PromptAura Logo PromptAura
Back to Home
Privacy Policy

PRIVACY POLICY FOR PROMPTAURA

A transparent explanation of how PromptAura collects, uses, and protects your information.

Effective: July 22, 2026 Last Updated: July 22, 2026
Contents
Section 01

Introduction

Welcome to PromptAura. This Privacy Policy explains how the PromptAura Chrome extension ("Extension"), developed and operated by PromptAura ("we," "us," or "our"), collects, uses, stores, and protects your information when you use our service.

PromptAura is a Chrome extension that helps users enhance, refine, and polish their text prompts and messages across various websites and AI platforms using AI-powered assistance via Google's Gemini API. The extension provides three core features: Refine (an AI-powered prompt improvement wizard), Quick Polish (one-click prompt cleanup), and Chat Assist (AI-crafted message composition).

By installing and using the PromptAura extension, you agree to the practices described in this Privacy Policy. If you do not agree, please uninstall the extension.

Section 02

How PromptAura Processes Your Data

2.1 The AI Processing Pipeline

All AI processing (Refine, Quick Polish, Chat Assist) routes through PromptAura's secure backend servers. When you trigger a feature:

1

The text in your active text field on a supported website is read by the extension's content script, running locally in your browser.

2

The text is transmitted over an encrypted HTTPS connection to PromptAura's backend servers. If you have provided your own Gemini API key, it is included in this same encrypted request.

3

Our backend servers forward the request to Google's Gemini API. The AI-generated response is returned to the extension.

4

Our backend records service usage metadata (platform category, feature used, token counts, credit consumed, timestamp) for billing and monitoring. A separate AI process also extracts abstract style preferences for the Live Memory feature (see §2.3).

5

The refined or polished text is returned to the extension and inserted into the text field on your screen.

Note: All AI requests are processed server-side regardless of whether you provide your own API key. This enables Live Memory, prompt history, and credit tracking.

2.2 Your Gemini API Key (BYOK — Bring Your Own Key)

PromptAura allows you to provide your own Google Gemini API key to use with the service. You can provide your key in two ways:

  • Manual entry: During onboarding, or at any time via the extension's Settings panel, you can paste your Gemini API key directly into the provided input field. This is the default method and requires no additional permissions.
  • Auto-detection (optional): With your explicit permission, the extension can assist you in setting up your key by detecting it from the Google AI Studio website. This feature is disabled by default and must be enabled by you — see §2.4.

Regardless of how you provide your key:

  • Your key is stored locally in your browser's secure extension storage on your device.
  • When a feature is triggered, the key is transmitted to our backend over HTTPS to authenticate with Google's Gemini API on your behalf.
  • Your key is used in server memory only for the duration of that single request and is never written to our database. It is discarded as soon as the request completes.

2.3 Live Memory

After each successful AI interaction, a background process analyzes the prompt and response to identify abstract writing-style preferences (e.g., a preference for concise answers or bullet-point formatting). These are called memory traits.

  • Memory traits are short, abstract summaries — not verbatim copies of your prompts.
  • They are stored on PromptAura's servers linked to your account to personalize future AI responses.
  • You can view, manage, and permanently delete all memory traits at any time through the extension's Memory settings panel.
  • You can disable Live Memory entirely from extension settings.

2.4 Optional API Key Auto-Detection from Google AI Studio

PromptAura includes an optional, user-initiated feature that assists with API key setup by detecting your Gemini API key from the Google AI Studio website (aistudio.google.com).

  • This feature is disabled by default. If you decline it during onboarding, your key will not be auto-detected from any website at any time.
  • When you choose to enable it, the extension reads only Gemini API key strings from the AI Studio page. No other page content is accessed or transmitted.
  • The detected key is saved only to your local browser extension storage.
  • You can revoke this permission at any time via Chrome Settings → Extensions → PromptAura → Permissions.
Section 03

Information We Collect

3.1 Account and Authentication Data

  • Email address — to identify your account, manage your session, and communicate with you.
  • Display name — collected during registration or Google Sign-In for account personalisation.
  • Password (email registration only) — transmitted over HTTPS and immediately hashed. Plain-text passwords are never stored or logged.
  • Google profile data (Google Sign-In only) — email address and name only. We do not receive access to Google Drive, Gmail, or any other Google service.
  • Session tokens — stored in your browser's secure extension storage to authenticate your requests.

3.2 Gemini API Key (BYOK)

  • Stored locally in your browser's secure extension storage.
  • Transmitted to our backend over HTTPS per request to authenticate with Google's Gemini API.
  • Never permanently stored in our database — held in server memory only for the duration of each request.

3.3 Text Prompts

When you trigger a feature, the text you have written in your active field is transmitted to our backend for AI processing. Our backend stores metadata (platform category, feature, token counts, credit consumed, timestamp) for billing. Your prompt and AI response are also retained in the Prompt History feature.

Prompt History: PromptAura stores prompt input and AI output to power the in-extension History feature. For Free plan users, history is retained for 30 days and then automatically deleted. You may request earlier deletion at any time.

3.4 Usage and Billing Data

  • Credit balance and consumption — tracked per account to enforce plan limits.
  • Aggregate usage summaries — token counts and feature usage per day.
  • Subscription plan status — Free, Plus, or Pro tier.

3.5 Anonymous Analytics Data

  • A randomly generated anonymous identifier (UUID) stored in your browser's local extension storage — not linked to your account or email.
  • A session identifier that refreshes after inactivity.
  • Event names describing which feature was triggered. No prompt text, email address, or personally identifiable information is ever included in analytics data.

3.6 Device-Only Local Settings

Stored exclusively in your browser's local extension storage and never transmitted to our servers:

  • Theme preference (dark or light mode)
  • Last detected platform category
  • Onboarding completion status
  • Feature preference flags set by your in-extension choices

3.7 Live Memory Traits (Server-Side)

Abstract writing-style preference summaries stored on our servers linked to your account. These are AI-generated summary phrases, not copies of your messages, and are fully deletable at any time.

Section 04

Chrome Web Store Limited Use Policy Compliance

PromptAura complies with the Chrome Web Store User Data Policy, including all Limited Use requirements.

Our Limited Use Commitment: All information obtained through PromptAura's access to Chrome APIs and supported websites is used only to provide and improve the PromptAura features that are clearly visible to the user.

We specifically commit that we do not:

  • Transfer user data to third parties, except where strictly necessary to provide core AI processing via Google's Gemini API on your behalf
  • Use or transfer data for purposes unrelated to the PromptAura service
  • Use or transfer data to determine creditworthiness or for lending purposes
  • Sell user data to any third party
  • Use user data to serve advertisements

The extension reads text from websites only from the specific input field you are actively composing in, and only when you explicitly activate a PromptAura feature. The extension never reads page content passively or in the background.

Section 05

Information We Do NOT Collect

  • We do not read or monitor your browsing history or track which websites you visit.
  • We do not monitor text as you type. The extension reads text only when you explicitly activate a PromptAura feature.
  • We do not access your Gmail inbox, sent messages, or email history — only the specific message you are composing when you activate a feature.
  • We do not access your WhatsApp or Telegram conversation history — only the message currently being composed.
  • We do not permanently store your Gemini API key in our database.
  • We do not sell, rent, or trade your personal data to any third party.
  • We do not use your data to serve targeted advertisements.
  • We do not collect payment card numbers or sensitive financial data — payments are handled entirely by our contracted payment service provider.
  • We do not access Google AI Studio unless you have explicitly enabled the optional auto-detection feature.
  • We do not make direct AI API calls from the extension — all requests route through our secure backend servers.
Section 06

How We Use Your Information

DataPurposeLegal Basis (GDPR)
Email address & nameAccount creation, authentication, communicationPerformance of Contract
Hashed passwordSecure authentication onlyPerformance of Contract
Session tokensKeeping you signed in; authorizing API requestsPerformance of Contract
Prompt text (in transit)AI processing via Gemini API to produce the refined output you requestedPerformance of Contract / Consent
Prompt history (stored)Powering the History feature; 30-day retention for Free usersPerformance of Contract
BYOK API key (in transit)Authenticating with Google's Gemini API on your behalf per requestPerformance of Contract
Credit & usage dataEnforcing plan limits, billing, capacity planningPerformance of Contract / Legitimate Interests
Live Memory traitsPersonalizing AI responses to match your writing preferencesConsent (opt-in; disableable)
Anonymous analyticsUnderstanding feature usage to guide product improvementsLegitimate Interests
Section 07

Data Sharing & Third Parties

We do not sell your personal data. We share data only with the service providers listed below, and only to the minimum extent required to operate PromptAura:

Service ProviderPurposeData InvolvedPrivacy Policy
Google LLC — Gemini APIAI text generation and refinementYour prompt text; your API key (if provided)Google Privacy Policy
Google LLC — Sign-InAccount authenticationEmail address, display name onlyGoogle Privacy Policy
Google LLC — AnalyticsAnonymous product analytics (via server-side proxy; see §7b)Anonymous identifier, event name only — no personal dataGoogle Privacy Policy
Cloud Infrastructure ProvidersSecure hosting for our backend servers and databasesAll data processed by our backend passes through our contracted cloud infrastructureAvailable on request

We may disclose information if required by law, court order, or governmental authority, or if necessary to protect the safety of any person, address fraud, or enforce our legal rights.

Section 7b

Analytics

PromptAura uses Google Analytics 4 (GA4) for anonymous product analytics. We use a server-side proxy architecture so that our analytics credentials are never included in the extension's code or sent to your browser.

How It Works

  • The extension generates a random anonymous identifier (UUID) stored only in your browser's local extension storage. It is not connected to your account or email.
  • When an event occurs, the event data (event name, anonymous identifier, session identifier) is sent to a proxy endpoint on our backend over HTTPS.
  • Our backend forwards the event to Google Analytics. Analytics credentials reside only in server-side environment configuration and are never sent to your browser.
  • Analytics event data never contains prompt text, your email address, or any other personal information.

What We Track

  • Which features are activated (event name only, not the content used)
  • General engagement duration within the extension
  • Platform category (never a specific URL)

How to Opt Out

Use any standard browser privacy extension or ad blocker to block analytics traffic. The extension will continue to function normally.

Section 08

Websites Where PromptAura Operates

PromptAura's content scripts are active on the following websites. The extension reads text only from the specific input field you are composing in, and only when you explicitly trigger a feature. It does not passively monitor, record, or transmit any other content.

AI Chat & Research Assistants
🤖 ChatGPT
🧠 Claude
✨ Google Gemini
🔍 Perplexity AI
📒 NotebookLM
🌟 Emergent Mind
📚 Elicit
🔬 Consensus
🐇 Research Rabbit
🗺 Litmaps
Creative & Development Tools
⚡ Bolt.new
💻 Replit
🔮 v0.dev
❤ Lovable.dev
🎫 Gamma
🎨 Figma
🖌 Canva
🎬 Runway ML
🎵 Suno AI
🔊 ElevenLabs
Communication & Productivity
📧 Gmail
💬 WhatsApp Web
✈ Telegram Web
💼 LinkedIn
📝 Notion
Google AI Studio (Optional): Access to Google AI Studio is an optional permission that is not active by default. It is requested only if you choose to use the API key auto-detection feature described in §2.4. You can revoke this permission at any time from Chrome's extension settings without affecting any other feature.
Section 09

Chrome Permissions

PermissionReason Required
activeTabTo interact with the tab you are currently using when you trigger a feature — to read text from and write the refined text back into the active input field.
sidePanelTo display the PromptAura side panel, which hosts the Refine wizard, prompt history, memory management, and account settings.
tabsTo open the side panel on the current tab and, when the optional Google AI Studio feature is enabled, to navigate to that page.
storageTo save your API key, session tokens, settings, and preferences securely in your browser's extension storage.
identityTo support Google Sign-In. Only your email and display name are accessed; no access to any other Google service is requested.
scriptingTo support the optional Google AI Studio feature by injecting a helper script on that page when you have explicitly enabled the feature.
Host Permissions (supported sites in §8)To inject the extension's interface into supported websites. The extension reads only from the active input field, only when you trigger a feature.
aistudio.google.com (Optional)An optional, user-initiated permission for API key setup assistance. Only active if you choose to enable it. Revocable at any time without affecting other features.
Section 10

Data Storage & Security

Local Storage (Your Device)

  • Data stored in your browser's extension storage is managed by Chrome's secure extension storage APIs, isolated from websites and other extensions.
  • Your API key and session tokens are stored using these secure browser APIs, not in general browser cookies or localStorage.

Server-Side Storage

  • Account data is stored in a secure relational database on industry-standard cloud infrastructure.
  • Prompt history and memory traits are stored in a secure document database on industry-standard cloud infrastructure.
  • All communication between the extension and our servers, and between our servers and third-party APIs, uses TLS encryption (HTTPS).
  • Passwords are processed using a strong one-way cryptographic hashing algorithm. Plain-text passwords are never stored or logged.
  • Authentication uses short-lived access tokens combined with refresh tokens that automatically rotate on use.

Security Controls

  • Encrypted Transmission — all data in transit uses TLS encryption.
  • Message Origin Verification — the extension validates the origin of all internal messages to ensure they come from within the extension itself.
  • Request Scoping — the extension's background service worker communicates only with an authorized set of server endpoints.
  • Rate Limiting — all backend API endpoints enforce rate limits to prevent abuse.
  • Content Security Policy — extension pages enforce strict Content Security Policies to prevent unauthorized script injection.
  • Credential Isolation — all service credentials are stored only in server-side environment configuration and are never exposed to the browser.

No system can guarantee complete security. If you believe your account has been compromised, please contact us immediately at promptaura.contact@gmail.com.

Section 11

Data Retention

Data TypeWhere StoredRetention Period
Gemini API keyDevice + server memory (per-request only)Device: until you remove it, sign out, or uninstall. Server: discarded immediately after each request.
Prompt history (input + AI output)Our backend serversFree plan: 30 days, then automatically deleted. Paid plans: per plan terms. Deletable on request anytime.
Live Memory traitsOur backend serversUntil you delete them via settings or request account deletion.
Account data (email, name, hashed password)Our backend serversUntil you request account deletion.
Session tokensDevice (extension storage)Until sign-out or token expiry. Tokens rotate automatically on use.
Credit & usage dataDevice + our backend serversDevice: per session. Server: retained for account lifetime for billing.
Anonymous analytics identifierDevice (extension storage)Until the extension is uninstalled or storage is cleared.
Theme preference & local settingsDevice (extension storage)Until changed by you or the extension is uninstalled.
Section 12

Your Rights

Under GDPR (EEA and UK Users)

  • Right of Access — Request a copy of personal data we hold about you.
  • Right to Erasure — Request deletion of your account and all associated data.
  • Right to Portability — Request your data in a machine-readable format.
  • Right to Object — Object to processing based on legitimate interests (e.g., analytics).
  • Right to Rectification — Request correction of inaccurate personal data.
  • Right to Restrict Processing — Request we limit processing in certain circumstances.

Under CCPA (California Users)

  • Right to Know — Know what personal data is collected and how it is used.
  • Right to Delete — Request deletion of your personal information.
  • Right to Opt-Out of Sale — We do not sell personal data; this right is inherently fulfilled.

Under India DPDP Act (Indian Users)

  • Right to Information — Know what personal data is processed and for what purpose.
  • Right to Correction and Erasure — Request correction or deletion of your personal data.
  • Right to Grievance Redressal — Contact us to raise any data-related concern.
  • Right to Nominate — Nominate a person to exercise your rights in case of death or incapacity.

To exercise any of these rights, contact us at promptaura.contact@gmail.com. We will respond to all verified privacy requests within 30 days.

Section 12b

Your Controls & Choices

What You Can DoHow
Delete your prompt historyEmail promptaura.contact@gmail.com. We will delete all stored history linked to your account within 30 days.
Delete all Live MemoryExtension side panel → Memory → Delete All Projects. Immediately and permanently deletes all memory traits on our servers.
Disable Live MemoryExtension → Settings → Memory Settings → Disable. No further extraction will occur.
Remove your API keyExtension → Settings → Remove API Key, or sign out. Immediately clears the key from your device storage.
Revoke the optional AI Studio permissionChrome Settings → Extensions → PromptAura → Site permissions → Remove AI Studio. Takes effect immediately.
Sign outExtension → Settings → Sign Out. Revokes your session and clears account-linked data from your device.
Delete your accountEmail promptaura.contact@gmail.com. We will permanently delete your account and all server-side data.
Opt out of analyticsUse a browser privacy extension to block analytics network requests. The extension functions normally without analytics.
Section 13

Legal Basis for Processing (GDPR)

  • Performance of a Contract — Processing your prompts to deliver AI results; managing your account; authenticating sessions; enforcing plan credits and billing.
  • Consent — Accessing the input field you are composing when you explicitly trigger a feature; extracting Live Memory traits (disableable at any time); accessing Google AI Studio when you have enabled the optional feature.
  • Legitimate Interests — Operating, securing, and improving the PromptAura service; anonymous product analytics; preventing abuse; ensuring service availability.
Section 14

Children's Privacy

PromptAura is not directed at children under the age of 13 (or under 16 where required by applicable law, including GDPR). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child below the applicable minimum age, we will delete that data promptly.

If you believe a child has provided us with personal information, please contact us at promptaura.contact@gmail.com.

Section 15

Contact Information

PromptAura
Email: promptaura.contact@gmail.com
Website: https://promptaura.in

We aim to respond to all privacy-related requests within 30 days of receiving them.

Section 16

Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our extension's features, data practices, or applicable legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this policy and, where reasonably practicable, notify you through the extension interface or the Chrome Web Store listing.

Your continued use of the extension after a revised policy takes effect constitutes your acceptance of the updated terms.

Section 17

Governing Law

This Privacy Policy is governed by the laws of India. Where applicable, local data protection laws — including the General Data Protection Regulation (GDPR) for EEA and UK users, and the California Consumer Privacy Act (CCPA) for California users — also apply and take precedence to the extent they provide additional protections.