S
SafePrompt
/ Privacy & Consent

Privacy Policy & Consent Notice

Last updated: May 2025 · Effective: May 2025

1. Who We Are

SafePrompt is operated by SG2 Technologies ("we", "our", "us"). We provide an AI Data Loss Prevention (DLP) service that protects organisations from data leaks through AI tools such as ChatGPT, Claude, Gemini, and Copilot.

Contact: sales@safeprompt.pro

2. Data We Collect

CategoryDataLegal BasisRetention
AccountName, email, company nameContract performanceDuration of account
AuthenticationPassword hash (Argon2), Firebase UIDContract performanceDuration of account
DLP Scan LogsRedacted text snippet, category, action, confidenceLegitimate interest (security)7–90 days (plan-dependent)
Usage AnalyticsPage views, feature usage (anonymised)Consent12 months
TechnicalIP address, browser type, timestampsLegitimate interest30 days

Important: SafePrompt does NOT store the original sensitive content that triggers a DLP scan. Only a redacted snippet (with PII replaced by [REDACTED_TYPE] placeholders) is retained for audit purposes.

3. How We Use Your Data

  • Providing and operating the SafePrompt DLP service
  • Authenticating your access and maintaining session security
  • Generating compliance audit logs for your organisation
  • Detecting and preventing abuse of the service
  • Sending transactional emails (account creation, security alerts)
  • With your consent: product updates and security tip newsletters

4. Cookie Policy

TypePurposeRequiredDuration
NecessaryAuthentication token, CSRF protection, session stateYesSession / 30 days
AnalyticsAnonymous usage statistics (page views, feature adoption)No12 months
MarketingConversion tracking, referral attributionNo90 days
PersonalisationDashboard layout preferences, theme settingsNo12 months

You can manage cookie preferences at any time using the cookie banner or by clearing your browser's local storage.

5. Data Sharing

We share data with the following third parties:

  • Google Firebase — Authentication service (Firebase Auth). Firebase Privacy
  • MongoDB Atlas — Database hosting for audit logs and policies (EU region available)
  • Upstream LLM Providers — When you use the API gateway, sanitised (redacted) prompts are forwarded to OpenAI/Anthropic/Google per your request

We do not sell your personal data to third parties.

6. Your Rights (GDPR)

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your account and data
  • Portability: Export your audit logs in CSV format
  • Objection: Object to processing based on legitimate interest
  • Withdraw Consent: Unsubscribe from marketing emails at any time

To exercise any right, email sales@safeprompt.pro. We respond within 30 days.

7. Data Security

We implement industry-standard security measures including:

  • Argon2id password hashing (not bcrypt) for maximum resistance to GPU attacks
  • TLS 1.3 in transit, AES-256 at rest
  • JWT tokens with short expiry (configurable)
  • SHA-256 prompt hashing for zero-knowledge audit logs
  • Role-based access control with tenant isolation

8. Children's Privacy

SafePrompt is a B2B enterprise service and is not intended for use by individuals under 16 years of age. We do not knowingly collect data from minors.

9. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via email or a prominent notice in the dashboard. Continued use after the effective date constitutes acceptance.

Questions about this policy? We're happy to help.

Contact Privacy Team →