Privacy Policy

PromptFern Privacy Policy - How we collect, use, and protect your data.

Last updated: December 15, 2025

PromptFern ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI brand monitoring service.

Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Name
  • Company name and size
  • Country and language preferences
  • Authentication credentials (encrypted)

Brand and Monitoring Data

When you use our service, we collect:

  • Brand names, websites, and descriptions you configure
  • Competitor information you add
  • Prompts and topics you create for monitoring
  • AI responses collected on your behalf
  • Citation and source data from AI platforms

Website Analytics Data

If you use our website analytics feature, we collect:

  • Page URLs visitors access on your website
  • Referrer information
  • User agent strings (to identify AI bots)
  • Anonymized geographic data (country, region)
  • Hashed IP addresses (we never store raw IPs)

Usage Data

We automatically collect:

  • Log data (access times, pages viewed, features used)
  • Device and browser information
  • IP address (hashed for privacy)

How We Use Your Information

We use collected information to:

  • Provide and maintain the PromptFern service
  • Monitor AI platforms on your behalf
  • Generate visibility reports and insights
  • Improve and personalize your experience
  • Send service-related communications
  • Respond to support requests
  • Detect and prevent fraud or abuse

Data Sharing

We do not sell your personal information. We may share data with:

Service Providers

Third parties that help us operate our service:

  • Cloud infrastructure (hosting, storage)
  • Payment processing (Stripe)
  • Email delivery (Resend)
  • Authentication services

AI Platforms

When monitoring AI platforms, we send prompts on your behalf. We do not share your personal or brand data with these platforms beyond the prompts themselves.

We may disclose information if required by law, court order, or government request.

Business Transfers

In the event of a merger, acquisition, or sale, user data may be transferred as part of the business assets.

Data Security

We implement industry-standard security measures:

  • Encryption in transit (TLS/HTTPS)
  • Encryption at rest for sensitive data
  • Access controls and authentication
  • Regular security audits
  • Secure password hashing
  • IP address hashing (never stored in plain text)

Data Retention

We retain your data as long as your account is active. After account deletion:

  • Personal data is deleted within 30 days
  • Aggregated, anonymized data may be retained for analytics
  • Backups are purged within 90 days

Your Rights

Depending on your location, you may have rights to:

  • Access: Request a copy of your data
  • Correction: Update inaccurate information
  • Deletion: Request account and data deletion
  • Portability: Export your data
  • Objection: Opt out of certain processing

To exercise these rights, contact privacy@promptfern.ai.

Cookies

We use essential cookies for:

  • Authentication and session management
  • Security and fraud prevention
  • Remembering your preferences

We do not use third-party advertising cookies.

International Data Transfers

We process data in the United States and European Union. If you're located outside these regions, your data may be transferred internationally with appropriate safeguards.

Children's Privacy

PromptFern is not intended for users under 18. We do not knowingly collect information from children.

Changes to This Policy

We may update this Privacy Policy periodically. Significant changes will be communicated via email or in-app notification.

Contact Us

For privacy-related questions: