Prompt Later privacy policy
Scope and purpose
Prompt Later is a browser extension that schedules user-written text messages for specific existing conversations on supported AI websites. The extension has no application backend, user account service, advertising system, or telemetry endpoint.
This policy covers the extension. The Chrome Web Store, the site hosting this policy, and the AI providers may process information under their own policies.
Data handled by the extension
The extension handles the messages you enter, selected conversation URLs and provider names, scheduling and time-zone settings, job identifiers and statuses, and activity records. Activity can include a message preview of up to 160 characters, the target URL, timestamps, and a delivery explanation.
With your permission, it reads a selected tab URL and matching provider-tab URLs. It inspects the saved conversation page to find the composer, check drafts and busy/error states, insert your scheduled text, and determine whether a matching user message appeared. This page inspection is transient; Prompt Later does not store or export conversation transcripts or AI responses, or collect general browsing history.
The extension processes your local vault passphrase in memory to derive an encryption key. It does not store the passphrase or read provider account passwords, authentication cookies, or API keys.
Local storage and encryption
Saved messages, conversation URLs, schedule definitions, and activity are stored in an AES-256-GCM encrypted vault in local extension storage. The key is derived using PBKDF2-HMAC-SHA256 with a random salt and 600,000 iterations. Each write uses a fresh random nonce.
While unlocked, the derived key is retained in chrome.storage.session, which Chrome holds in memory for the current extension session. The persistent vault and session storage are restricted to trusted extension contexts. The key is not written to the extension's persistent storage. Plaintext is used in memory and displayed where needed to operate the extension.
A browser restart, extension reload, disabling the extension, or an extension update clears the session key. You must unlock before scheduled sending resumes. Chrome's alarm system can separately retain the next wake-up time.
There is no recovery service for a forgotten passphrase. Encryption does not protect data from someone who can control an already unlocked browser, inspect its memory, or access your signed-in provider accounts. Operating-system backups, memory paging, password managers, and browser/profile backups are outside the extension's control.
When upgrading from an older unencrypted version, automatic scheduling remains paused until you create a passphrase. The original extension-storage record is removed only after the encrypted copy is saved and verified. Removing that record is not a guarantee of forensic erasure from disks or existing backups. If migration cannot finish safely, the extension preserves recoverable data and blocks scheduling.
Use, transmission, and sharing
Data is used only to provide the scheduling, delivery, safety, and activity features you request. The extension does not sell user data, use it for advertising or credit decisions, or send it to a Prompt Later server or an analytics service.
When a job runs, the extension opens or reuses the selected provider's HTTPS conversation page and sends your configured text through that website using your signed-in session. The provider receives and processes the message as an ordinary chat message under its own terms, account limits, and privacy policy. Opening the page also creates the provider's ordinary website traffic.
Store installation/update services and the host of this policy may receive standard traffic information when you use them. Those services are separate from the extension; this policy does not promise that third-party services keep no logs.
Retention and deletion
Saved jobs, including completed jobs, remain in the encrypted vault until you delete them. Sending a message does not automatically delete its saved job. Deleting a job does not delete its separate activity records. The extension retains up to the latest 200 finalized activity records; older finalized records are pruned during state updates.
The vault and its in-memory key are not synchronized by Prompt Later to another device. Uninstalling the extension removes its local extension data through Chrome. Copies made by you, browser/profile backups, operating-system backups, and records retained by an AI provider are not deleted by uninstalling Prompt Later.
To remove a message already sent to a provider, use that provider's own deletion controls and policies.
Your controls and important limits
You choose the conversation, text, time, recurrence, time zone, and late-run policy. You can edit, pause, or delete saved jobs and revoke site access through Chrome. Revoked access or a locked vault blocks new scheduled delivery attempts. A send already underway may complete; running jobs cannot be edited, paused, or deleted.
Keep the computer awake, browser running, vault unlocked, and target provider signed in. Scheduled times can be delayed. Unlocking resumes schedules and applies each saved late policy, so overdue messages may be sent immediately. Prompt Later does not bypass usage limits or guarantee provider availability.
You can clear the in-memory unlock key by reloading or disabling the extension or restarting the browser. Store your passphrase safely; the extension cannot recover it for you.
Changes and contact
Material changes to data handling will be reflected in this policy and the extension's disclosures before the changed handling is enabled.
If you email the support address, the information you choose to send is delivered to that inbox through email providers, including Gmail. Support correspondence is outside the extension's encrypted vault. Prompt Later does not automatically email logs or transcripts. Do not send vault passphrases, provider passwords, cookies, or API keys.
Contact: promptlater.support@gmail.com