Privacy

By default, only the prompt you choose to rewrite leaves your browser.

Last updated: 2026-09-24

This is the practical, plain-English version — and it describes behavior you can observe yourself. Open your browser’s Network tab on a supported site: clicking Rewrite sends one request carrying the text from the chat box, and nothing else. You may also see small outcome events (§4a) — those carry a verdict, never prompt text, and a failed one is retried later, so an event can arrive minutes after the rewrite it describes, or after a browser restart. Turn them off in the popup and they stop entirely. If a site change breaks how the extension finds the chat box, you may also see a small attach report and a download of updated matching rules (§4d); neither carries the page address or anything you typed. If what you observe and this page ever disagree, email us at hello@preprompt.org and we’ll fix it.

One extension feature is user-controlled from the popup: outcome telemetry (default on, opt-out — logs your accept/revert/reject verdict per rewrite, never the prompt text; the same switch covers attach reports, §4d). A conversation-aware mode that would read recent visible turns is planned but not yet enabled — today the rewriter only ever sees your chat textarea. See §4 below for exactly what each does and how it’s controlled.

1. What PrePrompt does, on data

PrePrompt is a Chrome extension that rewrites your prompt before you hit Send on ChatGPT, Claude, Gemini, or Perplexity. It’s free to use within a monthly allowance; paid plans raise the cap, and the data flow below is identical either way. On click, the extension sends one thing to PrePrompt’s backend — the text you typed into the chat textarea — and replaces it with the rewritten version. The rewrite is generated by Anthropic Claude (Haiku 4.5), so your prompt text is sent to Anthropic whichever chat site you use it on (ChatGPT, Gemini and Perplexity included). We do not save the prompt text or the rewrite on our servers. We record a usage entry (when, which site, the route taken and the quality scores) so your dashboard can show your usage. That is the entire prompt-text data flow for the Chrome extension. PrePrompt’s developer tools (VS Code, the CLI and MCP) send the prompt you ask them to rewrite in the same way. In those tools only, and only if you turn it on, Memory also keeps a few short labels inferred from your prompts, such as your programming language — never the prompt text itself. It is off by default; see §4c.

2. What we collect, and when

  • Prompt text — only the text in the chat textarea, only when you click Rewrite. Sent to Anthropic to generate the rewrite, then not kept by us: there is no prompt-text field in our database, signed in or not.
  • Usage records — one row per rewrite or check: when it happened, the site or tool, the route taken, the quality scores and the credits used. Linked to your account if you’re signed in; otherwise linked to a one-way hash of your IP address, not the address itself. This is what your dashboard shows.
  • IP address (signed-out use only) — if you rewrite without signing in, we store your IP address with a counter so the free anonymous allowance can be enforced per visitor. The outcome-event rate limit (§4a) also counts requests per IP.
  • Account email — if you sign up. Used to send the confirmation email and any billing notices. We do not market to you.
  • Usage counts — how many rewrites you’ve done this month, per site (so we can show you a dashboard).
  • Outcome events — after a rewrite is shown, we record what you did with it (accepted, reverted, rejected, edited, or abandoned), and if you reject one you can optionally pick a reason from a short list, so we can measure whether our rewrites are actually useful. The events do not contain your prompt text or the rewritten text — they carry the verdict, the route taken, the site, the length of the rewrite, the before and after quality scores, an ID linking back to the rewrite and (for a rejection) the reason category you chose. If you’re signed in, they are linked to your account. On by default; can be turned off from the extension popup. See §4.
  • Conversation context — not collected today. A conversation-aware mode that would (on your explicit opt-in) also read the recent visible turns of an existing chat is planned but not yet enabled. Until it ships, the rewriter only ever sees your chat textarea. See §4b.
  • Error events — if the backend or this website errors, we log it to Sentry with personal-data fields (prompt text, email, IP) scrubbed before send. Used to keep the product working. The Chrome extension does not send error reports.
  • Product analytics — we send events to PostHog when you sign up, complete a rewrite, or hit a limit. They are linked to your account ID (a random identifier, not your email) and carry the plan, route, scores and timing. No prompt text leaves with these events.

3. What we don't collect

  • No browsing history. The extension does not read your tabs, your URLs, or anything outside the prompt textarea on supported sites.
  • No conversation history. We do not read what the LLM said back to you. A conversation-aware mode that would read the recent visible turns on your explicit opt-in is planned but not yet enabled — see §4b.
  • No background scraping. The extension acts when you click Rewrite. The only thing it sends on its own is a retry of an outcome event that failed to send earlier (§4a). There are no idle pings.
  • No third-party analytics network on the marketing site beyond PostHog (product). Page-view counts go to our own backend (§8).
  • No selling, ever. We do not sell, license, or share your prompt data with anyone outside the third parties listed below.

4. Optional features — what they share and how to control them

Two features in the extension extend the default behaviour above. Both are user-controlled from the extension popup, both ship with their own protections, and you can turn either on or off at any time without losing data. A third, Memory (§4c), applies only to the developer tools and is controlled from your dashboard Settings.

4a. Outcome telemetry (default on, opt-out)

After a rewrite is shown in your chat textarea, the extension records what happened next, so the team can measure whether rewrites are actually adding value:

  • accepted — you sent the rewritten version.
  • reverted — you clicked Undo on the post-rewrite toast.
  • rejected — after undoing, you optionally picked a reason the rewrite didn’t work (e.g. “changed what I meant”, “too long”, “wrong tone”) from a short list. This step is always optional — dismiss it and nothing extra is recorded. When you do pick one, we store only the category you tapped, never free text.
  • edited — you modified more than ~10% of the rewrite before sending. (We treat this rate as directional only — the 10% threshold can mis-fire on small edits with big meaning, and on big edits that don’t change intent.)
  • abandoned — you didn’t send within 30 seconds while the page was still in focus. (We don’t fire this if you tabbed away — that’s interruption, not abandonment.)

Each event contains: the verdict (one of the five above), the route the rewriter took, the site you were on, the length in characters of the rewrite, the before and after quality scores, an ID that links the event back to the rewrite it came from, and — for a rejection — the reason category you picked from the list. If you’re signed in, the event is linked to your account. None of these events contain your prompt text or the rewritten text.

Each event also carries a sequence number and a random per-installation ID. These exist so we can tell a lost event from an event that never happened — without them, a dropped event is invisible and our coverage metrics read as perfect health. The ID is generated in your browser, is not your account ID, not a device fingerprint, and carries nothing identifying; its only job is keeping two browsers’ sequences from interleaving. Both live inchrome.storage.localand are cleared when you remove the extension. A failed event is retried a bounded number of times, then dropped.

You can turn outcome telemetry off entirely from the extension popup → Privacy → “Track rewrite outcomes.” When off, no outcome events fire at all. Turning it off doesn’t affect any rewrite you’ve done before, and the rewriter still works exactly the same way.

A server-side cap (100 outcome events per IP per hour) protects the database from a runaway content script.

4b. Conversation-aware rewrites (planned — not yet enabled)

Status: not yet enabled. Conversation-aware mode is planned but not active in the current extension — there is no toggle for it today, and the rewriter only ever sees your chat textarea (§1). The rest of this section is the design and the safeguards it will ship with, published before we turn it on rather than after.

Today the rewriter sees only the text in your chat textarea. When conversation-aware mode is enabled, clicking Rewrite inside an existing chat will also read the recent visible turns from that thread, so the rewriter can resolve back-references (“make it shorter,” “do that in Python instead”) instead of guessing.

Five things will be true any time conversation-aware mode is on:

  • The conversation context is read live from the page DOM at the moment you click Rewrite. It is never stored in the extension, never synced anywhere, and never carried between chats.
  • The conversation context goes to our backend only for that one rewrite. It is sent on to Anthropic to generate the rewrite, then discarded server-side. It is not added to your dashboard history.
  • We run our secret scanner on the full assembled payload— draft plus context — before sending anything. If a secret (API key, token, password pattern) is detected, the context is dropped entirely and the rewriter runs on the draft alone. We never display the matched secret back to you, and we never tell the server about it.
  • After every rewrite in this mode, the post-rewrite toast has an “Inspect what was sent” link that opens a panel showing exactly which turns from the conversation were included. Trust through visibility, not promises.
  • A new chat (no prior turns yet) behaves identically to the default mode — only the textarea is sent.

When conversation-aware mode ships it will be off by default and opt-in from the extension popup, reversible at any time. Until then, the extension behaves exactly as described in §1–§3 above.

We monitor an aggregate “context attached rate” per site (Sentry alert if it drops sharply — usually means a site redesign broke our reader, not anything you did). No individual user data is in that metric.

4c. Memory (developer tools only — default off, opt-in)

Memory lets PrePrompt tailor rewrites to how you work. When it is on, the backend infers a few short labels from the prompts you rewrite and adds the most confident ones to the start of later prompts it sends to Anthropic for rewriting, so it doesn’t have to guess your stack each time.

  • Off by default. Nothing is used until you turn Memory on in Settings.
  • What is stored: labels from a fixed list of categories — programming language, framework, database, tooling, domain, role, output format, style and tone (for example “language: typescript” or “tone: concise”). Each label is stored with a confidence score, how many times it has been seen, when it was last seen, and which tool it came from. Your prompt text is not stored as part of Memory.
  • Where: in your account’s database (Supabase, §5), tied to your account.
  • Where it’s used: only in the developer tools — VS Code, the CLI and MCP. It is never used by the Chrome extension.
  • Your controls: in Settings you can see every label PrePrompt remembers, turn Memory on or off, forget a single label, or clear all of them. Labels stored while Memory was on stay listed after you turn it off, but they aren’t used; you can clear them there.
  • How long: until you forget or clear them, or delete your account. Account deletion removes them before the account is closed. They are included in your data export.

4d. When a site change breaks how the Rewrite button finds the chat box (extension 0.5.0 and later)

ChatGPT, Claude, Gemini and Perplexity change their pages without notice. When a change breaks the extension’s usual way of finding where you type, even if a backup way still works, two things can happen:

  • An attach report. The extension tells PrePrompt which site it was on, which of our backup rules it had to use (or that none worked), and its version number, so we can fix it quickly. It never contains the page address, your prompt, or anything you typed, and it isn’t tied to your account: we keep only hourly counts. It is covered by the popup’s “Track rewrite outcomes” switch, the same one as outcome events — turn it off and no report is sent.
  • Updated matching rules. The extension downloads the latest list of places to put the Rewrite button from api.preprompt.org. The request carries no account information, and an install whose usual rules still work never makes it.

5. Third parties (subprocessors)

To run PrePrompt, your data passes through these providers:

  • Anthropic — runs Claude Haiku 4.5, which generates the rewrite. Your prompt text is sent to Anthropic per their privacy policy. Anthropic does not train on API traffic.
  • Supabase — stores your account, plan, usage records and any Memory labels (§4c). Hosted in their managed environment.
  • Railway — runs the PrePrompt backend.
  • Vercel — serves this marketing site and the dashboard.
  • Sentry — receives scrubbed error events. PII keys are stripped before send.
  • PostHog — receives product events linked to your account ID (§2). Prompt text is never sent.
  • Resend — sends welcome and billing emails.
  • Stripe — processes payments and subscriptions. We don’t store card data — Stripe handles it.

6. How long we keep your data

This section describes what we do today. We don’t yet run automatic deletion or pruning jobs; until we do, the periods below are “until deleted on request” rather than a fixed number of days. When scheduled deletion ships we’ll update this page first.

  • Prompt text — not kept on our servers. It is sent to Anthropic to generate the rewrite; Anthropic’s own retention applies (§5). The CLI and MCP server keep a local history file on your own computer (~/.preprompt/history.db), which you can delete at any time.
  • Account email and sign-in record — kept while you have an account, and after you delete it until you ask us to erase it (§7).
  • Usage records — kept indefinitely. We use them for your dashboard, for billing reconciliation and to investigate abuse. They are not pruned automatically today.
  • Billing records (plan history, credit ledger, Stripe customer and subscription IDs) — kept indefinitely for accounting and chargebacks.
  • IP addresses from signed-out use — kept indefinitely with the anonymous-allowance counter (§2). We plan to expire them automatically; until then, email us to have yours removed.
  • Memory labels — kept until you forget them, clear them from Settings, or delete your account (§4c).
  • Sign out clears the auth token and any cached usage from your browser. Sign back in and it’s restored.

7. Your rights

You can:
  • See your data — your plan, usage and credits are on your dashboard.
  • Export your data — download a JSON file of your profile, usage records, credit ledger, Memory labels and notification preferences from Settings. For anything that file doesn’t cover, email us.
  • Delete your account — from Settings. This takes effect straight away: any subscription is cancelled, your Memory labels are deleted, your access tokens are revoked and the account is deactivated, so PrePrompt no longer accepts its sign-in. Your email, sign-in record, usage records and billing records are not erased at that point; we don’t yet purge deleted accounts automatically.
  • Ask for full erasure — email hello@preprompt.org from the address on the account and we’ll erase what we hold about you, except records we have to keep for billing, tax or legal reasons, and tell you what we kept and why. Automatic purging of deleted accounts is planned.
  • View, forget or clear Memory — any time, from Settings.
  • Correct anything wrong — reach out by email.

You can make any of these requests wherever you live. If you’re unhappy with how we handled one, you can also complain to the data protection authority where you live.

8. Cookies and local storage

The marketing site uses no third-party cookies. It keeps one random ID in your browser’s local storage so page-view counts in our own analytics count a visitor once — it is not your email, IP address or a device fingerprint, and clearing site data removes it. Those page-view events are stored on our backend with the rest of the usage records (§6). When you sign in, the dashboard keeps your Supabase sign-in session in your browser’s local storage so you stay signed in. The Chrome extension stores your auth token and settings inchrome.storage.local— not in any cloud or sync layer.

On preprompt.org itself, the extension announces its presence and version to the page so the site can tell you it’s installed and hand off sign-in without a copy-pasted token. It reads nothing from the page, and it runs on no site other than the four chat sites listed above and preprompt.org.

9. Security

All traffic between the extension, backend, and Supabase is TLS. Every table holding your data has row-level security on, so another user’s sign-in can’t read your rows. Our backend reads them with a server-side service credential that never leaves the server. We don’t store payment data — Stripe handles all of that.

10. Children

PrePrompt is for people aged 18 or older (see the Terms). We don’t knowingly collect data from anyone younger. If you believe someone under 18 has signed up, email hello@preprompt.org and we’ll delete the account.

11. Changes to this policy

When this changes materially, we’ll bump the “Last updated” date at the top and email signed-up users for any change that affects what we collect or who we share it with.

12. Contact

Questions, requests, or concerns: hello@preprompt.org.

Grievances and data requests (access, correction, erasure, or a complaint about how we handle your data): hello@preprompt.org. Put “Data request” in the subject line.

See also: our Terms of Service and the on-page summary of our privacy story.