Privacy Policy
Last updated: August 28, 2026
This policy explains how ZANUBIO SRL ("we", "us", or "our"), operating PromptCreek at https://www.promptcreek.com, collects, uses, shares, and protects your personal data. We act as data controller and comply with the General Data Protection Regulation (GDPR).
Two things worth knowing up front
Prompts you generate on the Free plan are published publicly. They get a public URL, are visible to anyone on the internet, are attributed to your display name, and may be indexed by search engines. Keeping prompts private is a paid feature. Do not put personal data, credentials, or confidential information in a prompt you publish. See Terms of Service, section 4.
Text you submit to our AI features is sent to third-party AI providers. The Prompt Enhancer sends your input to OpenRouter, which routes it to the model that generates your result. Section 5 explains what that means.
1. Data controller
- Company: ZANUBIO SRL
- Registered office: Bucharest, Romania
- Trade register number: J40/20502/2023
- Registration code (CUI): 49033442
- Intra-community VAT code: RO49667881
- Email: hello@promptcreek.com
We have not appointed a Data Protection Officer, as we are not required to. Privacy questions go to the address above.
2. Data we collect
What you give us
- Account: email address, display name, and password (stored hashed, never in readable form). Optionally a profile picture, bio, and links to your GitHub, X, LinkedIn or website.
- Content: prompts, titles, descriptions, instructions, example outputs, variable configurations, reviews, ratings, bookmarks, folders, and saved variable presets.
- AI inputs: the text you submit to the Prompt Enhancer, and the settings you choose.
- Uploads: images you upload, for example a prompt banner.
- Reports: if you report a prompt or review, the reason and any description you write, together with your account identifier.
- Support: whatever you send us by email.
What we collect automatically
- Authentication: session tokens, sign-in timestamps, and the IP address and browser user-agent recorded with each session.
- Usage counters: views, copies, bookmarks, and shares on prompts, and equivalent counters on your account. These drive rankings and community challenges.
- Hashed IP address: each Prompt Enhancer run stores a SHA-256 hash of your IP address. We use it to detect people creating multiple accounts to farm free credits. The hash cannot be reversed to recover the original address.
- AI request logs: the exact request we send to the model and the response it returns, so we can investigate a failed or wrong generation. Section 5 covers this.
- Server logs: our host records request metadata including IP address, for security and debugging.
- Analytics: pages visited, device and browser information, and session recordings. These start when you arrive and stop as soon as you reject analytics cookies from our banner, or immediately if your browser sends a Global Privacy Control signal.
What we get from others
- Google Sign-In: if you sign in with Google, we receive your email address, name, and profile picture. We do not receive your Google password and have no other access to your Google account.
- Stripe: we receive your subscription status, plan, billing period and invoice history. Card details are handled entirely by Stripe — we never receive or store your card number.
We do not use GitHub sign-in. We do not buy personal data, and we do not build advertising profiles.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Running your account, prompts, bookmarks and library | Performance of contract — Art. 6(1)(b) |
| Publishing your public prompts and reviews on the platform | Performance of contract — Art. 6(1)(b) |
| Generating prompts through third-party AI models at your request | Performance of contract — Art. 6(1)(b) |
| Processing payments, subscriptions and credit balances | Performance of contract — Art. 6(1)(b) |
| Transactional email — address verification and sign-in links | Performance of contract — Art. 6(1)(b) |
| Keeping AI request logs to investigate failed generations | Legitimate interest — Art. 6(1)(f) — supporting our own service |
| Detecting multi-account credit farming via hashed IP addresses | Legitimate interest — Art. 6(1)(f) — preventing abuse of a free tier |
| Moderating reported content and enforcing our policies | Legitimate interest — Art. 6(1)(f) — a safe platform; and legal obligation — Art. 6(1)(c) |
| Security, fraud prevention and service integrity | Legitimate interest — Art. 6(1)(f) |
| Responding to your support requests | Legitimate interest — Art. 6(1)(f) |
| Analytics, heatmaps and session recording | Legitimate interest — Art. 6(1)(f) — understanding and improving the service, until you object by rejecting analytics cookies |
| Keeping invoices and tax records | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interest, we have weighed it against your rights, and you can object at any time — see section 9.
4. What becomes public
Most of PromptCreek is a public library. These are visible to anyone, signed in or not:
- Public prompts, including title, description, instructions, example output, and category
- The display name of the person who published them
- Reviews and ratings, with the reviewer's display name
- Aggregate counts such as views, bookmarks, and average rating
These are never public:
- Your email address, password, and IP address
- Private prompts, bookmarks, folders, and saved variable presets
- Your credit balance, transactions, invoices, and subscription status
- The content of reports you file, and your identity as a reporter
- The text of your Prompt Enhancer inputs, unless the resulting prompt is published
The full text of a public prompt is shown only to signed-in visitors; its title and description are visible to everyone and to search engines.
5. AI processing
This is the part most worth reading carefully.
- Where your text goes. When you use the Prompt Enhancer, the text you submit is sent to OpenRouter, a routing service that forwards it to the AI provider running the model that generates your result. Your text therefore leaves our systems and is processed by companies outside the EU.
- What we send. Only the prompt text and generation settings. We do not send your name, email address, or account identifier to the model provider.
- What we keep. We store the exact request and response for each generation so we can investigate failures and support requests. These logs contain your prompt text and are linked to your account.
- Training. We do not train AI models on your content. We ask OpenRouter to route to providers under terms that exclude training on submitted data, but we cannot audit each downstream provider. Treat anything you send to an AI feature as leaving your control.
- Practical advice. Do not paste other people's personal data, credentials, client material, or trade secrets into the Prompt Enhancer.
6. Who we share data with
We share data with the processors below to run the service. Each is engaged under data processing terms, and transfers outside the EEA rely on the European Commission's Standard Contractual Clauses or an adequacy decision. We do not sell personal data.
| Service | What it does | What it receives | Where |
|---|---|---|---|
| MongoDB Atlas | Database hosting | All stored account and content data | EU |
| Vercel | Application hosting, CDN, and file storage for uploads | IP address, request logs, uploaded images | US |
| OpenRouter | Routing AI requests to model providers | The prompt text you submit to AI features | US |
| AI model providers | Generating your result, reached through OpenRouter | The prompt text you submit to AI features | Varies by model |
| Stripe | Payments, subscriptions, and the receipts and invoices it emails you | Name, email, billing address, payment details, IP address | US |
| Resend | Transactional email — verification and sign-in links only | Email address, name | US |
| Sign-in with Google | Email, name, profile picture | US | |
| Google Analytics | Website analytics — runs until you reject analytics cookies | IP address, device information, browsing behaviour | US |
| Microsoft Clarity | Heatmaps and session recording — runs until you reject analytics cookies | IP address, device information, on-page interactions | US |
We may also disclose data where the law requires it, to establish or defend legal claims, or to protect the rights and safety of our users. If the business is sold or reorganised, data may transfer to the acquirer under this policy.
7. International transfers
Several processors are established in the United States. Where personal data leaves the European Economic Area we rely on the Standard Contractual Clauses approved by the European Commission, on adequacy decisions where one applies, and on additional technical measures such as encryption in transit. You can request a copy of the relevant safeguards from hello@promptcreek.com.
8. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While your account exists; deleted within 30 days of closure |
| Private prompts, bookmarks, presets | While your account exists; deleted with the account |
| Public prompts and reviews | Deleted with the account, or retained in anonymised form where other users depend on them — you can ask us to remove them entirely |
| AI request and response logs | 30 days, then deleted |
| Hashed IP addresses from Enhancer runs | Stored with the generation record and deleted with your account. Only the last hour of them is ever read, for rate limiting. |
| Sessions | Expire automatically; you can revoke them from account settings |
| Credit transactions | While your account exists, as your balance history |
| Invoices and payment records | 10 years, as required by Romanian accounting law |
| Content reports and moderation decisions | Kept while needed to recognise repeat problems, and reviewed periodically |
| Analytics data | Per Google Analytics and Microsoft Clarity settings, up to 26 months |
| Cookie consent record | 1 year, then we ask again |
Backups are retained on a rolling basis and overwritten within 30 days.
9. Your rights
Under the GDPR you can ask us to:
- Access (Art. 15) — give you a copy of the personal data we hold about you
- Rectify (Art. 16) — correct anything inaccurate. You can edit your name, profile, and content yourself in settings.
- Erase (Art. 17) — delete your account and data
- Restrict (Art. 18) — pause processing while a dispute is resolved
- Port (Art. 20) — receive your data in a machine-readable format, which we provide as JSON
- Object (Art. 21) — object to processing based on legitimate interest
- Object to analytics — reject analytics cookies from the banner, or any time afterwards via "Manage Cookies" in the footer. This takes effect immediately, though it does not undo processing that already happened.
Deleting your account
There is no self-service delete button yet. Email hello@promptcreek.com from the address on your account and we will confirm and delete the account within 30 days. Cancel any active subscription first, since deletion does not by itself stop billing. Invoices are kept for the statutory period described in section 8.
Making a request
Email hello@promptcreek.com from the address on your account. We respond within 30 days, and may ask you to confirm your identity if the request comes from elsewhere. Exercising these rights is free.
Complaints
If you are unhappy with how we handle your data, tell us first. You also have the right to complain to your national data protection authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro.
10. Cookies
We use a small number of cookies. Essential ones keep you signed in; analytics ones start when you arrive and stop as soon as you reject them from our banner, or immediately if your browser sends a Global Privacy Control signal. Details are in our Cookie Policy.
11. Security
- Encryption in transit (TLS) and at rest
- Passwords stored hashed, never in readable form
- HTTP-only, secure session cookies, with sessions you can revoke yourself
- Role-based access controls, with staff access limited to what the job requires
- Payment card data handled entirely by Stripe and never stored by us
No system is perfectly secure. If a breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and tell you without undue delay.
12. Children
PromptCreek is not for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
13. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by purely automated means. Automated signals — such as hashed IP addresses — help flag suspected credit farming, but a person reviews before an account is restricted or banned.
14. Changes
We update this policy as the product changes. For material changes we update the "Last updated" date and give notice in the app or by email. Please check back from time to time.
15. Contact
- Email: hello@promptcreek.com
- Company: ZANUBIO SRL, Bucharest, Romania