Master Prompt ("we", "our", or "the application") is a tool that helps you generate structured, state-machine system prompts. This Privacy Policy explains how we handle information when you use our application.
Our core commitment: we do not store your personal API keys
We do not collect, store, or retain your LLM provider API keys on our servers. When you enter an API key in Settings, it is saved locally in your browser only (using your device's local storage).
Before being saved, your API keys are protected using encryption and hashing so they are not stored in plain text on your device. A one-way hash may also be used internally for fingerprinting and integrity checks without exposing the original key.
API keys are sent to our application server only at the moment you run a generation, solely to forward your request to your chosen AI provider (OpenAI, Anthropic, Google, or Groq). They are used in memory for that request and are not written to disk on the server.
Information we do not collect
- API keys (not persisted on our servers)
- Payment or billing information (the app does not process payments)
- Precise geolocation data
- Advertising identifiers or cross-site tracking data
Where your data is stored
Without signing in: your settings, generation history, custom templates, and usage stats are stored locally in your browser (local storage). They stay on your device and are not sent to our servers except when you run a generation (prompt text only, as described below).
When signed in: your settings, history, templates, usage, and workspaces are stored in our MySQL database, linked to your account. When you sign in after using the app as a guest, locally stored data may be synced once to your account and then removed from local storage.
API keys are never stored in MySQL or any server database. They remain in encrypted browser storage only, regardless of whether you are signed in.
Information processed locally
The following may be stored on your device:
- API keys — encrypted in browser local storage, as described above (never synced to the server database)
- Draft ideas — auto-saved in browser local storage for convenience
- Theme preference — dark or light mode stored in browser local storage
- Settings, history, templates, and usage — stored in browser local storage when you are not signed in; synced to your account database when you sign in
Account sign-in (optional)
Sign-in is available only through Google or GitHub. When you authenticate, we receive basic profile information (such as your name and email address) from the OAuth provider solely to authenticate you and enable workspace features. We do not sell this information to third parties.
Third-party AI providers
When you generate a prompt, the text you submit is sent to the AI provider you select. That provider's own privacy policy governs how they handle your data. We encourage you to review the policies of OpenAI, Anthropic, Google, and Groq before use.
Cookies and sessions
If you sign in, a session cookie may be set to keep you authenticated. This cookie does not contain your API keys. You can sign out at any time to clear your session.
Data security
We use industry-standard practices including HTTPS in production, encrypted local storage for API keys, and rate limiting on API routes. No method of transmission over the Internet is 100% secure; you use the service at your own discretion.
Your rights
You may:
- Delete API keys by clearing your browser's local storage for this site
- Remove saved settings by clearing site data in your browser
- Sign out to end your authenticated session
- Stop using the application at any time
Children's privacy
Master Prompt is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the most recent revision.
Contact
If you have questions about this Privacy Policy, please contact us through the repository or support channel associated with your deployment of Master Prompt.