Privacy Policy
How we protect your data
Last Updated: January 2026
Introduction
PromptHub is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our service.
Data We Collect
We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support.
- Account information (name, email, password)
- Usage data and service interactions
- Technical data (IP address, browser type, device information)
- Prompts and content you create within the service
How We Use Your Data
We use your information to:
- Provide and improve our services
- Communicate with you about your account
- Ensure security and prevent fraud
- Comply with legal obligations
Data Storage & Security
All data is stored in EU-based data centers. We implement industry-standard security measures including encryption, access controls, and regular security audits.
Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Data portability
- Object to processing
Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account data: Retained for the duration of your account plus 30 days after deletion request
- Prompts and content: Retained for the duration of your account, deleted within 30 days of account closure
- Usage logs and analytics: 12 months from collection date
- Support tickets and communications: 3 years for legal compliance
- Security logs and audit trails: 2 years as required by ISO 27001
- Marketing preferences: Until consent is withdrawn
Sub-Processors & Third Parties
We work with trusted third-party service providers to deliver our services. All sub-processors are contractually bound to GDPR-compliant data processing agreements:
- Hetzner Cloud (Germany) - Infrastructure hosting and data storage
- SendGrid/Brevo - Transactional email delivery
- Microsoft Entra ID - Enterprise authentication (optional)
- Cloudflare Analytics - Privacy-focused web analytics
- Google reCAPTCHA - Bot protection (minimal data transfer)
- AI model providers - Prompt processing (data not stored by providers)
All data remains within the European Economic Area (EEA). No personal data is transferred outside the EU without adequate safeguards.
Legal Basis for Processing
We process your personal data under the following legal bases as defined by GDPR Article 6:
- Contract Performance: Processing necessary to provide our services to you
- Consent: For marketing communications and optional features
- Legitimate Interest: For security, fraud prevention, and service improvement
- Legal Obligation: For compliance with applicable laws and regulations
Cookies
We use essential cookies to ensure our website functions properly. For more information, please see our Cookie Policy.
Data Controller
The data controller responsible for your personal data is:
PromptHub GmbH
European Union
privacy@promthub.ai
Data Protection Officer: privacy@promthub.ai
Contact Us
For privacy-related inquiries, please contact our Data Protection Officer at privacy@promthub.ai