Privacy Policy
Last updated: March 2, 2026
PRD Creator ("we," "us," or "our") operates the website prdcreator.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered Product Requirements Document (PRD) generator.
By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Information You Provide
- Product descriptions: The text you enter to generate a PRD.
- Generated PRDs: The documents produced by our AI models based on your input.
- Account information: If you sign in via GitHub OAuth, we receive your email address, display name, and GitHub profile identifier as provided by GitHub.
- Payment information: If you purchase a Pro subscription or Single Doc, payment is processed by Lemon Squeezy. We do not store your credit card number or full payment details on our servers.
Information Collected Automatically
- IP addresses: We collect IP addresses solely for rate limiting purposes via Upstash Redis. IP addresses are stored transiently and are not linked to your account or used for tracking.
- Session cookies: We use minimal session cookies for authentication. We do not use advertising or third-party tracking cookies.
- Usage data: Basic server logs and analytics that may include browser type, pages visited, and timestamps, collected by our hosting provider (Vercel).
2. How We Use Your Information
We use the information we collect for the following purposes:
- To generate PRDs based on your product descriptions using AI models.
- To save and display your PRD history when you are signed in.
- To process payments and manage your subscription.
- To enforce rate limits and prevent abuse of the Service.
- To send transactional emails (account confirmations, receipts, and service updates).
- To improve, maintain, and troubleshoot the Service.
3. AI Model Data Usage
Your product descriptions and generated PRDs are NOT used to train AI models.
When you submit a product description, it is sent to our AI providers (Anthropic Claude API or OpenAI GPT-4o API) solely to generate your PRD. Both Anthropic and OpenAI have committed to not using API inputs and outputs for model training. Your data is processed in real time and is not retained by these providers beyond what is necessary to deliver the response.
4. Third-Party Services
We use the following third-party services to operate PRD Creator. Each has its own privacy policy governing its use of data:
- Anthropic (Claude API): Primary AI model for PRD generation. Privacy Policy
- OpenAI (GPT-4o API): Fallback AI model for PRD generation. Privacy Policy
- Vercel: Hosting and deployment platform. Privacy Policy
- Turso: Database provider for storing user accounts and saved PRDs. Privacy Policy
- Upstash: Redis provider for rate limiting. Privacy Policy
- Lemon Squeezy: Payment processing for subscriptions and one-time purchases. Privacy Policy
- Resend: Transactional email delivery. Privacy Policy
- GitHub (OAuth): Authentication provider. Privacy Statement
5. Data Storage and Retention
- Account data: Your email and profile information are retained for as long as your account is active.
- Saved PRDs: PRDs associated with your account are stored until you delete them or delete your account.
- Unregistered usage: If you generate a PRD without signing in, the PRD exists only in your browser session and is not stored on our servers.
- Rate limiting data: IP addresses stored in Redis for rate limiting are automatically expired within a short time window (typically under 24 hours).
6. Data Deletion
You may request deletion of your account and all associated data at any time by contacting us at support@prdcreator.ai. Upon receiving your request, we will delete your account data, saved PRDs, and any personally identifiable information from our systems within 30 days. Some data may be retained in backups for a limited period before being permanently removed.
7. Cookies
PRD Creator uses minimal cookies. We use session cookies solely for authentication purposes when you sign in with GitHub. These cookies are essential for the Service to function and cannot be disabled without losing access to account features.
We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify individual users.
8. Data Security
We implement reasonable technical and organizational measures to protect your data. All data is transmitted over HTTPS. Our database and infrastructure providers maintain industry-standard security practices. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
9. Children's Privacy
PRD Creator is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: