Cookie Policy
Last Updated: June 29, 2026
This Cookie Policy explains how Brewcode LLC (“Brewcode,” “we,” “us,” or “our”), the developer and operator of prmpts, uses cookies and similar tracking technologies on www.prmpts.app and the prmpts application (collectively, the “Service”).
Brewcode LLC is registered at 1130 Ogletown Road, PMB # 1857, Suite 2, Newark, Delaware 19711, USA.
By using the Service, you consent to the use of cookies as described in this policy. You can withdraw consent at any time by adjusting your browser settings or contacting us — though some features of the Service may not function correctly without certain cookies.
1. What Are Cookies?
Cookies are small text files placed on your device (computer, smartphone, or tablet) by a website or application. They are widely used to make websites work efficiently and to provide information to the operator. Cookies are not programmes and cannot carry viruses or install malware.
Beyond traditional cookies, we also use related technologies such as browser local storage, session storage, and in-memory storage. These serve similar purposes — persisting data on your device or in your browser tab — and are covered by this policy.
2. Types of Cookies and Tokens We Use
2.1 Essential / Strictly Necessary
These are required for the Service to function (chiefly to keep you signed in securely). They cannot be disabled without breaking core functionality. No consent is required for these under applicable law.
| Key | Purpose | Storage | Duration |
|---|---|---|---|
| Refresh token | Lets you stay signed in and obtain new access tokens without re-login | Cookie (HttpOnly, Secure) | ~30 days |
| Access token (JWT) | Authorises your requests during a session | In-memory (browser, not persisted) | ~15 minutes (auto-refreshed) |
| Claim token | Temporary token used to complete the prompt-claim flow | sessionStorage | Until the browser tab is closed |
| Cookie-consent / UI preferences | Remembers your consent choice and UI settings (e.g. theme) | localStorage | Until cleared |
Security note: the long-lived refresh token is stored in an HttpOnly cookie (inaccessible to JavaScript). The short-lived access token is kept in memory — deliberately not in localStorage — to reduce exposure to cross-site scripting (XSS).
2.2 Analytics Cookies
Where enabled by the site operator, these help us understand how users interact with prmpts so we can improve it. They are set with your consent where required by law.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Analytics | Distinguishes unique users; tracks session count and source | 2 years |
_gid | Google Analytics | Distinguishes users within a 24-hour window | 24 hours |
_ga_* | Google Analytics 4 | Stores and counts page views and events | 2 years |
_clck, _clsk | Microsoft Clarity | Session/behaviour analytics (where enabled) | up to 1 year |
prmpts may use Google Analytics, Google Tag Manager, and/or Microsoft Clarity (each enabled at the operator’s discretion) to understand page views, navigation patterns, and feature adoption. IP addresses sent to Google Analytics are anonymised. This data is processed subject to the respective provider’s privacy policy.
2.3 Payment Processor Cookies
When you access billing or checkout pages, our payment processor Stripe may set its own cookies for fraud prevention, transaction security, and payment-session management. These are governed by the Stripe Privacy Policy. Checkout is hosted by Stripe, so cookies on the checkout page are set directly by Stripe.
2.4 Marketing & Advertising Cookies
prmpts does not use third-party advertising cookies, retargeting pixels, or cross-site tracking cookies. We do not serve advertisements through the Service. If this changes, this policy will be updated and you will be notified.
3. Local Storage, Session Storage & In-Memory Storage
In addition to cookies, prmpts uses browser-based storage for performance and functionality:
3.1 Local Storage
Persistent client-side storage that survives browser restarts. We use it for UI preferences (such as theme) and your cookie-consent choice. Local storage data can be cleared via your browser settings or developer tools.
3.2 Session Storage
Temporary storage cleared when you close the browser tab. We use it for short-lived flow state, such as the prompt-claim token.
3.3 In-Memory Storage
Your access token is held only in memory for the duration of the page session and is never written to persistent storage.
prmpts does not currently use IndexedDB. If we introduce it in the future, this policy will be updated.
4. First-Party vs Third-Party Cookies
First-party cookies are set directly by prmpts (prmpts.app) and are used solely for operating the Service (primarily authentication).
Third-party cookies are set by external services we integrate with:
- Stripe (stripe.com) — payment processing and fraud prevention
- Google Analytics / Google Tag Manager (google.com) — usage analytics, where enabled
- Microsoft Clarity (microsoft.com) — usage analytics, where enabled
- Google / GitHub sign-in — may set cookies during the OAuth sign-in flow you initiate
- Google Cloud Platform — infrastructure/CDN (may set security/performance cookies)
We do not control third-party cookies beyond choosing which third parties to integrate with.
5. Cookie Security
- Cookies are transmitted over HTTPS-only connections (Secure flag).
- The authentication (refresh) cookie is set with the HttpOnly flag, making it inaccessible to JavaScript and protecting against XSS.
- The
SameSiteattribute is set appropriately to limit cross-site exposure. - We do not store passwords, full payment card details, or sensitive personal information in cookies.
6. How to Control Cookies
6.1 Browser Settings
You can control and delete cookies through your browser settings:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Preferences → Privacy & Security → Cookies and Site Data
- Apple Safari: Preferences → Privacy → Cookies and website data
- Microsoft Edge: Settings → Privacy, search, and services → Cookies
You may block all cookies, block third-party cookies only, or delete cookies for specific sites. Blocking essential cookies will prevent you from signing in to prmpts.
6.2 Opt Out of Analytics
You can opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-On, blocking analytics cookies via browser settings, or emailing us at support@prmpts.app.
6.3 Do Not Track (DNT)
Where your browser sends a “Do Not Track” signal, we honour it by not setting analytics cookies. Essential cookies necessary for the Service to function are not affected.
6.4 Impact of Disabling Cookies
- Block all cookies: you cannot sign in to prmpts or use authenticated features.
- Block third-party cookies only: full prmpts functionality is available; analytics and payment flows may be affected.
- Block analytics cookies only: prmpts functions normally; we lose usage-insight data.
7. Retention Periods
- Access token (in-memory): refreshed about every 15 minutes; discarded when the tab/session ends or you sign out.
- Refresh token (HttpOnly cookie): valid up to ~30 days; deleted on sign-out or account deletion.
- Analytics cookies: retained up to 2 years; data retention at the provider is subject to its policy.
- Preference / consent (localStorage): persists until you clear browser storage.
- Session storage: cleared when the browser tab is closed.
8. International Compliance
8.1 India (IT Act 2000, IT Rules 2011 & MEITY)
Our cookie practices comply with the Information Technology Act, 2000, the Information Technology Rules, 2011, and MEITY guidelines. We implement reasonable security practices for cookie data and obtain consent for non-essential tracking cookies.
8.2 European Union (GDPR & ePrivacy Directive)
For users in the EU/EEA and UK, we obtain prior consent before setting non-essential cookies (analytics). You may withdraw consent at any time. Essential cookies are set on the basis of legitimate interest in operating the Service.
8.3 United States — California (CCPA)
Cookie data (such as IP addresses and device identifiers) may constitute “personal information” under the CCPA. We do not sell this information. California residents may request disclosure, deletion, or opt-out by contacting support@prmpts.app.
8.4 Other Regions
We strive to comply with cookie regulations in all regions where prmpts is used. For jurisdiction-specific questions, contact us at support@prmpts.app.
9. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in technology, law, or our practices. We will post the updated policy on this page with a revised “Last Updated” date. Where changes are material, we will provide notice via email or a banner on our website. Continued use of the Service after the update constitutes acceptance of the revised policy.
10. Contact Us
- Company: Brewcode LLC
- Product: prmpts
- Email: support@prmpts.app
- Website: www.prmpts.app
- Registered Address: 1130 Ogletown Road, PMB # 1857, Suite 2, Newark, Delaware 19711, USA
- Response Time: Within 7 business days
Compliance: IT Act 2000 • IT Rules 2011 • MEITY Guidelines • GDPR / ePrivacy • CCPA