Skip to content
Prompt Organizer
Evidence Pricing
Open app

Privacy Policy

Local-first privacy, written plainly.

Prompt Organizer is designed so your prompt library, files, imports, exports, and vault data stay in your browser unless you choose to move them.

Last updated: July 14, 2026

Who operates Prompt Organizer

Prompt Organizer is operated by MCK Strategy, which is the controller for personal data it receives through the site, support contact, checkout handoff, or other business records. This policy covers the local-first app and marketing site at promptorganizer.app and the hosted Prompt Library service at library.promptorganizer.app; the Prompt Library section below describes the data the hosted service stores on servers. For privacy, support, or data-rights requests, contact support@promptorganizer.app.

MCK Strategy has not appointed a data protection officer or EU representative for Prompt Organizer unless one is legally required for a future processing activity.

Categories of data

The core app stores your prompts, references, tags, preferences, vault handle metadata, imported packs, dismissed notices, local activation state, and — if you connect your own AI provider keys (for Prompt Lab and other Bring-Your-Own-Key features) or a Prompt Library access key — those keys in encrypted form, in browser-local storage such as IndexedDB or localStorage. This information is not sent to a Prompt Organizer server by default.

Files selected in the File Concatenator are processed in the browser where supported. You control any copy, export, vault backup, download, or manual transfer.

MCK Strategy may receive limited data when you contact support, open an email link, complete a Stripe checkout, or use a future deployment where optional analytics has been explicitly enabled. Data you provide to the hosted Prompt Library service is stored on servers and is described separately in the Prompt Library section below.

Purposes and lawful bases

Where MCK Strategy processes personal data, it does so for the following purposes and lawful bases:

  • Providing the local-first app, settings, imports, exports, vault workflows, and local activation features: necessary to provide the service you request.
  • Responding to support, privacy, or business contact messages: legitimate interests in responding to requests and, where relevant, steps before entering or performing a contract.
  • Handling paid checkout and Pro activation handoff through Stripe: contract performance, fraud prevention, and legal obligations for transaction and tax records.
  • Maintaining security, abuse prevention, troubleshooting, and service integrity: legitimate interests in protecting the site, users, and business records.
  • Optional analytics, if explicitly enabled in a future deployment: consent or legitimate interests depending on the deployment configuration and any cookie or consent notice shown at that time.
  • Operating the hosted Prompt Library — accounts, sign-in, submissions, public display, ratings, collections, and access keys: necessary to provide the Prompt Library service you request.
  • Automatically scanning submitted Prompt Library content for safety and prompt-injection patterns: legitimate interests in protecting users, the service, and people who download items.
  • Sending the Prompt Library email digest: consent, which you can withdraw at any time by unsubscribing.

When data may leave your browser

  • When you choose to copy, export, download, import, share, or back up content.
  • When you open an external destination, such as Stripe checkout, GitHub, MCK Strategy, or an email link.
  • When you use Prompt Lab or the editor's Improve, Compare, or test-matrix features with an AI provider: the prompt content and any system prompt you submit are sent from your browser directly to the provider you choose — such as Anthropic, OpenAI, Google, or OpenRouter — using your own API key. If you instead select a local model server you run (such as Ollama or LM Studio), that content goes to that local server rather than a third-party provider.
  • When optional analytics is explicitly enabled in deployment configuration. The current default configuration disables analytics.
  • When you use the hosted Prompt Library service — for example to sign in, submit an item, rate or collect items, or subscribe to the digest. See the Prompt Library section for what the service stores.

Chrome extension (Prompt Organizer Companion)

The Prompt Organizer Companion browser extension has a browser-local offline core and an optional first-party network surface. Its single purpose is to help you save, organize, stage, copy, and insert your prompt library on supported AI chat sites. The local extension library works without the hosted Prompt Library; Discover and private-library access use library.promptorganizer.app as described below.

The extension handles some Chrome Web Store personal or sensitive data categories because prompt text can be website content, form data, personal communications, user-generated content, or authentication information when you choose to save an API key. Local-only handling still counts as handling data, so this section explains what the extension collects, uses, and shares.

  • Extension library data: prompts, references, shortcuts, staged prompts, onboarding state, launcher preferences, panel settings, and template values you explicitly choose to remember are stored in chrome.storage.local on your device. Template-value persistence is opt-in through an unchecked “Remember on this device” control. Secret-like normalized names — including token, password, secret, key, credential, authentication or authorization, bearer, and private-key forms — remain usable for the current insertion but are never saved or prefilled. Legacy pre-consent records, sensitive values, orphaned records, and values belonging to deleted, replaced, or content-changed prompts are removed. None of these records are written to chrome.storage.sync or uploaded to Prompt Organizer servers.
  • Local mutation worker: a packaged Manifest V3 service worker validates and serializes prompt-library and remembered-value changes, maintains a local revision, verifies a session-only recovery snapshot before destructive changes, and sends data-free change notices to open extension surfaces. It imports only code packaged with the extension and does not create a new network service.
  • Page content and form data: the extension reads text from a supported AI site only when you click an import, capture, save, or insert action, or when you use a configured /shortcut in a visible composer. It does not run background conversation monitoring, browsing-history collection, or hidden page scraping.
  • Clipboard: clipboard read/write happens only after a user action: an explicit clipboard action such as stage, copy, or import from clipboard, or the automatic local copy fallback after a user-requested insertion cannot find the site's composer. Clipboard contents are processed locally and are not sent to a server by the extension.
  • Supported AI sites: when you insert a prompt into ChatGPT, Claude, Gemini, or Perplexity, the text is placed into that site's composer for you to review. If you submit it there, that third-party service processes it under its own terms and privacy policy. The extension declares no content-script access for other AI products.
  • Catalogue requests: the side panel can fetch public catalogue items from https://library.promptorganizer.app using GET requests. Search terms, kind and page filters, and normal HTTPS request metadata needed to return catalogue results may reach that first-party service. Copying, inserting, or saving catalogue results sends no engagement event. Saved prompt text, page content, clipboard contents, and the local extension library are not uploaded.
  • Optional API key: if you save a pol_… API key to load your private library items, the key is stored in chrome.storage.local without separate application-level encryption, shown only in masked form after save, sent only to https://library.promptorganizer.app over HTTPS as an authorization header when private items are requested, and removable at any time from extension settings.
  • Limited use and sharing: extension data is used only to provide or improve the prompt capture, library, catalogue, copy, and insertion features described in the extension UI and Chrome Web Store listing. MCK Strategy does not sell extension data, use it for advertising, transfer it for unrelated purposes, or allow humans to read your saved prompts except if you explicitly send content to support or disclosure is required for legal or security reasons.
  • Deletion and control: deleting an extension prompt requires confirmation and also removes its remembered template values. A full restore clears all remembered template values. You can clear values for one prompt, clear every remembered value from Settings, clear the API key, uninstall the extension, or clear the extension's Chrome storage. Removing prompts from the extension does not delete copies you exported, copied, inserted into third-party sites, or saved in the main Prompt Organizer app.
  • No extension telemetry: the extension contains no analytics, tracking, or copy/save engagement-reporting code. The catalogue and private-library GET requests described above are feature requests, not telemetry.

Prompt Library service (library.promptorganizer.app)

The Prompt Library at library.promptorganizer.app is a hosted, account-based service operated by MCK Strategy. Unlike the local-first app, it stores data on servers. You can browse and download public library items without an account; the categories below apply when you sign in, submit content, rate items, build collections, create access keys, or subscribe to the email digest.

  • Account and authentication: signing in requires an email address, using either an emailed magic link or an email-and-password pair. Accounts, authentication, and library content are stored with Supabase, our database and authentication provider. A signed-in session is maintained using necessary browser cookies.
  • Public profile: you may set a handle (username) and an optional bio. Your handle is shown publicly as the “submitted by” attribution on items you publish and on your public contributor page; your bio, if set, is shown on that page. Do not put anything in your handle or bio that you do not want to be public.
  • Submitted items: prompts, references, skills, and agent packs you submit — including their titles, descriptions, bodies, system prompts, and tags — are stored on the server. Items submitted for public visibility are reviewed before they appear; once approved they are displayed publicly and can be browsed, copied, downloaded, and imported by anyone. Items you keep private are not shown to other users, but remain readable by MCK Strategy administrators for moderation and support.
  • Automated content moderation: when you submit or edit an item, its text is checked for safety and prompt-injection patterns. It is always scanned by local heuristics, and where those services are configured it is additionally sent to third-party moderation services — currently Hugging Face and OpenAI — for automated scanning. Those providers process the submitted text under their own terms; review their policies for details. Scan results are stored with the item.
  • Ratings, collections, and engagement: star ratings and collections you create are linked to your account. The service also keeps aggregate, non-identifying daily counts of downloads, imports, and copies per item.
  • Access keys: you can create access keys (shown with a pol_ prefix) so the app and Chrome extension can load your private items. A key is stored only as a one-way hash plus a short display prefix; the full key is shown once at creation. You can revoke a key at any time.
  • Email digest: if you subscribe to the weekly digest, your email address is stored and a confirmation email is sent (double opt-in). Digest and confirmation emails are delivered through Resend, our email provider. Every email includes an unsubscribe link, and you can unsubscribe at any time.
  • Technical and security data: the service uses your IP address for rate limiting and abuse prevention. It is hosted on Vercel, which provides privacy-friendly, cookieless web analytics and may process standard request logs.

Supabase (database and authentication), Vercel (hosting and cookieless analytics), Resend (email), and the moderation services named above process Prompt Library data on MCK Strategy's behalf and may process it outside the UK or EEA under their published transfer mechanisms.

Managing and deleting library data: you can delete individual items you submitted from your dashboard, update your handle and bio in your account, revoke access keys, and unsubscribe from the digest. You can delete your account yourself from the Account page. When you delete your account, public items that were approved for the library remain available but are anonymized — your name and account are removed from them — while everything else, including private and pending items, collections, ratings, access keys, your digest subscription, and your profile, is permanently deleted. You can also contact support@promptorganizer.app with any deletion request. Copies of public items that others have downloaded, imported, or cached are outside MCK Strategy's control.

Recipients and processors

Prompt Organizer does not send your local prompt library, files, imports, exports, or vault data to MCK Strategy by default. When you choose external actions, recipients may include Stripe for checkout, email infrastructure for contact messages, Plausible if optional analytics is enabled later, and any external destination you intentionally open or share content with. If you use Bring-Your-Own-Key features, the AI provider you select — such as Anthropic, OpenAI, Google, or OpenRouter — receives the prompt content you submit, sent directly from your browser with your own key; Prompt Organizer does not relay or store that content on its own server. If you opt into the Prompt Library service (library.promptorganizer.app, operated by MCK Strategy), how data is handled depends on how you use it: when the app merely checks your saved items for updates, it sends only item identifiers and version numbers, not your prompt content; when you sign in to the hosted service, submit items, rate them, or subscribe to the digest, the server-side processors described in the Prompt Library section above apply — Supabase (database and authentication), Vercel (hosting and cookieless analytics), Resend (email), and the Hugging Face and OpenAI moderation services.

Payment details are handled by Stripe. Prompt Organizer may store a local activation marker in your browser after checkout, but browser-local Prompt Organizer storage does not store full payment card details.

International transfers

Browser-local app content stays on your device unless you choose to move it. External providers such as Stripe, email infrastructure, AI providers you connect through Bring-Your-Own-Key features (such as Anthropic, OpenAI, Google, or OpenRouter), analytics providers if enabled later, and destinations you open may process data outside the UK or EEA. Where transfer safeguards are needed, MCK Strategy relies on the relevant provider's published transfer mechanisms, such as adequacy decisions, standard contractual clauses, or equivalent safeguards.

Retention and deletion

Because core app data is stored locally in your browser, you control retention by deleting browser data, clearing app storage, removing vault files, or deleting exported files. Contact requests are retained only as long as needed to respond and maintain ordinary business records. Payment and business records may be retained by Stripe and MCK Strategy as needed for transaction history, fraud prevention, tax, accounting, and legal obligations.

For the hosted Prompt Library service, your account, profile, submitted items, ratings, collections, and digest subscription are retained on the server until you delete them. You can delete your account yourself from the Account page: public approved items remain in the library with your attribution removed, and all other account data is permanently deleted. Deleting an item removes it from the service, though copies others already downloaded, imported, or cached are outside MCK Strategy's control. Digest subscribers can unsubscribe at any time using the link in any digest email.

Your privacy rights

If GDPR, UK GDPR, or similar privacy laws apply to you, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent where processing is based on consent, or request portability of personal data. Most local-first app content is stored locally under your control, but you can contact support@promptorganizer.app for any data-rights request involving data MCK Strategy may hold. For personal data held by the Prompt Library service — such as your account, profile, submitted items, ratings, and digest subscription — you can use the in-product controls and contact options described in the Prompt Library section above.

You may also have the right to complain to your local data protection supervisory authority. MCK Strategy asks that you contact support@promptorganizer.app first so it can try to resolve the issue directly.

Whether data is required

Creating prompts, importing packs, processing files, exporting data, and using vault backups are optional local app actions. Checkout data is required only if you choose a paid upgrade. Contact details are required only if you want MCK Strategy to respond to your message. Optional analytics is not required to use Prompt Organizer and is disabled by default.

Analytics and cookies

No optional tracking cookies are enabled by default. On the local-first app at promptorganizer.app, the codebase includes a privacy-preserving Plausible analytics adapter, but analytics is disabled unless a deployment explicitly configures it. The adapter is designed to send only allowlisted event names and coarse properties, never prompt bodies, file names, tags, references, imported data, or generated output. The Prompt Library subdomain (library.promptorganizer.app) is different: it sets necessary cookies to keep you signed in and uses Vercel's privacy-friendly, cookieless web analytics, as described in the Prompt Library section above. It does not set optional tracking cookies.

Read the Cookie Settings page for current cookie and browser-storage details. If analytics is enabled in a future deployment, this page and the cookie information should be updated before activation with the provider, purpose, data categories, and opt-out or consent behavior.

Automated decision-making

Prompt Organizer does not use personal data for automated decision-making that produces legal or similarly significant effects.

Security

Prompt Organizer is static-file friendly and local-first. You are responsible for protecting devices, browsers, exported files, and vault backups you create. Use browser and operating-system security features appropriate for the sensitivity of your prompts and files.

Prompt Organizer

A local-first AI workbench for reusable prompts, file prep, markdown, token checks, and portable workflow exports.

Open app

Prompt data stays in this browser unless you choose to move it.

Privacy Terms Cookies Contact
More links
ProductOpen appPricingChangelog
WorkflowsPrompt managerFile concatenatorMarkdown rendererToken estimatorSkillsAgent pack
ResourcesStarter packImport a packDocs
CompanyPrivacy PolicyCookie SettingsTermsRefund PolicyContact

Product

Open appPricingChangelog

Workflows

Prompt managerFile concatenatorMarkdown rendererToken estimatorSkillsAgent pack

Resources

Starter packImport a packDocs

Company

Privacy PolicyCookie SettingsTermsRefund PolicyContact

© 2026 MCK Strategy. All rights reserved.

No optional tracking cookies are enabled by default. Prompts, files, imports, exports, and vault data stay in this browser unless you choose to move them.