Privacy Policy

Prizom Generative Prompt Engineering Registry Data Auditing & Compliance

Last Updated: June 26, 2026

Sections:
Prizom ("we", "our", or "us") is dedicated to protecting the privacy, identity, and personal records of our prompt creators. This Privacy Policy details how we collect, process, index, and safeguard your account parameters, cloud metadata, files, and interactions across our Supabase servers and cloud integrations.

1. Information We Collect

To run our open prompt registry and dynamic remix engine, we process various data types depending on your platform activities. We collect both information you directly provide and analytics triggered during usage.

This includes registration inputs, prompt text structures, image files, social telemetry, saved collections configuration, and device diagnostic records necessary for platform stability.

2. Account & Authentication Data (Supabase Auth)

All creator accounts are registered and secured using **Supabase Authentication** pipelines.

When establishing a profile, we collect your verified email address, chosen username, display name, and avatar image. Passwords are encrypted instantly on Supabase's secure infrastructure. Prizom engineers never store, see, or transmit plain-text passwords or hashes on external nodes. Secure access tokens (JWT) are dispatched to verify your identity on subsequent refreshes.

3. Usage Analytics

To optimize searching and highlight trending workflows, Prizom logs user interactions.

We track specific metrics including prompt page views, copy actions (when you click the clipboard copy button on a prompt text block), prompt star ratings, and following events. This analytics data is stored securely in our databases to control feed ordering algorithms. We do not drop analytics tracking cookies on guests without active opt-in consent.

4. Cookies & Session Tracking

We use standard browser cookies, LocalStorage objects, and secure session identifiers.

These trackers are used strictly to retain your session state (preventing continuous logouts) and store minor UI preferences (like sidebar collapse states). You can configure your browser to reject cookies, though doing so will restrict Supabase from logging you into active creator dashboards. For more details, see our dedicated Cookie Policy.

5. Uploaded Content Handling (Cloud Storage)

When you upload an AI prompt template, the textual structures (the prompt text, negative variables, settings) are written to our relational databases.

Any output images or illustrative assets you submit are securely transmitted and stored inside dedicated public **Supabase Storage Buckets**. By publishing content to public tables, you acknowledge that all associated prompt texts and output files are accessible to global web crawlers and public search queries.

6. Profile Visibility

By design, Prizom creator profiles are public index pages.

Any details you fill out in your settings (including your display name, creator username, avatar graphic, personal bio description, and social profile links) are visible to all visitors. We advise against placing private, identifying contact numbers inside public biography fields.

7. Saved Collections Data

When you bookmark prompts into aesthetic folders, this metadata is written to Prizom database associations.

Saved collections catalog prompt linkages and are stored within your profile. By default, these collection lists are configured according to your chosen settings, allowing you to organize AI workflows cleanly.

8. Remix & Interaction Data

Prizom's signature remix engine logs parent prompt relationships.

When you click the "Remix" button, our database tracks the origin prompt ID to establish the genetic lineage. This relationship, including your creator username and the linked parent profile avatar, is published to the public prompt details page to acknowledge dual attribution.

9. How Data Is Used

We process gathered parameters to: (i) administer and secure your creator profile; (ii) index prompts to facilitate fast search results; (iii) deliver trending analytics; (iv) verify system safety and block injection payloads; and (v) resolve user support requests submitted via our contact forms.

10. Lawful Bases for Processing (GDPR Compliance)

If you reside within the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following lawful bases:

  • Contractual Necessity: To create your account, manage your profile, and host your prompt registries.
  • Consent: For non-essential tracking cookies and marketing analytics, which you can withdraw at any time.
  • Legitimate Interests: To optimize feed ordering, secure the platform, prevent spam, and enforce RLS controls.
  • Legal Obligation: To satisfy corporate records audits or answer lawful subpoenas.

11. Data Sharing Practices

**Prizom does not sell, rent, or trade your personal information or prompt metadata to third-party brokers.**

We share data exclusively with trusted third-party cloud infrastructure vendors (such as Supabase for core databases and storage buckets) to host our digital platform, and under statutory obligations if requested by law enforcement to address fraud or safety issues.

12. Third-Party Integrations

Prizom's search canvas integrates multiple cloud modules, including:

  • Supabase: For relational tables, file storage nodes, and auth handlers.
  • Cloudinary: For responsive profile avatar storage.

13. Security Practices

We prioritize data safety. Prizom enforces standard enterprise security rules, including:

  • Enforced SSL/TLS 1.3 encryption protocols for all data in transit.
  • Strict Supabase Row-Level Security (RLS) filters preventing creators from modifying or editing other engineers' prompt entries.
  • AES-256 cloud encryption parameters for data at rest.

14. Data Retention

We retain your profile data, database entries, and saved collections for as long as your account remains active.

If you submit a formal account erasure trigger, your database entries, files, and credentials enter a 15-day recovery window. After this cooling-off period, data is deleted from active tables. Backup archives are overwritten naturally within a 90-day retention cycle.

15. International & DPDP Compliance

Prizom operates globally. For residents of India, we process your personal data in accordance with the **Digital Personal Data Protection (DPDP) Act, 2023**.

Under the DPDP Act, you possess the Right to correction, right to erasure, and right to grievance redressal. You can appoint a **Consent Manager** to manage or withdraw your consent. If you wish to withdraw consent or exercise your rights under the DPDP Act or GDPR, please contact our Grievance Officer detailed in Section 20.

16. Children’s Privacy

Prizom is not intended for minors.

In accordance with the India DPDP Act 2023 (Section 9), we do not knowingly process personal data of children under **18 years of age** in India without verifiable parental consent. For US and global residents under COPPA, we do not knowingly collect records of children under 13. If we learn that we have inadvertently collected data of a minor without appropriate consent, we will delete the account immediately.

17. User Rights & Controls

You retain extensive rights over your information, including the ability to: (i) access and export your profile and prompt database entries; (ii) edit or update your display parameters; and (iii) configure active visibility settings for folder collections.

For California residents, under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), your rights also include the Right to Know what personal information we collect, the Right to Delete that information, the Right to Opt-Out of the sale or sharing of personal information, and the Right to Non-Discrimination for exercising your privacy rights.

18. Account Deletion Requests

You can trigger an account deletion request inside your user settings portal.

This will schedule your account for permanent deletion after 15 days, after which a SQL delete trigger cleanly wipes your profile rows, followers, saved folders, and public prompt template associations from our active tables.

19. Updates to Policy

We may update this Privacy Policy from time to time. When modifications are performed, we will publish the adjusted policy here and revise the "Last Updated" metric at the top of the portal.

20. Contact & Grievance Desk

If you have inquiries, complaints, seek to withdraw consent, or wish to exercise your data subject rights, please email our privacy Operations desk or file a ticket with our Grievance Redressal Desk. Under the Indian IT Rules, we will acknowledge any complaint within 24 hours and resolve it within 15 days of receipt.

Privacy & Data Protection Desk

Email: privacy@prizom.in

Address: Prizom operates remotely from India. The registered office address will be updated after company incorporation.

Grievance Redressal Desk (India)

Grievance Officer: Darshan Vaghela, Founder

Email: grievance@prizom.in

Address: Prizom operates remotely from India. The registered office address will be updated after company incorporation.