Skip to content

Legal

Prismr Privacy Policy

Last Updated: September 2, 2026

This Privacy Policy describes how Targeted Coaching International, Ltd., operating as Prismr ("we," "our," or "us"), collects, uses, stores, shares, and protects your information when you use the Prismr application on macOS, Windows, iOS, or Android (the "App") and our website at prismr.ai (the "Website"). Together, the App and Website are referred to as the "Services."

Prismr is an AI workspace. It can send the content you work on to AI models, take actions on your behalf, and keep conversations and work records in our cloud so your devices and collaborators stay in sync. This policy explains exactly what leaves your device, where it goes, and how long it stays. Where a feature is optional, we say so.

1. Information You Provide to Us

1.1 Account Information

You sign in to Prismr with an email address and password, with an email sign-in link, with Sign in with Apple, or with Sign in with Google. You can add multi-factor authentication using an authenticator app. Available methods vary by platform. To create and secure your account, we process:

  • Your email address and account identifier
  • Your first and last name, and an optional profile photo, which you enter at sign-up
  • Password-related authentication data, where you use a password (we store a hash, never the password itself)
  • Apple or Google account identifiers and authentication tokens, where you sign in with Apple or Google; Apple may also provide your name and a relay email address
  • Multi-factor authentication status
  • Sign-in and security records

When you sign in with Apple or Google, those services confirm your identity and provide Prismr with tokens and identifiers. Prismr does not receive or have access to your Apple or Google password. Your account is personal to you and may not be shared with or transferred to another person.

1.2 API Keys and Provider Sign-Ins

Prismr works with AI providers in two ways:

  • Bring Your Own Key (BYOK). You can enter your own API keys for AI providers and optional connectors. These keys are stored only on your device: in the iOS Keychain, in the Android Keystore, and in Electron's secure storage on macOS and Windows. They are never sent to or stored on Prismr's servers. We cannot view, retrieve, or recover them. Where a provider allows you to sign in with your own account instead of a key, the resulting tokens are stored the same way.
  • Pilot-managed AI access. During our pilot, some accounts are given access to AI models through Prismr's own provider account. This is a limited, invitation-based feature, not a standard part of every subscription, and it may end after the pilot. When you use it, your request is sent to Prismr's servers, which forward it to OpenRouter using Prismr's account, and the response comes back the same way. We do not create or deliver any key to your device. See Section 3.2 for what our servers log.

1.3 Payment Information

When you purchase a Prismr subscription through our website, payment is processed by Creem.io. We do not collect or store your card number, bank details, or billing address. We receive and store from Creem your customer identifier, subscription identifier, product, subscription status, and a history of billing events. We send Creem the email address on your account so it can match the purchase to you. Creem's own privacy policy governs the data it holds.

If we offer purchases through the Apple App Store or Google Play in future, those purchases will be processed by Apple or Google under their privacy policies, and we will update this section first.

1.4 Support Requests

When you send us a support request from inside the App or by email, we store your message, your email address and display name, and any files or screenshots you attach. If you choose to include diagnostics, we also store a short list of app settings (app version, platform, operating system version, theme, active model, enabled providers) and recent app logs. We automatically mask email addresses, phone numbers, card numbers, and similar patterns in logs before storing them; we do not mask the free-text message you write or files you attach. Support requests are stored in our database and are visible to our support staff.

1.5 Early-Access Requests on the Website

If you request early access on the Website, the name, work email, company, and role you enter are sent to Web3Forms, a form-processing service, which forwards them to us by email. We use them only to contact you about early access.

2. Information We Collect Automatically

2.1 Device Information

To manage your account across devices we record a device identifier, a device name, the platform, and the app version for each device you sign in on.

  • Desktop (macOS, Windows): The device identifier is a randomly generated value created on first use. For account validation we also compute a soft fingerprint from your browser user-agent string, screen resolution, language, and time zone. Neither is a hardware serial number or an operating-system identifier. The device name we record is your computer's network name (hostname).
  • iOS: Apple's per-vendor identifier (identifierForVendor), a software identifier assigned by Apple. It is not a hardware serial number or advertising identifier. The device name is the device model.
  • Android: A software identifier generated for the App. The device name is the device model.

While the App is open and signed in, it reports every 20 seconds that the device is online, together with the list of Projects available on that device, so your other devices can send work to it (see Section 5). Each time the App starts, it also sends the email address on your account to our licensing service to confirm your account status.

Your IP address may be processed by our servers and service providers whenever the App or the Website connects to them, for rate limiting, security, and abuse prevention. We do not keep a separate log of IP addresses beyond the standard server logs described in Section 2.3.

2.2 Usage Records and Crash Reports

Usage records. While you are signed in on desktop, the App sends us a summary every five minutes and when it closes: your account identifier and email, how many seconds the App was active and idle, how many messages you sent to each AI model, and the app version. We use this to understand how the pilot is being used and to plan capacity. We do not record what you typed, the content of any conversation, or your location. These records are kept for 90 days. You may object to this processing at any time by emailing [email protected].

Crash and error reports. The desktop App uses Sentry to report crashes and errors so we can fix them. A report contains the error message, a stack trace, the app version, your operating system type and version, and whether the build is a production or development build. Before a report leaves your device we remove email addresses, IP addresses, local file paths, access tokens, API keys, request bodies, and cookies. We do not send performance traces or session replays. Reports are processed by Sentry (Functional Software, Inc.) and stored in the European Union. The mobile Apps do not include Sentry.

What we do not do. The App does not include Firebase Analytics, Crashlytics, or any advertising or tracking SDK. We do not profile you, and we do not sell or share usage data.

2.3 Software Updates and Server Logs

The desktop App checks for updates shortly after launch and every six hours by contacting GitHub, where we publish releases. That request discloses your IP address, app version, and operating system to GitHub. Downloads happen only when you accept an update.

Our servers keep standard request logs (IP address, request path, timestamps, response codes) for up to 30 days to maintain and secure the Services. When you visit the Website, its host (Cloudflare) collects the same kind of standard log data.

2.4 Cookies

Our Website uses only essential cookies, if any, required for basic functionality. We do not use analytics, advertising, or tracking cookies on the Website. The Website's cookie notice records your acknowledgement in your browser's local storage so it is not shown again. Third-party services you choose to use through links from our Website may set their own cookies, subject to their respective privacy policies.

3. Where Your Content Goes

This section explains what happens to the content you work on. We believe you should know exactly where your information goes.

3.1 AI Providers

To answer you, Prismr sends your prompts, the relevant parts of your files, conversation history, and tool results to the AI model you choose. Which provider receives that content depends on the model you select and how you connected it:

  • Providers you connect with your own key or account. Content goes directly from your device to that provider. Depending on the models you enable, providers include companies operating from the United States (for example Anthropic, OpenAI, Google, xAI, and OpenRouter), from China (for example Moonshot AI, Xiaomi, MiniMax, Zhipu AI, and DeepSeek), and elsewhere. Models reached through OpenRouter may be served by any of OpenRouter's underlying providers, in any country. The App shows you which provider serves each model before you enable it.
  • Pilot-managed access. Content goes to Prismr's servers, then to OpenRouter under Prismr's account, then to the provider serving the model. See Section 3.2.
  • Local models. If you connect a model running on your own hardware (for example Ollama or LM Studio), content stays on your machine or local network.

If a provider you connected is unavailable, the App may retry with the next route you have configured. Unless you turn that off in the App, the last fallback is pilot-managed access where your account has it.

Each provider processes your content under its own terms, privacy policy, and retention rules. We cannot make one privacy promise that covers every provider. Before enabling a provider, review its policy; the main ones are:

3.2 Pilot-Managed AI Access

When your account has pilot-managed access and you use it, our server receives your full request, adds Prismr's OpenRouter credentials, forwards it, and streams the response back to you. Our server records the model name, your account identifier, the time, and the number of tokens used, so we can apply fair-use limits and understand cost. It does not store your prompt or the model's response. Managed usage is subject to per-minute and per-hour limits and a global cap; when a limit is reached, requests fail until the next window.

We do not use your prompts or AI responses to train AI models, for advertising, or for any purpose other than delivering the Service to you.

3.3 Optional Tools and Connectors

You can enable tools that let the AI complete tasks. Each tool sends only what it needs to the service behind it, using a key or account you supply, and each service processes that data under its own policy. Tools currently available include web search (for example Tavily, Exa, Perplexity, Brave, SerpAPI), web page retrieval (Firecrawl, ScrapingBee), messaging and posting (Resend, Twilio, Slack, X, Agent Mail), workspace and data lookups (Notion, GitHub, YouTube, Reddit, weather, finance, maps, and news services), people and company data (Hunter.io, Clearbit), media generation (ElevenLabs, Replicate), and any MCP servers you connect. Data sent to a tool can include your search terms, page addresses, message text and recipients, and file contents you ask it to use.

The built-in browser tool visits websites from your device using a browser profile that keeps its own cookies and sign-ins. Page contents and screenshots from that browser are sent to the AI model you selected so it can decide what to do next, and screenshots may be saved into the Huddle where the task was started.

3.4 Cloud Storage Integrations (iOS and Android)

On iOS and Android you can connect Google Drive, OneDrive, or Dropbox so the App can read and write Project Files stored there. On desktop, the App simply works with folders on your computer, including folders that your cloud provider's own desktop app keeps in sync.

  • Sign-in happens directly between your device and the provider using OAuth 2.0 with PKCE and state validation. Access and refresh tokens are stored only on your device, in the iOS Keychain or the Android Keystore, and are never sent to Prismr's servers.
  • Your files are read from and written to your cloud storage provider directly by your device. We do not mirror your Drive, OneDrive, or Dropbox to Prismr's servers.
  • Permissions requested: Google Drive: full file access (the "drive" scope), which covers all files in your Google Drive, not only files created by Prismr; we read your Google account email address through the Drive service to label the connection. Dropbox: file read/write, metadata read/write, sharing, and account info. OneDrive: file read/write (Files.ReadWrite) and basic profile.
  • Prismr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Each cloud storage provider's own privacy policy governs how it handles your data: Google, Microsoft, Dropbox, Apple iCloud.

4. Data on Your Device

Your Project Files stay where you put them: a local folder, a server or network drive, or a cloud-synchronized folder such as iCloud Drive. We do not mirror your project folder to Prismr's servers. Prismr may read and write those files when you ask it to do work. Section 5 describes the separate records we keep in our cloud.

The App also stores the following on your device or inside your project folder:

  • Your Project Files, documents, and workspace settings
  • Local copies of conversation history and project context, inside your project folder
  • Full transcripts of each Job, inside the project folder: your request, the instructions given to the AI, every tool call and its result, and files fetched from the web
  • Project memories, reusable prompts, and document comments (including the commenter's initials or email and position in the document)
  • Application preferences (theme, model selections, persona and communication style)
  • API keys and provider sign-in tokens, in secure encrypted storage
  • Cloud storage sign-in tokens, in secure encrypted storage (iOS and Android)
  • The browser tool's browsing profile, including cookies and website sign-ins it has kept, and a list of the accounts it has signed in with
  • MCP server configuration you set up, including any credentials you put in it
  • Installed skills, including any playbooks the AI has written for itself
  • Account validation data (your email and device identifier), your initials, and the recent project list (names, folder paths, last opened)
  • Cached model lists, thread indexes, outputs of code the AI ran, a small routing log, and crash dumps

Uninstalling the App does not remove this data. On macOS, application data stays in Library/Application Support/Prismr; on Windows it stays in your AppData folder; everything written inside your project folders stays there. Keychain and Keystore entries also remain until you remove them.

5. Data in Prismr's Cloud

Prismr uses Google Firebase and Google Cloud to keep your devices and collaborators in sync. The following is stored in our cloud, not only on your device:

  • All conversations, including ones with no other people in them. For every message: the text, who sent it (name and email), the AI model used, a summary of tool activity (tool names, arguments, and short result excerpts), sources and web addresses the AI used, and links to attachments. Files you attach to a conversation are uploaded to our cloud storage so every participant and device can open them.
  • Jobs. For each Job you run: the request summary, plan and status, a record of tool activity with tool names and short summaries of arguments and results, the final answer and drafts, the names of files created, the model used, token counts, and cost estimates. Screenshots taken by the browser tool during a Job are stored in our cloud storage.
  • Projects and collaboration. Project names, who owns and belongs to each Project (name and email), which Huddles each person can see, and invitations, which include the invited person's email address and the inviter's email address.
  • Your profile. First name, "about me", your persona, document style, and saved AI teams, so they follow you between devices. The profile is visible to people you share a Project or Huddle with.
  • Devices and remote control. Each signed-in device's identifier, name, platform, app version, list of available Projects, and last-seen time, plus the commands you send from one device to another (for example "start this Job on my desktop"). Commands expire within two minutes.
  • Settings. Model preferences and routing choices, favourite commands, and tool-routing choices.
  • Account and billing. Email, account status, subscription status and history from Creem, and per-day token usage for pilot-managed access.
  • Usage records and support requests as described in Sections 1.4 and 2.2.
  • Push notifications. On mobile, a push token for your device. Notification messages sent through Apple and Google contain the sender's name, the Huddle name, and the first 100 characters of the message.
  • Operator audit record. A record of account-security events: account deletion requests, multi-factor enrolment changes, administrator role changes, and service configuration changes. Each entry holds the event type, the account identifier (and, for administrator actions, the administrator's and affected account's email), the outcome, and a timestamp. It is kept for the life of the account.

Who can see what. People in a Huddle with you see your name, your email address, and everything posted in that Huddle. Members of a Project can see the Project's member list. Access to a Huddle's content is limited to its members; being invited to one Huddle does not give access to others in the same Project. Our staff can access cloud data when needed to provide support, keep the service secure, or meet a legal obligation; see Section 7.

Google services used. Firebase Authentication, Cloud Firestore, Cloud Storage, Realtime Database, Cloud Messaging (push notifications), and Firebase Installations. We do not use Firebase Analytics or Crashlytics. Google processes data as our processor under its terms: https://firebase.google.com/support/privacy

6. Legal Basis for Processing (GDPR and UK GDPR)

If you are in the European Economic Area (EEA), the United Kingdom, or another place that requires a legal basis for processing personal data, this is the basis we rely on:

Purpose Legal Basis
Account creation, sign-in, and multi-factor authentication Performance of a contract
Syncing conversations, Jobs, Projects, profile, and settings across your devices and collaborators Performance of a contract
Sending your content to the AI providers and tools you choose Performance of a contract
Device registration, presence, and remote control between your devices Performance of a contract
Push notifications Performance of a contract
Payment processing and account validation Performance of a contract
Storing invitation details about people you invite Legitimate interest (carrying out the invitation you asked for)
Usage records (active time, model usage) Legitimate interest (operating and planning the pilot); you may object
Crash and error reports Legitimate interest (fixing defects); reports are scrubbed of personal data before sending
Update checks, rate limiting, server logs, operator audit record Legitimate interest (security, abuse prevention, keeping the software current)
Responding to support requests Performance of a contract / Legitimate interest
Contacting you about early access from the Website form Consent (you can withdraw it by telling us)
Sending service notices (security, changes to terms) Performance of a contract / Legal obligation
Complying with legal obligations Legal obligation

Where we rely on legitimate interest, you can object at any time (see Section 11). Where we rely on consent, you can withdraw it at any time. Targeted Coaching International, Ltd. is also subject to the Cayman Islands Data Protection Act.

7. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Prismr application
  • Keep conversations, Jobs, Projects, and settings in sync across your devices and with your collaborators
  • Send your content to the AI providers and tools you choose, and take the actions you ask for
  • Verify your identity, manage your account, and validate your subscription
  • Send notifications you have turned on
  • Apply fair-use limits on pilot-managed access
  • Send you important service updates (such as security notices or changes to these terms)
  • Respond to your support requests
  • Investigate abuse, security incidents, and violations of our Terms of Service

Staff access. We do not routinely read your conversations or files, and we run no automated content scanning. Authorised staff can access cloud data, including searching messages, when needed to answer a support request you made, to investigate a security incident or abuse report, or to meet a legal obligation. Such access is limited to what the task requires and is logged.

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not use your data for advertising of any kind, and we do not use your content to train AI models.

8. How We Share Your Information

We do not sell, rent, or trade your personal information. We share it only in these ways:

  • With your collaborators, as described in Section 5.
  • With the AI providers and tools you choose, as described in Section 3. These act on your instructions under their own terms.
  • With service providers that help us run Prismr. They receive only what their service needs and are bound to protect it. They are: Google (Firebase and Google Cloud hosting, Cloud Messaging), Cloudflare (Website hosting and our account licensing service), Sentry (crash and error reports, EU region), Resend (sending invitation, sign-in, and security emails), GitHub (software update distribution), Web3Forms (Website early-access form), Apple (Sign in with Apple, push notifications on iOS), Creem.io (payments), and OpenRouter (pilot-managed AI access).
  • When required by law, or when we believe in good faith that disclosure is necessary to comply with legal process, protect our rights, or ensure the safety of our users.
  • In a business transfer. If Prismr is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

9. Data Security

We take reasonable measures to protect your information, including:

  • Storing API keys and tokens in platform-native secure storage (iOS Keychain, Android Keystore, Electron secure storage)
  • Using HTTPS for all communication between the App, the Website, and our servers
  • Offering multi-factor authentication and platform sign-in (Sign in with Apple, Sign in with Google)
  • Requiring a fresh sign-in before sensitive account actions such as deleting your account
  • Database security rules that restrict each record to its owner and the collaborators it is shared with
  • Encryption at rest for all data held by Google Cloud
  • PKCE and state validation for all OAuth flows with cloud storage providers
  • Confining the AI's file access to the Project you are working in, and running code the AI writes in a sandbox

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

10. Data Retention and Deletion

  • Account data is kept while your account is active.
  • Deleting your account. You can delete your account from Settings in the App (a fresh sign-in is required), or by emailing [email protected]. In-app deletion runs immediately; email requests are completed within 30 days of verification. Deletion removes your sign-in, your profile, your conversations, Jobs, devices, settings, usage records, push tokens, and files you uploaded.
  • What remains after deletion. Messages you posted in Huddles and direct messages with other people stay visible to those people, with your name and email replaced by "Deleted user". Support requests you sent are kept with your identity removed. Billing records are kept as long as accounting and tax rules require.
  • Conversations and Jobs are kept until you delete them or delete your account. Deleting a conversation removes its messages from our cloud. Job records in our cloud are deleted 12 months after the Job ends; the full transcript stays in your project folder under your control.
  • Invitations stop working after 7 days and are deleted when they expire, or sooner if the inviter cancels them.
  • Usage records are kept for 90 days. Crash reports are kept by Sentry for 90 days. Server request logs are kept for up to 30 days. The operator audit record is kept for the life of the account.
  • Data on your device stays until you delete it. See Section 4 for what uninstalling does and does not remove.

11. Your Rights

Depending on where you live, you may have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate information.
  • Deletion: Request that we delete your personal information.
  • Portability: Request a copy of your data in a portable format.
  • Restriction: Request that we restrict processing of your personal information.
  • Objection: Object to processing based on legitimate interests, including usage records.

To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within 30 days.

Privacy contact: Questions or concerns about your personal data can be sent to [email protected]. If we are required to appoint a representative in the EEA or the United Kingdom, we will publish the representative's details here.

Right to lodge a complaint: If you are located in the EEA or the United Kingdom, you have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed unlawfully.

12. California Privacy Notice

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you specific rights regarding your personal information.

Categories of personal information we collect: identifiers (name, email address, account identifiers, device identifier, IP address); commercial information (subscription status and billing history); user content (conversations, Jobs, files you attach, profile text); internet or electronic network activity (usage records, server logs, crash reports); and audio, where you use dictation on iOS (processed by Apple's speech service on your device or Apple's servers; we do not receive the audio). We do not collect precise geolocation. We do not sell your personal information and we do not share it for cross-context behavioural advertising.

Your California rights include the right to know what personal information we collect, use, and disclose; the right to request deletion; the right to correct inaccurate information; the right to opt out of sale or sharing (we do neither); and the right not to be discriminated against for exercising these rights. To exercise them, contact [email protected].

13. International Data Transfers

Prismr is operated by Targeted Coaching International, Ltd., registered in the Cayman Islands. Our database and file storage are hosted by Google Cloud in the United States (Firestore in us-central1; our application servers in us-east1). Crash reports are stored by Sentry in the European Union. Our other service providers (Section 8) operate from the United States or globally. AI providers you choose process your content in their own locations, which may include China.

For users in the EEA and the United Kingdom, transfers to our service providers outside those regions are covered by the European Commission's Standard Contractual Clauses (and the UK Addendum) and, where the provider is certified, the EU-U.S. Data Privacy Framework. You can ask us for details of the safeguards in place by contacting [email protected]. Transfers to an AI provider you connect with your own key or account are made on your instruction, under your own agreement with that provider.

14. Children's Privacy

Prismr is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from anyone under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] and we will take steps to delete that information.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will publish the new version on our website with a new "Last Updated" date. If we make material changes, we will also email the address on your account before the changes take effect.

16. Contact Us

If you have any questions about this Privacy Policy, contact us at:

Targeted Coaching International, Ltd.
PO Box 30080
Seven Mile Beach, Grand Cayman
Cayman Islands KY1-1201

Email: [email protected] | Website: https://www.prismr.ai