Prompt Box Privacy Policy
Effective: September 22, 2026. Applies to Prompt Box v4.0.0 and later. End-to-end encryption of synced prompts applies from v4.1.0.
The short version
Prompt Box stores your prompts in your own browser. The free extension has no account, no analytics, and no trackers, and by default nothing you type or save ever leaves your device. Prompt Box Pro is an optional, opt-in upgrade: only if you sign in and turn on Cloud sync do your prompts get stored on our server so they follow you across devices, and they are end-to-end encrypted, so we cannot read them. You are always in control of whether that happens.
What Prompt Box stores, and where
- Your prompt library (titles, prompt text, tags, shortcuts, favorites) is stored in Chrome extension storage on your device. If you choose Chrome Sync storage, Google syncs it between your own Chrome profiles the same way it syncs bookmarks.
- Settings (theme, filters, storage preference) are stored the same way.
- Prompt Box never stores your keystrokes, browsing history, or page content.
When data leaves your device
- Clipboard, on your action only. When you click Copy, or when a site blocks text expansion and Prompt Box falls back to copying the prompt so you can paste it, your prompt is written to your clipboard. Prompt Box never reads your clipboard.
- Survey, on your action only. If you choose to take our feedback survey, your answers are sent to our survey service. Declining or ignoring it sends nothing.
- Waitlist (now closed), on your action only. If you joined the Pro waitlist while it was open on this website, we stored your email address (processed by Resend, our email delivery provider) to contact you about the Prompt Box Pro launch, and for nothing else. One email to us removes you from the list at any time.
- Pro cloud sync, only if you enable it. If you sign in and turn on Cloud sync, your prompt library is stored on our backend (Supabase) so it stays in sync across your devices. Your prompt titles, text, tags, and shortcuts are end-to-end encrypted (AES-256-GCM) on your device before they are uploaded, using a key unlocked by a sync passphrase that only you know. Our server stores only the encrypted data, plus a copy of your key that is itself locked with your passphrase or your one-time recovery code; neither the passphrase nor the recovery code is ever sent to us, so we cannot read your synced prompts. On top of that, data is encrypted in transit and at rest, and row-level security means only your account can read or write your prompts. Sign-in uses Google (via Supabase Auth); we receive your email address and an account identifier, never your Google password. Local-only remains the default, and turning sync on always takes an explicit action on each device.
- Pro payment, only if you upgrade. When you choose to upgrade, checkout opens on Stripe's secure hosted page in a browser tab. Payment details are entered only on Stripe's page; the extension never sees, collects, or stores your card information. We store only your resulting subscription status (whether you are Pro, and which plan) and a Stripe customer identifier.
Permissions the extension uses
- storage: saving your prompt library and settings.
- activeTab and context menus: the right-click "Save to Prompt Box" action.
- clipboardWrite: copying prompts when you click Copy, and the expansion fallback described above.
- Content script on web pages: watches only for your own shortcut keystroke patterns inside text fields so it can expand them. It never records what you type, and it never touches password fields.
- identity (Pro only): used to sign you in with Google when you choose to create a Prompt Box Pro account.
- alarms (Pro only): used when Cloud sync is on, to periodically check our backend for changes made on your other devices. It does nothing for signed-out or local-only users.
What we never do
- No selling or sharing of data. There is no data to sell.
- No analytics, no fingerprinting, no ads.
- No reading of your clipboard, history, or page content.
Your data, your control
Export your entire library as CSV at any time from Settings. Uninstalling the extension deletes all locally stored data. If you use Pro cloud sync, signing out removes your session from a device, and you can request deletion of your synced prompts and account by contacting us. Because synced prompts are end-to-end encrypted, we cannot recover them if you lose both your sync passphrase and your recovery code; the copies on your devices are not affected. To remove a waitlist email, contact us and we will delete it.
Contact
Questions or data requests: lbwalton@gmail.com, or the support tab on the Chrome Web Store listing.
Changes
If a future version changes what data is stored or transmitted, this policy will be updated before that version ships, as was done for Pro cloud sync and for end-to-end encryption in v4.1.0.