Prism
Start free

Privacy Policy

Last updated: August 2026

What we collect, why we collect it, who else touches it, and how to get it back or get it deleted.

Introduction

This policy explains how Prism Analytics ("we", "us", "our") collects, uses and protects your personal information when you use the Prism platform ("the Service"). If anything in it is unclear, email privacy@searchprism.io and a person will answer.

Information we collect

Account information

When you create an account we collect your name, email address and profile information through our authentication provider, Clerk. We do not store your password.

Google Search Console data

When you connect Search Console we access your search analytics data: queries, pages, clicks, impressions, click-through rate, average position, device type and country. This is fetched through the official Search Console API using OAuth 2.0 with read-only permissions.

Google Analytics 4 data

When you connect a GA4 property we access its reporting data through the GA4 Data API, again with read-only permissions. This covers sessions, users, engagement, conversions and revenue by channel, source and landing page.

Site crawl data

When you run a crawl we fetch pages from the site you nominated and store what we find about each URL, including status codes, markup, headings, links, images and performance measurements.

Answer-engine prompts and responses

The prompts you write are sent to AI answer engines on your behalf, and the responses are stored against your property so the reports can be built from them.

Usage data

We collect information about how you use the Service, including pages visited, features used and credit consumption. We use it to improve the product and to answer support questions.

How we use your information

  • To provide and maintain the Service
  • To process and display your search, analytics and crawl data
  • To run the answer-engine scans you schedule
  • To manage your account and subscription
  • To send service updates and notifications
  • To improve the Service based on usage patterns
  • To provide customer support

Payment information

We use Stripe to process all payments. When you buy a subscription or a credit package, your payment details (card number, expiry, CVC) are entered directly into Stripe’s payment form and transmitted to Stripe. We never see, store or have access to your raw card details.

We store only the outcome of a transaction: the amount charged, the date, and a reference supplied by Stripe. Your billing history is in the Billing section of your account. Stripe’s privacy policy governs how they handle payment data: stripe.com/privacy.

Data storage and security

Your data is stored using Turso, a SQLite-compatible database service, with encryption in transit and at rest. We use HTTPS throughout, OAuth 2.0 for third-party connections, and secure token storage.

We never store your Google credentials. Authentication happens entirely through Google's own OAuth flow, which returns a token rather than a password. We never store raw payment card details, because all payment processing is handled by Stripe.

Third-party services

The Service depends on the following processors. Each has its own privacy policy governing how it handles data.

  • Clerk, for authentication and user management.
  • Stripe, for payment processing and subscription billing.
  • Google Search Console API, for read-only access to your search analytics data.
  • Google Analytics 4 Data API, for read-only access to your GA4 reporting data.
  • Turso, for database storage.
  • DataForSEO, for carrying the prompts you write to the AI answer engines (ChatGPT, Claude, Gemini and Perplexity) and bringing back their responses, and for supporting search data.
  • Google Gemini embedding API, for turning your search queries and prompts into numeric embeddings so they can be grouped by meaning.
  • Logo.dev, for brand and website logo images shown inside the application.

Data retention

We retain your data for as long as your account is active. Disconnecting a Google property deletes the analytics data associated with it. Deleting a property removes its rows across every table that holds them, including crawl and warehouse data. When you delete your account, all of your data is permanently deleted within 30 days.

Your rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Revoke Google access at any time, from your Google account or from inside Prism
  • Opt out of non-essential communications

Cookies

We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. Our authentication provider, Clerk, may set cookies necessary for secure login.

Children's privacy

The Service is not intended for use by children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. We will tell you about material changes by email or through the Service. The "last updated" date at the top of this page shows when it was last revised.

Contact us

For questions about this policy or your data, email privacy@searchprism.io.