PromptRecon legal
GDPR Information
Last updated: June 28, 2026
This page explains how PromptRecon approaches privacy and data protection for users in the European Economic Area, United Kingdom, and other regions with similar data protection laws.
1. Controller
For the purposes of applicable data protection law, the controller is:
PromptRecon
Website: promptrecon.com
Contact: privacy@promptrecon.com
2. What Personal Data We May Process
Depending on how you use PromptRecon, we may process:
- Account details, such as name and email address
- Prompt text submitted for analysis
- Generated recon reports
- Usage history and usage limits
- Billing status, if paid plans are enabled
- Support messages
- Technical logs, device data, and security logs
3. Purposes of Processing
We process personal data to:
- Provide PromptRecon and generate prompt recon reports
- Manage accounts, plans, and usage limits
- Improve product reliability and functionality
- Provide customer support
- Detect abuse, security issues, or misuse
- Comply with legal obligations
4. Lawful Bases
Where GDPR applies, our lawful bases may include:
Contract
We process data needed to provide the service you request.
Legitimate Interests
We process limited data to secure, maintain, improve, and prevent abuse of the service.
Consent
We rely on consent where required, such as optional communications or certain analytics.
Legal Obligation
We may process data where necessary to comply with applicable laws.
5. Prompt Content
Prompt content may contain personal data if users include it. Users should avoid submitting personal, sensitive, confidential, or regulated information unless they have a lawful basis and authority to do so.
PromptRecon is designed for prompt analysis, not for processing sensitive datasets or confidential business records.
6. Processors and Subprocessors
PromptRecon may use third-party processors to operate the service, including:
- Cloud hosting providers
- AI model providers
- Payment processors
- Analytics providers
- Error monitoring providers
- Email or support tools
These providers process data only as needed to provide their services to PromptRecon.
7. International Transfers
Some service providers may process data outside the EEA or UK. Where required, we use appropriate safeguards such as contractual protections or other lawful transfer mechanisms.
8. Retention
We keep personal data only as long as necessary for the purposes described above.
Retention may depend on:
- Whether you have an account
- Whether prompt history is enabled
- Legal, billing, or tax requirements
- Security and abuse prevention needs
- Support history
You may request deletion of your personal data by contacting privacy@promptrecon.com.
9. Your GDPR Rights
Subject to applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Delete your personal data
- Restrict processing
- Object to processing based on legitimate interests
- Request data portability
- Withdraw consent where processing is based on consent
- Lodge a complaint with a data protection authority
To exercise your rights, contact privacy@promptrecon.com.
10. Response Time
We aim to respond to valid GDPR requests within one month, unless a longer period is permitted by law due to complexity or volume.
11. Security Measures
PromptRecon uses reasonable technical and organizational measures designed to protect personal data, including access controls, secure infrastructure, limited retention, and security monitoring where appropriate.
12. Data Protection Contact
For GDPR or privacy-related requests, contact:
13. Important User Responsibility
Because PromptRecon analyzes text submitted by users, users are responsible for ensuring they do not submit personal data, confidential information, regulated information, or third-party data without proper authority and lawful basis.
You can also review our Privacy Policy and Terms of Use.
Related legal pages
