No mystery layer
Privacy policy.
The current AI workspace on our homepage saves your project on our server. The older browser workshop and the free workshop inside the iPhone app are separate, local-storage experiences. The sections below distinguish them.
Updated September 10, 2026The current AI workspace
The homepage preview saves your conversation, generated project and workspace records on our server. Requests and relevant project content go to your chosen AI provider. A secure session cookie opens that workspace; verifying your email links it to your account. Paid hosting and payment management use that verified account. Review the workspace terms for the current service.
To understand which campaigns lead to useful work, a fixed set of campaign labels is first kept in this tab’s session storage, then associated with the existing workspace and, at checkout, the existing account. Unknown labels become “other.” We use those existing private project/account references to avoid counting the same first build, account save or first paid activation twice, and to count later-day returns once per saved workspace per day. Reports contain only dates, campaign categories, milestone names and totals—not account references, email addresses, prompts, project contents, payment identifiers, IP addresses or complete URLs. We do not add an analytics cookie, a separate visitor identifier or cross-site tracking.
Daily measurement reports cover the last 90 days; old aggregate rows are pruned as new milestones are recorded. Campaign context and first-milestone markers stay with the related workspace/account until deletion. Deleting a free workspace removes its associated measurement references; anonymous totals remain. Paid-account deletion is coordinated with support so payment records and running services are handled safely. Automated checks, review previews and known server probes are excluded where detected. These counts are operational measurements, not audited unique-person counts or proof of an app installation.
1. The older private workshop
The browser workshop stores its draft in your browser’s local storage so you can continue on that device. The workshop does not require an account and does not send those draft answers to our server. Clearing browser storage or choosing start over removes that browser copy.
The free workshop in the App Store app (currently version 1.1) saves progress in local app storage. It does not require a One Small Prompt account or paid subscription and does not send workshop answers to One Small Prompt or a third-party AI provider. The local app and browser workshop drafts do not sync or transfer through One Small Prompt. Apple or device backup and restore may include app data depending on your settings, and Apple may process standard App Store and device diagnostics under its policies.
The managed-project client in app version 1.1 opens only after you enter a one-time activation code. Using it is an explicit, authenticated connection to the separate paid service; it does not upload or convert the local workshop draft.
2. Information used for managed publishing
- Checkout and service details: email, name, requested domain, chosen domain mode, Stripe customer/session/subscription identifiers, and the business brief you choose to carry forward. The $39 subscription is purchased through Stripe on the One Small Prompt website, not inside the app.
- Website acquisition and funnel context: on One Small Prompt web pages, a small allowlist of campaign labels and recognized referring-site hostnames—not full referring addresses—may be carried through checkout; unknown values are grouped as “other.” We also keep aggregate counts of a small allowlist of web milestones, including an outbound App Store visit. This first-party website measurement uses no analytics cookie or visitor identifier, does not claim an app installation, does not retain IP addresses, and never receives your private workshop answers, business name, domain, or generated copy. The iPhone and iPad app itself does not send these events.
- Payment: Stripe handles card and payment information. We do not receive or store your full card number.
- Domain registration: when you request an included domain, the registrar needs registrant contact information such as name, email, phone, and postal address. We use it only to place and administer that registration.
- Project content: website files, business details you place in the site, editor requests, change history, automatic safety checkpoints, and service configuration needed to operate your project. This is one server-backed project shared by its secure browser and managed app clients, not a copy of a local workshop draft.
- Managed access: expiring sign-in, activation, and session information needed to authenticate the secure browser or managed app client and connect it to the correct paid project.
- Operations and security: server logs, request time, IP address, uptime/TLS/storage status, error information, and support correspondence.
3. Claude-assisted website edits
When you submit a managed edit request in the secure browser—or in the iPhone and iPad app (version 1.1 or later)—the request and relevant website context go to One Small Prompt servers and are processed by Anthropic’s Claude to propose or make the requested change. The resulting history is retained with the managed project so both clients show the same continuity and draw from the same monthly allowance.
The editor is scoped to that customer’s website workspace. It is not given domain, DNS, billing, account, hosting-control, or cross-customer access. Do not place unnecessary sensitive personal information in an editor request.
4. Providers and disclosure
We use service providers only for their operational roles, including Stripe for payments, Anthropic for requested AI processing, Hostinger for infrastructure and domain services, email providers for transactional and support messages, Apple for app distribution, and certificate/security providers such as Let’s Encrypt.
We may disclose information when required by law, to protect customers or the service, or as part of a business transaction subject to appropriate safeguards. We do not sell personal information. We do not load an advertising pixel on One Small Prompt pages.
5. Retention and security
Active project information is kept while needed to provide the subscription. When an authenticated permanent-deletion request is accepted, managed sessions and activation links are revoked immediately. The site is taken offline and its Stripe subscription is ended by a retrying lifecycle worker. Primary website, editor-history, and account data then remain only in restricted recovery quarantine until the receipt’s recovery-retention date, normally 30 days, before they are erased or irreversibly anonymized.
Once the deletion worker moves a project into restricted quarantine, that quarantine is outside the configured active file-backup inputs. File-level project backups are purged with the primary project at the recovery-retention date. A backup captured before that move, and older encrypted disaster-recovery snapshots, may retain a residual copy for no more than 30 additional days while those snapshots rotate. They are unavailable to the active service, and a retained deletion lock prevents a snapshot restore from reactivating the project. Payment and domain records may be kept as required for tax, fraud prevention, registration, dispute, and legal obligations. Security logs are retained only for their disclosed operational rotation period.
Each paid website uses a separate operating-system project workspace. Its secure browser and managed app clients use authenticated access to the same scoped tooling, history, and local metered AI broker. The service creates automatic safety checkpoints behind those clients. No system is perfectly secure; contact us promptly if you suspect unauthorized access.
6. Your choices
You can request access, correction, export, cancellation, or deletion by writing from the checkout email. An authenticated deletion request submitted inside the managed client is irreversible: it cannot be undone with a new activation code. Domain transfer requires identity verification and can be delayed by registrar rules. Deletion may exclude records we must retain for payment, security, domain, dispute, or legal reasons.
Privacy or data request:
support@onesmallprompt.com