Privacy Policy
Last updated: 23 May 2026
PrizePilot ("we", "our", or "us") is a Chrome browser extension that helps users discover and enter online competitions. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Who We Are
PrizePilot is operated as an independent product. You can contact us at prizepilot@prizepilot.app with any privacy-related questions.
2. Data We Collect
We collect only the minimum data needed to provide the service:
- Account data — your email address, used to create and authenticate your PrizePilot account (via Supabase Auth).
- Profile data — personal details you voluntarily enter in Settings (e.g. name, address, date of birth, phone number, country). This data is stored locally on your device using
chrome.storage.syncand is never uploaded to our servers. - Participation history — a record of competitions you have entered, including competition URLs and timestamps. This is stored locally and, for Plus/Pro plan users, optionally synced to our database to enable cross-device history.
- Subscription data — your active plan (Free, Plus, or Pro) and subscription status, managed via Stripe and stored in our database.
- AI usage data — a count of AI form-fill credits used. No form content or personal responses are sent to or stored by us.
3. How We Use Your Data
- To authenticate your account and enforce plan limits.
- To sync your participation history across devices (Plus and Pro plans only).
- To process subscription payments via Stripe.
- To display personalised competition recommendations filtered by your country (Discover feature).
- To auto-fill competition entry forms using your locally stored profile — this data never leaves your device.
4. Data Storage and Third Parties
- Supabase — our backend database and authentication provider, hosted in the EU. Stores your email, plan status, and participation history (Plus/Pro). See Supabase Privacy Policy.
- Stripe — payment processing. PrizePilot never stores card details. See Stripe Privacy Policy.
- OpenAI — used optionally for AI-assisted form filling (Plus/Pro). Only the visible form field labels from the current page are sent; your personal profile data is never included in these requests. See OpenAI Privacy Policy.
We do not sell, rent, or share your personal data with any other third parties.
5. Permissions We Use
- storage — to save your profile, history, and preferences locally on your device.
- tabs / scripting / webNavigation — to detect competition entry forms on pages you visit and auto-fill them on your request.
- notifications — to alert you when a scan finds new competitions (optional, browser-level permission).
- identity / identity.email — to support sign-in via Google (if used).
- alarms — to schedule background scans at set intervals.
- contextMenus — to provide right-click actions on competition pages.
- host_permissions (https://*/* and http://*/*) — required to inject the autofill script on competition websites you choose to enter.
The extension only activates on pages where you explicitly initiate an action (scan, autofill, or Discover). It does not monitor your general browsing activity.
6. Data Retention
- Profile data is stored locally on your device and deleted when you uninstall the extension or clear extension data.
- Cloud participation history (Plus/Pro) is retained while your account is active. You can request deletion at any time by contacting us.
- Account data is deleted upon request within 30 days.
7. Your Rights (GDPR)
If you are based in the EU or UK, you have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Withdraw consent or object to processing at any time.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at prizepilot@prizepilot.app.
8. Children
PrizePilot is not directed at children under 16. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the extension or our website. The "Last updated" date at the top reflects the most recent revision.
10. Contact
For any privacy questions or data requests, contact us at prizepilot@prizepilot.app.