Privacy Policy
Last updated September 2026
This explains what Graft collects, why, and who else sees it. We keep this short on purpose — read the whole thing, it's not long.
What we collect
- Account info: the email and username you sign up with.
- What you build: your conversations with Sprout, the prompts you save, and what you post to the Feed.
- Usage: how many Sprout prompts you've used this month, so we can apply the free-tier limit correctly.
- Billing: if you subscribe to Cultivator, Stripe handles your card details — we never see or store your card number ourselves.
Who else sees it
We use a small number of outside services to run Graft. Each one only gets what it needs to do its job:
- Supabase — hosts our database and handles login. Your account data and saved prompts live here.
- Anthropic (Claude) — powers Sprout. Your messages to Sprout are sent to Anthropic to generate a response.
- Stripe — processes Cultivator payments. Only used if you subscribe.
- Vercel — hosts the website itself.
We don't sell your data to anyone, ever.
What's public
Saved prompts, your username, your reputation tier, and your Cultivator status (if you have it) are visible to anyone using Graft — that's how forking and the Feed work. Your email address is never shown publicly.
Your choices
You can delete prompts you own, and you can ask us to delete your account and associated data by emailing us below — forked copies other people made from your prompts before deletion will stay, the same way a fork on GitHub survives the original being deleted.
Cookies
We use essential cookies to keep you logged in. We don't use tracking or advertising cookies.
Changes
If this policy changes in a meaningful way, we'll update the date at the top and do our best to let active users know.
Contact
Questions, or want your data deleted? Contact us.