Skip to content

Privacy Policy

Last updated: 23 August 2026

Prow is a marketing studio: you brief it, it generates video and copy for your brand, watches your competitors, and publishes to the accounts you connect. Doing that means handling your account details, the material you give it, and the work it makes for you.

This page says exactly what that involves — including the third parties your prompts and media are sent to, because a tool like this cannot work without them.

1Who this covers

This policy covers Prow — the website at prow.app, the signed-in product, and the APIs behind them. It explains what we collect, why we have it, who we pass it to, and what you can ask us to do with it.

Prow is a business tool. It is not intended for children, and you must be 16 or older (or the age of digital consent where you live, whichever is higher) to hold an account.

2What we collect

Account details

Your email address, and — if you sign in with Google — the name and profile picture Google returns with it. Accounts and sessions are handled by Supabase; if you use a password, Supabase stores it hashed and we never see it.

Billing details

Payments run through Stripe. Prow never receives or stores your card number. What we keep is what Stripe hands back: a customer and subscription id, your plan, the status of your subscription, and a record of invoices and top-up purchases.

What you give the product

  • Briefs and prompts — everything you type into Superchat or the Marketing Studio, including product details, brand notes and instructions.
  • Uploads — images, video and other files you add, including product photos and reference clips.
  • Your business profile — what you tell us during onboarding, plus anything we import from a product or store URL you give us.
  • Links you ask us to analyse — the social and video URLs you paste in for a teardown, and the pages or profiles you add to Competitor Spy.

What the product makes

Generated images, videos, captions and copy, the teardowns and summaries behind them, your saved assets and your chat history. Media files are stored in Cloudflare R2; the records that point at them live in Supabase.

Connected accounts

If you connect a social account, we store the access tokens needed to act on your behalf, along with the account name and id, the postsProw queued or published, and the performance figures the platform reports back. You can disconnect an account at any time, which revokes our access going forward.

Usage and metering

Credit balances and the ledger behind them, which jobs ran and what they cost, plan limits and how much of them you have used, and how much storage your workspace is holding. This is what makes the product bill correctly and what lets us show you where your credits went.

Technical data

Our hosting and infrastructure providers record ordinary server logs — IP address, browser and device type, timestamps, and which requests errored. We use these to keep the service up and to investigate abuse.

3Cookies and local storage

Prow sets authentication cookies only. They are Supabase session cookies: they keep you signed in and are refreshed on each request. Without them the product cannot tell who you are.

We also use your browser’s local storage for interface preferences — for example, whether you last read this site in the dark or light theme. That value never leaves your browser.

We run no advertising trackers and no third-party analytics — no Google Analytics, no advertising pixels, no session recording. If that ever changes, this section changes with it and we will say so before it goes live.

4How we use it

  • To run the product: generating media, answering in chat, tearing down videos, watching competitors, queueing and publishing posts.
  • To keep your account and workspace — your history, assets and saved work — where you left it.
  • To meter and bill: charging credits, enforcing plan limits, taking subscription payments and top-ups.
  • To support you when you write in, and to send service email you cannot opt out of (password resets, billing notices, security and material service changes).
  • To keep the service secure and working: debugging, preventing abuse, and enforcing our terms.
  • To meet legal, tax and accounting obligations.

5AI model providers

Prow does not train or host its own models. To fulfil what you ask for, we send your prompts, briefs and any reference media to third-party model providers — image and video generation runs through Kie AI and the models it hosts, and the chat and analysis models are reached through OpenRouter. What comes back is stored in your workspace.

This is the mechanism of the product, not an optional extra: a video cannot be generated without the prompt and reference material reaching the model that generates it. Those providers process what we send them under their own terms, and we choose providers on the basis that they do not train on our customers’ content — but we do not control their systems.

Do not put anything into Prow that you are not willing to have processed by a third-party model provider — including other people’s personal information, confidential material, or anything you are contractually barred from sharing.

6Who we share it with

We do not sell your data and we do not share it for advertising. We do use service providers to run the product, and they only ever get what their part of the job needs:

  • Supabase — accounts, authentication and the application database.
  • Cloudflare — media storage (R2), and the Workers platform that runs the agent behind Superchat.
  • Vercel — hosting for the web app.
  • Stripe — payments, subscriptions and invoices.
  • Kie AI and the model providers it hosts — image and video generation.
  • OpenRouter and the model providers it routes to — chat, analysis and summarisation.
  • bundle.social — connecting your social accounts, publishing posts and retrieving analytics.
  • Firecrawl — fetching the public web and social pages you asked Competitor Spy to watch.
  • Google — only if you choose to sign in with Google.

We will also disclose information where the law requires it, to enforce our terms, or to protect the rights and safety of our users. If Prow is ever acquired or merged, account data may transfer as part of that business — you will be told before it does.

7Competitor monitoring

Competitor Spy fetches publicly available pages and profiles that you specifically ask it to watch. It does not sign in to anything, it does not scrape private or gated content, and it does not build profiles of individuals for us.

The public content it retrieves, and the summaries and teardowns made from it, are saved to your workspace so a find survives the original being deleted. You are responsible for the accounts and pages you choose to watch and for using what you get back lawfully.

8Keeping and deleting data

We keep your account data and workspace content for as long as your account is open. You can delete individual assets, chats and watches from inside the product at any time; deleting an asset removes the underlying file from storage and frees the space against your quota.

To close your account and have its content deleted, email support@prow.app. We will delete or anonymise your workspace within 30 days of the request, except for records we are required to keep — chiefly billing and tax records, which we retain for as long as the applicable law requires. Backups roll off on their own schedule and are overwritten in the ordinary course.

Content already published to your own social accounts is on those platforms, not ours; deleting it there is up to you.

9Security

Traffic is encrypted in transit. Access to the product is gated by your Supabase session, and workspace data is scoped to your account at the database level rather than only in the interface. Credentials for the services above — including the tokens for your connected social accounts — are held as secrets in our server environments and are never exposed to the browser.

No system is perfectly secure. If we ever become aware of a breach affecting your data, we will tell you and any regulator we are required to notify, without undue delay.

10Where your data is processed

Prow and the providers listed above operate globally, so your data may be processed in countries other than your own — including the United States. Where we move personal data out of the UK, the EEA or another region with transfer rules, we rely on the safeguards those rules provide, such as standard contractual clauses in our agreements with providers.

11Your rights

Depending on where you live — for example under the UK GDPR, the EU GDPR, or California law — you have some or all of the following rights over your personal information:

  • Ask for a copy of what we hold about you.
  • Have inaccurate details corrected.
  • Ask us to delete your account and its content.
  • Ask for your data in a portable form.
  • Object to, or ask us to restrict, particular processing.
  • Withdraw consent where our basis for processing is consent.

Email support@prow.app and we will answer within the time the applicable law allows. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing here to opt out of on that front. If you think we have got something wrong, you can also complain to your local data protection authority.

12Changes to this policy

We will update this page when the product changes — a new provider in the list above, or a new category of data, means a new version here. The date at the top is the date of the current version. If a change materially affects how we handle your information, we will tell account holders by email before it takes effect.

13Contact

Privacy questions, data requests and everything else reach us at the same place: support@prow.app.

This policy is written to be read and understood rather than to be impressive, and it describes what the product actually does. It is not legal advice, and it has not been reviewed by a law firm. See also our Terms of Service.