Version 2.3 · Effective Date: July 14, 2026
Introduction
EnginifyAI (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI prompt building platform, content generation services, and Global Prompt Library.
By using EnginifyAI, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Personal Information
- Account Information: Name, email address, username, and password
- Profile Data: Professional title, company information (optional)
- Payment Information: Billing address, payment method details (processed securely through Stripe)
- Contact Information: Information you provide when contacting our support team
Usage Information
- Prompt Data: AI prompts you create, edit, and generate using our platform
- Content Generated: AI outputs and content created through our templates or prompt tools
- Published Content: Prompts you choose to publish to the Global Prompt Library
- Usage Analytics: Feature usage, session duration, frequency of use
- Technical Data: IP address, browser type, device information, operating system
Platform Activity
- Tool Usage: Which tools, templates and prompts you use and how frequently
- Prompt Interactions: Prompts you create, modify, or favorite
- Library Management: Organization and categorization of your libraries
- Global Library Activity: Prompts you publish, unpublish, or interact with in the Global Libraries
- Output Preferences: Your selected output formats and customization settings
How We Use Your Information
Service Provision
- Platform Access: Authenticate your account and provide access to EnginifyAI features
- Content Generation: Process your prompts through AI models to generate requested outputs
- Global Library: Display prompts you publish and manage your publishing preferences
- Personalization: Customize your experience based on your usage patterns and preferences
- Feature Development: Improve our prompt tools and template systems
Business Operations
- Billing & Payments: Process subscription fees and manage your account status
- Customer Support: Respond to your inquiries and provide technical assistance
- Platform Improvement: Analyze usage patterns to enhance our AI prompt building tools
- Content Moderation: Review and moderate content published to the Global Library
- Communication: Send important updates about your account, new features, or service changes
Legal & Security
- Fraud Prevention: Detect and prevent unauthorized access or suspicious activity
- Legal Compliance: Meet our legal obligations and enforce our terms of service
- Data Security: Monitor for security threats and protect platform integrity
Global Prompt Library – Data Practices
This section describes specific data practices that apply when you publish content to the EnginifyAI Global Library.
What Happens When You Publish
When you publish a prompt to the Global Library:
- Your prompt content becomes visible to all EnginifyAI users
- Your display name or username may be shown as the author
- EnginifyAI may display, curate, edit, or feature your published prompt
- You grant an irrevocable license as described in our Terms of Service
Publishing Consent
Before publishing to the Global Library, you will be presented with a clear consent prompt explaining the license grant and its irrevocable nature. Publishing requires explicit agreement.
Account Deletion and Published Content
IMPORTANT EXCEPTION: When you delete your account, content you have published to the Global Library is NOT deleted. Ownership of your published content transfers to EnginifyAI upon account deletion. We may retain, edit, curate, or remove that content at our discretion. Your personal identifying information (name, email, account details) is still deleted per our standard deletion process – only the published prompt content itself is retained under EnginifyAI ownership.
If you wish to remove specific published prompts before deleting your account, you can unpublish them through your account settings or contact support@enginifyai.com prior to initiating account deletion.
Data Storage and Security
Security Measures
- Encryption: All data is encrypted in transit using TLS, and encrypted at rest using AES-256. Sensitive credentials such as API keys are additionally encrypted at the application level before storage.
- Access Controls: Strict authentication and authorization controls for all system access. Access to production data is limited to authorized personnel on a need-to-know basis; we do not browse or review your private prompts.
- Regular Audits: Ongoing security assessments and vulnerability testing.
- Certified Infrastructure: Our platform is built on enterprise-grade infrastructure that is independently certified to SOC 2 Type 2 and ISO 27001 standards (see Subprocessors below). These certifications belong to our infrastructure providers; EnginifyAI relies on their certified controls.
Data Location
- Primary Storage: Your account data and saved prompts are stored in our database, operated by Supabase, in the West US (North California), region. Data remains within this region at rest.
- Application Hosting: Our application is hosted on Vercel.
- Backup Systems: Encrypted backups are maintained for data recovery purposes within the same region.
Subprocessors
We use a limited set of trusted third-party providers (“subprocessors”) to operate the service. Each is bound by a data processing agreement and, where data is transferred internationally, appropriate safeguards such as the EU Standard Contractual Clauses. Our current subprocessors are:
| Subprocessor | Purpose | Compliance posture |
|---|---|---|
| Supabase | Primary database, authentication, and storage of account data and saved prompts | SOC 2 Type 2, ISO 27001; AES-256 encryption at rest |
| Vercel | Application hosting and content delivery | SOC 2 Type 2; TLS in transit; ephemeral compute |
| Anthropic (Claude) | AI model processing | SOC 2; no training on API data; short-term retention only |
| OpenAI | AI model processing | SOC 2 Type 2; no training on API data; up to 30-day retention |
| xAI (Grok) | AI model processing | SOC 2 Type 2; no training on API data; up to 30-day retention |
| Google (Gemini) | AI model processing | SOC 2 Type 2, ISO 27001; no training on paid-tier API data |
| Stripe | Billing and payment processing | PCI-DSS Level 1; SOC 2 Type 2 |
| InMotion Hosting | Hosting for our WordPress marketing website (contact form submissions, standard server logs) and email services (support and transactional email via cPanel/Roundcube). Does not host the application, user accounts, or saved prompts. | Marketing website and email only |
| Google Analytics | Usage analytics on our marketing website | Marketing website only |
We will update this list before engaging a new or replacement subprocessor. To request notice of changes to our subprocessors, contact privacy@enginifyai.com.
Data Retention
- Active Accounts: Data is retained while your account remains active.
- Account Deletion: All private personal data is permanently deleted from EnginifyAI’s own systems within seconds of account deletion confirmation. Prompts you previously transmitted to third-party AI providers may persist in those providers’ short-term logs for up to 30 days (see “Third-Party AI Providers” below); this is controlled by the provider and cannot be accelerated by us.
- Legal Requirements: Minimal audit logs may be retained to comply with legal obligations (these contain no personal content).
- Backup Systems: When you delete your account, private data is immediately purged from all EnginifyAI backup systems.
- Global Library Exception: Published Global Library content transfers to EnginifyAI ownership upon account deletion and is not subject to the deletion promise above.
Complete Account Deletion Process
Immediate and Comprehensive Deletion
When you choose to delete your EnginifyAI account, we execute a complete deletion process for your private data held on our systems:
- Immediate Action: Your private data is permanently deleted using our automated deletion system, not a “mark for deletion” process.
- Atomic Operation: All private data is deleted in a single, all-or-nothing transaction with no partial deletions or lingering data fragments.
Comprehensive Private Data Deletion Scope
When you delete your account, we permanently remove the following private data from our systems:
- Account & Profile Information: Your personal details, preferences, and account settings
- Private Content: All private prompts, templates, libraries, versions, and generated outputs
- Usage & Activity Data: Platform analytics, session data, and feature usage history
- Billing & Subscription Data: Payment records, usage quotas, and transaction history
- API & Integration Data: Your API keys (including BYOK), custom configurations, and connected services
- Communications: Support conversations, feedback submissions, and help documentation interactions
What Is NOT Deleted Upon Account Deletion
EXCEPTION: The following are not deleted:
- Published Global Library content: Ownership transfers to EnginifyAI. See “Global Prompt Library – Data Practices” above.
- Minimal audit logs required for legal compliance (no personal content).
- Third-party AI provider logs: Prompts already transmitted to an AI provider to generate a response may remain in that provider’s short-term abuse-monitoring logs for up to 30 days, after which the provider deletes them. This retention occurs on the provider’s systems and is outside our control.
Important Deletion Characteristics
- No Recovery: Deleted private data cannot be recovered under any circumstances.
- No Backup Retention: Private data is immediately purged from all EnginifyAI backup systems.
- No Cache: All cached private data is immediately invalidated and removed.
- Provider Logs: Prompts already sent to an AI provider remain subject to that provider’s own retention window (up to 30 days), which we cannot accelerate.
- Audit Compliance: Only minimal audit logs are retained (deletion timestamp, admin initiator if applicable, reason for deletion, no personal content).
Before You Delete
We strongly recommend:
- Export Your Data: Download any important private prompts, templates, or content
- Review Published Prompts: Unpublish any Global Library content you do not want retained by EnginifyAI
- Review Your Libraries: Ensure you have saved any valuable private work elsewhere
- Cancel Active Subscriptions: Close any active payment subscriptions to avoid future charges
- Contact Support: Reach out if you have questions about alternatives to deletion
Once confirmed, deletion of private data from our systems is instant and permanent. There is no grace period or recovery option for private data.
Information Sharing and Disclosure
Third-Party AI Providers
- AI Model Access: When you run a prompt, its content is sent to the AI provider you select (Anthropic, OpenAI, Google, or xAI) to generate the requested output.
- No Training Use: Your prompts and outputs are not used to train or improve any of these providers’ models. This is the default and contractual position across all four providers.
- Provider Retention: Providers may retain API inputs and outputs for a limited period, typically up to 30 days, solely for abuse monitoring and legal compliance, after which they are deleted.
- Data Protection: All AI providers are bound by data protection agreements, and we do not sell or otherwise share your prompts with any party beyond the provider needed to fulfil your request.
Service Providers
- Payment Processing: Payment information is shared with our secure payment processor, Stripe (PCI-DSS Level 1 certified). EnginifyAI does not store full card numbers.
- Cloud Infrastructure: Data is stored and processed using Supabase (database) and Vercel (hosting), as listed under Subprocessors.
- Marketing Website & Email: Our marketing website is hosted by InMotion Hosting and uses Google Analytics. Email routing (support and transactional email) is handled through InMotion Hosting via cPanel/Roundcube. Contact form submissions from the marketing site are stored on this infrastructure and are separate from your application account data.
- Customer Support: Support ticket information may be shared with customer service tools.
Global Library Content
Content you publish to the Global Library is visible to all EnginifyAI users and may be featured, promoted, or distributed by EnginifyAI as part of our platform services.
Legal Disclosure
- Legal Compliance: We may disclose information when required by law, legal process, court orders, or valid requests from law enforcement.
- Safety Protection: If we receive credible reports regarding threats to user safety or public safety, we may share relevant information as necessary.
- Business Transfers: Data may be transferred in connection with mergers, acquisitions, or business sales.
We do not actively monitor private user content or prompts. Global Library content is subject to moderation.
No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Your Privacy Rights
Account Management
- Access: Request a copy of the personal information we have about you
- Correction: Update or correct inaccurate personal information
- Deletion: Request immediate and complete deletion of your private personal information
- Data Portability: Receive your data in a portable format
- Global Library Unpublish: Remove your prompts from the Global Library before account deletion
Privacy Controls
- Prompt Privacy: Control the privacy settings of your prompts and generated content
- Library Sharing: Choose which prompt libraries to keep private or publish to the Global Library
- Communication Preferences: Opt out of non-essential communications
- Account Deactivation: Deactivate or delete your account at any time
How to Exercise Your Rights
- Account Deletion: You can initiate account deletion through your account settings or by contacting support
- Data Export: Use our data export tools to download your information before deletion
- Unpublish Prompts: Use your dashboard to unpublish Global Library content before account deletion
- Support Contact: Email privacy@enginifyai.com for privacy-related requests
- Response Time: We respond to privacy requests within 30 days
Data Processing Agreement (DPA)
Business and enterprise customers who require a Data Processing Agreement can review and accept our standard DPA at enginifyai.com/dpa, which is incorporated into our Terms of Service by reference and reflects the subprocessor list above. For a countersigned copy, email dpo@enginifyai.com.
GDPR Rights (EU Users)
If you are located in the European Union, you have additional rights under GDPR:
- Right to object to processing
- Right to restrict processing
- Right to data portability
- Right to lodge a complaint with supervisory authorities
Note: The GDPR Right to Erasure (Article 17) applies to your private personal data. Content published to the Global Library under an irrevocable license may be retained by EnginifyAI after account deletion, consistent with GDPR recital 65 (retention for overriding legitimate interests). We recommend unpublishing content before account deletion if you wish to maximize erasure.
Cookies and Tracking
Essential Cookies
- Authentication: Maintain your login session and account security
- Preferences: Remember your platform settings and customizations
- Security: Protect against fraud and unauthorized access
Analytics Cookies
- Usage Analytics: We use Google Analytics on our marketing website to understand how visitors interact with it
- Performance Monitoring: Track platform performance and identify issues
- Feature Usage: Analyze which features are most valuable to users
Cookie Management
You can control cookies through your browser settings, and via the cookie settings link in our website footer. Note that disabling certain cookies may limit platform functionality.
Children’s Privacy
EnginifyAI is designed for professional use and is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete that information promptly.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. Where we transfer personal data outside the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum) to protect your data.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending an email notification to your registered email address
- Displaying a prominent notice within the EnginifyAI platform
Your continued use of our services after any changes constitutes acceptance of the updated policy.
Contact Us
- Privacy Inquiries: privacy@enginifyai.com
- Data Protection Officer / DPA requests: dpo@enginifyai.com
- General Support: support@enginifyai.com
California Privacy Rights (CCPA)
California residents have specific rights regarding their personal information:
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to access personal information
- Right to request deletion of private personal information
- Right to equal service and price
CCPA deletion rights apply to private personal data. Global Library published content transferred to EnginifyAI under an irrevocable license is retained under EnginifyAI’s legitimate business interests.
Data Processing Lawful Basis (GDPR)
We process your personal information based on:
- Contract Performance: To provide our services as agreed
- Legitimate Interests: To improve our platform, moderate the Global Library, and provide customer support
- Legal Obligations: To comply with applicable laws
- Consent: For Global Library publishing, analytics cookies, and certain marketing communications
Transparency Commitment
At EnginifyAI, we believe in complete transparency about data practices:
- Clear Communication: We explain our practices in plain language
- User Control: You have full control over your private data
- Global Library Clarity: We clearly disclose the irrevocable nature of publishing before you publish
- Technical Excellence: Our deletion process reflects our commitment to privacy
- Continuous Improvement: We regularly review and enhance our privacy practices
Your privacy is not just a legal obligation, it is a core value.
Privacy Policy Version: 2.3, Last Updated: July 14, 2026

