Privacy Policy
Last updated: 6 August 2026
PrizePilot ("we", "our", or "us") is a Chrome browser extension that helps users discover and enter online competitions. This Privacy Policy explains what user data the extension collects, how that data is handled and used, where it is stored, when it is shared, how long it is retained, and the choices available to you.
1. Who We Are
PrizePilot is operated as an independent product. You can contact us at prizepilot@prizepilot.app with any privacy-related questions.
2. User Data We Collect
Depending on the features you use, PrizePilot collects or processes the following categories of data:
- Account and authentication data: email address, Supabase user ID, authentication and refresh tokens, account status, and password-reset requests. Passwords are handled by Supabase Auth and are not visible to PrizePilot.
- Chrome profile data: where available, the ID and email address associated with the signed-in Chrome profile. These are used to create or reconnect a guest account. Chrome provides this data through the
identityandidentity.emailpermissions. - Entry profile and settings: information you choose to enter, including title, name, email address, telephone number, postal address, country, date of birth, gender, friend names used for tagging, custom scan URLs, and extension preferences.
- Competition and browsing-related data: URLs and titles of competition pages you ask PrizePilot to scan or enter; visible page, form, and social-post text; form labels, options, and questions; detected entry requirements; scan results; recurring competition settings; and action outcomes.
- Participation history: competition URL and title, entry timestamp, detected or completed actions, autofill counts, entry strategy, and related competition identifiers.
- AI data: content sent for an AI feature, such as competition or social-post text, page text, form labels and options, detected questions, competition URL/title, limited relevant profile context such as title or gender, configured tagging names, and AI-generated analyses, answers, checklists, or comments.
- Subscription and transaction data: plan, subscription status, trial and billing-period dates, credit balance and usage, Stripe customer/subscription identifiers, and transaction status. Complete payment-card details are collected and retained by Stripe, not PrizePilot.
- Optional OpenAI API key: Pro users may choose to provide their own key. The key is transmitted to our backend and stored encrypted; only its last four characters are used for display.
- Technical and service data: timestamps, feature usage counters, error information, request status, and security or operational logs generated while providing and protecting the service.
3. How We Collect and Use User Data
Data is collected when you enter it in PrizePilot, sign in or subscribe, select a competition, start a scan or entry, use an AI feature, or allow the extension to read your Chrome profile identity. PrizePilot uses this data only to provide and improve its single purpose of helping you find and enter competitions, including:
- creating and authenticating your account, reconnecting a guest account, and securing sessions;
- saving and synchronising your profile, settings, scans, recurring tasks, and participation history;
- finding, filtering, and analysing competitions and their entry requirements;
- filling third-party competition forms with the profile values you have supplied;
- preparing requested social actions and suggested comments for your review;
- providing AI-assisted analysis, form interpretation, and answer suggestions;
- processing subscriptions, trials, credit purchases, and plan limits;
- providing support, diagnosing errors, preventing abuse, and maintaining service security; and
- complying with legal obligations and enforcing our Terms.
PrizePilot does not collect browsing history unrelated to the competition pages you ask it to process. It does not use user data for advertising, creditworthiness, or sale to data brokers.
4. How We Handle and Protect User Data
- Network requests to PrizePilot's backend and service providers use HTTPS encryption in transit.
- Cloud records are associated with an authenticated or guest user ID. Supabase row-level access controls are used to restrict user-scoped records.
- Authentication tokens are stored in local extension storage and used to authorise requests to PrizePilot's backend.
- Optional user-provided OpenAI API keys are encrypted before database storage and are not placed in browser-synchronised settings.
- PrizePilot processes only the page content and profile fields needed for the feature you initiate. AI requests are routed through PrizePilot's backend so the platform API key is not exposed to the extension.
- Autofill places your chosen profile values into fields on the third-party competition page. Those values become available to that website and are subject to its privacy policy. You should review the form before submitting it.
No internet service can guarantee absolute security. If you believe your account or data may be at risk, contact us promptly.
5. Where User Data Is Stored
- On your device: settings, profile information, authentication session, cached scan results, local participation history, and operational state may be stored using
chrome.storage.localorchrome.storage.sync. - Google Chrome Sync: data placed in
chrome.storage.sync, including profile and settings data, may be synchronised by Google across browsers signed in to your Chrome account, subject to your Chrome Sync settings and Google's privacy terms. - PrizePilot cloud storage: Supabase stores account/guest identity, profile and settings data, scan sources and results, recurring tasks, participation history, plan and AI-credit status, billing identifiers, and encrypted optional API keys.
- Service-provider systems: data sent to Stripe or OpenAI is processed on their systems as described below and under their respective privacy policies.
Data may be processed in countries other than your own. Where required, transfers are handled under the safeguards offered by the relevant service provider and applicable law.
6. When and With Whom We Share User Data
We do not sell or rent user data. We disclose data only as needed to provide a feature you request, operate the service, comply with law, or protect users and the service:
- Supabase: provides authentication, database, storage, and serverless backend services. It processes the account, profile/settings, competition, participation, usage, and subscription records described above. See the Supabase Privacy Policy.
- OpenAI: processes the AI request content described in Section 2 to return analyses, answers, and suggested comments. If you supply a personal OpenAI key, requests are still routed by PrizePilot but use that key. See the OpenAI Privacy Policy.
- Stripe: processes checkout and payment information and provides customer, subscription, invoice, and transaction status to PrizePilot. PrizePilot does not receive complete card details. See the Stripe Privacy Policy.
- Google: provides Chrome profile identity and may synchronise extension settings through Chrome Sync. See the Google Privacy Policy.
- Competition websites and social networks: when you choose to fill a form or complete an entry action, the relevant profile values, form answers, comments, and actions are disclosed to that third party as necessary to carry out your request. Their own privacy policies apply.
- Legal and safety disclosures: we may disclose information if reasonably necessary to comply with law, legal process, or a valid governmental request, or to detect, prevent, or address fraud, security, or technical issues.
- Business transfers: if PrizePilot is involved in a merger, acquisition, financing, reorganisation, or sale of assets, user data may be transferred subject to this Policy and applicable law.
7. Chrome Web Store Limited Use Disclosure
PrizePilot's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. In particular:
- Chrome API data is used only to provide or improve PrizePilot's disclosed competition-assistance features.
- Chrome API data is transferred only when necessary to provide those features, for security, to comply with law, or as part of a permitted business transfer.
- Chrome API data is not used or transferred for personalised, retargeted, or interest-based advertising.
- Humans do not read Chrome API user data except with the user's specific consent for support, when necessary for security or legal compliance, or after the data has been aggregated and anonymised for internal operations.
8. Chrome Permissions We Use
- storage — to save your profile, history, and preferences locally on your device.
- tabs / scripting / webNavigation — to detect competition entry forms on pages you visit and auto-fill them on your request.
- notifications — to alert you when a scan finds new competitions (optional, browser-level permission).
- identity / identity.email — to support sign-in via Google (if used).
- alarms — to schedule background scans at set intervals.
- contextMenus — to provide right-click actions on competition pages.
- host permissions (
https://*/*andhttp://*/*) — required because competition forms are hosted on many unrelated domains and to inject the autofill script on competition websites you choose to enter.
PrizePilot uses these permissions only for the functionality described in this Policy. Facebook and supported competition-site content scripts may load on matching pages so that a user-initiated PrizePilot action has the required page context; they do not transmit unrelated browsing activity.
9. Data Retention and Deletion
- Local extension data remains until you clear it, remove it through PrizePilot where that option is available, or uninstall the extension. Data managed by Chrome Sync may remain in your Google account according to your Chrome Sync settings.
- Cloud account, profile/settings, scan, recurring-task, participation, and AI-usage data is generally retained while your account remains active so the service and cross-device features continue to work.
- An optional OpenAI API key is retained until you remove it, lose eligibility to use a personal key, or delete your account.
- Subscription and transaction records may be retained as needed for accounting, tax, fraud prevention, dispute resolution, and other legal obligations.
- Service and security logs are retained only as reasonably necessary for operation, diagnosis, abuse prevention, and legal compliance.
You may request deletion of your PrizePilot account and associated cloud data by emailing prizepilot@prizepilot.app. We will complete verified deletion requests within 30 days unless retention is required by law. Deleting PrizePilot data does not delete information you already submitted to a competition website, social network, Stripe, Google, or another third party; contact that provider directly.
10. Your Choices and Rights
You may edit your profile and preferences, clear local history, remove an optional API key, cancel a subscription, disable Chrome Sync, or stop using and uninstall the extension. Depending on where you live, you may also have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Withdraw consent or object to processing at any time.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at prizepilot@prizepilot.app.
11. Children
PrizePilot is not directed at children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the extension or our website. The "Last updated" date at the top reflects the most recent revision.
13. Contact
For any privacy questions or data requests, contact us at prizepilot@prizepilot.app.