1. Overview
This Privacy Policy explains how Prism collects, uses, discloses, stores, and protects information when you use Prism, including the web application, public website, mobile application, research library, publishing tools, community features, alerts, newsletters, article audio, billing flows, AI-assisted research features, and Model Context Protocol integrations.
This policy is product-grounded and describes Prism's current service areas at a practical level. It is intended for review and should be completed by qualified counsel before production reliance.
2. Information Prism Collects
Prism collects information you provide, information generated through your use of the service, information from connected services, and information from service providers that help operate Prism.
The information Prism collects depends on how you use the product and which features, plans, integrations, devices, and settings you choose.
- Account and identity information, such as email address, name, username, avatar, profile details, public handle, publication profile, community identity settings, authentication identifiers, session metadata, and account preferences.
- Subscription and billing information, such as plan tier, Stripe customer and subscription identifiers, subscription status, billing events, usage limits, payment status, and tax or checkout metadata handled by billing providers.
- Research, library, and workspace content, such as folders, notes, documents, uploaded files, extracted text, source metadata, tags, website imports, RSS feeds, inbound library emails, chunks, embeddings, artifacts, charts, tables, live HTML or React artifacts, canvases, and knowledge graph relationships.
- AI and chat information, such as prompts, chat messages, file attachments, retrieved context, citations, generated responses, model settings, feedback, saved messages, token usage, memory entries, summaries, and user-configured model-provider metadata.
- Publishing and newsletter information, such as drafts, published posts, article images, source links, publication settings, subscribers, unsubscribe tokens, email delivery events, public profile content, article likes, comments, saves, view counts, signed-in reader activity, and visitor identifiers used for engagement measurement.
- Community information, such as communities, memberships, join requests, posts, comments, votes, saves, attachments, uploaded media, moderation actions, bans, karma, display choices, and community-linked article activity.
- Market, alert, portfolio, and watchlist information, such as tickers, company records, research jobs, generated reports, alerts, notification preferences, holdings you enter or import, portfolio files, cost basis data, and watchlist activity.
- Integration information, such as MCP clients, OAuth clients, access scopes, tokens or token previews, audit logs account links, inbound email routing metadata, RSS source settings, AI provider connections, and mobile API activity.
- Google Drive connection and source information, such as the connected Google account identifier and email address, selected-file identifiers and metadata, encrypted refresh credentials, synchronization status, and the document, workbook, presentation, or PDF snapshots and extracted text Prism creates from files you select.
- Device, usage, analytics, and technical information, such as IP address, browser and device type, operating system, app version, locale, approximate location inferred from technical signals, product areas viewed, feature actions, errors, logs, cookies, local settings, performance data, Vercel Analytics events, and PostHog product events.
3. Sources of Information
Prism receives information directly from you when you create an account, configure settings, upload or import sources, write messages, publish posts, create communities, subscribe to a plan, connect integrations, or use the mobile app.
Prism may also receive information from service providers and connected services, including Clerk for authentication, Stripe for billing, Resend for email delivery and inbound email workflows, Vercel for hosting and aggregate web analytics, PostHog for product analytics and feature rollouts, Neon or Postgres infrastructure for application data, blob or media storage providers, AI model providers, search or market-data providers, RSS feeds, websites you import, and MCP or OAuth clients you authorize.
When you connect Google Drive, Prism requests access only to files you select through Google Picker. Google remains the authoritative service; Prism receives selected-file content and metadata to create read-only, searchable snapshots and periodically check for updates.
If another user publishes content, invites you, replies to you, follows you, subscribes to your publication, comments on your post, or otherwise interacts with you through Prism, Prism may process information about that interaction.
4. How Prism Uses Information
Prism uses information to provide, maintain, secure, personalize, support, analyze, and improve the service.
Prism also uses information to operate specific product workflows you choose, including research, publishing, community, billing, mobile, AI, and integration features.
- Create and manage accounts, authenticate users, maintain sessions, route mobile API requests, and enforce access controls.
- Store, index, retrieve, summarize, render, and organize your library content, sources, files, notes, documents, artifacts, and graph relationships.
- Run AI-assisted chat, research, drafting, retrieval, source analysis, artifact generation, article audio, and related model workflows.
- Operate publishing, public profiles, newsletters, article engagement, community discussions, community media, moderation, and subscriber unsubscribe flows.
- Provide article authors with reader analytics. When you view an article while signed in, the author may see your public Prism identity and related in-product engagement; anonymous article readers are reported only as aggregate counts.
- Process subscriptions, reconcile billing status, enforce plan limits, track usage quotas, and provide billing management.
- Deliver notifications, alerts, market digests, publication emails, transactional emails, mobile experiences, and integration workflows.
- Provide MCP and OAuth connections, verify scopes and plan limits, record audit logs, and help connected clients access authorized Prism context.
- Detect, prevent, investigate, and respond to fraud, abuse, security incidents, unauthorized access, policy violations, service errors, and legal requests.
- Understand product usage, improve reliability, debug performance, measure feature adoption, and develop new features.
5. AI, Search, and Automated Processing
Prism uses AI-assisted features to help retrieve, summarize, transform, draft, classify, embed, search, compare, and generate content. These features may process your prompts, files, notes, sources, research history, chat messages, drafts, selected context, article text, attachments, and generated outputs.
Depending on feature configuration, Prism may send relevant inputs and context to AI providers, model gateways, embedding providers, search providers, text-to-speech providers, or user-configured AI providers. Prism tries to send only what is needed for the selected feature, but you should not submit content to AI workflows unless you are comfortable with that processing.
AI outputs may be saved in Prism when they form part of chats, drafts, documents, summaries, artifacts, article audio metadata, memories, or research records. You remain responsible for reviewing outputs before relying on them or publishing them.
7. Public and Shared Content
Some Prism features are intentionally public or shared. Public profiles, publication pages, published articles, public article previews, shared artifacts, community posts, comments, votes, saves, media, display names, avatars, subscriber-facing emails, and related engagement may be visible to others depending on your choices and the feature's settings.
Public content may be indexed by search engines, copied by others, cached, archived, quoted, or reshared outside Prism. If you remove or restrict public content later, copies may remain outside Prism's control.
Private, unlisted, or group-linked content may still be visible to authorized users, community members, moderators, connected clients with permission, or service providers that process the content for Prism.
When a Project owner invites a collaborator, Prism processes invitation and membership information and makes the shared Project research content available according to the selected Viewer or Editor role. Project Email, publishing drafts, portfolios, personal memory, private chats, and integration settings are not included in Project sharing.
A Project owner may separately allow a collaborator's MCP clients to read or make limited non-destructive changes to the shared Project. Prism records the collaborator, MCP client, target Project, action, and outcome so the collaborator can review their MCP use and the owner can review activity limited to that Project. The owner cannot use that audit view to inspect the collaborator's unrelated MCP activity.
A Project owner or editor may connect a private Google account to import selected Drive files. The connected account address and credentials remain private to that person, while cached source snapshots, extracted text, and source status are visible to Project readers. Opening the original file in Google remains subject to Google's separate access controls.
9. Retention
Prism retains information for as long as needed to provide the service, maintain your account, operate features you use, comply with legal obligations, resolve disputes, enforce agreements, secure the service, maintain backups, and support legitimate business operations.
Different categories of information may have different retention periods. For example, account data may be retained while your account is active; billing records may be retained for tax and accounting purposes; audit logs may be retained for security; published content may remain available until unpublished or removed; and backups may persist for a limited period after deletion from active systems.
Some data associated with public content, community activity, subscriber emails, logs, integrations, or legal/security events may be retained even after account cancellation where needed for legitimate operational, legal, safety, or audit purposes.
Disconnecting Google Drive freezes linked sources and stops synchronization but does not automatically remove the last successful Project snapshot. A retained snapshot remains available to authorized Project members until the source or account data is deleted under Prism's applicable deletion and retention processes.
10. Your Choices and Controls
You can control many types of information directly in Prism, including profile settings, community identity, publication settings, article visibility, subscriber workflows, notifications, billing settings, AI provider connections, MCP clients, OAuth grants connections, Project sources, and uploaded content.
You may unsubscribe from Prism publication emails through unsubscribe links where available. Transactional, security, billing, account, and service emails may still be sent where necessary.
You can revoke integrations, delete or rotate tokens, disconnect providers, delete content, change visibility settings, and cancel paid plans through available product controls. Some changes may not affect content already sent, published, cached, indexed, emailed, or shared outside Prism.
You can disconnect a Google account to revoke future access where possible. You can separately remove a linked source from its Project; disconnecting alone retains the last successful read-only snapshot so the Project does not silently lose research history.
11. Access, Deletion, and Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have rights to appeal a privacy decision or opt out of certain sharing or targeted advertising if those activities apply.
To request access, correction, deletion, export, or another privacy action, contact Prism at team@tryprism.xyz. Prism may need to verify your identity and may retain certain information where required or permitted by law, such as billing records, security logs, abuse-prevention records, legal records, backups, or public content already shared with others.
If you want to delete your account or content, Prism may provide in-product controls or handle requests through contact with Prism. Deletion may not immediately remove information from backups, logs, provider systems, emails already delivered, public search indexes, or content copied by others.
12. Security
Prism uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include authentication, access controls, scoped tokens, OAuth flows, audit logs, rate limits, encryption or secret handling for sensitive credentials, private media routes, and provider security controls.
No service can guarantee absolute security. You are responsible for keeping your account, devices, sessions, API keys, MCP tokens, OAuth grants, and connected services secure.
13. Children
Prism is not intended for children under 13, and Prism does not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Prism, contact Prism so the information can be reviewed and deleted where appropriate.
14. International Use
Prism is operated with a United States-oriented policy structure. If you access Prism from outside the United States, your information may be processed in the United States and other locations where Prism or its service providers operate.
Privacy laws vary by jurisdiction. Final region-specific disclosures, transfer mechanisms, and consumer-rights language should be reviewed by counsel before production reliance.
15. Service Providers and Subprocessors
Prism relies on service providers to operate the product. Current provider categories include authentication, hosting, analytics, database infrastructure, blob or media storage, email delivery and inbound email handling, billing, AI models and gateways, embeddings, text-to-speech, search, market data, error logging or diagnostics, and communications integrations.
Examples of provider families reflected in Prism's product include Clerk, Stripe, Vercel, PostHog, Neon or Postgres infrastructure, Resend, AI providers such as OpenAI and Anthropic or AI gateways, search or market-data providers, and storage providers. The exact provider set may change as Prism evolves.
16. Changes to This Policy
Prism may update this Privacy Policy from time to time. When changes are material, Prism may provide notice through the service, by email, or by updating the effective date. Continued use of Prism after the updated policy takes effect means the updated policy applies to your information.
17. Contact
Questions or requests about this Privacy Policy can be sent to team@tryprism.xyz.
This draft does not identify a separate legal entity, mailing address, or formal privacy officer. Those details should be added before production reliance if required for Prism's launch, jurisdiction, or app-store obligations.