Prism
Start free
Security

Read-only access to Google, and how to take it away again.

Hesitating over the Google consent screen is the correct instinct. So here are the exact scopes Prism asks for, what is stored behind each of them, and how to take the whole thing away again without asking us.

The consent screen

What Prism asks for.

These are the exact permissions Google will show you. No write scope appears in the list. Without one, Prism cannot change a setting, submit a sitemap, request indexing or alter anything at all in your account.

  • webmasters.readonly

    Read your Search Console performance data and property list.

  • analytics.readonly

    Read your Google Analytics 4 reporting data.

  • userinfo.email

    Read the email address of the Google account doing the connecting, so the property can be labelled.

Every one of them ends in readonly.

What Prism holds, and what it never sees.

The two things people picture when they hesitate are a password and a card number. Neither ever reaches us.

No Google password
Connecting happens on Google's own consent screen. Google hands back a token, never a password, so there is nothing for us to see or to lose.
No Prism password either
Sign-in is handled by Clerk, an authentication provider. Prism stores your name, email and a Clerk identifier. It does not store a password for you.
No card details
Payments go through Stripe. Card numbers are entered on Stripe's side and never reach Prism's database. We record which plan you are on, not how you paid for it.
Your search and crawl data
The Search Console rows Prism syncs, the pages the crawler fetched, the prompts you wrote and the answers the engines gave. The 33 free reports read from it.

Turning it off.

Open your Google account’s third-party access settings, find Prism, remove it. The connection dies immediately, from Google’s side, with nobody here in the loop and nothing for us to drag our feet over.

Disconnecting from inside Prism works too. Deleting a property removes its rows across every table that holds them, the crawl and the warehouse included.

Who else touches the data.

A short list rather than a long chain. Google supplies the search and analytics data, Clerk handles sign-in, Stripe handles payment, Turso stores everything, and the answer engines receive the prompts you wrote and nothing else about you.

The privacy policy lists what each one does and how long things are kept.

What we don’t claim

Prism has not been through a SOC 2 or ISO 27001 audit and this page is not going to imply otherwise. If your procurement process requires one, tell us, and you will get an honest account of where we actually are rather than a badge.

Data is stored and queried per property, and access is granted per user. Details on how that is enforced are available on request.

Questions before you connect

What can Prism do with my Google account?

Read your Search Console and Analytics data, and nothing else. The connection asks for webmasters.readonly and analytics.readonly. There is no write scope, so Prism cannot change a setting, submit a sitemap, request indexing or alter anything in your Google account.

Do you store my Google password?

We never see it. Connecting goes through Google's own OAuth screen, and Google hands back a token rather than a password. Your Prism sign-in is handled by Clerk, so we do not store a password for that either.

How do I revoke access?

Go to your Google account's third-party access page and remove Prism. That cuts the connection immediately, without going through us. You can also disconnect from inside Prism.

What happens to my data if I delete a property?

It is deleted with it. Removing a property removes its rows across every table that holds them, including the crawl and warehouse data.

Connect it, look at it, disconnect it if you want to.

There is no card to enter and no clock to beat, so the whole cost of finding out is a two-minute consent screen you can undo from Google whenever you like.