Legal

Privacy Policy

This Privacy Policy explains how Code Art Web Solutions S.R.L. ("we", "us", "our") collects, uses, shares, and protects your personal data when you use VantagePrompt (the "Service"), and the rights you have under the EU General Data Protection Regulation (GDPR).

Last updated: 18 August 2026

1. Data controller

The data controller for your personal data is Code Art Web Solutions S.R.L. (CUI 50223815 · EUID ROONRC.J29/1424/2024), Sat Plavia, Comuna Iordacheanu, nr. 81, Prahova County, Romania. For any privacy question or to exercise your rights, contact us at contact@vantageprompt.com or by phone at +40 771 006 756.

We have not appointed a statutory Data Protection Officer, as we are not required to. Privacy requests sent to the address above reach the person responsible for data protection.

2. What data we collect

CategoryExamples
Account dataName, email address, hashed password, timezone; if you use Google sign-in: your Google account identifier and profile picture.
Usage & prompt contentThe prompts you submit, the optimized outputs, the model used, quality scores, and token/cost metadata. You can turn off storage of your prompt text (see “Your privacy controls” below).
Billing dataPlan, subscription status, credit balances, invoices, and a Stripe customer identifier. Card details are handled by Stripe — we do not store them.
Country data used for billingThe billing address you enter at checkout, and — where paid plans are restricted — the country that issued your card, which we read from Stripe. We keep the country in our billing and audit records; we never receive or store the card number itself.
Team dataIf you use a team workspace: team membership, role, and credit quota.
Technical & security dataIP address, session identifiers, security-incident records (e.g. blocked adversarial inputs), and error logs.
CommunicationsMessages you send us for support and our replies.

A name and email address are required to create an account and receive the Service; without them we cannot provide it. Prompt storage is on by default as part of the Service, and you can switch it off at any time without losing access; providing a Google profile picture is optional.

PurposeLegal basis (GDPR Art. 6)
Create your account and provide the ServicePerformance of a contract
Process payments, credits, and invoicesPerformance of a contract; legal obligation (accounting)
Secure the Service, prevent abuse and fraud, enforce limitsLegitimate interests
Check whether paid plans are available in your country, before and after a purchaseLegal obligation (VAT registration and invoicing); legitimate interests (not selling into countries where we are not yet registered to collect the tax)
Maintain, debug, and improve the ServiceLegitimate interests
Store your prompt text in your historyPerformance of a contract (history is part of the Service; you can switch it off at any time)
Send service and billing notificationsPerformance of a contract; legitimate interests
Comply with legal and tax obligationsLegal obligation

We do not sell your personal data, and we do not use behavioural advertising or third-party analytics trackers on the Service.

4. Your privacy controls

  • Prompt storage — history is switched on by default, because saving your prompts is part of the Service you sign up for. You can stop us from saving your raw prompt text at any time, while still keeping your usage statistics, from your account settings.
  • Zero Data Retention (ZDR) — you can route a request only to model providers that do not retain or train on it, per request or as your account default.
  • Delete history — you can delete individual history items or your whole history at any time.

5. Who we share data with

We share personal data only as needed to run the Service. Some recipients act as our processors (only on our instructions, under a data-processing agreement); others are independent controllers who decide how they use the data under their own privacy notices.

ProviderRolePurpose & data shared
StripeIndependent controller (payment services)Payment processing and billing; name, email, billing country, and card data collected directly by Stripe
Google — Gemini APIProcessorModel inference; prompt content routed to Google models
Google — sign-inIndependent controllerOptional Google sign-in; your profile (email, name, avatar)
OpenRouterProcessorRouting requests to language-model providers; prompt content and outputs
ZeptoMail (Zoho Corporation, EU region)ProcessorSending account and billing emails; your email address and the content of those messages. Handled on Zoho’s EU infrastructure.
Zoho Mail (EU region)ProcessorReceiving the mail you send to our published address; your email address and whatever you write to us
Hostinger (Germany)ProcessorRunning the Service’s servers and database; all data stored by the Service. The machine is in Düsseldorf, Germany — inside the EU.

When you enable ZDR for a request, we route it only to providers that commit not to retain or train on it. We may also disclose data where required by law or to protect our rights. Each independent controller listed above handles your data under its own privacy notice, which we link to where available.

6. International transfers

Some recipients (for example, model providers and Stripe) may process data outside the European Economic Area, including in the United States. Where they do, the transfer is protected by an appropriate safeguard under the GDPR — such as the European Commission’s Standard Contractual Clauses, an adequacy decision, or certification under the EU–US Data Privacy Framework. You can ask us for a copy of the relevant safeguards at the contact address above.

7. How long we keep it

DataRetention
Account dataFor as long as your account is active; deleted or anonymised after closure, unless we must keep it longer by law.
Prompt historyUntil you delete it or close your account (and not stored at all if you turn prompt storage off).
Billing and invoice recordsFor the period required by Romanian tax and accounting law.
Billing audit entries (including the country a purchase was allowed or reversed on)Kept while your account exists and for as long as the purchase they explain can still be queried, disputed, or audited.
Security and error logsFor a limited period necessary for security and troubleshooting.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased (“right to be forgotten”);
  • restrict certain processing;
  • object to processing based on our legitimate interests (see the purposes in section 3);
  • receive your data in a portable format;
  • withdraw consent at any time where we rely on consent (this does not affect processing already carried out). We do not currently rely on consent for any of the purposes in section 3 — the prompt-storage switch in section 4 is an opt-out we offer you, not a consent we depend on.

To exercise any of these rights, contact us at contact@vantageprompt.com. You also have the right to lodge a complaint with a supervisory authority — in Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro.

9. Automated processing

Two things on the Service are decided automatically. Neither of them profiles you, and neither is used for marketing.

  • Abuse screening. To keep the Service safe, we automatically screen the prompts you submit for adversarial and abusive patterns before processing. A prompt flagged as an attack may be blocked and, for repeated violations, may incur a small credit penalty. The decision concerns the individual prompt, not you as a customer: your account, plan, and access are unaffected. If you believe a prompt was blocked in error, contact us and a person will review it.
  • Availability of paid plans in your country. Paid plans are not offered in every country (see the Terms). When you buy, we compare the billing country you entered — and, if that does not already fall outside the restriction, the country that issued your card — against the list of countries we do not yet sell in. If either is on it, the purchase is reversed without anyone reviewing it first: the payment is refunded in full and a subscription is cancelled immediately. We tell you by email when this happens, and the free plan stays available.

The second decision has a legal effect on you, because it ends a contract you had just entered. We make it because completing the sale would oblige us to register for a tax we are not yet registered for — in GDPR terms, it is necessary for entering into the contract and required by law (Art. 22(2)(a) and (b)). You are not left with the machine's answer: write to us at contact@vantageprompt.com and a person will review the decision, hear your point of view, and correct it if it was wrong.

10. Cookies

We use only strictly necessary cookies to run the Service and process payments; we do not use advertising or analytics cookies. See our Cookie Policy for details.

11. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, access controls, and automated screening of abusive input. No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.

12. Children

The Service is not intended for anyone under 16 years old, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we will give reasonable notice before it takes effect. The “last updated” date at the top of this page shows the current version.

14. Contact

For any question about this policy or your personal data, contact us at contact@vantageprompt.com, by phone at +40 771 006 756, or by post at Code Art Web Solutions S.R.L., Sat Plavia, Comuna Iordacheanu, nr. 81, Prahova County, Romania.

More legal documents