Privacy Policy

Prompt Vault - AI Prompt Management

Last Updated: May 9, 2026

1. Introduction

Prompt Vault ("we", "our", or "the app") is developed by Romingsquare. This Privacy Policy describes how information is handled when you use our Flutter application for organizing and improving AI prompts. The app is designed to be offline-first: your prompts, tags, projects, favorites, version history, and usage statistics are stored locally on your device unless you choose features that require network access.

2. Information We Collect

We do not operate a user account system inside the app. Information exists primarily on your device.

Stored locally on your device

  • Prompt content (titles, system prompts, expected answers, notes)
  • Tags, project names, favorites, and "useful" markers
  • Version history and draft prompts
  • App settings (including theme preferences)
  • Usage analytics shown in the app (for example counts and trends) derived from your local activity
  • If you enable it: a Google Gemini API key you enter yourself, stored on the device for optional AI enhancement via Google's services

We do not require you to create an account or provide an email address to use Prompt Vault.

3. How We Use Information

Local data is used only to provide app functionality: organizing prompts, search and filters, version history, drafts, analytics views, sharing and clipboard actions you initiate, and optional AI-powered prompt enhancement when you explicitly use that feature.

We do not use your prompts for advertising, and we do not sell your personal information.

4. AI Enhancement & Network Requests

When you use AI enhancement, portions of your prompt (and related text needed for the request) are sent over the internet to process the improvement. This does not happen in the background without your action.

Default path (Cloudflare Worker)

The app may send enhancement requests to a Cloudflare Worker endpoint operated as part of the Prompt Vault project. That worker acts as a server-side proxy to an AI provider (for example NVIDIA NIM). Provider API keys are configured on the server side so they are not embedded in the application package. Requests may be logged by Cloudflare and the provider according to their respective policies.

Optional path (your Gemini API key)

If you choose to supply your own Google Gemini API key in settings, enhancement requests are sent to Google under your key. Google's privacy policy and terms apply to those requests. You can disable this option at any time.

Do not submit secrets, regulated health data, or other highly sensitive information to third-party AI APIs unless you accept the risk that such content will be processed on external systems.

5. Permissions We Request

Depending on platform and version, the app may request permissions such as:

  • Network access — only needed for AI enhancement and related online features you use
  • Storage / app-specific storage — for local Hive databases and app data
  • Clipboard — when you copy prompts or shared content (if supported on your platform)

6. Data Sharing

We do not sell your prompts or personal information. Data you create stays on your device except:

  • When you use AI enhancement, as described in Section 4 (Cloudflare / AI provider, or Google if you use your own Gemini key)
  • When you use OS share sheets or export features — content is shared only through mechanisms you choose (for example another app or messaging)

7. Data Security

Local data is protected by your device's operating system and storage isolation. Optional API keys you enter are stored on-device; you should protect your device with a screen lock and keep backups in mind.

No method of storage or transmission is completely secure. Use AI features thoughtfully and review provider documentation for enterprise or compliance needs.

8. Data Deletion

You can remove prompts, clear optional API keys in settings, or uninstall the app to delete local databases. Uninstalling typically removes app-specific data from your device; behavior may vary slightly by platform.

Data already transmitted to Cloudflare, NVIDIA, or Google as part of a past enhancement request is governed by those services' retention practices and is not something we can erase from your device after the fact.

9. Third-Party Services

Prompt Vault may interact with services you do not host yourself, including:

  • Cloudflare (Workers) — proxy and edge infrastructure for the default enhancement path
  • AI providers (for example NVIDIA NIM) — model inference when using the default path
  • Google Generative AI (Gemini) — only when you enable and supply your own API key

Those services have their own privacy policies and terms. We encourage you to read them if you rely on AI enhancement.

10. Children's Privacy

Prompt Vault is not directed at children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided information through the app in a way that concerns you, please contact us.

11. Changes to This Privacy Policy

We may update this Privacy Policy when features or legal requirements change. The "Last Updated" date at the top will be revised, and significant changes may also be noted in app release notes where practical.

12. Contact Us

If you have questions about this Privacy Policy or Prompt Vault, you can reach us at:

Privacy-first by design

Your prompt library and analytics stay on your device. Network access is used for optional AI enhancement through services you can understand and, where applicable, configure yourself.