Back to home
Legal

Privacy Policy

How Prizm collects, uses, and protects your personal information.

Last updated: 20 June 2026

Contents

  1. 01Introduction
  2. 02Information We Collect
  3. 03How We Use Your Information
  4. 04How We Share Your Information
  5. 05Data Security
  6. 06Data Retention
  7. 07Cookies and Tracking Technologies
  8. 08Your Rights
  9. 09International Data Transfers
  10. 10Children's Privacy
  11. 11Google API Integrations, OAuth Scopes & Use of Google User Data
  12. 12Third-Party Links
  13. 13Changes to This Policy

01 Introduction

Prizm ("Prizm", "we", "our", or "us") operates the stage.web.getprizm.dev website and the Prizm platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.

02 Information We Collect

We collect information in the following ways:

  • Account Information: When you register, we collect your name, email address, company name, and password.
  • Usage Data: We automatically collect information about how you interact with the Service, including API call logs, feature usage, and performance metrics.
  • Third-Party OAuth Credentials: When you connect a connector (e.g., Slack, Salesforce), we receive and securely store OAuth tokens on your behalf. We never store plaintext passwords for third-party services.
  • Payment Information: If you subscribe to a paid plan, payment details are processed by our payment provider (Stripe). Prizm does not store full card numbers or CVV codes.
  • Communications: If you contact us via email or support channels, we keep a record of that correspondence.
  • Cookies and Tracking: We use cookies and similar technologies to maintain sessions, remember preferences, and analyse usage. See Section 7 for more detail.

03 How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service.
  • Authenticate your identity and maintain the security of your account.
  • Execute API requests on your behalf to connected third-party services using your stored OAuth tokens.
  • Send transactional emails (billing receipts, password resets, security alerts).
  • Send product updates and marketing communications where you have opted in — you may unsubscribe at any time.
  • Comply with applicable laws, regulations, and legal processes.
  • Detect, investigate, and prevent fraudulent or unauthorised activity.

04 How We Share Your Information

Prizm does not sell your personal data. We may share information in limited circumstances:

  • Service Providers: We share data with trusted vendors who help us operate the Service (cloud hosting, analytics, email delivery, payment processing). These providers are contractually bound to use data only as directed by Prizm.
  • Third-Party Connectors: Data is transmitted to third-party services only when you explicitly initiate an API action through our platform.
  • Business Transfers: If Prizm is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you before this occurs.
  • Legal Requirements: We may disclose information if required by law or if we believe disclosure is necessary to protect our rights or the safety of others.

05 Data Security

We implement industry-standard technical and organisational measures to protect your data, including:

  • TLS 1.2+ encryption for data in transit.
  • KMS encryption for sensitive credentials at rest.
  • Role-based access controls.
  • Security monitoring and periodic assessments.

Despite our safeguards, no method of transmission over the Internet is 100% secure. We encourage you to use a strong password and enable two-factor authentication.

06 Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or compliance purposes. OAuth tokens for connected connectors are revoked and deleted immediately upon account deletion.

The following specific retention periods apply:

  • Execution logs — retained for 90 days, then automatically purged.
  • Webhook delivery logs — retained for 90 days, then automatically purged.
  • User activity logs — retained for 1 year, then automatically purged.
  • Admin audit logs — retained for 7 years for legal and compliance purposes (SOC 2 / GDPR Article 5(2)).
  • Data export files — download links expire after 7 days and the underlying files are deleted automatically.
  • Financial records — retained for 7 years as required by applicable tax law.

07 Cookies and Tracking Technologies

We use the following categories of cookies:

  • Essential Cookies: Required for authentication, security, and core functionality. Cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with the Service (e.g., PostHog, Amplitude). You may opt out via your browser settings or our cookie consent manager.
  • Marketing Cookies: Used to deliver relevant advertisements. Only placed with your consent.

You can manage cookie preferences in your browser settings. Disabling non-essential cookies will not affect core functionality.

08 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten").
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests or for direct marketing purposes.
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise these rights, email us at privacy@prizm.dev. We will respond within 30 days. We may ask you to verify your identity before processing your request.

09 International Data Transfers

Prizm is based in the United States. If you are accessing the Service from outside the US, your information may be transferred to and processed in the US or other countries. Where required, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection for transfers from the EEA, UK, and Switzerland.

10 Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us at privacy@prizm.dev and we will take steps to delete that information.

11 Google API Integrations, OAuth Scopes & Use of Google User Data

Prizm is an AI connectivity platform that enables users and organisations to securely connect applications, data sources, and services to AI agents, automation workflows, and MCP-compatible clients.

Users may connect Google services such as Gmail, Google Drive, Google Docs, Google Sheets, Google Slides, Google Calendar, Google Chat, Google Forms, Google Contacts, Google Tasks, Google Meet, Google Photos, Google Classroom, Google Analytics, Google Ads, Google Search Console, YouTube, Google Admin SDK, BigQuery, and other supported Google services.

Google integrations are optional. Users explicitly choose which Google services to connect and which permissions to grant. Prizm requests Google OAuth scopes only when a user connects and authorises a corresponding Google service.

Prizm does not request access to Gmail, Google Drive, Google Calendar, Google Docs, Google Sheets, Google Chat, Google Forms, Google Classroom, Google Analytics, Google Ads, YouTube, Google Photos, Google Meet, Search Console, BigQuery, or Google Admin data during account login. During authentication, Prizm may request only basic profile and account identification information necessary to authenticate users and manage accounts.

How Prizm Uses Google User Data

Google user data is accessed, processed, and transferred only to provide functionality explicitly requested and authorised by the user. Examples include:

  • Reading, drafting, sending, organising, and managing Gmail messages
  • Creating, updating, and managing Google Calendar events
  • Checking calendar availability and scheduling meetings
  • Creating, editing, organising, and managing Google Drive files
  • Creating and updating Google Docs, Sheets, Slides, and Forms
  • Reading and updating Google Contacts
  • Managing Google Tasks
  • Creating and managing Google Meet conferences
  • Sending and reading Google Chat messages
  • Managing Google Classroom resources
  • Reading Google Analytics reports
  • Managing Google Ads data
  • Reading Search Console data
  • Managing YouTube content
  • Performing Google Workspace administration tasks
  • Querying and analysing BigQuery datasets
  • Executing user-authorised AI workflows and MCP tool operations

Google user data is never accessed unless explicitly authorised by the user through the applicable Google OAuth consent flow. Only the scopes required for the specific integration you enable will be requested. Prizm applies the principle of least privilege — we request only the minimum permissions necessary for the functionality you have chosen to use.

Google Account

ScopeWhat it allows & how Prizm uses it
userinfo.emailAccess to your primary Google Account email address. Used to identify your account when connecting Google services and to associate integrations with your user identity.
userinfo.profileAccess to your basic Google Account profile information that you have made publicly available, such as your name and profile photo. Used to display your identity within Prizm when managing connected integrations.
user.emails.readAccess to read all email addresses associated with your Google Account. Used alongside Google Contacts to identify all addresses linked to your account, enabling accurate contact lookups, email routing, and identity matching across connected workflows.

Gmail

ScopeWhat it allows & how Prizm uses it
gmail.readonlyRead-only access to all email messages, threads, and labels. Used to search your inbox, retrieve email content for summaries or analysis, and read thread history in user-initiated workflows.
gmail.metadataAccess to email headers (sender, recipient, subject, date) without reading email body content. Used to list emails, filter by sender or date, and display inbox overviews without accessing private message body text.
gmail.composeAbility to create and manage email drafts. Used to draft emails on your behalf based on your instructions, without sending them until you explicitly approve.
gmail.modifyAbility to read, modify, and delete emails and labels, but not permanently delete threads. Used to archive messages, apply or remove labels, mark messages as read/unread, and organise inbox folders per your instructions.
gmail.sendAbility to send email messages on your behalf. Used only when you explicitly instruct Prizm to send an email or reply to a thread as part of a user-authorised automation workflow.
gmail.labelsAccess to create, read, update, and delete Gmail labels. Used to create custom labels for organising emails and apply label-based routing in automation workflows.
mail.google.comFull access to your Gmail account including reading, composing, sending, and permanently deleting messages. Requested only for advanced workflows that require complete mailbox management capabilities as explicitly authorised by you.

Google Drive

ScopeWhat it allows & how Prizm uses it
drive.fileAccess only to files that Prizm has created or that you explicitly open or share with the app. Used to create, read, and update specific files as part of user-authorised workflows, without accessing your entire Drive.
drive.readonlyRead-only access to all files in your Google Drive. Used to search for files, retrieve file content, list folder structures, and display file information in user-initiated queries without modifying any data.
driveFull access to all files in your Google Drive including creating, reading, updating, moving, and deleting files and folders. Requested only for advanced file management workflows explicitly authorised by you.

Google Docs

ScopeWhat it allows & how Prizm uses it
documentsFull read and write access to your Google Docs documents. Used to create new documents, read existing document content, insert or update text, generate structured reports and meeting summaries, and modify document content as directed by your instructions.

Google Sheets

ScopeWhat it allows & how Prizm uses it
spreadsheetsFull read and write access to your Google Sheets spreadsheets. Used to create new spreadsheets, insert rows, update cell values, format sheets, and manage structured data as directed by your instructions.
spreadsheets.readonlyRead-only access to your Google Sheets spreadsheets. Used to retrieve and analyse spreadsheet data, generate reports or summaries, and display cell values in user-initiated queries without making any changes.

Google Calendar

ScopeWhat it allows & how Prizm uses it
calendar.app.createdAccess only to calendars and events that Prizm has created. Used to manage events created by Prizm on your behalf, such as scheduling meetings or reminders, without accessing your personal or pre-existing calendar data.
calendar.calendarlist.readonlyRead-only access to the list of calendars in your Google account. Used to discover which calendars you have (e.g., personal, work, shared) so that events can be scheduled to the correct calendar.
calendar.freebusyAccess to free/busy time information from your calendar without revealing event titles or details. Used to check your availability for scheduling meetings and suggest open time slots without reading the content of your calendar events.

Google Chat

ScopeWhat it allows & how Prizm uses it
chat.messagesFull read and write access to messages in Google Chat spaces and direct messages. Used to send messages, update message content, and delete messages as directed by your instructions.
chat.messages.readonlyRead-only access to messages in Google Chat. Used to read message history, search conversations, and retrieve message content in user-initiated queries without sending or modifying any messages.
chat.messages.createAbility to send new messages in Google Chat spaces and direct messages. Used to post messages, notifications, and updates to Chat conversations as explicitly instructed by you.
chat.spacesFull read and write access to Google Chat spaces (group conversations). Used to create new spaces, update space settings, and manage space details as directed by your instructions.
chat.spaces.readonlyRead-only access to the list and details of Google Chat spaces you belong to. Used to discover available spaces and retrieve space information without creating or modifying any spaces.
chat.membershipsFull access to manage memberships in Google Chat spaces. Used to add or remove members from spaces and update membership roles as directed by your instructions.

Google Contacts

ScopeWhat it allows & how Prizm uses it
contactsFull read and write access to your Google Contacts. Used to search for contacts by name or email, create new contacts, update existing contact details, and support contact-based communication workflows as directed by your instructions.
contacts.readonlyRead-only access to your Google Contacts. Used to look up contact information, autocomplete names and email addresses, and retrieve contact details without creating or modifying any contact records.

Google Tasks

ScopeWhat it allows & how Prizm uses it
tasksFull read and write access to your Google Tasks. Used to create new tasks, update task titles and due dates, mark tasks as complete, organise tasks into lists, and manage task-based workflows as directed by your instructions.
tasks.readonlyRead-only access to your Google Tasks. Used to list and read task details, display pending tasks, and retrieve task information without creating or modifying any tasks.

YouTube

ScopeWhat it allows & how Prizm uses it
youtube.readonlyRead-only access to your YouTube account including channel information, video details, playlists, and subscriptions. Used to retrieve channel statistics, list videos, and analyse content performance without modifying any YouTube data.
youtubeFull access to your YouTube account including managing videos, playlists, comments, and channel settings. Used to update video metadata, manage playlists, and perform channel management actions as directed by your instructions.
youtube.uploadAbility to upload videos to your YouTube channel. Used exclusively when you instruct Prizm to publish or upload video content to your channel as part of a content publishing workflow.

Google Analytics

ScopeWhat it allows & how Prizm uses it
analytics.readonlyRead-only access to your Google Analytics account data including traffic reports, audience metrics, conversion data, and website performance statistics. Used to retrieve analytics reports and produce business performance insights without modifying any analytics configuration.

Google Admin SDK

ScopeWhat it allows & how Prizm uses it
admin.directory.userFull access to manage user accounts in your Google Workspace directory. Used by Workspace administrators to create, update, suspend, and delete user accounts as directed by admin instructions.
admin.directory.user.readonlyRead-only access to user account information in your Google Workspace directory. Used to list users, retrieve user profiles, and search the directory without modifying any user accounts.
admin.directory.groupFull access to manage Google Groups in your Workspace including creating, updating, and deleting groups and their settings. Used by administrators to manage mailing lists and security groups as directed by admin instructions.
admin.directory.group.readonlyRead-only access to Google Groups in your Workspace. Used to list groups, retrieve group details, and search the groups directory without creating or modifying any groups.

BigQuery

ScopeWhat it allows & how Prizm uses it
bigqueryFull access to your Google BigQuery resources including datasets, tables, and query execution. Used to run SQL queries against your datasets, retrieve query results, list available tables and schemas, and generate data analysis reports as directed by your instructions. Prizm does not store raw BigQuery data beyond the scope of the immediate query execution.

Data Storage & Retention

Prizm may process and retain execution-related information for operational functionality, auditability, debugging, security monitoring, abuse prevention, compliance, and service reliability. Execution logs are retained for up to 90 days and are automatically deleted after the retention period expires.

Security

OAuth access tokens and refresh tokens are encrypted at rest using KMS encryption. All communication with Google APIs occurs over encrypted TLS-secured connections. OAuth credentials are never exposed through application logs, execution history, analytics systems, monitoring systems, or user-facing interfaces.

Limited Use Compliance

Prizm's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace and Google API-derived user data is never:

  • Sold to third-party entities or advertising brokers.
  • Used for targeted advertising displays or behavioural profiling.
  • Used to train any artificial intelligence, large language, or machine learning models.
  • Handled by human personnel unless explicit consent has been provided to troubleshoot an isolated error, to comply with legal/statutory investigations, or when data is thoroughly scrubbed of personal identifiers for structural safety checks.

Revoking Access

Users may revoke Google access at any time through Google Account Permissions or Prizm Integration Settings. Revoking access immediately prevents future access to Google-connected functionality. Stored OAuth credentials associated with revoked integrations become invalid and can no longer be used for future requests.

12 Third-Party Links

The Service may contain links to third-party websites or services. Prizm is not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.

13 Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

Questions about this policy? Contact us at privacy@prizm.dev. For our terms of use, see the Terms of Service.