and may be indexed by search engines. Do not put personal or confidential information in a prompt.
Activity data
- Saves — which prompts you saved to your library, and when. Your library is private to you.
- Copies — a record that a prompt was copied, and when. It is linked to your account if you were signed in, and is anonymous otherwise. This produces the public copy count on a prompt.
- Reports — if you report a prompt, we store the reason you selected, any details you write, and your account, so we can review the report and prevent duplicates.
Session and technical data
When you sign in we create a session and store its token, expiry, and the IP address and browser user-agent it was created from. This is used to keep you signed in and to detect abuse. Our hosting and infrastructure providers also process standard server logs, including IP addresses, as part of delivering and securing the site.
2. Cookies
We use a small number of first-party cookies and no advertising or cross-site tracking cookies:
- Session cookie — set when you sign in, so the site knows who you are. Strictly necessary. Removed when you sign out or when it expires.
- Session cache — a short-lived cached copy of your session (a few minutes) so that every page load does not require a database lookup. Strictly necessary.
- Theme preference — remembers whether you chose light, dark or your system setting, so the correct theme renders without a flash. Functional; it contains no identifier.
Because these are strictly necessary or functional preferences you set yourself, and none are used for tracking or advertising, we do not show a consent banner. You can clear cookies in your browser at any time; clearing the session cookie signs you out.
3. Why we use it, and our legal bases
- To provide the Service — accounts, publishing, libraries, search, attribution. Legal basis: performance of a contract with you.
- To keep the Service safe — moderation, handling reports, preventing abuse, spam and manipulation of counts. Legal basis: our legitimate interests in a safe, working service.
- To measure and improve — aggregate counts of saves and copies to show which prompts are useful. Legal basis: legitimate interests.
- To meet legal obligations — responding to lawful requests and to copyright notices. Legal basis: legal obligation.
4. Who we share it with
We share personal data only with:
- Identity providers (GitHub, Google) — only as part of you signing in. Their own privacy policies apply to what happens on their side.
- Infrastructure providers — our hosting platform and managed database, which process data on our instructions to run the site.
- Authorities or third parties — where we are legally required to, or where it is necessary to establish or defend legal claims or protect someone’s safety.
- A successor — if the Service is merged with or acquired by another organisation, subject to this policy.
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
5. International transfers
Our providers may process data in countries other than yours, including the United States. Where data is transferred out of the UK or European Economic Area, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
6. How long we keep it
- Account data — while your account exists, and deleted with it.
- Published prompts — while published. A deleted prompt is hidden from browsing but retained so that copies already saved by others still resolve and so that its content fingerprint stays claimed, as described in the Terms.
- Sessions — until they expire or you sign out.
- Copies, saves and reports — retained for the integrity of counts and the moderation record. When an account is deleted, copies are de-linked from it and saves are removed.
7. Your rights
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, obtain it in a portable format, object to or restrict processing, and withdraw consent where processing is based on consent. If you are in California, you also have the right not to be discriminated against for exercising these rights; note again that we do not sell or share personal data as those terms are defined there.
You can change your display name and username yourself in Settings, and delete individual prompts from a prompt’s page. For anything else — including deleting your account — write to hello@tidemark.one from the address on your account. We respond within 30 days.
If you are in the UK or EEA and think we have handled your data badly, you can complain to your local data protection authority. We would appreciate the chance to put it right first.
8. Security
Data is transmitted over TLS and stored on managed infrastructure with access limited to those who need it. We hold no passwords, because sign-in is delegated to your identity provider. No system is perfectly secure; if a breach affects your data, we will notify you and the relevant regulator where the law requires it.
9. Children
The Service is not directed to children under 13 (or under 16 where local law sets that threshold), and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy. The “last updated” date above always reflects the current version, and we will give notice on the Service before a material change takes effect.
11. Contact
For privacy questions or to exercise your rights, email hello@tidemark.one.