Privacy Policy
Last updated 29 September 2026
This describes exactly what ProphetTalk stores, where it goes and how to get rid of it. It is written against what the software actually does, not against what a policy template assumes.
What we store
If you have an account: your email address, the date you signed up, your subscription status, and an identifier for your customer record at Stripe.
Your conversations: the questions you ask and the replies you receive, so you can return to them. These are stored only for signed-in users, and only you can read them.
Usage records: one row per reply holding which figure you spoke to, which model answered, the number of tokens used and what it cost. These rows contain no message text. They are kept separate from your conversations on purpose, so questions about cost never touch what you said.
If you are not signed in: a random identifier in a cookie named pt_visitor, so your free monthly message can be counted. It is not linked to a name, an email or an IP address.
We do not store your IP address in our database. It is used in memory, for the moment of the request, to apply rate limits and to check the anti-bot token.
Cookies and local storage
- Session cookie — keeps you signed in. Set by Supabase.
pt_visitor— counts the free message for signed-out visitors.- Your theme choice — kept in your browser's local storage. It never reaches our servers.
- Cloudflare Turnstile may set a cookie to confirm you are not a bot.
There is no advertising, no analytics tracker and no third-party pixel on this site.
Who else sees it
We do not sell your data and we do not share it for advertising. It reaches these providers only because they are needed to run the service:
- Anthropic — receives your messages in order to generate a reply. Under their commercial terms your inputs and outputs are not used to train their models.
- Supabase — hosts the database and handles sign-in.
- Stripe — takes payments. Card details go straight to Stripe and never touch our servers.
- Vercel — hosts the site and keeps short-lived server logs.
- Cloudflare — provides the anti-bot check on the free message.
- Resend — delivers sign-in emails, if you use an email link rather than Google.
- Google — only if you choose to sign in with it, in which case they tell us your email address.
Sensitive subjects
People bring grief, illness and despair to a conversation like this one. Two things follow from that.
First, when a message contains language suggesting a crisis, the app puts crisis-line details on screen. A record that this happened is written to our server log for a short period. The text of your message is not written to that log, and nobody is contacted on your behalf.
Second, what you ask a figure of scripture can reveal your religious beliefs, which the law treats as a special category of personal data. We store it only to show you your own conversation, and you can delete any of it at any time.
How long we keep it
- Conversations — until you delete them, or until you ask us to close your account.
- Usage records — kept as aggregate billing history. They hold no message text.
- Payment records — held by Stripe for as long as tax and accounting law requires.
Deleting things
Any single conversation: the delete button beside it in the sidebar. It and every message in it are removed immediately.
Your whole account: email prophettalksupport@gmail.com from the address you signed up with and we will delete it, and every conversation in it, within 30 days.
You can also ask for a copy of what we hold about you, or ask us to correct it, at the same address.
Where it is held
Our providers operate in the United States, and your data is processed there. If you are in the UK, the EEA or Switzerland, the transfer is made under the standard contractual clauses those providers offer.
Children
ProphetTalk is not for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
Security
Everything travels over HTTPS. Conversations are protected by row-level security in the database, which means the key used by your browser cannot read another person's conversation even if it is asked to. No system is perfect, but the boundary is enforced by the database rather than only by the application.
Changes
If this policy changes in a way that matters, we will say so in the app or by email before it takes effect.