Privacy Policy
Last updated: April 24, 2026
We built Prysm because data scattered across five tools is a liability — so we're not going to turn around and be careless with yours.
Overview
This policy explains what Prysm collects when you use the marketing site and the product, why we collect it, and the choices you have. We've tried to write it like humans talk — where legal precision matters, we've kept the precise version.
The short version: we collect what we need to run the service, we don't sell your data, and your workspace content is yours.
What we collect
- Account information — name, work email, company, and authentication credentials when you sign up.
- Workspace content — spreadsheets, scripts, docs, connection metadata, and anything else you create or import. This is your data; we store it to provide the service.
- Connector credentials — OAuth tokens and secrets you authorize for Postgres, MySQL, Sheets, Excel, REST, and file sources. These are encrypted per-workspace and used only to perform the syncs you configure.
- Usage data — product events like feature usage, performance metrics, and error reports that help us find and fix problems.
- Billing information — processed by our payment provider; we never see or store full card numbers.
- Support conversations — emails, demo requests, and messages you send us.
How we use it
We do not train AI models on your workspace content. When Juno processes your data to answer a question, it does so within your workspace's permission boundary, secrets are never exposed to the model, and the request is logged like any other action.
- Provide, maintain, and improve the product — including running scripts, syncing connections, and enforcing contracts you've configured.
- Authenticate you, enforce permissions, and keep the audit log accurate.
- Respond to your requests — demos, support, security reviews.
- Send product updates you've opted into. You can unsubscribe anytime; transactional mail (security alerts, billing) isn't optional.
- Meet legal obligations and prevent abuse.
Retention
We keep your workspace content for as long as your account is active. When you delete content or close your account, we delete it from primary storage within 30 days and from encrypted backups within 90 days.
Audit log entries are retained for the life of the workspace and for 12 months after workspace deletion, because a log you can erase isn't a log.
Support conversations are kept for 24 months. You can ask us to delete them sooner.
Third parties
We share data with a small set of subprocessors — cloud hosting, payment processing, error monitoring, and transactional email — each under a data-processing agreement and limited to what's needed for their role.
We don't sell personal data, and we don't share it with advertisers. We'll publish our current subprocessor list with any security packet — just ask.
We may disclose data if required by law, and we'll notify you unless legally prohibited.
Security
Data is encrypted in transit with TLS 1.3 and at rest with AES-256, and connector credentials are stored encrypted at rest. Workspaces are org-scoped, mutations pass CSRF same-origin checks, every change lands in an append-only audit log, and access is governed by role-based permissions — owner, admin, member, viewer, plus custom roles.
We're working toward SOC 2 Type II. See the security page for the current, honest state of our program — including how to report a vulnerability.
Your rights
To exercise any of these, email privacy@prysmhq.co. We respond within 30 days.
- Access, correct, or export your data at any time — workspace exports are built into the product.
- Delete your account and its content.
- Object to or restrict certain processing, and withdraw consent where consent was the basis.
- Complain to your local data protection authority if you're in the EEA, UK, or another jurisdiction that provides one.
Contact
Questions about this policy or your data: privacy@prysmhq.co. For security reports: security@prysmhq.co. For everything else: hello@prysmhq.co.
If we change this policy materially, we'll say so in the product and by email before the change takes effect.