← BACK TO HOME
Privacy Policy — PromptMatrix
LAST UPDATED: AUGUST 15, 2026 · VERSION 1.1.0
At PromptMatrix ("we", "our", or "us"), we value data sovereignty and security. This Privacy Policy details our practices regarding information collection, storage, encryption, and protection across our web presence, managed cloud APIs, and developer tooling.
Zero AI Model Training Guarantee: PromptMatrix will never use your proprietary prompts, variables, system persona instructions, or evaluation outputs to train, fine-tune, or benchmark public or proprietary AI models.
1. Data We Collect
- Account & Auth: Email address, hashed credentials (bcrypt), name, and organisation identifiers.
- Prompt Registry Metadata: Prompt keys, version tags, environment bindings (dev/stg/live), variable schemas, and audit logs.
- Encrypted Secrets (BYOK): Third-party LLM evaluation API keys (OpenAI, Anthropic, Gemini, Groq, Mistral) are encrypted at rest using AES-256-GCM.
- Billing Information: Payments are processed directly by Razorpay. We do not receive or store credit card numbers; we receive only tokenized payment IDs, billing email, and plan status.
- Operational Telemetry: Anonymized request volume counters, serving latency metrics, and error rates to enforce rate limits and optimize edge caches.
2. Purpose & Lawful Basis for Processing
We process data to deliver the core services of prompt governance under the lawful basis of contract fulfillment and legitimate interest:
- Authenticating developers and enforcing Role-Based Access Control (RBAC).
- Hot-patching approved prompt versions to client agent swarms in sub-10ms.
- Sending transactional notifications (welcome emails, waitlist verification, team invites, and password resets).
- Preventing fraudulent abuse, malicious injection attacks, and DDoS traffic.
3. Authorized Subprocessors
We work exclusively with SOC-2, ISO-27001, or GDPR-compliant infrastructure providers:
- Supabase / PostgreSQL: Managed relational database storage with encrypted backups.
- Vercel: Edge network and serverless cloud runtime hosting.
- Razorpay: PCI-DSS Level 1 certified payment gateway.
- Brevo / SMTP: Transactional email delivery service.
4. Security Controls
- Encryption: TLS 1.3 enforced for all data in transit. AES-256-GCM encryption for stored API keys.
- Row-Level Isolation: Multi-tenant isolation at the database layer ensuring organizations can only query their own workspaces.
- Key Hashing: Prompt serving API keys are stored as non-reversible SHA-256 hashes. Full keys are shown only once upon generation.
5. Your Rights (GDPR & CCPA)
Under GDPR, CCPA, and global privacy regulations, you have the right to:
- Access all personal data associated with your user and organisation profiles.
- Request correction of inaccurate information.
- Request complete deletion of your account, workspace, and prompt versions ("Right to be Forgotten").
- Export your prompt configurations via our JSON/YAML export APIs.
To exercise any of these rights, email our data privacy lead at jachinchsaikiasonowal@gmail.com.
6. Data Retention
We retain workspace data for as long as your account remains active. When you delete a workspace, prompt versions and encryption keys are permanently purged from active databases.
7. Contact
For privacy inquiries, Data Protection Officer communications, or DPA execution requests, contact jachinchsaikiasonowal@gmail.com.