Legal
Privacy Policy
Last updated September 29, 2026
This policy explains what Click2Share (“we”, operated by Click2Share) collects when you use the site, why, who we share it with, and how you can control it. We collect as little as we can: no ads, no selling data, no tracking cookies.
1. Who is responsible
Click2Share, India, is the controller of your personal data. Contact us at legal@notaislop.xyz for any privacy question or request.
2. What we collect
Account data (creators)
- Email address, used to sign you in with a magic link and to contact you about your account.
- If you continue with Google: your name, email, profile picture URL and Google account ID. We never see your Google password.
- Profile details you add: display name, username, bio and social links. These are public.
Content you publish
Prompt titles, descriptions, prompt text, example outputs and tags. Public and unlisted prompts are visible to anyone with the link; protected prompts are shown only after the password is entered. Passwords for protected prompts are stored as salted hashes, never in plain text.
Billing data
Payments are processed by Dodo Payments, which acts as the merchant of record. We never receive your card details. We store your Dodo customer and subscription IDs, your plan, billing period and subscription status.
Usage and technical data
- View and copy counts. When someone opens or copies a prompt, we count it. To avoid double counting we combine the visitor's IP address and browser user agent into a one-way hash that changes every day. The hash is kept in memory for up to 30 minutes and is not linked to any account.
- Security logs. To stop abuse (password guessing, email spam) we keep your IP address, and for sign-in requests your email address, in a rate-limit record for up to one hour.
- Vercel Web Analytics. Our host's cookieless analytics counts page views, referrers, country and device type in aggregate. It does not use cookies or track individual visitors across sites.
Readers who only view or copy prompts don't need an account, and we don't ask them for any personal data.
3. Why we use it (legal bases)
- To provide the service you signed up for: accounts, publishing, billing (performance of a contract).
- To keep the service secure and prevent fraud and abuse (legitimate interests).
- To understand usage in aggregate and improve the product (legitimate interests).
- To meet legal obligations, such as tax and accounting records kept by our payment provider.
We do not sell or “share” personal data for advertising, and we do not use it to train AI models.
4. Who we share it with
We use these service providers (processors), only for the purposes above:
| Provider | Purpose |
|---|---|
| “Continue with Google” sign-in (only if you choose it) | |
| Resend | Sending sign-in emails |
| Dodo Payments | Checkout, subscriptions, invoices, tax (merchant of record) |
| vercel | Hosting the website and database |
| Vercel Web Analytics | Cookieless, aggregate site statistics |
We may also disclose data if required by law, or to protect our users and the service.
5. Cookies
We only use cookies that are strictly necessary for the site to work, so no cookie banner is needed:
| Cookie | Purpose | Duration |
|---|---|---|
authjs.session-token | Keeps you signed in | 30 days |
authjs.csrf-token, authjs.callback-url, authjs.pkce.*, authjs.state | Protect and complete the sign-in flow | Session / minutes |
pf_unlock_* | Remembers that you unlocked a protected prompt | 30 days |
pf_theme | Remembers your light/dark theme choice | 1 year |
6. How long we keep it
- Account and content: until you delete your account. Deleting it removes your profile, prompts and linked sign-in accounts from our database immediately.
- A single deleted prompt disappears from the site at once; its record is kept (so old links can say it was removed) until you delete your account.
- Sign-in links expire after 24 hours; rate-limit records after about an hour.
- Backups are overwritten on a rolling basis.
- Billing records are kept by Dodo Payments for as long as tax law requires.
7. Your rights
Depending on where you live (including under the GDPR, UK GDPR and CCPA/CPRA), you can:
- access the personal data we hold about you, or get a copy of it;
- correct it (most of it you can edit yourself in Settings);
- delete it: use Delete account in Settings, or email us;
- object to or restrict certain processing;
- complain to your local data protection authority.
Email legal@notaislop.xyz to exercise any right. We'll answer within 30 days and won't treat you differently for asking.
8. Security
We use HTTPS everywhere, passwordless sign-in, hashed prompt passwords, signed and HTTP-only cookies, and rate limits on sensitive actions. No system is perfectly secure; if we learn of a breach affecting your data, we'll notify you as the law requires.
9. International transfers
Our providers may process data outside your country. Where required, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
10. Children
Click2Share is not directed at children. You must be at least 16 years old (or the age of digital consent in your country) to create an account.
11. Changes to this policy
If we make material changes, we'll update the date above and, for significant changes, notify account holders by email before they take effect.
Questions? Email legal@notaislop.xyz. See also our Privacy Policy and Terms of Service.