Privacy Policy
Last updated: April 22, 2025
Introduction
Welcome to the privacy policy of Prism AI and Prism Replay (by Prism Technologies Inc.). This policy applies to all our products and services, including our website (www.prismreplay.com), our applications, and our Google OAuth application (Project ID: orbital-amulet-457322-b5). This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.
Owner and Data Controller
Prism Technologies Inc. - 2261 Market Street STE 86585, San Francisco, CA, 94114
Owner contact email: founders@prismai.sh
Types of Data collected
Among the types of Personal Data that Prism AI and Prism Replay collects, by itself or through third parties, there are:
Email address
Usage Data
Trackers
Number of Users
Session statistics
Device information
First name
Last name
Google account information (when using our Google OAuth application, Project ID: orbital-amulet-457322-b5)
Authentication data
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection. Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using Prism AI or Prism Replay. Unless specified otherwise, all Data requested by Prism AI and Prism Replay is mandatory and failure to provide this Data may make it impossible for us to provide our services.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner. Any use of Cookies – or of other tracking tools — by Prism AI, Prism Replay or by the owners of third-party services used by our applications serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.
Mode and place of processing the Data
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of Prism AI and Prism Replay (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located. Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
The purposes of processing
The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:
Contacting the User
Analytics
Heat mapping and session recording
Tag management
Displaying content from external platforms
Handling payments
Hosting and backend infrastructure
Detailed information on the processing of Personal Data
Google OAuth Application
Our Google OAuth application (Project ID: orbital-amulet-457322-b5) collects and processes user data in accordance with Google's API Services User Data Policy. When you authenticate with our application using your Google account, we may access and store certain information from your Google account to provide our services.
We only request access to the data that is necessary for the functionality of our application. This data is not sold to third parties and is only used for the purposes stated in this privacy policy.
You can revoke our application's access to your Google account at any time through your Google account settings.
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics 4
Company: Google LLC
Place of processing: United States
Personal Data processed: number of Users and related data
Contacting the User
Contact form
Personal Data processed: email address and other contact information
Mailing list or newsletter
Personal Data processed: email address and user information
Displaying content from external platforms
This type of service allows you to view content hosted on external platforms directly from the pages of Prism Replay and interact with them. This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Google Maps widget
Company: Google LLC
Place of processing: United States
Personal Data processed: Trackers and usage data
Google Fonts
Company: Google LLC
Place of processing: United States
Personal Data processed: Trackers and usage data
Handling payments
Unless otherwise specified, Prism Replay processes any payments by credit card, bank transfer or other means via external payment service providers. In general and unless where otherwise stated, Users are requested to provide their payment details and personal information directly to such payment service providers. Prism Replay isn't involved in the collection and processing of such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.
Stripe
Company: Stripe, Inc.
Place of processing: United States
Personal Data processed: email address and payment information
Heat mapping and session recording
Heat mapping services are used to display the areas of Prism Replay that Users interact with most frequently. This shows where the points of interest are. These services make it possible to monitor and analyze web traffic and keep track of User behavior. Some of these services may record sessions and make them available for later visual playback.
PostHog session replay
Company: PostHog, Inc.
Place of processing: United States
Personal Data processed: device information and session data
Hosting and backend infrastructure
This type of service has the purpose of hosting Data and files that enable Prism Replay to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of Prism Replay.
Vercel
Company: Vercel Inc.
Place of processing: United States
Personal Data processed: Usage Data and system information
Tag management
This type of service helps the Owner to manage the tags or scripts needed on Prism Replay in a centralized fashion. This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.
Google Tag Manager
Company: Google LLC
Place of processing: United States
Personal Data processed: Trackers and usage data
Cookie Policy
Prism AI, Prism Replay, and our Google OAuth application (Project ID: orbital-amulet-457322-b5) use Trackers. To learn more, Users may consult the Cookie Policy.
Further Information for Users in the European Union
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
Users have given their consent for one or more specific purposes.
Provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
Processing is necessary for compliance with a legal obligation to which the Owner is subject;
Processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
Processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
The rights of Users based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to do the following, to the extent permitted by law:
Withdraw their consent at any time.
Object to processing of their Data.
Access their Data.
Verify and seek rectification.
Restrict the processing of their Data.
Have their Personal Data deleted or otherwise removed.
Receive their Data and have it transferred to another controller.
Lodge a complaint.
How to exercise these rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users' request, the Owner will inform them about those recipients.
Further information for Users in the United States
This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running Prism Replay and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as "we", "us", "our").
The information contained in this section applies to all Users who are residents in the United States.
Your privacy rights under US state laws
You may exercise certain rights regarding your Personal Information. In particular, to the extent permitted by applicable law, you have:
The right to access Personal Information: the right to know.
The right to correct inaccurate Personal Information.
The right to request the deletion of your Personal Information.
The right to obtain a copy of your Personal Information.
The right to opt out from the Sale of your Personal Information.
The right to non-discrimination.
How to exercise your privacy rights under US state laws
To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.
For us to respond to your request, we must know who you are. We will not respond to any request if we are unable to verify your identity and therefore confirm the Personal Information in our possession relates to you. You are not required to create an account with us to submit your request.
Additional information about Data collection and processing
Legal action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), or related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
System logs and maintenance
For operation and maintenance purposes, Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), and any third-party services may collect files that record interaction with our services (System logs) or use other Personal Data (such as the IP Address) for this purpose.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.
Definitions and legal references
Personal Data (or Data) / Personal Information (or Information)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Sensitive Personal Information
Sensitive Personal Information means any Personal Information that is not publicly available and reveals information considered sensitive according to the applicable privacy law.
Usage Data
Information collected automatically through Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), or third-party services employed in our applications, which can include: the IP addresses or domain names of the computers utilized by the Users who use our services, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer, the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit, and other parameters about the device operating system and/or the User's IT environment.
User
The individual using Prism AI, Prism Replay, or our Google OAuth application (Project ID: orbital-amulet-457322-b5) who, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor (or Processor)
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller (or Owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of Prism AI, Prism Replay, and our Google OAuth application (Project ID: orbital-amulet-457322-b5). The Data Controller, unless otherwise specified, is the Owner of Prism AI and Prism Replay services.
How can we help?
What you can do
Your data
Ask us to know and access the information we hold on you
Ask us to correct information we hold on you
Ask us to be forgotten (delete the information we hold on you)
Ask to port your data to another service
In case of issues
While we strive to create a positive user experience, we understand that issues may occasionally arise between us and our users. If this is the case, please feel free to contact us at founders@prismai.sh.