What we store
- Your account. Your email address, and your name and picture if you sign in with Google or GitHub.
- Your work. Prompts, bloks, versions and test results.
- Your models. The label, provider, model name, address and prices of each model you add, and its key, encrypted, as described below.
- Your plan. Whether you are on Free or Performance, and a reference to your Stripe customer record if you pay.
All of it lives in a Postgres database hosted by Neon, through Vercel.
Your prompts are private
Every prompt and version is visible only to you. Nothing becomes public unless you publish a share page, and you can take that page down at any time. We do not sell your content and we do not use it to train models.
Your models and keys
Keys for hosted providers are encrypted at rest with AES-256-GCM and bound to the address they were saved for. They are decrypted only to check them, list the provider’s models and run your own prompts on the provider you chose, and they are never written to logs. When you run a prompt on a hosted model, it goes from our server to that provider with your key, and the provider’s own privacy policy applies to it.
A model on your own computer or network (Ollama, LM Studio, or a custom address you mark as running in your browser) is called straight from your browser. Its prompts and replies never pass through our servers, and a key for it is kept only in that browser; we store the model’s label and address so it shows up in your list. Browsers differ in what they can reach: Chrome and Edge reach models anywhere on your network after asking you once, Firefox reaches models on the same computer, and Safari needs the model served over https.
Signing in
You sign in with a link sent by email (delivered by Resend), or with Google or GitHub. A sign-in lasts 30 days, kept in a cookie that exists only to keep you signed in. We use no advertising cookies.
Analytics and errors
We count page views and product events with PostHog in cookieless mode, so it sets no cookies, and the text of your prompts is never sent to it. When something breaks, an error report goes to Sentry. Request bodies and anything shaped like an API key are removed before a report leaves our servers.
Payments
When Performance is on sale, payment goes through Stripe Checkout with Managed Payments. Stripe, through Link, is the merchant of record: it collects your payment details and handles tax, receipts and refunds. Your card number never reaches us.
Who helps us run 41prompts
- Vercel hosts the site and the app.
- Neon hosts the database.
- Resend delivers sign-in emails.
- Google and GitHub, if you sign in with them.
- PostHog for analytics and Sentry for error reports.
- Stripe for payments.
- The model providers you add (for example OpenAI, Anthropic, Google or OpenRouter), only for the checks and runs you start with your own keys.
Export and deletion
You can export everything at any time from Settings, as Markdown and JSON in one .zip file. Deleting your account removes everything straight away: prompts, versions, saved models, keys and sign-ins. A prompt you delete on its own is removed for good by a daily cleanup once it has been deleted for 24 hours.
Changes
If this page changes, we will update the date at the bottom of it. If a change affects how your data is handled, we will also tell you by email.
Contact
Questions about your data go to connect@mail.41prompts.ai.