← home
privacy

privacy.

last updated 2026-07-30

short version: we collect what we need to run and improve the product, sell nothing, and accept deletion requests by email.

what we collect

seven kinds of data.

  • progress in localStorage. which chapters you opened, which steps you finished. anonymous. lives on your device unless you opt in to sync.
  • your email (optional). if you sign in for progress sync, join the email list, or contact support. used for magic links, opt-in updates, and replies — no password.
  • payment provider customer id + receipt. if/when you buy paid access. used to check your tier across devices and validate the purchase with the billing provider.
  • team roster and progress, if/when you are on a team plan. used for team-plan operations: seat usage, roster status, per-person progress, and review state for your team admin.
  • privacy-safe product analytics. page path, event name, coarse country/device, coarse visitor class (human, agent, or bot), and a daily rotating visitor hash. the durable analytics event contains no raw ip address, email, code, prompts, query strings, session replay, or full referrer urls. the class is derived from request headers and optional cloudflare bot fields already on the request. we do not store the raw user-agent or the agent header value.
  • short-lived signed-in presence. while you are signed in and active, the analytics request also refreshes a record containing your email, current page path, coarse country, and last-seen time. it expires after five minutes and is visible only in the owner console. anonymous visitors never get a named presence record.
  • prospective team contact records. after a direct business conversation, the owner may record a company, contact name/email, follow-up date, status, and notes so the conversation can be followed up. this does not create an account or subscribe the contact to marketing.
what we do with it

seven purposes.

  • sync your progress across devices when you sign in.
  • check whether your paid access is active, if/when you buy it.
  • email you a magic link, opt-in updates, or support replies.
  • show team admins cohort progress if/when you use a team plan.
  • understand which pages, lessons, and calls to action are working.
  • show the owner who is actively signed in for live support.
  • follow up on direct conversations about a team plan.

we rely on consent for opt-in marketing, on providing the service or contract for accounts, purchases, and teams, and on legitimate interests for product measurement, live support, security, and direct business follow-up. cloudflare hosts the service, and email and billing providers process only the data needed for those jobs.

what we don't do

no ad-tech. no fingerprinting.

  • we don't sell your data. ever.
  • we don't share it with advertisers, brokers, or partners.
  • no ad-tech analytics, cross-site fingerprinting, session replay, or targeted-ad pixels. cloudflare may also count basic page views for site health.
  • no marketing email unless you opt in. unsubscribe works.
  • no profiling. no targeted ads. no resale.
retention

different data, different clocks.

progress, email, and team-plan roster records are kept for the life of your account or team contract. if you delete your account, account-linked data is purged within 30 days. signed-in presence expires after five minutes. prospective-team records are kept while a conversation is active or useful for business follow-up, then deleted; the contact can ask for earlier deletion at any time. privacy-safe analytics events are kept for product measurement and are rolled up or purged when no longer useful. localStorage data lives on your device and is yours to clear at any time.

payment providers retain purchase records per their own policies and legal tax / audit requirements. that data is not used by us for ads, resale, or profiling.

your rights

export, delete, ask.

  • export. email us; we send your data as json within 14 days.
  • delete. email us; account and synced progress are purged within 30 days. if you appear only as a prospective team contact, we delete that lead record and its notes after verifying the request.
  • ask. any question about what we have on you — we answer.

gdpr / ccpa / similar applies if you live where it applies — use the same contact path.

children

promptdojo is not directed at children under 13. we don't knowingly collect data from anyone under 13. if you believe a child has signed up, email us and we'll delete the account.

changes

if this policy changes in a way that matters, we'll update the date at the top and notify subscribers by email. minor wording fixes ship without a notice.

contact

email a human.

questions, exports, deletions, anything else — write to [email protected]. a person reads it.