Legal

Privacy Policy

Last updated: May 2, 2026

What we collect

When you create an account, we collect your email address and a hashed password. When you subscribe to a Pro plan, Stripe processes your payment information — we never see or store your card details. We also store your GoatedPrompts settings (keyboard shortcut, auto-accept preference) so they sync across devices.

Your OpenAI API key is stored only in your browser's local storage and is never transmitted to our servers.

How we use it

We use your email to send account-related emails (receipts, password resets). We use your settings data to sync preferences between your browser and the extension. We use Stripe's webhook data (subscription status) to determine whether you're on the Free or Pro plan.

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described below.

Third-party services

We use Supabase to store account data (email, plan status, settings). Supabase is hosted in the US and complies with GDPR. We use Stripe to process payments. Stripe's privacy policy governs how your payment data is handled. We use Vercel to host the application.

Your API key

GoatedPrompts uses your OpenAI API key to rewrite prompts directly from your browser. The key is stored in chrome.storage.sync, which is encrypted and tied to your Chrome profile. It is sent directly to OpenAI's API — it never passes through our servers. We have no access to it.

Cookies and tracking

We use a session cookie to keep you logged in. We do not use analytics tracking cookies, advertising cookies, or third-party tracking scripts. We do not use Google Analytics or similar services.

Data retention

If you delete your account, we delete your email, settings, and subscription data from our database within 30 days. Stripe retains payment records as required by law.

Your rights

You can request a copy of your data, ask us to delete your account, or update your information at any time by emailing goatedprompts@gmail.com. If you're in the EU, you have additional rights under GDPR — contact us and we'll respond within 30 days.

Contact

Questions about this policy? Email us at goatedprompts@gmail.com.