Privacy Policy
Last updated: 9 August 2026
1. Who we are
Prompten ("we", "us") operates the website at www.prompten.xyz, a free self-paced course in prompt engineering.
- Data controller: Daniels Bloom
- Contact for privacy matters: privacy@prompten.xyz
- Location: Nigeria
If you have a question about this policy or about your data, email the address above. We aim to respond within 30 days.
2. What we collect, and why
We collect only what the course needs to work. We do not sell data, we do not run advertising, and we do not use third-party trackers.
When you create an account
As you use the course
When you earn a certificate
3. Certificates are publicly verifiable — please read this
Every certificate has a verification page at www.prompten.xyz/verify/<credential-ID>.
Anyone who has that link can see the name on the certificate, the score, the grade, and the issue date. That is the purpose of the page — it lets an employer confirm a certificate is real.
- Your email address is never shown on the verification page.
- Verification pages are marked
noindex, so search engines are instructed not to list them. - The link is not secret. If you share it — for example on LinkedIn — anyone with the link can view it.
If you would prefer your certificate not to be publicly verifiable, email privacy@prompten.xyz and we will remove it.
4. Our lawful basis for processing
Under section 25 of the NDPA, we rely on:
- Contract — for your account, progress and certificate. We cannot provide the course without this data.
- Consent — for optional profile fields, and for any future emails. You may withdraw consent at any time.
- Legitimate interest — for basic usage analytics, to improve the course. This is limited and you may object.
5. Where your data is stored, and cross-border transfer
Our database and authentication are provided by Supabase, and the site is hosted by Vercel. Both are outside Nigeria; our database is located in West EU (Ireland), AWS region eu-west-1.
This means your personal data is transferred outside Nigeria. Under sections 41–43 of the NDPA we rely on the contractual protections in our agreements with these providers, which require them to protect your data to a standard comparable to the NDPA.
6. Cookies and local storage
We do not use cookies for tracking or advertising.
To keep you signed in, we store an authentication token in your browser's local storage. This is strictly necessary for the site to function — without it you would be signed out on every page. It contains no advertising or tracking identifiers, and it is removed when you sign out.
We use no analytics cookies, no advertising cookies, and no third-party trackers.
7. How long we keep it
- Account, profile and progress — until you delete your account.
- Certificates — indefinitely, unless you ask us to remove yours, because a certificate that stops verifying is worthless.
- Usage events — kept for 24 months, then deleted.
When you ask us to delete your account, we delete your profile, progress and usage events. Tell us if you also want your certificate removed.
8. Your rights
Under the NDPA you have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data ("right to erasure")
- Restrict or object to processing
- Portability — receive your data in a usable format
- Withdraw consent at any time, where we rely on consent
- Not be subject to solely automated decisions with legal or similarly significant effects. We make none.
To exercise any of these, email privacy@prompten.xyz. We will respond within 30 days and will not charge you.
If you are unhappy with how we handle your data, you may complain to the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
9. If you are in the UK or EU
If you access the course from the UK or EU, the UK GDPR or EU GDPR may also apply. The rights in section 8 are substantially the same, and you may complain to your national supervisory authority as well as, or instead of, the NDPC.
10. Security
We protect your data with:
- Encrypted connections (HTTPS) throughout
- Row-level access controls, so one account cannot read another's data
- Passwords hashed by our authentication provider — we never store or see them
- Server-side issuing of certificates, so they cannot be fabricated by a browser
No system is perfectly secure. If we discover a personal data breach we will report it to the NDPC within 72 hours of becoming aware of it, and will notify you directly where the risk to you is high, as required by the GAID.
11. Children
This course is intended for adults. You must be 18 or older to create an account.
Under the NDPA, processing a child's data requires verifiable parental consent, which we are not set up to obtain. If you believe someone under 18 has created an account, email privacy@prompten.xyz and we will delete it.
12. Changes to this policy
If we change this policy we will update the date at the top. If the change materially affects your rights we will tell you by email before it takes effect.