Privacy Policy
Last updated: July 11, 2026
Booru Prompt Gallery ("the app", "we") is a tool for browsing booru-style image boards and turning their tags into clean prompts. It is built around data minimization: you can use almost every feature without an account, and most of your data never leaves your own browser.
This page explains exactly what data is stored, where it lives, and which third parties are involved.
By default the app stores everything locally in your browser's Local Storage — no account required and nothing is sent to our servers:
- Favorites (when you are not signed in)
- Copy history and recent tags
- Presets, blacklist, tag weights, and content filter preferences
- UI settings such as provider selection, card scale, and dismissed announcements
You can clear all of this at any time by clearing your browser's site data for this domain.
Signing in is entirely optional and only exists to sync your favorites and preferences across devices. Authentication uses a passwordless Magic Link sent to your email, so we never handle or store a password.
What we collect: only your email address, used solely as the unique identifier that links your account to your synced favorites and settings. We do not use it for marketing and we do not sell or share it.
Where it lives: account and synced data are stored in Supabase (a hosted PostgreSQL provider) acting as our data processor. See Supabase's privacy policy.
We use analytics to understand how the app is used and prioritize development. We do not sell this data, use it for advertising, or track you across other websites.
- Cloudflare Web Analytics: Aggregate, cookieless page views and performance metrics. Does not fingerprint or track you across sites.
- PostHog (Product Analytics):We record specific in-app behavioral events to understand feature usage. PostHog stores an anonymous session identifier in your browser's local storage (not a tracking cookie). The events we capture include:
- Searches performed (query length, provider, shuffle on/off — not the search text itself)
- Prompts copied (whether it was AI-converted text or raw tags, and the source provider — not the prompt content)
- Tags copied by category (e.g. "appearance", "clothing" — not the tag text itself)
- Images downloaded (source provider only)
- AI tag conversion started and completed (provider name, success/fail — not the tags)
- Feature used: Merge mode, Variant mode, Teach Modal, Dynamic tag opened/copied — no content is recorded
- Favorite added or removed — no post ID or content is recorded, only that the action happened
- Feedback form submitted (type only: bug / feature / other — not the message)
- Generation settings toggled (which setting and its new on/off value)
- Background option changed (which mode was selected)
- Import used (drag-and-drop or file picker, file type)
- Content filter changed (SFW / NSFW preference value)
- Provider changed (which booru provider was selected)
- Sign-in occurred (no email or identity is sent to PostHog)
If you are not signed in, all of the above is fully anonymous — it cannot be linked to you personally. If you sign in, telemetry is associated with your anonymous account ID (a random UUID) to help us troubleshoot issues. Your email address is never sent to PostHog.
PostHog is operated by PostHog, Inc. See their privacy policy for details on how they handle this data.
To diagnose crashes we use Sentry. Diagnostic data (such as the error, a technical breadcrumb trail of in-app actions, and basic device/browser info) is only transmitted when an error actually occurs. We do not send your prompts, favorites, or browsing content as part of normal use.
Images and tags are fetched from external providers (Danbooru, Gelbooru, e621, Aibooru, Rule34). When you browse, requests to these providers (sometimes via our image proxy) may expose your IP address to them as part of the normal web request process. We do not control their data practices and recommend reviewing the privacy policy of any provider you use.
We do not use advertising or cross-site tracking cookies. We use only functional cookies and local storage to:
- Keep you signed in and maintain a secure session.
- Store your preferences and favorites locally.
- Maintain an anonymous session identifier for our product analytics (PostHog) so we can understand continuous usage.
Local data stays until you clear it. Account data is retained while your account exists. You have the right to access, correct, or delete your data.
Deleting your account: request deletion through the in-app Feedback tool. On deletion we remove your account record and associated synced favorites/preferences from Supabase. You can also stop syncing at any time by signing out and clearing your local site data.
Opting out of product analytics: PostHog respects the browser's Do Not Tracksignal. You can also block analytics by using a content blocker (e.g. uBlock Origin) — the app will continue to work fully without it. Clearing your browser's local storage for this domain will also reset your anonymous PostHog session identifier.
Some supported providers host explicit or mature (NSFW) content. The app is intended for adults and you must be of legal age in your jurisdiction (at least 18) to view such content. A content filter is enabled where applicable, but you are responsible for the material you choose to display.
We may update this policy; material changes will be reflected in the "Last updated" date above. See also our Terms of Service.
Questions about your data or this policy? Reach out via the Feedback tool in the app.