Privacy Policy
Last updated: January 31, 2025
1. Information We Collect
We collect the following types of information:
Account Information:
- Name and email address
- Password (encrypted and hashed)
- Profile photo (if provided via Google OAuth)
Usage Data:
- Lessons and modules you've accessed
- Projects submitted and completed
- Time spent on platform
- Progress and achievement data
- Community posts and interactions
Technical Data:
- IP address and approximate location
- Browser type and version
- Device information (type, OS)
- Referring URLs
- Pages visited and time stamps
Payment Information:
- Processed securely by Stripe (PCI-DSS compliant)
- We do NOT store credit card numbers or CVV codes
- We only store: billing name, last 4 digits, card brand, expiry date
Communications:
- Emails you send us
- Support tickets and responses
- Survey responses (if you participate)
2. How We Use Your Information
- Provide the Service: Create and manage your account, track progress, deliver content
- Improve the Service: Analyze usage patterns to enhance features and content
- Communicate: Send important updates, course announcements, and support responses
- Process Payments: Handle subscriptions, billing, and refunds
- Prevent Fraud: Detect and prevent unauthorized access or misuse
- Marketing: Send promotional emails (you can opt out anytime)
- Legal Compliance: Comply with legal obligations and enforce our Terms
3. Information Sharing and Disclosure
WE DO NOT SELL YOUR PERSONAL INFORMATION.
We may share your information with:
Service Providers:
- Hosting: Vercel (website hosting)
- Database: Google Firebase (user data storage)
- Payments: Stripe (payment processing)
- Email: [Email service provider] (transactional emails)
- Analytics: Google Analytics (anonymized usage data)
These providers have access only to perform tasks on our behalf and are obligated to protect your data.
Legal Requirements:
We may disclose information if required by law, subpoena, or to protect our rights and safety.
Business Transfers:
If PromptKey Academy is acquired or merged, your information may be transferred to the new owner.
Aggregated Data:
We may share anonymized, aggregated data that cannot identify you (e.g., "50% of users complete Module 1").
4. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: All data transmitted via HTTPS/TLS encryption
- Password Security: Passwords are hashed using bcrypt (never stored in plain text)
- Access Controls: Limited employee access to user data on need-to-know basis
- Regular Audits: Security reviews and vulnerability assessments
- Secure Infrastructure: Data stored on secure, monitored servers
Important: No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential Cookies: Keep you logged in, remember your preferences
- Analytics Cookies: Understand how you use the Service (Google Analytics)
- Functional Cookies: Enhance your experience (e.g., remembering dark mode preference)
Managing Cookies:
You can control cookies through your browser settings. Note that disabling cookies may affect Service functionality.
6. Your Privacy Rights
Depending on your location, you have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and data
- Data Portability: Receive your data in a machine-readable format
- Opt-Out: Unsubscribe from marketing emails (click "unsubscribe" in any email)
- Object: Object to certain processing of your data
- Withdraw Consent: Withdraw consent for data processing (may limit Service access)
To exercise these rights, email us at privacy@promptkey.ai
Note: Deleting your account will permanently remove your progress, projects, and access to the Service. This action cannot be undone.
7. Data Retention
We retain your information for as long as necessary to provide the Service and comply with legal obligations:
- Active Accounts: Data retained while your account is active
- Cancelled Accounts: Data retained for 90 days in case you reactivate, then deleted
- Legal Obligations: Some data retained longer if required by law (e.g., financial records for 7 years)
- Anonymized Data: We may retain anonymized usage data indefinitely for analytics
8. Children's Privacy
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent and believe your child has provided us with personal information, please contact us and we will delete it.
9. International Data Transfers
Your information may be transferred to and processed in the United States, where data protection laws may differ from your country.
By using the Service, you consent to the transfer of your information to the United States and other countries where we operate.
For EU/UK Users:
We comply with applicable data protection regulations. Data transfers are protected by appropriate safeguards.
10. Third-Party Links
The Service may contain links to third-party websites (e.g., GitHub, OpenAI, Anthropic). We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies.
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information we collect, use, and share
- Right to delete personal information
- Right to opt-out of sale of personal information (we don't sell your data)
- Right to non-discrimination for exercising your rights
To exercise these rights, contact us at privacy@promptkey.ai
12. Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification to your registered email address
- Prominent notice on the Service
- Updating the "Last Updated" date at the top
Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
Questions, concerns, or requests regarding this Privacy Policy?
Email: privacy@promptkey.ai
General Inquiries: admin@promptkey.ai
PromptKey Academy
Bellevue, WA 98004
United States