FramePromptsBack to library

Legal

Privacy Policy

This Policy explains what personal data FramePrompts processes, why it is processed, and the choices and rights available to you.

Privacy PolicyTerms of UseCookie Policy

Effective date: 13 September 2026 · Last updated: 13 September 2026

FramePrompts is currently a public, free prompt library. Visitors do not need an account, and the public site does not currently use analytics or advertising cookies.

1. Who is responsible for your data?

The controller of personal data processed through FramePrompts is Denys Holovatiuk, operating FramePrompts, based at Smoluchowskiego 5, 02-679 Warsaw, Poland (referred to as “FramePrompts”, “we”, “us” or “our”).

Privacy enquiries and requests may be sent to privacy@frameprompts.com. If a data protection officer is appointed in the future, their contact details will be added here.

2. Scope of this Policy

This Policy applies to frameprompts.com, its prompt pages, and the private administration area. It does not govern third-party AI tools or websites that you may visit or use after leaving FramePrompts. Those services have their own privacy practices.

3. Personal data we process

When you browse the site

Our systems and infrastructure provider may automatically process technical data needed to deliver and protect the site, including:

  • IP address and approximate network or geographic information derived from it;
  • request date and time, requested URL, referring URL, response status and similar request metadata;
  • browser type, operating system, device type, language settings and protocol information;
  • security signals, error information and records of suspected malicious or abusive activity; and
  • network and performance information needed to route, cache and serve content.

We do not use this information on the public site to create advertising profiles or make decisions that produce legal or similarly significant effects.

Cookies and browser storage

The public site does not currently set analytics or advertising cookies. Cloudflare or the site may use strictly necessary cookies or similar mechanisms if required for security, traffic routing or reliable delivery. The private admin area currently uses HTTP Basic Authentication rather than an application session cookie.

In supported browsers, the admin tool uses IndexedDB to remember an administrator’s chosen local backup-folder handle. This information stays in that browser unless the administrator removes it. More detail is available in our Cookie Policy.

Administrators and invited contributors

For administrators and any invited contributors, we may process identifiers and professional contact details, authentication or access-control information, audit and security logs, contribution records, uploaded prompts and images, metadata, correspondence, and moderation or rights-management records. The current admin area is private and is not a registration service for the public.

Information you send voluntarily

If you contact us by email or through a form introduced later, we process the information you provide—such as your name, email address, message, attachments and the history of our correspondence—to respond to you and manage the matter. Please do not send confidential information, special-category personal data, or personal data about others unless it is necessary and you are entitled to do so.

4. Why we process data and our legal bases

PurposeTypical dataGDPR legal basis
Deliver the site, route requests, show prompts and maintain availabilityIP address, device and request dataOur legitimate interests in operating a functional website (Article 6(1)(f))
Prevent abuse, investigate incidents, secure the service and enforce our TermsIP address, request and security logs, authentication and audit dataOur legitimate interests in protecting the service, users and our rights (Article 6(1)(f)); where necessary, compliance with legal obligations (Article 6(1)(c))
Manage administrators, invited contributors and their submissionsIdentity, contact, access and contribution dataPerformance of a contract or pre-contract steps (Article 6(1)(b)); legitimate interests in editorial and access management (Article 6(1)(f))
Answer enquiries, privacy requests and content noticesContact details, message, evidence and correspondenceLegitimate interests in communicating and handling claims (Article 6(1)(f)); legal obligations (Article 6(1)(c)); or pre-contract steps when applicable (Article 6(1)(b))
Establish, exercise or defend legal claims and keep required recordsRelevant account, communication, security and submission dataLegitimate interests in protecting legal rights (Article 6(1)(f)) and legal obligations (Article 6(1)(c))
Use optional analytics, advertising or similar technologies if introduced laterData described in an updated noticeConsent (Article 6(1)(a)) where required; such tools will not be activated before the required information and controls are provided

Where we rely on legitimate interests, we consider the necessity of the processing and balance those interests against your rights and reasonable expectations. You may object as described below. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.

5. Sources of data

We obtain data directly from you when you contact us or contribute content; automatically from your browser, device and network when you use the site; from administrators who manage the library; and from service providers that operate or protect the service. If a rights complaint concerns you or your content, we may also receive relevant information from the person making the complaint.

6. Who receives personal data?

We disclose personal data only where needed for the purposes described above, including to:

  • Cloudflare, which provides website delivery and security, Cloudflare D1 database services, and Cloudflare R2 object storage. Depending on the processing activity, Cloudflare acts as our processor or handles certain data under its own documented responsibilities;
  • Zoho Mail, which provides our email hosting and processes messages sent to or from our domain;
  • professional advisers and contractors subject to appropriate confidentiality obligations, where necessary;
  • public authorities, courts or other parties where required by law or necessary to protect legal rights; and
  • a successor in connection with a merger, acquisition or transfer of the project, subject to applicable law.

We do not sell personal data. An up-to-date list of other processors, if any, may be requested using the privacy contact above.

7. International transfers

Cloudflare operates a global network, so personal data may be processed outside Poland or the European Economic Area. Where GDPR requires a transfer safeguard, we rely on an applicable adequacy decision or contractual safeguards such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate. Cloudflare’s current data-processing terms describe its transfer mechanisms. You may contact us for information about applicable safeguards and how to obtain a copy, subject to necessary redactions.

8. How long we keep data

We retain personal data only as long as reasonably necessary for the relevant purpose, taking into account the data’s nature, security needs, applicable limitation periods, legal obligations and the settings of the services we use. In particular:

  • request, diagnostic and security logs under our control are normally kept for up to 30 days unless an incident, abuse investigation or legal obligation requires longer preservation;
  • correspondence and content notices are normally kept for up to 3 years after the matter closes, unless a longer period is needed for legal claims or compliance;
  • administrator and contributor records are kept while access or the contributor relationship remains active and for up to 6 years afterward, subject to legal and rights-management needs;
  • published content and its provenance or licence records may be retained while it is published and afterward where needed to document rights and resolve disputes; and
  • local backup copies made through the admin tool remain under the administrator’s control until the administrator deletes them; managed infrastructure copies are removed or overwritten according to the applicable provider cycle and our operational settings.

Information stored locally by an administrator in IndexedDB remains until that administrator clears the site’s browser data or replaces/removes the saved permission.

9. Your GDPR rights

Subject to the conditions and exceptions in applicable law, you may ask us to:

  • confirm whether we process your personal data and provide access to it;
  • correct inaccurate or incomplete data;
  • erase personal data;
  • restrict processing;
  • provide data you supplied in a structured, commonly used, machine-readable format and transmit it where the portability right applies;
  • stop processing based on legitimate interests, including an unconditional right to object to direct marketing; and
  • withdraw consent at any time where consent is the basis for processing.

FramePrompts does not currently use solely automated decision-making that produces legal or similarly significant effects. To exercise a right, email privacy@frameprompts.com. We may ask for information reasonably necessary to verify your identity. We normally respond within one month, subject to extensions permitted by law.

You may also complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO). Information on complaints is available at uodo.gov.pl. You may instead contact the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred. We encourage you to contact us first so we can try to resolve the concern.

10. Security

We use technical and organisational measures designed to protect personal data, including access restrictions for the private admin area, encrypted transport, infrastructure security controls and limited access based on operational need. No internet service or storage method is completely secure, so we cannot guarantee absolute security.

11. Children

FramePrompts is intended for designers and creative professionals and is not directed to children under 16. We do not knowingly request personal data from children. If you believe a child has provided personal data to us, contact us so we can assess and, where appropriate, delete it. Visitors should also comply with the age requirements of any third-party AI service they use.

12. Changes to this Policy

We may update this Policy when the service, providers or law changes. The revised version will be posted here with a new “Last updated” date. If a change materially affects how we process existing personal data, we will provide additional notice or request consent where required.

13. Contact

Controller: Denys Holovatiuk, operating FramePrompts
Postal address: Smoluchowskiego 5, 02-679 Warsaw, Poland
Privacy email: privacy@frameprompts.com

FramePrompts

Curated AI prompts for designers, creators and better visual work.

Company

About

Library

Curated picks

Resources

Licenses
Copyright © 2026 FramePrompts. All rights reserved.
Privacy PolicyTerms of ServiceCookie Policy