Legal
Privacy policy
We do not sell your data, and we never share it for anyone else’s marketing or advertising. We do not build advertising profiles, we do not trade contact lists, and we do not let third parties mine your content. The only companies that touch your data are the ones listed below that we need in order to run the service for you.
What we collect
Your account
Your name, email address, and timezone. Your password is stored only as a one-way hash — we cannot read it, and neither can anyone who obtained a copy of our database. If you turn on two-factor authentication, we store the secret needed to verify your codes and one-way hashes of your recovery codes.
Your content
The posts, captions, calendars, templates, and brand details you create or upload. This is yours. We use it to operate the service for you and for nothing else.
Connected social accounts
When you connect a social account we store the access token that platform issues us, encrypted at rest. We use it only to publish the posts you approve and to read the account’s name and profile picture so you can tell your accounts apart. We do not read your messages, your followers, or anything else the platform would let us.
Payments
If you subscribe, a payment processor handles the payment. Card numbers are entered on their systems and never reach ours. We store only your plan, its status, and the identifiers they give us so we can tell which subscription is yours.
Technical records
Server logs, and the IP address a message or sign-up came from. We keep these to diagnose faults and to stop abuse of the contact form and login. They are not used to track you across the web, and we do not use advertising or analytics cookies.
In your browser we store two things, both only on the device you are using: the token that keeps you signed in, and a note that you have seen our privacy notice. Clearing your browser data removes both.
Who else sees it
To run the service we use a small number of providers. They process data on our instructions and are not permitted to use it for their own purposes.
| Provider | Why | What they see |
|---|---|---|
| Cloud infrastructure provider | Hosting and database storage | Everything stored by the service |
| Content generation provider | Producing draft captions, calendars, and templates | The brief you provide and your brand details — never your credentials or connected-account tokens |
| Payment processor | Subscription payments | Billing details, which you enter on their systems directly. Card numbers never reach our servers. |
| Image storage provider | Holding the photographs you upload to your library | The images you choose to upload, in a folder of your own |
| Email delivery provider | Transactional email (password resets, replies to your messages) | Your name and email address |
| The social platforms you connect | Publishing the posts you schedule | Only the posts you approve, sent to the accounts you connect |
We describe these providers by category rather than by name. Publishing the list of vendors a service depends on mainly helps people trying to attack it, and it tells you nothing useful about how your data is handled — which is what the table above is for. If you need the specific providers — for a vendor review, a data protection impact assessment, or your own compliance records — email us and we will send you the current list.
Beyond these, we disclose data only where the law requires it — for example a valid court order — or where it is necessary to investigate abuse or protect someone’s safety.
Leads you collect
If you use lead capture, people who respond to your posts give you their details through a form, and we store them for you. This is the one kind of data here that belongs to someone who is not our customer, so it works differently from everything above.
You decide what that data is for; we only hold it on your instructions. In data protection terms you are the controller and we are your processor. That means:
- we never contact your leads, market to them, or use their details for anything of our own;
- we never combine or compare leads across different businesses;
- you can export them at any time, and delete any of them permanently;
- if one of your leads asks you to erase them, you can do it yourself and it is genuinely gone.
We store the wording of the consent shown on your form at the moment someone submitted it, because you may later need to show on what basis you were entitled to contact them. Making sure that wording is accurate, and that you have a lawful reason to hold the data, is your responsibility — see the terms.
Link clicks
When someone clicks a trackable link in one of your posts, we record that a click happened, which post it came from, and roughly where it came from. We do not set a cookie, we do not store the visitor’s IP address, and we do not build a profile of them. To tell twelve visitors apart from one visitor clicking twelve times we keep a one-way fingerprint that is re-salted every day, so it cannot be used to follow anyone from one day to the next.
Content generation
When you ask Prizm to draft a calendar, a caption, or a template, the brief you write and your brand details are sent to a content generation provider to produce that draft. Your password, your connected-account tokens, and your payment details are never included. Drafts are yours to edit, keep, or discard, and nothing is published anywhere until you approve it.
How long we keep it
Your content stays for as long as your account exists. Delete your account and we delete your content, your brand kit, and your connected-account tokens. Some records are kept longer where we have to: billing history for accounting, and abuse-related logs for a limited period. Password reset links expire within minutes, and unused ones are removed automatically.
Your choices
- See your data. Ask us and we will send you a copy of what we hold.
- Correct it. Most of it is editable in the app; ask us about the rest.
- Delete it. Ask us to close your account and we will remove your data.
- Disconnect a platform. Do this at any time from Accounts. We drop the stored tokens immediately, and you can also revoke access from the platform’s own settings.
Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA — including the right to object to processing, to export your data, and to complain to a regulator. Write to us and we will help.
Security
Passwords are hashed with a per-user salt. Connected-account tokens are encrypted at rest. Traffic to the service is encrypted in transit, as is traffic between the service and its database. No system is perfect, and we will tell affected users promptly if something goes wrong.
Children
Prizm is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.
Contact
Questions, requests, or complaints: prizm@buzzzillion.com, or use the contact form at the bottom of any page.
