Privacy policy
Last updated: July 2, 2026
This privacy policy explains what information Prism collects, how it is used, and the choices you have. Prism is a data standardization platform that connects to data sources you designate — your Snowflake data warehouse and Google Sheets — and helps you map inconsistent text values to canonical names. It applies alongside our terms of service.
1. Data we collect
- Account information — your name, email address, and profile picture from Google sign-in, plus your workspace role and invitation history.
- Connection credentials — Snowflake credentials (password or private key) and Google OAuth tokens (including refresh tokens for connected Sheets pipelines) that you provide to connect your data sources.
- Customer data values — the distinct text values from the columns and sheets you choose to standardize, and the confirmed mappings between raw values and canonical names.
- Operational data — run history, pipeline configuration, review decisions, and audit logs generated by your use of the Service.
2. How we use it
- To authenticate you and manage workspace access and invitations;
- To connect to and read from the data sources you configure;
- To propose groupings and canonical names for your data values, including by sending those values to our language model provider for classification;
- To store confirmed mappings and write standardized output where you direct it;
- To operate, secure, troubleshoot, and improve the Service.
We do not sell your data, and we do not use your Customer Data to build products for other customers.
3. Subprocessors
- Snowflake — mappings, run state, and pipeline configuration are stored in your connected Snowflake account, under your agreement with Snowflake.
- AI provider (Anthropic by default; OpenAI or Google if your workspace configures one) — distinct data values (never your credentials) are sent to the configured provider’s API to propose groupings and canonical names.
- Google — used for sign-in and, when you connect them, for reading and writing the Google Sheets you authorize.
4. Retention
Confirmed mappings, run history, and pipeline configuration are retained for as long as your workspace remains active, since accumulated mappings are the core value of the Service. Stored credentials are retained until you replace or remove them, or until the associated connection is deleted. Account information is retained while your account exists and is removed when a user is removed from the workspace, except where retention is required for audit or legal purposes.
5. Security measures
- Stored credentials — Snowflake passwords, private keys, and Google refresh tokens — are encrypted at rest at the application level using AES-256-GCM, in addition to the storage-layer encryption provided by the underlying platform.
- All data in transit is protected with TLS.
- Sessions use signed, HTTP-only cookies; removing a user invalidates their active sessions immediately.
- Access to workspace data requires a valid invitation from a workspace administrator.
No method of transmission or storage is completely secure, but we work to protect your information using industry-standard practices.
6. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain processing. Workspace administrators can remove users and delete pipelines and connections directly in the Service. For other requests, contact us using the details below and we will respond within a reasonable timeframe.
7. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the “last updated” date above and, where appropriate, notified within the Service.
8. Contact
Questions about this policy or your data can be sent to privacy@prism.example.com.