Prompt Petal

Privacy

What Prompt Petal can see, what it sends, what we store, and how to delete it. Last updated September 14, 2026.

What you select and type stays on your device

Prompt Petal reads the text you have selected, builds the prompt you picked from it, and types the result into the app you are using. All of that happens on your device. It watches one keyboard shortcut and ignores every other key you press. While a password field is active, it does nothing at all.

On a Mac this needs Accessibility permission, which macOS requires for any app that reads a selection or types into another app. That is the only permission Prompt Petal asks for there. On iPhone and Android, the part that types for you is a keyboard, and it makes no network connections of any kind. On iPhone it also runs with Full Access turned off.

Clipboard history

Off until you turn it on. When it is on, Prompt Petal remembers the last five things you copied so you can pick them from the ring. They are held in memory only, never written to disk and never sent anywhere, and they are forgotten when you quit the app or turn the setting off. Anything a password manager marks as private when it copies is skipped.

Sharing a prompt

A shared link carries the prompt inside the link itself, after the # sign. Browsers keep that part of a link to themselves and do not send it to the website, so when someone opens a link you shared, promptpetal.com never receives the prompt and has no copy of it. Only prompts can be shared this way. Opening a shared link shows you the prompt and adds nothing until you choose to keep it.

Syncing between your Apple devices

Free, and it needs no account. Your prompts, boards and the settings that follow you travel between your Mac, iPhone and iPad through your own iCloud account. They go to Apple, never to us, and Apple's privacy policy covers them there. You can turn this off in Settings.

Your account

You only need an account to sync across different kinds of device, for example between an iPhone and a Windows PC. To create one you give us an email address, and we send a six digit sign in code to it. The code expires after 15 minutes and stops working after five wrong tries. Emails are delivered for us by Resend.

For each account we store your email address, an account identifier, when the account was created, and which plan you have. A device stays signed in for up to 400 days, or until you sign out.

Syncing across all your devices

Part of Pro. Sync carries your prompts, your boards, which prompt packs you added, and the settings that follow you: your flower and its color, what a prompt does when nothing is selected, and whether a petal also copies what it inserts. Before any of it leaves your device, it is encrypted with a key made from your recovery code, which is created on your device and kept in its protected storage.

How your other devices get that code is your choice. With QR codes, it passes straight from one of your devices to another, encrypted so only the new device can read it, and it is never sent to us in a form we can read. With a passcode of 4 to 6 digits, we keep a locked copy of the code so a new device only needs the passcode. That copy is sealed with a key made from your passcode and a secret that is kept apart from our database, we only answer guesses from a device signed in to your account, and 10 wrong tries erase it. Choosing a passcode means we hold that locked copy; choosing QR codes means we never do.

Alongside each encrypted record we store what the service needs to work: which record it is, a counter that goes up each time it changes, when it changed, and whether it was deleted. Each record also carries a short fingerprint that lets your own devices tell whether they hold the same version. That fingerprint is made with a key from your recovery code too, so we cannot use it to recognize a prompt, including the ones that come with the app.

If you use QR codes and lose every device that holds the code, the synced copies cannot be read again by anyone, including us. The prompts on your devices are unaffected.

Deleting your account

You can delete your account in Settings. That removes the account and every synced record stored under it. The prompts on your devices stay where they are. Signing out keeps everything as it is, on the server and on your device.

No longer have the app? Email hello@littlebirdtrading.com from the address you signed in with and ask us to delete your account. We remove the account and every synced record stored under it, and reply when it is done. Purchase records kept by Apple, Google or Stripe stay with them.

Prompt packs and updates

Browsing and downloading prompt packs asks promptpetal.com for the list and for each pack you add. The version of the Mac app downloaded from this website checks promptpetal.com for updates. Neither request carries anything about you or your prompts.

If you buy Pro

Payment is handled by Stripe or by the app store you bought through. We receive your email address and which plan you bought, and we never see your card details. When you buy through the App Store or Google Play, the app sends the store's own proof of purchase to promptpetal.com so your purchase can be confirmed.

Crash reports

You decide whether we see one. If Prompt Petal quits unexpectedly, the next time it opens it offers to start an email to us with a crash trace in it, which you can read first. The report reaches us when you send that email yourself.

Watches

On Apple Watch and Wear OS, your phone passes your prompts to your watch directly, over the connection the two already share.

Contact

Little Bird Trading, hello@littlebirdtrading.com. A person reads it.