Last updated: August 10, 2026 ยท Version 2.06
Privacy Policy
Scope and Summary
Promptron has no model-request backend: the operator does not receive your workspace, provider key, prompt, attachment, microphone audio, or model response. This does not mean that nothing leaves your device. When you permit and use an online feature, content is sent directly to Anthropic or OpenAI. Pasted web links are fetched from the relevant website. Apple processes App Store purchases you initiate; Google processes authentication only when that option is configured and selected. Those parties process data under their own policies and your account settings.
Promptron does not operate analytics, advertising, cross-app tracking, or a data broker, and does not use your content for Promptron model training.
What Is Stored on Your Device
- Provider keys: Anthropic and OpenAI keys are stored separately in the device Keychain with this-device-only accessibility where available. In an iOS Simulator debug build only, keys may be stored in that simulator's local preferences. A key is sent only to its matching provider as request authentication and never to Promptron.
- Workspace: account/profile details, projects, conversations, your text, generated prompts, scores, saved prompts, and preferences are stored in the App's local Application Support container. Model-derived files and new avatars are kept in a private directory for the active local account. They are not uploaded to Promptron.
- Local email profile: the normalized email, display name, random salt, and salted password hash are stored locally. It is not a Promptron cloud account, and Promptron does not receive the password.
- Generation cache: generated model text is cached in the active local account's private directory to avoid identical repeat calls. The cache key is a hash of the request rather than a readable copy of the input. Unattributed cache and evaluation files created at the App-data root by an older release are discarded rather than migrated into any account.
- Consent and settings: account-specific provider permissions and local consent timestamps/versions, subscription preferences, feature-usage counters, and UI settings are kept in local preferences.
- Selected attachments: files and images are read only when you select them. Extracted text and image data are held for the action. The App stores attachment names and resulting conversation content, not a cloud copy of the original file.
Anthropic and OpenAI Processing
Before the current local Promptron account first contacts each AI provider, and again after revocation or a material disclosure change, the App shows a provider-specific notice and asks for permission. One local account's permission is not reused by another account on the device. Anthropic and OpenAI choices are separate. Depending on the feature, an allowed provider may receive:
- Your current request, relevant local conversation context, and saved profile context.
- Capability guidance from the encyclopedia bundled with the App.
- Text extracted locally from files you select or web pages you ask the App to fetch.
- Images you select or linked images fetched from a pasted reference page.
- Generated prompt candidates and instructions or candidates used for optional evaluation and follow-up suggestions.
BYOK requests go directly to the matching API under your key. A separately distributed local macOS build may pass the same categories to an installed, signed-in Claude or Codex CLI, which then communicates under your provider subscription and settings. If automatic fallback is available, only providers you have separately allowed are eligible.
OpenAI Responses API requests set store: false to request that application state
not be stored. This is not a promise of zero data retention: OpenAI may retain abuse-monitoring
logs or other data under its policy unless your organization has separately approved controls.
Retention and training choices for Anthropic API and Claude subscription, and for OpenAI API
and Codex subscription, depend on the applicable product, contract, and your provider account settings.
Review the current
Anthropic privacy policy and
OpenAI privacy policy before sending
sensitive content.
Promptron requires every third-party integration that receives user data through the App to provide the same or equivalent protection of that data as stated in this Policy. If that protection cannot be maintained, Promptron will disable the affected integration until the issue is resolved.
References, Images, and On-Device Recognition
Local txt, markdown, HTML, PDF, docx, and xlsx extraction is performed on the device. PDF OCR uses Apple's on-device Vision framework. When you paste an http/https link and start an action, the App fetches that page and up to a limited number of linked images directly. That website can receive ordinary connection data such as your IP address, user agent, and request time; its policy applies. Fetched content can be included in an AI request only after the relevant provider permission.
Microphone dictation uses Apple's Speech framework with on-device recognition required. If on-device recognition is unavailable for the selected language or device, recording does not start. Microphone audio is not sent to Promptron, Anthropic, or OpenAI. Recognized text is treated like typed composer text and is sent only if you later start an online action for an allowed provider.
Authentication and Purchases
Promptron 2.0.6 does not offer Sign in with Apple. Google OAuth is contacted only when a Google client is configured and you choose it; Google handles the browser session, returned display name/email are stored locally, and Promptron does not persist the access token. App Store purchases and entitlement verification are handled by Apple. Promptron stores a local feature state and does not receive payment-card details.
Support and Public Policy Pages
If you email support, the Promptron operator and its email service receive the address, message, and attachments you choose to send. They are used to answer the request, prevent abuse, and meet legal obligations, and retained only as reasonably necessary for those purposes. Do not send an API key or material that is not needed for support. Opening these public pages connects to GitHub Pages, which receives ordinary web-request data under GitHub's policy; Promptron adds no analytics or tracking scripts to them.
No Analytics, Advertising, or Tracking
The App contains no Promptron analytics or advertising service, does not use data for cross-app tracking, and does not sell data. Operational requests made directly to AI providers, websites, Apple, or configured Google authentication are not Promptron analytics, but those parties may process account, usage, device, or network data under their own policies.
Your Choices, Retention, and Deletion
In Settings you can revoke Anthropic or OpenAI permission independently, remove each local API key, and delete the current local profile, its provider permissions and keys, on-device workspace, conversations, Prompt library, standing context, model cache, saved evaluation data, and avatar. Other local Promptron accounts and their data remain. Revocation or local deletion prevents future requests for that account, but cannot retract provider-received content or delete your Anthropic or OpenAI provider account. Exercise provider-side access, retention, training, or deletion choices with Anthropic or OpenAI under your provider account. Deleting a local profile does not cancel an App Store subscription; use Apple's controls to manage or cancel Pro.
Local data remains until you delete it through the App, reset the relevant setting, or the operating system removes it. Device/cloud backups and Keychain items follow their own operating-system lifecycles; because provider keys use this-device-only protection where available, a restored workspace may require you to enter those credentials again. Where GDPR, UK GDPR, CCPA/CPRA, the Australian Privacy Act 1988, or other privacy laws apply, contact us about data the Promptron operator controls. Because there is no Promptron model backend, provider-request rights generally must be exercised with the provider that received the request.
Children and International Processing
Promptron is a general-purpose productivity tool and is not designed specifically for children. Online AI features may be used only by people who meet the selected provider's age, account, and parental-consent requirements. A parent or guardian should supervise a child's use where applicable. Anthropic, OpenAI, Apple, Google, and referenced websites may process data in countries other than your own. Their policies and account controls describe locations and safeguards. Avoid online AI features if you cannot permit that processing.
Changes and Contact
Material changes will be notified in the App and may require renewed provider permission.
Email: hello@pawse.au