Data Handling Policy
Overview
This policy describes how TryPromptFlow processes, stores, and protects the data involved in running diagnoses. It supplements our Privacy Policy, which covers what data we collect and your rights regarding it.
1. Submission Processing
When you submit a prompt, workflow, or agent description for diagnosis, the following process occurs:
Intake
Your submission is received and associated with your account.
Processing
Submission content is sent to model provider APIs for analysis, challenge, and verification.
Report
Findings are combined into a structured diagnostic package stored in your account.
Retention
Submission content and report are retained per your plan. Metadata is retained as described below.
Your submission content is used only to perform the requested diagnosis. It is not used to train shared models, improve other users' results, or build shared datasets.
2. Model Provider Usage
To generate diagnoses, TryPromptFlow sends your submission content to third-party model provider APIs. These providers process your content as API inputs to generate diagnostic output.
- We select providers that offer API terms designed to limit their use of customer content, including terms that restrict training on API inputs.
- We do not control the internal practices of model providers beyond the terms of their API agreements. We cannot guarantee how providers handle your content internally once received.
- We may change model providers or add new providers over time. If we do, we will apply the same selection criteria.
- Your submission content is sent to providers for the purpose of your diagnosis only — not for any provider's product improvement unless required by the provider's API terms, which we attempt to limit.
3. No Shared Model Training
We do not use customer submission content to train shared models — models available to other users, the public, or used across multiple customers. This applies to both the diagnostic process and any internal tools we build.
If we ever change this practice, we will not do so without explicit customer authorization. We will not quietly repurpose customer content for model training.
For avoidance of doubt: the model providers we use may have their own terms regarding API inputs. We select providers whose API terms are designed to restrict training on customer content, but the practices of third-party providers are outside our direct control.
4. Account and Mobile Verification Data
When you create an account, we collect your name, email address, and mobile number. We normalize the mobile number into an international format, send that number to our SMS verification provider to deliver a one-time code, and keep the normalized number after successful verification to help secure accounts and protect the free-diagnostic offer from repeat use.
Before verification is complete, the submitted name, email address, normalized mobile number, and verification state are held with the pending signup. Verification is not consent to receive marketing messages.
5. Account Isolation
Each diagnosis runs in its own account context. Your submission content is associated with your account and is not shared with or accessible by other customers.
- Account-level access controls restrict who can view your submissions and reports.
- Within a team or organization account, access is governed by the permissions set by the account administrator.
- We do not cross-reference or combine submission content across customer accounts.
- Diagnostic processing for different customers does not share context — each diagnosis is processed independently.
6. Retention
This policy does not promise a fixed retention period for account data, diagnostic content, reports, or verification records. We retain data needed to operate the account and provide the diagnostic service; contact us with a data-handling question or request.
7. Security
Account access requires authentication, and mobile verification is used during signup. No system can guarantee complete security. This policy does not make claims about a specific encryption method, processor practice, or security certification.
8. Questions and Requests
For questions or requests about your account, submission content, reports, or mobile verification data, contact us at privacy@trypromptflow.com. We do not state a deletion timeline or outcome in this policy.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date above. For material changes, we will provide notice through the platform or by email where possible.
10. Contact
For questions about how your data is handled, contact us at privacy@trypromptflow.com. For privacy rights questions, see our Privacy Policy.
Get your free diagnosis.
One free diagnosis. Structured report. Most under 10 minutes. No credit card.
Structured diagnostic output you can review, test, and act on.