Promptly AI Logo Promptly AI Back to site
Home

Privacy Policy

Last updated: July 26, 2026

How this applies to your deployment

Promptly AI is delivered today as on-premise and private cloud deployments. A multi-tenant Managed Cloud Coming soon is planned.

  • On-Premise & Private Cloud Available now: The platform runs entirely inside your own infrastructure or cloud tenancy. Promptly AI does not access, collect, store, or process the content and data you use in the platform ("Customer Data")—it never leaves your environment. You remain the sole controller and processor of that data. The sections below about content processing apply only to the Managed Cloud.
  • Managed Cloud Coming soon: When available, Promptly AI will host the platform and process Customer Data as your processor to provide the Services, under this policy and our DPA.

In every case we may process limited account, billing, and website data to provide licensing and support, and we never use your Customer Data to train publicly available AI models.

Contents 1. Scope 2. Information we collect 3. How we use information 4. Legal bases for processing 5. Sharing and disclosure 6. Data retention 7. Security 8. Your rights 9. International transfers 10. Children's privacy 11. Changes to this policy 12. Contact us

This Privacy Policy explains how Promptly AI ("Promptly AI", "we", "us") collects, uses, and protects personal information when you use our website and platform (the "Services"). As explained in the box above, how it applies depends on your deployment: with on-premise and private cloud we do not access your Customer Data, whereas in the Managed Cloud we act as a processor on your organization's behalf, as described in our Data Processing Addendum.

1. Scope

This policy applies to information we process about website visitors, account holders, and end users of the Services. It does not apply to third-party services you connect to the platform, which are governed by their own privacy policies.

2. Information we collect

Information you provide

  • Account data — name, work email, organization, and role when you register.
  • Content (Managed Cloud only) — documents, prompts, messages, and other data you upload or generate in the platform. In on-premise and private cloud deployments this content stays entirely in your environment and is never collected by us.
  • Communications — messages you send to support or sales.

Information we collect automatically

  • Usage data — features used, pages viewed, and interactions, for reliability and product improvement.
  • Device and log data — IP address, browser type, and timestamps.
  • Cookies — for authentication, preferences (such as language), and analytics. You can control cookies through your browser settings.

3. How we use information

  • Provide, maintain, and secure the Services.
  • Authenticate users and enforce access controls.
  • Respond to requests and provide support.
  • Improve and develop features and reliability.
  • Comply with legal obligations and enforce our terms.

We do not use your organization's content to train publicly available AI models.

4. Legal bases for processing

Where the GDPR or similar laws apply, we process personal data on the bases of performance of a contract, legitimate interests (such as securing and improving the Services), consent (where required, for example certain cookies), and compliance with legal obligations.

5. Sharing and disclosure

We share information only as needed to operate the Services:

  • Subprocessors — vetted vendors that provide hosting, infrastructure, and, where you enable them, AI model providers. See our DPA for details.
  • Legal and safety — when required by law or to protect rights, safety, and security.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not sell personal information.

6. Data retention

We retain personal information for as long as needed to provide the Services and for legitimate business or legal purposes. Your organization controls retention of its content and can delete it at any time; deletions are processed within a commercially reasonable period.

7. Security

We apply administrative, technical, and organizational safeguards including encryption in transit and at rest, role-based access control, and audit logging. Learn more on our Security page. No method of transmission or storage is completely secure.

8. Your rights

Depending on your location, you may have the right to access, correct, delete, or port your personal data, object to or restrict certain processing, and withdraw consent. To exercise these rights, contact us using the details below. If we process data on behalf of your organization, we will refer your request to that organization.

9. International transfers

We may process information in countries other than your own. Where required, we use appropriate safeguards such as Standard Contractual Clauses for cross-border transfers.

10. Children's privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the "Last updated" date above. Material changes may be communicated through the Services.

12. Contact us

Questions about this policy or your data? Contact us at info@promptly-ai.co.

Promptly AI Logo Promptly AI
Privacy Policy Terms of Service Security DPA Home
© 2026 Promptly AI · All rights reserved.
Enterprise-grade security · SOC 2 Type II in progress