Promptly

Privacy

Last updated 24 August 2026

Promptly tells students when an internship opens. To do that we need a little information about you. This page explains exactly what we keep, where it goes, and what we will never do with it — in plain English, not legal boilerplate.

Stays on your device

Your profile photo and application progress (applied, interview, offer) stay in your browser. Promptly does not send them to its backend, analytics, email provider, authentication provider, or an AI service. Clearing Promptly's browser data removes them from that device.

Account and alert information

When you create an account and set up alerts, Promptly processes:

  • Name, email address, and authentication account information
  • School, graduation year, major, location preference, and location flexibility
  • Interests, alert fields, saved alerts, and companies you choose to watch
  • Email, recap, reminder, and push-notification preferences
  • A browser push subscription if you explicitly enable push notifications

Your account profile and saved-list references are stored in your Supabase account metadata so they can follow you across devices. The alert-delivery copy is stored in Upstash so Promptly can match openings and send the notifications you requested.

These two copies are not the same. The alert-delivery copy holds only what is needed to decide whether an opening matches you and how to reach you. It does not include your major or your interests text, and it stores your graduation year only as a range — “1 year out”, “2 years out”, “3+ years out” — never the exact year. Your school is included, so we can tell how many students at a given school use Promptly when we talk to that school. We do not ask for your government ID, Social Security number, bank details, or passwords for any other service.

Automatic collection

Like any hosted website, a visit sends network information such as your IP address, browser request headers, requested page, and time of request to Vercel, our hosting provider. Promptly uses short-lived, one-way-digested request identifiers for abuse limits; it does not put the raw address into those Redis key names. Hosting and security logs may still be processed by Vercel under our service configuration and Vercel's own retention practices.

Browser storage, cookies, and caching

Promptly's own code does not set cookies. It uses browser local storage for your on-device profile, photo, progress, saved-list references, seen-alert markers, and push subscription. When you sign in, Supabase also persists the account session in browser storage. Signing out, restarting the demo, or deleting your data clears Promptly's local and session storage on that device.

The service worker caches public app files for offline use. It does not intercept or cache API responses. Choosing Google sign-in or opening an employer's website takes you to that provider's site, where its own cookies and privacy terms may apply.

First-party analytics

Promptly stores short-lived counts for a small allowlist of actions, such as an app open, listing view, official-posting click, signup, listing report, or request to watch a company. The event contains only its name: no email, name, school, search text, listing details, full profile, or persistent browser/session identifier. Daily analytics keys expire after about nine days.

There are no advertising cookies, tracking pixels, ad networks, session-replay tools, or cross-site behavioral analytics in Promptly. Company logos are served from Promptly's own files.

AI

Promptly does not send your profile, questions, or other information to an AI or large-language-model provider. Matching runs in your browser. “Ask Promptly” is a scripted, on-device help tool rather than an AI chat service.

Service providers and outside sites

  • Vercel hosts the site and server functions and receives normal web-request data.
  • Supabase provides accounts, authentication emails, and cross-device profile metadata.
  • jsDelivr serves the Supabase browser library when account support is enabled.
  • Upstash stores alert profiles, preferences, operational queues, reports, and aggregate counters.
  • Resend receives the recipient address and operational email content needed to deliver alerts and support notifications.
  • Apple, Google, Mozilla, or Microsoft push services receive a browser push subscription and notification payload only after you enable push.
  • Google processes the optional Google sign-in flow. Our support inbox is hosted by Gmail, which processes messages you send to it and listing-report notifications.

Promptly's backend reads public job data from employer career sites and applicant tracking systems. It does not send your profile to those job-data sources. When you choose “Open Official Posting,” you leave Promptly and the employer or recruiting platform receives the normal web data involved in visiting its site.

Email, reports, and notifications

Promptly sends account messages and the internship alerts, recaps, and deadline reminders you enable; it does not currently send advertising or third-party marketing email. Alert emails go to one recipient at a time and include a one-click unsubscribe link. You can also turn email, recap, reminder, and push categories on or off in Settings.

A listing report includes the listing, selected reason, and optional note. Promptly does not attach your account email to that report. Do not put personal information in the note. Push alerts can show a company, role, or deadline on a locked device; you can leave push off or hide notification previews in your device settings.

How long we keep information

  • Account and verified alert profiles remain until you delete the account or ask us to delete them. Promptly has not yet adopted an automatic inactive-account deletion period.
  • If you never confirm your email, your account is deleted after 14 days — both the alert profile and the sign-in account itself. Confirmation links expire after seven days.
  • Unsent daily-digest items expire after three days.
  • First-party analytics counters expire after about nine days.
  • Listing-problem reports expire after 90 days. They do not retain the reporter's account email.
  • Most abuse-control buckets expire between 10 seconds and one hour; delivery-deduplication records last only as long as needed to prevent a duplicate alert.

Public job-feed history and service-health records are operational, not student profiles. Service-provider logs and backups follow the applicable provider settings and contracts and may not disappear at the same instant as an active-record deletion.

What we never do

  • We never sell your data. Not to advertisers, not to data brokers, not to recruiters.
  • We never apply to a job on your behalf. Every alert links to the employer's own posting.
  • We never charge you to apply, and we will never ask you to pay an employer.
  • We never post anything anywhere as you.

Your controls

You can view and correct profile information, change each notification category, remove your photo, and clear a listing's progress inside the app. Open Profile → Settings → Delete My Data to remove the active Supabase account, Promptly alert profile, saved alerts, watched-company links, queued digest, unsubscribe mapping, and push subscription, and to clear this device. You can also email us to request access, correction, deletion, or a copy of stored account information; a self-service download is not available yet.

Students under 18

Promptly is built for college students and is intended for students aged 16 and over. It is not directed at children under 13, and we do not knowingly collect their information. If you believe a child under 13 has given us information, email help.promptly@gmail.com and we will delete it. You can delete your own account and data at any time from Profile → Settings → Delete My Data.

Questions

A real person reads this inbox: help.promptly@gmail.com. If something here is unclear or looks wrong, tell us and we will fix the page.

Back to Promptly · Terms · help.promptly@gmail.com