Privacy Policy

Last updated: October 2026

Overview

Prism is a social media analytics app. This policy covers the Prism web application. We collect only what is needed to provide the service, and we never sell your data to third parties.

Prism is open-source and self-hostable. If you run your own instance, this policy applies only to instances we operate. You are responsible for the data handling of your own server.

Your Account

When you create an account and use Prism, we store:

  • Your name, email address and a hashed version of your password
  • The workspaces you create or are invited to, and your role in each
  • The analyses you run and the report schedules you set up

Passwords are hashed with a strong one-way algorithm and are never stored or transmitted in plain text.

Connected Accounts

When you connect a social media, analytics or mailing account (Facebook, Instagram, Twitter / X, LinkedIn, TikTok, Google Analytics, Mailchimp, Klaviyo or Brevo), you authorize Prism through that platform's own consent screen, or with an API key you provide. Prism then stores:

  • The access and refresh tokens, or the API key, for that account, encrypted at rest and never returned by the API
  • The account's public profile information, such as its name and handle
  • Daily account metrics, such as followers, reach, views and engagements
  • Your posts and email campaigns, with their metrics, such as likes, comments, opens and clicks

Prism only reads data. It never publishes, edits or deletes anything on your connected accounts, and it does not read private messages. Data obtained from a platform is used only to show you your own analytics and is handled according to that platform's terms for developers.

You can disconnect an account at any time from the Integrations page, which deletes its tokens and synced data from Prism and, where the platform allows it, revokes Prism's access there too. You can also revoke Prism's access from the platform's own settings.

AI Insights and Reports

When you generate an insight, a report or an analysis, the relevant metrics and post texts of your workspace are sent to an AI provider (OpenAI, Anthropic or Google, depending on the server configuration) to write it. On instances we operate, we use these providers under their standard API terms, which do not allow them to use submitted data to train their models.

Emails

We send email for password resets and for the scheduled reports you set up. Reports go only to the recipients a workspace owner or admin chooses.

Cookies and Tracking

The web application keeps your sign-in token in your browser's local storage. No advertising, analytics or third-party tracking cookies are used, on the app or on this site, and fonts are served from our own domain.

Data Retention and Deletion

Your data is kept for as long as your account exists. You can delete your account at any time from your settings, which permanently deletes your account and the data attached to it. A workspace's data is deleted with the workspace.

Contact

If you have questions about this policy or would like to request deletion of your data, you can reach us by opening an issue on the GitHub repository.