Privacy Policy

Last updated: July 1, 2026

This Privacy Policy describes how Prism ("we", "us", "Prism") collects, uses, and shares information when you use our AI pipeline intelligence service (the "Service"). This page is maintained by the Prism team.

Information we collect

How we use information

Workspace (tenant) isolation

Every record in Prism — opportunities, activities, files, notifications, and integration settings — carries the identifier of the workspace that owns it. Our database enforces row-level security policies so that a query issued by a signed-in user can only ever return rows belonging to that user's own workspace. Isolation is enforced at the data layer, not only in application code, so it applies to every screen, export, and API call.

Mailbox connections are per person

When you connect Microsoft 365 or Gmail, you sign in with your own credentials and grant consent yourself. Prism never asks for or stores your mailbox password. The resulting authorization is stored encrypted, on our servers only, and is bound to your individual user account inside your workspace. Colleagues — including workspace administrators — cannot read your mailbox or reuse your connection. You can revoke access at any time from the Integrations page, which deletes the stored authorization.

What managers can see

Manager and administrator accounts see aggregated pipeline metrics and the opportunity records that belong to their own workspace — for example forecast totals, stage distribution, health scores, and activity counts. They do not receive raw mailbox contents, message bodies, or credentials from another user's connected account. Visibility never extends beyond a single workspace.

AI processing

Prism sends the minimum necessary content to AI providers to generate summaries, risk signals, and suggested next steps for your workspace. That content is processed to return a result to you and is not used to train third-party foundation models.

Data sharing

We do not sell your personal information. We share data only with subprocessors necessary to operate the Service (hosting, database, payments, email delivery, AI providers), all bound by data-processing agreements.

Data retention & deletion

You may delete your workspace at any time from settings. Backups are purged within 30 days.

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and audited.

Your rights

You may request access to, correction of, or deletion of your personal information by emailing privacy@prismaipro.com.

Contact

Questions? Contact privacy@prismaipro.com.