Privacy
Effective 6 September 2026. This is the first version.
Preppit turns a sketch, some pinned notes and a line of instruction into a prompt for an AI. Everything it holds, it holds so that it can do that. This page says what it holds, why, for how long, who else sees it, and how you get it back or make it go away.
Who is responsible. Preppit is made and run by This Is Rupture Ltd, a company registered in England and Wales, trading as Rupture (thisisrupture.com). Registered office: 9 Gatwick Road, London SW18 5UF. For anything on this page: privacy@preppit.ai, or support@preppit.ai for everything else.
What Preppit holds
Your account
Your email address and a password, held by Supabase (our sign-in and database provider). We never see the password. Each connector link you create — one for Claude, one for ChatGPT, one for the Mac app — is a token we store only as a hash, with the label you gave it and when it was last used, so you can tell them apart and revoke them one at a time.
Your canvases
Everything you put on a canvas: the drawing, shapes, typed text, pinned notes, the overall instruction, and any pictures you place or capture. Each canvas is stored under your account, keyed by an id like vp_…, so that the AI you send it to can fetch it again at full resolution and so that you can reopen it from the larder.
Captures and where they came from
When the Mac app captures part of your screen, it also records where the capture came from — the application's name, its window title and, for a browser, the page's address — so the brief can say "a Keynote slide" or "a web page" rather than leaving the AI to guess. A window title can be the most sensitive thing on a canvas ("Acme — redundancy plan v3"). It travels with the capture to whichever AI you serve it to. There is not yet a switch to keep it back; until there is, the way to keep a title out of a brief is to remove that capture from the rail before serving, and we say so here rather than pretend otherwise.
Voice notes
A voice note is stored as audio and transcribed, and the transcript is what the AI reads; the audio itself is never sent to the AI. Transcription is done by a third-party speech-to-text provider (see below). If you correct a transcript, we remember the spelling you corrected it to, in a small list of your own terms, so the next transcript gets it right. That list holds words, not sentences.
Text read from pictures
When you place or capture a picture, Preppit reads the text in it so that a note pinned near a line can say which line. On the Mac this uses Apple's on-device text recognition. On the server it uses open-source recognition running on our own machine. The picture does not go to a third party for this.
The instruction suggester
If you ask Preppit to suggest an instruction, the typed text and notes on the canvas — not the pictures — are sent to a third-party language model to draft one line. This only happens when you ask.
Which AIs are connected
When an AI adds your connector, it introduces itself by name. We keep that name, its version and the time, so the app can show you which AIs are connected. Nothing about what you said to that AI is recorded.
Logs
The server keeps ordinary operational logs — errors, timings, sizes and counts — and never the contents of a canvas, a picture, a note or a voice recording. A diagnostics panel exists for debugging on devices without a console; it is off by default, shows only sizes and types, and stays on your device.
What Preppit does not hold
Your conversations with the AI. Preppit sends a brief into a conversation and can be asked by the AI for a canvas by id; it cannot read the conversation, your chat history, the AI's memory, or files you have uploaded elsewhere. It sets no advertising or tracking cookies, and this website uses no analytics.
Where it goes
When you serve a canvas, the brief and its pictures go to the AI you chose — Anthropic's Claude or OpenAI's ChatGPT — through the connector you added there. From that moment their privacy terms govern that copy. Preppit gives the AI the pictures only when it asks for them by id.
We use these providers to run the service. Each acts on our instructions; none is allowed to use your content for anything else.
| Provider | What for | What they receive |
|---|---|---|
| Supabase | Sign-in, database, file storage | Account details, canvases, pictures, voice notes, transcripts |
| Render | Hosting the server | Everything the server processes, in transit and in its logs |
| Groq | Transcribing voice notes | The audio of a voice note, when it is recorded |
| A language-model API (currently Groq) | Suggesting an instruction, only when you ask | The typed text and notes on the canvas, never the pictures |
| Cloudflare | Domain and email routing | Requests to preppit.ai; email to our addresses |
We do not sell your data, share it with advertisers, or use your canvases, pictures, notes or recordings to train any model.
How long
- Account and everything under it: until you delete the account.
- Canvases, pictures, transcripts and records: until you delete them, or the account. A record you have pinned is never removed automatically.
- Voice audio: kept so a note can be replayed on the pass; deleted with the canvas it belongs to.
- Connector tokens: until you revoke them. Revoking one is immediate.
- The connected-AIs list: held in memory and forgotten when the server restarts.
- Server logs: for the short period our hosting provider keeps them — days, not months.
- Backups: our database provider may keep rolling backups for up to 7 days; deleted data leaves them on that schedule.
Your controls
- See it: the larder shows every record; the account page lists every connector link.
- Take it away: the account page exports everything under your account as one file.
- Delete some of it: any canvas or record can be deleted from the larder; a conversation that already received it keeps its copy but can no longer fetch it again.
- Delete all of it: the account page deletes your account and everything under it. This is immediate and cannot be undone.
- Revoke a connector: from the account page, one link at a time; that AI stops being able to reach anything of yours.
Under UK data protection law you can also ask us to correct something, to restrict or object to how we use it, or to send you a copy, and you can complain to the Information Commissioner's Office. Write to privacy@preppit.ai; we answer within a month.
Legal basis
We process your account and your canvases because that is the service you asked for (performance of a contract). We keep operational logs and the connected-AIs list because running a reliable service depends on them (legitimate interests). We ask for microphone access before recording and only record while you hold the button (consent).
Security
Traffic is encrypted in transit. Connector tokens are stored hashed. Each account's data is separated from every other's in the database and in file storage. If you find a vulnerability, please tell us at security@preppit.ai; we will acknowledge within two working days and will not take action against good-faith reports.
Children
Preppit is not for anyone under 13, and is not designed for use by children.
Changes
When this page changes in a way that matters, the date at the top changes and we email everyone with an account.