Last updated: 2026-09-03

Data Handling Policy

Operator: Javier Aguilar Martín, trading as AGILabs — 82 Chatterton Road, BR2 9QE, United Kingdom
Applies to: The operator, and anyone he engages to work on Prompt Scripter
Effective Date: 28 August 2026
Version: 1.0


1. Purpose

This policy sets out how user data is handled in Prompt Scripter, in compliance with the UK GDPR, the Data Protection Act 2018, the EU GDPR where it applies, and other applicable regulations.

Prompt Scripter is run by one person. This policy is the standard he holds himself to, and it binds anyone engaged to work on the Service. It is published so that users can see the rules, not only be told that rules exist. What users are entitled to, and what we do with their data and why, is in the Privacy Policy; this document is about how the data is handled operationally.


2. Scope

This policy applies to all personal data and user-generated content processed by Prompt Scripter, including:

  • Prompts, responses, and datasets stored by users.

  • Account data (email, login credentials, subscription status).

  • Logs and metadata used for abuse monitoring and debugging.

  • Mailing list addresses submitted through the website sign-up form.

It does not cover payment card details, because we never receive them. Stripe is the merchant of record for Pro subscriptions and collects and holds payment data itself.


3. General Principles

These principles apply to every handling of user data:

  1. Minimisation – Access only the data necessary for the task in hand.

  2. Confidentiality – Treat all user data as confidential. Do not disclose it outside the Service unless legally required.

  3. Integrity – Do not alter user data unless explicitly requested by the user or required for system operation.

  4. Transparency – Be honest with users about how their data is used, and keep the Privacy Policy accurate.

  5. Security – Follow best practices for securing accounts, devices, and access credentials.


4. Access & Permissions

  • Access to production databases and storage is limited to the operator.

  • Anyone engaged to work on the Service is given the narrowest access the work requires, and it is withdrawn when the work ends.

  • Administrative access is authenticated and access is logged.

  • User data is not copied onto personal devices, into spreadsheets, or into tools that are not part of the Service.


5. Data Collection & Storage

  • Only data explicitly stored by users is collected.

  • No scraping or background collection takes place.

  • Data is held only in the systems that run the Service: its managed database and the hosting platform it runs on. We will name our current infrastructure suppliers on request — write to info@javieraguilar.ai.

  • Temporary caches are cleared in line with the retention rules below.


6. Data Retention & Deletion

  • User data is retained only for as long as it is needed to provide the Service.

  • User-initiated deletions are respected: removed from the user’s view immediately, and purged from the underlying systems within the retention schedule.

  • Deleted data may be held briefly for abuse monitoring, safety checks, or legal compliance, and is purged once it is no longer needed for those purposes.

  • Moving from Pro to the free plan is not a deletion event. Nothing is removed; the user is prevented from creating more while over a limit. See the Terms of Service.


7. Data Transfers

  • Data may be processed in the UK and in other regions where service providers operate.

  • Transfers outside the UK are made under a mechanism recognised by the UK GDPR — an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — with any additional safeguards the transfer requires.


8. Payments

  • Pro subscriptions are sold through Stripe, which acts as merchant of record and as a controller in its own right for the sale.

  • Card details are entered on Stripe’s own checkout and never pass through our systems.

  • What we receive and store is a Stripe customer identifier and the state of the subscription, which is what is needed to grant or withdraw access to Pro.


9. Incident Response

  • Any suspected data breach is investigated immediately by the operator.

  • Incidents are logged, with what happened, what data was involved, and what was done about it.

  • A breach that poses a risk to people’s rights and freedoms is reported to the ICO within 72 hours of becoming aware of it, as the UK GDPR requires. Where the risk is high, affected users are told directly and without undue delay.


10. Suppliers and Contractors

  • Suppliers who process user data on our behalf do so under a written agreement containing the terms Article 28 of the UK GDPR requires.

  • Anyone engaged to work on the Service must meet the standards in this policy, and agrees to do so as a condition of the engagement.


11. Review

  • This policy is reviewed annually, and sooner after any significant change to the Service, to the regulations, or to how data is processed.

  • Questions about it go to info@javieraguilar.ai.