Privacy Policy
Effective date: July 17, 2026
Controller
The data controller is Digital Gold Technologies LLC (Wyoming, USA), operator of golden-prompts.com. Contact: support@golden-prompts.com.
Data we store
Your email and authentication information; prompts generated in the ateliers and the inputs that produced them; usage counts and plan status.
Legal basis for processing
We process your data on the following legal bases: performance of our contract with you (providing the account, generations and subscription you requested); our legitimate interests (preventing fraud and abuse, securing the service, and improving the product); your consent (where required, e.g. optional cookies); and compliance with legal obligations (tax, accounting and responding to lawful requests).
Fraud prevention
To prevent repeated free trials, automated abuse and fraudulent code redemptions, our server-side security records may include the account, IP address and a coarse privacy-preserving client marker. We do not collect browser user-agent strings. These records are used only for security and entitlement enforcement, never for advertising.
Payments
Payments are processed by Creem (Merchant of Record). Creem handles card data, tax calculation and remittance. We only receive customer and subscription identifiers.
Cookies
Essential cookies for authentication and session state. We do not run advertising trackers.
Data retention
Account data (email, authentication, saved prompts and usage counters) is retained while your account is active and deleted within 30 days of account deletion, except where a longer legal period applies (for example invoices and tax records kept by our Merchant of Record for up to 10 years). Fraud-prevention usage records and the canonical free-trial ledger are kept for no more than 12 months. IP addresses attached to creator-code redemption records are anonymised after 30 days. Raw product events are deleted after 180 days. Pending Team invitations expire after 30 days. Operational email-delivery logs and stranded queue payloads are deleted or anonymised after no more than 30 days. If an address unsubscribes, or is added to our suppression list following a bounce or complaint, we retain the minimum email-suppression record for as long as needed to honour that choice and protect deliverability; it is not used for marketing.
Security measures
We apply appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS/TLS) and at rest, hashed credentials, role-based access controls, row-level security on our database, least-privilege service keys, audit logging, and regular dependency and security reviews. Card data never reaches our servers — it is handled directly by Creem.
Privacy-first product analytics and feedback
For signed-in users, we record a limited set of product events so we can understand whether key features work: the event name, product surface, interface language, free or paid access status and timestamp. On the first app-open event in a browser session, we may also record first-party attribution values supplied in the landing URL (UTM source, medium and campaign) and the hostname of an external referring site; we do not store the full referrer URL or its query string. These product events never contain prompt text, prompt inputs, your IP address or your browser's user-agent. Raw product events are deleted after 180 days. If you voluntarily rate a saved prompt, we store your verdict, selected issue and any optional model name or note you submit, linked to that saved prompt and your account. Feedback does not create another copy of the prompt text and is removed when the linked prompt or account is deleted. We do not use advertising trackers.
Your rights
You can request export or deletion of your account data at any time by writing to support@golden-prompts.com.
Contact
support@golden-prompts.com