Privacy Policy
Effective date:
This Privacy Policy explains how Prime UI, Inc. ("Prime UI", "we", "us") collects, uses, and shares personal data when you visit our website, use our documentation and support resources, purchase a license, access our customer portal, or use our AI Builder to generate website code (together, the "Services").
Who is the controller?
Prime UI, Inc.
1111b South Governors Ave STE 28388
Dover, DE, 19904, US
Contact: help@primeui.com
What this Policy does not cover
Websites built by our customers using the Software are controlled by those customers; they are responsible for their own privacy disclosures and compliance.
1. Data we collect
1.1 Data you provide
- Account and profile: name, company, role, email, password (hashed), billing address.
- Payments: we receive payment confirmations and limited details from our processor (for example, last 4 digits, card brand, status). Full card data is processed by our payment provider and never stored by us.
- Support and communications: email messages, ticket contents, survey responses, interview notes.
- AI Builder inputs (Customer Content): prompts, content, configuration choices, and files you upload to generate site code and related artifacts.
- Legal and compliance: license acceptance, consent records, opt-in and opt-out choices.
1.2 Data collected automatically
- Usage and device: IP address, device and operating system, browser type, pages viewed, referring URL, time on page, clicks and scrolls, error and performance metrics.
1.3 Data from third parties
- Payments and fraud: payment processor (for example, Stripe) sends us payment results and risk signals.
- Auth and identity: Better Auth, GitHub Auth, for example, email, name, avatar.
- Partners: if you buy via a referral link, we receive basic attribution data.
2. Why we use your data (purposes and legal bases)
AI Builder content. We process Customer Content to generate code for you. We do not use Customer Content to train any machine learning models without your explicit consent, and we do not permit our AI/model subprocessors to use Customer Content to train their models without your explicit consent.
Contractual restriction. The Software License prohibits customers from intentionally using the Software, Components, or Generated Output to train or fine-tune AI/ML models.
3. Sharing your data
We share personal data only with:
- Processors (service providers) who act on our instructions (for example, payments [Polar], hosting/CDN [Vercel, Cloudflare], analytics [Visitors], email [Resend], and AI/model providers used to generate outputs in the AI Builder [OpenAI]).
- Partners when you buy via a referral link (limited attribution data for commission).
- Authorities when required by law.
- Corporate events (merger, acquisition) where data is transferred in accordance with this Policy.
We do not sell personal data.
4. International transfers
We are a U.S. company. When we transfer personal data from the EEA/UK/Switzerland to the U.S. or other countries, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses and, where applicable, participation by certain providers in the EU-U.S. and UK-U.S. Data Privacy Framework. Details are available on request.
5. Retention
We keep personal data only as long as necessary for the purposes above:
- Account and license records: for the life of the account and 7 years thereafter for tax and accounting.
- Payment records (non-card): 7 years.
- Logs and analytics: 12-18 months (aggregate thereafter).
- Support tickets: 24 months after closure unless required longer.
- AI Builder inputs and generated artifacts: retained until you delete them in the product or request deletion, and in any event deleted from active systems within 30 days after account deletion, subject to limited retention for legal, security, and billing dispute purposes. Backups expire on a rolling basis within 60 days.
6. Your rights (EEA/UK and similar jurisdictions)
You may have the right to access, rectify, erase, port, or restrict processing of your personal data, or object to certain processing. You can also withdraw consent at any time (does not affect prior lawful processing).
Requests: help@primeui.com. We will verify your identity and respond within statutory timeframes.
Supervisory authority: You can lodge a complaint with your local authority (for example, in the EEA or the UK ICO).
California and US state rights: If applicable, you may have rights under CCPA/CPRA and similar laws (access, deletion, correction, opt-out of "sale/share"). We do not "sell" personal information. Contact us to exercise rights.
7. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege practices, and regular dependency updates. No system is perfectly secure; please notify us immediately of any suspected unauthorized access.
8. Children
Our Services are not directed to children under 16 (or lower age as permitted by local law). We do not knowingly collect personal data from children.
9. Changes to this Policy
We may update this Policy from time to time. We will post the updated version and change the "Last updated" date. Material changes may be communicated via email or in-product notices.
10. Contact
Questions or requests: help@primeui.com
Postal:
Prime UI, Inc.
1111b South Governors Ave STE 28388
Dover, DE, 19904, US
Appendix A - Primary processors
- Payments: Polar - payment processing, billing management (including invoices), and fraud prevention.
- Hosting/CDN: Vercel and Cloudflare - website and application hosting, respectively, content delivery network (CDN), security, and performance.
- Analytics: Visitors - website and product analytics.
- Email delivery: Resend - transactional email delivery.
- Auth: Better Auth, GitHub Auth - identity and access management (authentication, session management).
- AI/model provider(s): OpenAI - processes AI Builder prompts and files to generate outputs on our instructions.
We will update this Appendix as our subprocessors change; material changes will be reflected on this page.