Privacy & Data Policy
Last updated: October 2025
1. Overview
The Public Prompt Project is an open research initiative committed to transparency, privacy, and ethical data use. We collect anonymous prompt data to help researchers, creators, and citizens understand how AI systems decide what information to show — without collecting or storing any personal information.
We believe the future of search should be open, transparent, and fair — and that visibility into AI systems should be a public right.
2. What We Collect
When you use the Public Prompt Project browser extension, web app, or connected API, we may collect the following only after your explicit consent:
| Type | Purpose | Data Stored |
|---|---|---|
| Anonymous User ID | To associate prompts within a single installation | Random UUID (hashed; no IP, name, or email) |
| Prompt Text | To analyze trends in AI-generated answers | Text of prompt (if you consent) |
| Engine Results | To evaluate visibility and ranking in AI systems | Ranked URLs, citations, or snippets |
| Technical Metadata | To maintain performance and prevent spam | Browser type, extension version, timestamp |
We do not collect or store your name, email, account ID, IP address, location, or device identifiers.
3. Legal Basis for Processing
Under the EU General Data Protection Regulation (GDPR), our lawful bases for data processing are:
- Consent (Art. 6(1)(a)) — You explicitly opt in during installation or before submitting prompts.
- Public Interest / Research (Art. 6(1)(e)) — We process anonymous data for public transparency and research on AI systems.
You may withdraw consent at any time.
4. Cookies & Local Storage
We use only functional cookies and local storage to remember your consent and anonymous ID.
| Name | Purpose | Duration |
|---|---|---|
| ppp_consent | Stores your consent choice | 12 months |
| ppp_uuid | Stores your anonymous hashed ID | 12 months |
We do not use tracking, analytics, or advertising cookies.
5. Data Retention
Anonymous data may be stored for up to 24 months, then aggregated and stripped of text content for long-term research purposes.
You can request deletion of your data by emailing privacy@publicpromptproject.ai with your anonymous ID (found in your plugin settings). We will remove all records within 30 days.
6. Data Transfers & Storage
Your data is securely stored in the United States, using the following providers:
| Processor | Purpose | Data Center | Compliance |
|---|---|---|---|
| Vercel, Inc. | Hosting and edge deployment | United States | SCCs (Standard Contractual Clauses) |
| Supabase, Inc. | Managed Postgres database | United States | SCCs (Standard Contractual Clauses) |
Data Transfer Outside the EU
If you are located in the European Union (EU), your data may be transferred to the United States. Both Vercel and Supabase adhere to the EU–U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data is protected under equivalent safeguards to EU law.
7. Data Security
We employ multiple technical and organizational measures to protect your data:
- Transport encryption via TLS (HTTPS)
- UUIDs are SHA-256 hashed before storage
- No IP addresses or user accounts stored
- Strict access control and audit logging
Because data is anonymized, it cannot be linked back to any individual.
8. Your Rights
If you are located in the EU, EEA, or UK, you have the right to:
- Access or export your anonymized data
- Request deletion of your data
- Withdraw consent at any time
- Lodge a complaint with your local Data Protection Authority
To exercise these rights, email: 📧 privacy@publicpromptproject.ai
9. Children's Data
The Public Prompt Project is intended for users aged 16 and above. We do not knowingly collect or store any data from children.
10. Policy Updates
We may occasionally update this policy to reflect improvements in privacy practices or regulatory changes. When changes occur, we'll update this page and notify users through the extension.
Last updated: October 2025
11. Contact Us
If you have questions or concerns about this policy, contact: