Privacy Policy for Prompt Helio

Last Updated: January 24, 2026

Thank you for reading this post, don’t forget to subscribe!

Version: 1.0.0

1. Introduction

Prompt Helio, we respect your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome extension “Prompt Helio” (the “Extension”).

2. Information We Collect

A. Personal Information

When you create an account to use synchronization or cloud features, we collect:

  • Email Address: Required for account creation and password recovery.
  • Authentication Data: If you log in via Google or Facebook, we receive authentication tokens and basic profile information (email, ID) authorized by those providers.
  • User ID: A unique identifier assigned to your account in our database.

B. User Content

  • Prompts & Notes: Text prompts, image generation prompts, and notes you explicitly save.
  • Chat Logs: Saved conversations from ChatGPT that you choose to archive.
  • Generated Images: URLs of images generated or saved via the extension.
  • This content is stored in your browser’s local storage and, if you are logged in, synced to our secure cloud database (Supabase).

C. Technical & Usage Data

  • Browser Storage: We use chrome storage local and chrome.storage.sync to store your preferences, themes, and temporary data.
  • Interaction Data: We interact with the active tab on chat.openai.com and chatgpt.com to insert prompts or save content, but we do not passively track your browsing history on other websites.

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: To provide core features like prompt management, note-taking, and theme application.
  • Synchronization: To sync your prompts and settings across multiple devices using our cloud database.
  • AI Enhancement: To process your requests using AI services (e.g., Google Generative AI) for optimizing prompts.
  • Authentication: To verify your identity and secure your saved data.

4. Third-Party Services and Data Sharing

We utilize specific third-party services to operate the Extension. Data is shared only as necessary for functionality:

  • Supabase (Database & Auth):
    • Purpose: We use Supabase to host our database and manage user authentication.
    • Data Shared: Email addresses, encrypted passwords, and synced user content (prompts, notes).
    • Security: Data is protected by Row Level Security (RLS) policies, ensuring users can only access their own data.
  • Google Generative AI (Gemini):
    • Purpose: To provide AI-powered prompt enhancements.
    • Data Shared: The specific text prompts you submit for enhancement are sent to Google’s API.
  • Google & Email (OAuth):
    • Purpose: Optional login methods.
    • Data Shared: Authentication tokens and email addresses are exchanged to verify identity.

5. Data Security

  • Encryption: Communications with our servers are encrypted using TLS/SSL (HTTPS).
  • Access Control: We implement strict Row Level Security (RLS) in our database, meaning your private prompts and data cannot be accessed by other users.
  • Local Storage: Data stored locally on your device is subject to your browser’s security protections.

6. User Rights

You have the following rights regarding your data:

  • Access & Portability: You can export your stored data (local and synced) to a JSON file at any time via the extension’s settings.
  • Deletion: You may delete specific prompts or notes directly within the UI. You can also request full account deletion, which will remove your data from our servers.
  • Visibility: You can toggle specific image prompts to be “Public” or “Private.” Private items are only visible to you.

7. Permissions Usage

The extension requires specific permissions to function:

  • storage: To save your settings and prompts.
  • activeTab: To analyze the current chat page for inserting prompts.
  • identity: To facilitate secure login via Google/Facebook.
  • host_permissions: Access is restricted strictly to OpenAI (for functionality) and our backend services (supabase.co, prompt-helio.vercel.app).

8. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

[Support@prompthelio.com]