Promptscout logo

Promptscout

promptscout.app
Low Risk
Updated July 30, 2026

PromptScout is an AI visibility monitoring tool operated by a Polish sole proprietorship, and its consumer-facing policies are unusually clear, EU-centric, and GDPR-grounded. The documents affirm user ownership of submitted data, grant only a limited processing license, disclose all sub-processors with EU-based data locations, and explicitly commit that OpenAI does not train on API data and that PromptScout does not use advertising cookies or sell data. The main limitations are the absence of any formal third-party certifications (SOC 2, ISO 27001), no enterprise/DPA-for-customers documents supplied, and reliance on aggregated (rather than raw) data being sent to third-party AI providers. For a small-vendor SaaS handling primarily business/brand data rather than sensitive personal data, the risk posture is favorable for professional use with standard precautions.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Low Risk

The Terms explicitly state that users retain ownership of the data and content they provide, and that PromptScout receives only a limited license to process that data for delivering the service. This is user-favorable and clearly worded.

Confidence
90%

Output Data Ownership

Moderate Risk

The Terms confirm the vendor owns the platform's software, graphics and functionality, and that AI-generated insights are stored in the user's account for reference, but the documents do not expressly assign ownership of the generated insights/outputs to the user. Insight ownership is therefore ambiguous, even though the practical framing ('in your account for your reference') leans user-favorable.

Confidence
55%

Training Data Usage

Low Risk

PromptScout does not operate its own models; it uses OpenAI's API and states that OpenAI does not use API data to train its models. User data is used for service improvement via privacy-respecting analytics, but there is no indication that inputs feed model training. This is a favorable posture.

Confidence
78%

Data Retention & Deletion

Low Risk

The Privacy Policy provides a clear retention schedule: account and usage data retained while active and deleted with the account (account data within 30 days of a deletion request), and billing data kept 5-7 years for tax law. GDPR erasure rights and a 30-day response window are stated. There is no security-specific audit-log retention schedule, but for this type of tool that is not required.

Confidence
85%

Third-Party Data Sharing

Low Risk

Sharing with third parties (OpenAI, Google, Perplexity, SearchApi, and infrastructure sub-processors) is integral to the service and clearly disclosed in tables with data locations and transfer safeguards. Only configured prompt text — not personal identifiers — is sent to AI providers, and the policy explicitly states data is not sold to advertisers or data brokers.

Confidence
88%

Opt-Out Rights

Low Risk

Users can withdraw consent for marketing communications and analytics cookies at any time, and GDPR rights to object and restrict processing are explicitly provided. Analytics cookies are only set after consent via the banner. Core service-processing sharing (to AI providers) cannot be opted out of while using the service, which is inherent to the product.

Confidence
82%

Compliance & Certifications

Moderate Risk

The vendor grounds its operations firmly in GDPR and Polish/EU data protection law, and references PCI-DSS for its payment processor and the EU-US Data Privacy Framework/SCCs for transfers. However, no independent certifications relevant to the universal baseline (SOC 2, ISO 27001, ISO 42001) or the marketing_adtech set are claimed or attested, and there is no trust center or audit report referenced. Compliance is claimed, not certified.

Confidence
72%

Model Explainability & Auditability

Moderate Risk

The documents describe what data is sent to OpenAI and other AI providers and how responses are stored and categorized, providing reasonable transparency into data flows. However, there is no dedicated model explainability, auditability, or enterprise audit-access commitment, and the AI insights are explicitly disclaimed as informational only.

Confidence
55%

Security Practices & Breach History

Low Risk

The Privacy Policy discloses concrete security controls including TLS 1.3 in transit, AES-256 at rest, row-level security for data isolation, access controls, optional 2FA, and regular security audits. A GDPR-aligned breach notification process (72-hour authority notification) is committed. No dedicated trust center is referenced and no penetration testing or bug bounty is named, and no breach history is disclosed.

Confidence
80%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The tiers differ in features (AI insights, monitoring frequency, prompt counts, support) but the documents describe no material difference in data handling or privacy protections between free and paid tiers. AI-powered insights (and the associated OpenAI data flow) are paid-only, which is the only data-flow distinction disclosed. No separate enterprise data terms were supplied.

Confidence
60%

Human Review of User Inputs

Moderate Risk

The documents state that access is limited to authorized personnel and that data is isolated per account via row-level security, implying restricted staff access. However, they do not expressly address whether staff may read prompts or outputs for support or debugging, so the topic is only partially covered.

Confidence
50%

Regulatory & Litigation Exposure

Moderate Risk

The documents reference legal-obligation processing for tax and accounting purposes and the ability to lodge complaints with the Polish DPA, but they are silent on government data requests, law enforcement cooperation, or litigation history. This silence limits transparency on how the vendor would handle authority demands.

Confidence
45%

PII & SPI Data Inventory

Low Risk

The Privacy Policy provides a clear PII inventory: email, full name, company/brand name, IP address, device/browser information, and usage logs — all with a stated purpose. Payment card details are not stored, and no sensitive personal information (health, biometric, government ID, precise geolocation) is collected. Collection is proportionate and purpose-limited.

Confidence
82%

Policy–Product Currency

Low Risk

The Terms are dated February 9, 2026 and the Privacy and Cookie Policies February 2, 2026 — well within 12 months of the July 2026 analysis date. The policies explicitly address the AI-first product: they name the third-party AI providers (ChatGPT, Gemini, Perplexity, Bing Copilot via SearchApi), the OpenAI insights data flow, and the integrations/analytics visible in the product surface. Coverage matches the shipped capabilities well.

Confidence
85%

Cross-Document Consistency

Low Risk

Multiple documents were supplied (Terms, Privacy Policy, Cookie Policy, plus duplicate www/non-www versions of Terms and Privacy). The documents are consistent with one another — the training-use, sub-processor, retention, and no-advertising-sharing statements align across the Privacy and Cookie Policies, and the AI-features description in the Terms matches the Privacy Policy. No contradictions were identified.

Confidence
80%

You've read all 15 risk ratings for Promptscout. Create a free account to see the exact policy wording behind each rating.