Privacy
Last updated 1 January 2026.
What the snippet collects
When Prept runs on a customer’s page it reads page context, not people: referring URL, UTM parameters (source, medium, campaign, term), page title and path, browser language, timezone, viewport size, device class, entry page, pages viewed this session, and whether this browser has seen the page before.
Cookies and local storage
Prept sets no cookies. It writes two first-party browser storage keys on the customer’s own domain: prept.seen.<site key> (last visit timestamp and visit count) and a session key holding page-view count and entry page. Existing installations may retain the legacy key name. Clearing site data removes both.
Company-level enrichment from IP address
Server-side, the visitor’s IP address is passed to an IP-to-organisation lookup provider (currently ipwhois) to identify the organisation or network the visit comes from. Results are cached for 30 days so repeat visits require no further lookups. Generic consumer ISPs, mobile carriers and hosting networks are discarded.
Prept never attempts to identify an individual person. No name, no personal profile, no social account matching, no de-anonymisation. If deep enrichment is switched on for a site, an AI agent reads the identified company’s public website to build a company profile (industry, positioning, likely needs). That research is about companies only, is refreshed at most once every 30 days, and costs 25 credits per company.
Customer-supplied traits
Customers may pass known-visitor details to Prept themselves through window.preptIdentify({ email, traits }). Prept only receives what the customer explicitly sends and never auto-collects email addresses or form contents. Customers are responsible for having a lawful basis to share those details.
PII redaction
With “Redact PII” enabled (the default), generated copy may not contain personal data, names or email addresses. With “Strict claims” enabled, rewrites may only restate claims already present in the original page copy.
Retention
Visit records, generated variants and credit ledger entries are retained for the life of the account and deleted within 30 days of account deletion. IP-to-organisation cache entries expire after 30 days. Raw IP addresses are used for lookup and caching only and are never shown in the dashboard.
Sub-processors
Hosting and database (Lovable Cloud), AI model inference (Lovable AI Gateway), payment processing and invoicing (Paddle, merchant of record), and the IP-to-organisation provider named above.
Contact
Privacy questions and data requests: privacy@prept.dev.
