Legal

Privacy Policy

This policy explains how Prism handles information across web, mobile, research library, publishing, community, AI, billing, analytics, and MCP integration features.

Effective June 2, 2026Last updated August 28, 2026

1. Overview

This Privacy Policy explains how Prism collects, uses, discloses, stores, and protects information when you use Prism, including the web application, public website, mobile application, research library, publishing tools, community features, alerts, newsletters, article audio, billing flows, AI-assisted research features, and Model Context Protocol integrations.

This policy is product-grounded and describes Prism's current service areas at a practical level. It is intended for review and should be completed by qualified counsel before production reliance.

2. Information Prism Collects

Prism collects information you provide, information generated through your use of the service, information from connected services, and information from service providers that help operate Prism.

The information Prism collects depends on how you use the product and which features, plans, integrations, devices, and settings you choose.

  • Account and identity information, such as email address, name, username, avatar, profile details, public handle, publication profile, community identity settings, authentication identifiers, session metadata, and account preferences.
  • Subscription and billing information, such as plan tier, Stripe customer and subscription identifiers, subscription status, billing events, usage limits, payment status, and tax or checkout metadata handled by billing providers.
  • Research, library, and workspace content, such as folders, notes, documents, uploaded files, extracted text, source metadata, tags, website imports, RSS feeds, inbound library emails, chunks, embeddings, artifacts, charts, tables, live HTML or React artifacts, canvases, and knowledge graph relationships.
  • AI and chat information, such as prompts, chat messages, file attachments, retrieved context, citations, generated responses, model settings, feedback, saved messages, token usage, memory entries, summaries, and user-configured model-provider metadata.
  • Publishing and newsletter information, such as drafts, published posts, article images, source links, publication settings, subscribers, unsubscribe tokens, email delivery events, public profile content, article likes, comments, saves, view counts, signed-in reader activity, and visitor identifiers used for engagement measurement.
  • Community information, such as communities, memberships, join requests, posts, comments, votes, saves, attachments, uploaded media, moderation actions, bans, karma, display choices, and community-linked article activity.
  • Market, alert, portfolio, and watchlist information, such as tickers, company records, research jobs, generated reports, alerts, notification preferences, holdings you enter or import, portfolio files, cost basis data, and watchlist activity.
  • Integration information, such as MCP clients, OAuth clients, access scopes, tokens or token previews, audit logs account links, inbound email routing metadata, RSS source settings, AI provider connections, and mobile API activity.
  • Google Drive connection and source information, such as the connected Google account identifier and email address, selected-file identifiers and metadata, encrypted refresh credentials, synchronization status, and the document, workbook, presentation, or PDF snapshots and extracted text Prism creates from files you select.
  • Device, usage, analytics, and technical information, such as IP address, browser and device type, operating system, app version, locale, approximate location inferred from technical signals, product areas viewed, feature actions, errors, logs, cookies, local settings, performance data, Vercel Analytics events, and PostHog product events.

3. Sources of Information

Prism receives information directly from you when you create an account, configure settings, upload or import sources, write messages, publish posts, create communities, subscribe to a plan, connect integrations, or use the mobile app.

Prism may also receive information from service providers and connected services, including Clerk for authentication, Stripe for billing, Resend for email delivery and inbound email workflows, Vercel for hosting and aggregate web analytics, PostHog for product analytics and feature rollouts, Neon or Postgres infrastructure for application data, blob or media storage providers, AI model providers, search or market-data providers, RSS feeds, websites you import, and MCP or OAuth clients you authorize.

When you connect Google Drive, Prism requests access only to files you select through Google Picker. Google remains the authoritative service; Prism receives selected-file content and metadata to create read-only, searchable snapshots and periodically check for updates.

If another user publishes content, invites you, replies to you, follows you, subscribes to your publication, comments on your post, or otherwise interacts with you through Prism, Prism may process information about that interaction.

4. How Prism Uses Information

Prism uses information to provide, maintain, secure, personalize, support, analyze, and improve the service.

Prism also uses information to operate specific product workflows you choose, including research, publishing, community, billing, mobile, AI, and integration features.

  • Create and manage accounts, authenticate users, maintain sessions, route mobile API requests, and enforce access controls.
  • Store, index, retrieve, summarize, render, and organize your library content, sources, files, notes, documents, artifacts, and graph relationships.
  • Run AI-assisted chat, research, drafting, retrieval, source analysis, artifact generation, article audio, and related model workflows.
  • Operate publishing, public profiles, newsletters, article engagement, community discussions, community media, moderation, and subscriber unsubscribe flows.
  • Provide article authors with reader analytics. When you view an article while signed in, the author may see your public Prism identity and related in-product engagement; anonymous article readers are reported only as aggregate counts.
  • Process subscriptions, reconcile billing status, enforce plan limits, track usage quotas, and provide billing management.
  • Deliver notifications, alerts, market digests, publication emails, transactional emails, mobile experiences, and integration workflows.
  • Provide MCP and OAuth connections, verify scopes and plan limits, record audit logs, and help connected clients access authorized Prism context.
  • Detect, prevent, investigate, and respond to fraud, abuse, security incidents, unauthorized access, policy violations, service errors, and legal requests.
  • Understand product usage, improve reliability, debug performance, measure feature adoption, and develop new features.

5. AI, Search, and Automated Processing

Prism uses AI-assisted features to help retrieve, summarize, transform, draft, classify, embed, search, compare, and generate content. These features may process your prompts, files, notes, sources, research history, chat messages, drafts, selected context, article text, attachments, and generated outputs.

Depending on feature configuration, Prism may send relevant inputs and context to AI providers, model gateways, embedding providers, search providers, text-to-speech providers, or user-configured AI providers. Prism tries to send only what is needed for the selected feature, but you should not submit content to AI workflows unless you are comfortable with that processing.

AI outputs may be saved in Prism when they form part of chats, drafts, documents, summaries, artifacts, article audio metadata, memories, or research records. You remain responsible for reviewing outputs before relying on them or publishing them.

6. How Prism Shares Information

Prism shares information when needed to provide the service, when you direct Prism to share it, when required by law, or when necessary to protect Prism, users, or others.

Prism does not sell personal information in the ordinary meaning of exchanging it for money. Some analytics, hosting, or service-provider activity may be considered sharing under certain privacy laws, and final legal classification should be reviewed by counsel.

  • With service providers that operate authentication, hosting, databases, storage, analytics, email, billing, AI, search, market data, security, support, and infrastructure services.
  • With AI providers, search providers, model gateways, embedding providers, text-to-speech providers, or user-configured AI services when you use features that require those providers.
  • With connected integrations, MCP clients, OAuth clients, mobile clients, and other external tools according to the permissions, scopes, tokens, settings, and actions you authorize.
  • With other users or the public when you publish posts, enable a public profile, share artifacts, comment, vote, create communities, upload community media, send newsletters, or otherwise choose public or shared features.
  • With billing providers such as Stripe for checkout, subscription management, payment processing, tax, fraud, and billing support.
  • With legal, safety, compliance, and security recipients when Prism believes disclosure is needed to comply with law, enforce terms, respond to requests, prevent abuse, protect rights, or investigate security incidents.
  • As part of a business transaction, such as a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards where required.

7. Public and Shared Content

Some Prism features are intentionally public or shared. Public profiles, publication pages, published articles, public article previews, shared artifacts, community posts, comments, votes, saves, media, display names, avatars, subscriber-facing emails, and related engagement may be visible to others depending on your choices and the feature's settings.

Public content may be indexed by search engines, copied by others, cached, archived, quoted, or reshared outside Prism. If you remove or restrict public content later, copies may remain outside Prism's control.

Private, unlisted, or group-linked content may still be visible to authorized users, community members, moderators, connected clients with permission, or service providers that process the content for Prism.

When a Project owner invites a collaborator, Prism processes invitation and membership information and makes the shared Project research content available according to the selected Viewer or Editor role. Project Email, publishing drafts, portfolios, personal memory, private chats, and integration settings are not included in Project sharing.

A Project owner may separately allow a collaborator's MCP clients to read or make limited non-destructive changes to the shared Project. Prism records the collaborator, MCP client, target Project, action, and outcome so the collaborator can review their MCP use and the owner can review activity limited to that Project. The owner cannot use that audit view to inspect the collaborator's unrelated MCP activity.

A Project owner or editor may connect a private Google account to import selected Drive files. The connected account address and credentials remain private to that person, while cached source snapshots, extracted text, and source status are visible to Project readers. Opening the original file in Google remains subject to Google's separate access controls.

8. Cookies, Analytics, and Local Storage

Prism uses essential cookies, local storage, and similar technologies to support authentication, security, preferences, locale selection, sidebar state, public article visitor measurement, and service operation. Optional product analytics are enabled only after you choose to allow them.

When enabled, Prism uses Vercel Analytics to understand aggregate website usage and performance, and PostHog for limited signed-in product analytics across web and mobile, including coarse product areas, feature adoption, activation, retention, and rollout measurement linked to an opaque account identifier. If you keep analytics off, these optional product analytics clients do not load in the web app.

Prism configures PostHog product analytics not to collect prompts, research queries, Project names, filenames, tickers, document contents, generated writing, chat identifiers, Project identifiers, or raw private route paths. Session replay, touch autocapture, and automatic exception capture are disabled in Prism's PostHog clients.

Your browser or device may allow you to control cookies and local storage. Disabling them may break sign-in, preferences, billing, analytics opt-outs, or other product functionality.

9. Retention

Prism retains information for as long as needed to provide the service, maintain your account, operate features you use, comply with legal obligations, resolve disputes, enforce agreements, secure the service, maintain backups, and support legitimate business operations.

Different categories of information may have different retention periods. For example, account data may be retained while your account is active; billing records may be retained for tax and accounting purposes; audit logs may be retained for security; published content may remain available until unpublished or removed; and backups may persist for a limited period after deletion from active systems.

Some data associated with public content, community activity, subscriber emails, logs, integrations, or legal/security events may be retained even after account cancellation where needed for legitimate operational, legal, safety, or audit purposes.

Disconnecting Google Drive freezes linked sources and stops synchronization but does not automatically remove the last successful Project snapshot. A retained snapshot remains available to authorized Project members until the source or account data is deleted under Prism's applicable deletion and retention processes.

10. Your Choices and Controls

You can control many types of information directly in Prism, including profile settings, community identity, publication settings, article visibility, subscriber workflows, notifications, billing settings, AI provider connections, MCP clients, OAuth grants connections, Project sources, and uploaded content.

You may unsubscribe from Prism publication emails through unsubscribe links where available. Transactional, security, billing, account, and service emails may still be sent where necessary.

You can revoke integrations, delete or rotate tokens, disconnect providers, delete content, change visibility settings, and cancel paid plans through available product controls. Some changes may not affect content already sent, published, cached, indexed, emailed, or shared outside Prism.

You can disconnect a Google account to revoke future access where possible. You can separately remove a linked source from its Project; disconnecting alone retains the last successful read-only snapshot so the Project does not silently lose research history.

11. Access, Deletion, and Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have rights to appeal a privacy decision or opt out of certain sharing or targeted advertising if those activities apply.

To request access, correction, deletion, export, or another privacy action, contact Prism at team@tryprism.xyz. Prism may need to verify your identity and may retain certain information where required or permitted by law, such as billing records, security logs, abuse-prevention records, legal records, backups, or public content already shared with others.

If you want to delete your account or content, Prism may provide in-product controls or handle requests through contact with Prism. Deletion may not immediately remove information from backups, logs, provider systems, emails already delivered, public search indexes, or content copied by others.

12. Security

Prism uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include authentication, access controls, scoped tokens, OAuth flows, audit logs, rate limits, encryption or secret handling for sensitive credentials, private media routes, and provider security controls.

No service can guarantee absolute security. You are responsible for keeping your account, devices, sessions, API keys, MCP tokens, OAuth grants, and connected services secure.

13. Children

Prism is not intended for children under 13, and Prism does not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Prism, contact Prism so the information can be reviewed and deleted where appropriate.

14. International Use

Prism is operated with a United States-oriented policy structure. If you access Prism from outside the United States, your information may be processed in the United States and other locations where Prism or its service providers operate.

Privacy laws vary by jurisdiction. Final region-specific disclosures, transfer mechanisms, and consumer-rights language should be reviewed by counsel before production reliance.

15. Service Providers and Subprocessors

Prism relies on service providers to operate the product. Current provider categories include authentication, hosting, analytics, database infrastructure, blob or media storage, email delivery and inbound email handling, billing, AI models and gateways, embeddings, text-to-speech, search, market data, error logging or diagnostics, and communications integrations.

Examples of provider families reflected in Prism's product include Clerk, Stripe, Vercel, PostHog, Neon or Postgres infrastructure, Resend, AI providers such as OpenAI and Anthropic or AI gateways, search or market-data providers, and storage providers. The exact provider set may change as Prism evolves.

16. Changes to This Policy

Prism may update this Privacy Policy from time to time. When changes are material, Prism may provide notice through the service, by email, or by updating the effective date. Continued use of Prism after the updated policy takes effect means the updated policy applies to your information.

17. Contact

Questions or requests about this Privacy Policy can be sent to team@tryprism.xyz.

This draft does not identify a separate legal entity, mailing address, or formal privacy officer. Those details should be added before production reliance if required for Prism's launch, jurisdiction, or app-store obligations.