Last updated · 2026-08-15
Privacy policy
We keep as little data as we can: enough to log you in, write your PRD, take payment, stop people farming free PRDs, and email you. We don't run ad trackers or analytics cookies.
What we collect
GitHub login is the only auth method. When you sign in, we store your GitHub id, login, display name if available, primary email, avatar URL if available, and GitHub account creation date. We store your idea text, intake answers, generated brief, generation status, generated PRD, public/private setting, and operational event history. We also store session records, payment attempt records, email delivery records, and server logs needed to operate and secure the service.
Free-claim fingerprint
When you claim a free Founding PRD we store a one-way salted hash of your connection metadata (IP address, browser identifier) to prevent free-tier abuse. We cannot reverse it, we don't use it for tracking, and we delete it when the Founding 100 program data is archived.
The browser sends no fingerprint id. The server derives the hash from request metadata when evaluating or enforcing free eligibility.
Processors
We use GitHub for authentication, Stripe for payments, Resend for transactional email, and Anthropic through the CRHQ platform to process your idea text and intake answers into a PRD. Stripe handles card data; we never see card numbers. CRHQ orchestrates the AI agent sessions that write the PRD.
There are no advertising trackers and no analytics cookies. The only cookies are functional session and OAuth-state cookies.
Retention
| Account | Kept until you request deletion, unless records must remain for payment, abuse, or public-license reasons. |
|---|---|
| Sessions | Rolling 30-day sessions; expired sessions are removed by maintenance. |
| Intake and brief data | Kept while your generation is active. Idle pre-payment work can be archived after 7 days and hard-deleted later if no payment exists. |
| Payments | Payment audit records are retained because they support receipts, disputes, and manual refunds. |
| Public PRDs | Public PRDs remain public under CC BY 4.0. Account deletion does not remove the public license. |
| Free-pool fingerprint | Kept for the life of the Founding-100 program and deleted when that program data is archived. |
Deletion rights and public PRDs
You can ask us to delete your account by contacting support@generateprd.com. We delete or anonymize account data where we can. Public PRDs are the carve-out: free PRDs and paid PRDs published for the discount stay public under their license. Deleting your account also does not restore a used free slot.
License: CC BY 4.0. This PRD is published under the Creative Commons Attribution 4.0 International license. Use it freely for anything — including commercial projects. Just credit GeneratePRD.com with a link. Full license text: https://creativecommons.org/licenses/by/4.0/
We send transactional and lifecycle email only: welcome, generation started, generation complete, and payment receipt. We do not send marketing email unless you separately opt in later.