Promptable
Promptable
FREE — Google Play
VIEW
Prompt copied
Log in
or
Don't have an account? Sign Up
Built by Dreamy Labs

Privacy Policy

Last Updated: August 20, 2026

1. Introduction & Scope

This Privacy Policy explains how Promptable, developed, owned, and operated by Dreamy Labs ("we," "us," or "our"), collects, uses, stores, shares, and protects your personal information when you interact with our platform.

This policy applies to all services offered through:

  • Our official website at https://promptable.space (the "Website");
  • Our mobile applications available on the Google Play Store (Package: com.promptable.app) and Apple App Store (the "Mobile App");
  • All related APIs, backend services, community features, and user interfaces (collectively, the "Platform" or "Service").

Promptable is a creative discovery and sharing hub for text prompts designed for third-party artificial intelligence (AI) image and video generation tools. By accessing, downloading, installing, or using Promptable, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with our policies, please do not access our Website or install our Mobile App.


2. Information We Collect

We collect information in several ways when you interact with Promptable. The types of data collected depend on your specific usage and whether you browse as a guest or sign in to an account.

2.1 Personal Information You Provide

When you create an account, customize your creator profile, submit prompts, or communicate with us, you may provide:

  • Account Credentials: Your email address and encrypted password (for email registration) or Google account profile identifier, name, and verified email address (for Google OAuth Single Sign-On).
  • Profile Information: Display name, unique username handle, biographical summary, avatar profile image, and optional social media links (Instagram, X/Twitter, Telegram, YouTube, TikTok).
  • User-Generated Content (UGC): AI prompt text recipes, prompt titles, descriptions, negative prompts, aspect ratio metadata, recommended AI tools/models (e.g., Midjourney, ChatGPT, DALL·E, Gemini, Flux, Runway, Kling), tags, category selections, and preview imagery uploaded to illustrate prompt outputs.
  • Interactions & Preferences: Saved/bookmarked prompts, likes, copy count events, creator followings, blocked user lists, and notification preferences.
  • Communications & Reports: Support inquiries, feedback, and moderation reports (including report reasons and optional explanatory notes).

2.2 Information Collected Automatically & Mobile Device Data

When you browse our Website or use our Mobile App, certain technical data is gathered automatically:

  • Device & Hardware Data: Device model, manufacturer, operating system version (Android / iOS), screen resolution, preferred language, internet service provider, and network connection type.
  • Approximate Location: Coarse geographic location derived from IP address or device timezone, utilized to comply with regional privacy regulations (such as European UMP consent forms) and optimize content delivery. We do not collect precise GPS location data.
  • Usage & Telemetry Data: Search queries, prompt view durations, feed navigation patterns, filter interactions, and feature engagement metrics.
  • Log Data: Server request timestamps, referring URLs, HTTP headers, and IP addresses used for security auditing and DDoS mitigation.

2.3 Mobile Device Permissions

The Mobile App may request specific system permissions on your device to enable core features:

  • Photos & Media Library: Required if you choose to upload custom avatar photos for your profile or sample preview images for submitted AI prompts. Access is only requested at the moment you initiate an upload.
  • Push Notifications: Required to deliver transactional alerts (such as prompt review approvals/rejections, follower updates, and product announcements). You can enable or disable push notifications at any time in the app's Settings.

2.4 Mobile Identifiers & Advertising Data

On Android and iOS devices, we and our advertising partners may collect mobile advertising identifiers (such as the Android Advertising ID / AAID or IDFA where permitted) to manage ad frequency, prevent fraud, and serve personalized or non-personalized advertisements via Google AdMob.


3. How We Use Your Information

We process your personal information strictly for legitimate business and operational purposes:

  • Core Service Delivery: To manage your user profile, authenticate your identity, publish and showcase your submitted prompts, power search indexing, and maintain your saved collections across devices.
  • Community Moderation & Safety: To review submitted prompts against our Content Standards, process community abuse reports, enforce user blocks, and prevent harmful, illegal, or NSFW content.
  • Communications & Notifications: To send critical account notices (security alerts, password resets, verification OTPs), push updates regarding prompt approval status, and respond to support inquiries.
  • Diagnostics & Stability: To detect, diagnose, and resolve software bugs, ANRs (Application Not Responding), native crashes, and performance bottlenecks via Sentry error monitoring.
  • Analytics & Optimization: To analyze aggregated usage trends, measure feature adoption, and improve the user experience via PostHog analytics.
  • Advertising & Free Tier Support: To display non-intrusive banner, native, and rewarded advertisements via Google AdMob and Google AdSense, keeping Promptable free for creators worldwide.
  • Legal Compliance & Rights Protection: To comply with applicable laws, respond to lawful law enforcement requests, enforce our Terms of Service, and defend our legal rights.

4. Third-Party SDKs & Service Providers

We integrate trusted third-party SDKs and service providers to operate, secure, and monetize our Platform. These providers process data under strict confidentiality agreements:

Service / SDKProviderData ProcessedPurpose
Google AdMob & UMPGoogle LLCAdvertising ID (AAID/IDFA), coarse IP location, ad interaction events, consent status.In-app advertising, rewarded ad credits, and European UMP consent management.
SupabaseSupabase Inc.Email, user ID (UUID), hashed credentials, profile data, avatar storage bucket files.User authentication (OAuth & Email), database storage, and secure token management.
SentryFunctional Software, Inc.Application crash logs, stack traces, device hardware specs, OS version, breadcrumbs.Crash diagnostics and stability monitoring. Auth headers are automatically sanitized.
PostHogPostHog Inc.Anonymized UI navigation, feature usage events, session metrics.Product analytics and UX optimization. Text inputs are masked during capture.
Expo & EAS650 Industries, Inc.Push notification device tokens, application build runtime identifiers.Push notification dispatch and application updates.
Google Analytics & AdSenseGoogle LLCWebsite cookies, browser client identifiers, page view telemetry.Web analytics and display advertising on the website.

5. Advertising & Consent Choices

Promptable displays advertisements to sustain free access for creators:

  • Personalized Advertising: Ads tailored to your interests based on device identifiers and browsing activity. In the European Economic Area (EEA) and the United Kingdom, personalized ads are served only with your explicit consent via Google's User Messaging Platform (UMP).
  • Non-Personalized Advertising: Contextual ads based on current app screen content without creating a user advertising profile.
  • Managing Your Ad Choices:
    • In-App Consent Management: You can review or revoke your European advertising consent anytime in the Mobile App via Settings > Ad & Privacy Choices.
    • Device-Level Opt-Out: On Android devices, you can reset your Advertising ID or opt out of personalized ads by navigating to Settings > Google > Ads or Settings > Privacy > Ads. On iOS devices, you can manage tracking permissions under Settings > Privacy & Security > Tracking.

6. Account Deletion & Data Purge Policy

In full compliance with Google Play Store Developer Policies and global privacy laws, we provide clear, accessible mechanisms for you to delete your account and all associated personal data.

6.1 In-App Account Deletion Workflow

You can delete your account directly inside the Mobile App at any time:

  1. Navigate to Settings and select Delete Account under the Account section.
  2. Complete the mandatory Identity Verification step (confirming your registered email address for Google SSO accounts or re-entering your account password for email accounts).
  3. Review and confirm the final deactivation notice.

6.2 30-Day Deactivation Grace Period & Restoration

Upon confirming deletion:

  • Your account is immediately deactivated, all active sessions and secure auth tokens are revoked, your push tokens are unregistered, and you are logged out.
  • Your profile, username, and private saved collections become inaccessible to other users.
  • We provide a 30-day grace period during which you may restore your account simply by signing back in with your original credentials.

6.3 Permanent Hard Purge Mechanism

If you do not restore your account within 30 days, an automated daily server purge permanently executes the following erasure:

  • Supabase Authentication: Your user identity record is permanently wiped from the authentication system.
  • Supabase Storage: All uploaded custom avatar files are permanently deleted from cloud storage buckets.
  • WordPress Backend Database: Your personal profile, biographical data, social handles, push tokens, and blocked user lists are completely deleted.
  • User-Generated Prompts: To protect community continuity and shared links, publicly published prompt recipes are disassociated from your personal identity and permanently reassigned to an anonymous community attribution, or permanently removed upon specific written request.

6.4 External Web-Based Deletion Request

If you do not have access to the Mobile App or prefer to submit a deletion request online, you can request full account and data erasure through either of the following channels:

We process all verified external deletion requests within 30 days of receipt.


7. Data Security & Storage

We implement robust technical and organizational measures to safeguard your personal data:

  • Encryption in Transit: All data transmitted between the Mobile App, Website, and backend servers is encrypted using modern TLS 1.3 cryptographic protocols over HTTPS.
  • Secure In-App Token Storage: Authentication tokens on mobile devices are stored securely in hardware-backed storage utilizing the Android Keystore system (via expo-secure-store) with AES-256 encryption.
  • Access Controls & Sanitization: Backend database access is restricted to authorized personnel. Telemetry and diagnostic tools automatically sanitize authorization headers and sensitive payload fields before transmission.

While we employ industry-standard safeguards, please note that no electronic transmission or storage system can be guaranteed 100% secure.


8. Children's Privacy

Promptable is not directed to children under the age of 13 (or under 16 in the European Union). We do not knowingly collect, solicit, or process personal information from children under 13.

If you are a parent or guardian and believe that your child has provided us with personal information without required parental consent, please contact us immediately at [email protected]. Upon verification, we will promptly delete the account and purge all associated personal data from our servers.


9. Your Global Privacy Rights

Depending on your geographic location, you possess specific legal rights concerning your personal data:

9.1 For Residents of the European Economic Area & United Kingdom (GDPR / UK GDPR)

Under the General Data Protection Regulation (GDPR), your rights include:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to Erasure / Right to be Forgotten (Art. 17): Request deletion of your personal data.
  • Right to Restriction of Processing (Art. 18): Request temporary or permanent suspension of data processing.
  • Right to Data Portability (Art. 20): Request your data in a structured, commonly used machine-readable format.
  • Right to Object (Art. 21): Object to data processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Revoke previously granted consent (including advertising consent) at any time.
  • Supervisory Authority: You have the right to lodge a complaint with your local Data Protection Authority.

9.2 For California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act as amended by the CPRA:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected, sources, and commercial purposes.
  • Right to Delete & Correct: Request deletion or correction of inaccurate personal information.
  • No Sale or Sharing of Personal Information: We do not sell your personal information. We do not share personal information for cross-context behavioral advertising without providing appropriate opt-out mechanisms.
  • Non-Discrimination: We will not discriminate against you in pricing or service quality for exercising your privacy rights.

9.3 For Residents of India (Digital Personal Data Protection Act - DPDPA 2023)

Under India's Digital Personal Data Protection Act, 2023:

  • Data Fiduciary: Dreamy Labs operates as the Data Fiduciary.
  • Data Principal Rights: You have the right to obtain a summary of your personal data, seek correction or completion of inaccurate data, request erasure, and access grievance redressal mechanisms.
  • Grievance Officer: Inquiries and grievances will be resolved within 30 days by our designated Grievance Officer. You also have the right to appeal to the Data Protection Board of India (DPBI).

To exercise any of these rights, please email us at [email protected] or visit our Contact Page. We will verify your identity and respond within 30 days.


10. Google API Limited Use Disclosure

Promptable's use and transfer of information received from Google APIs (such as Google OAuth authentication) adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data received through authentication is strictly limited to account creation and profile identity verification, and is never used to serve advertisements or transferred to data brokers.


11. International Data Transfers

Promptable is operated by Dreamy Labs from India, utilizing cloud infrastructure and service providers located in various jurisdictions including India, the United States, and the European Union. By using the Platform, you acknowledge that your information may be transferred across borders. We employ appropriate safeguards, including Standard Contractual Clauses (SCCs) and robust encryption, to ensure your personal data remains protected.


12. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect enhancements to our Mobile App and Website, emerging legal requirements, or evolving industry practices. When material updates are made, we will revise the "Last Updated" date at the top of this document and provide prominent notice via in-app alerts or website banners.

Your continued use of Promptable following the publication of an updated Privacy Policy signifies your acceptance of the revised terms.


13. Contact Information & Data Controller

If you have any questions, comments, or data privacy requests regarding this policy, please contact our Data Protection and Grievance team:

By accessing Promptable on the web or installing the Promptable mobile application, you acknowledge that you have read and agree to this Privacy Policy.