Prizm
How it worksPricingStart free

Legal

Privacy policy

Effective 5 August 2026

We do not sell your data, and we never share it for anyone else’s marketing or advertising. We do not build advertising profiles, we do not trade contact lists, and we do not let third parties mine your content. The only companies that touch your data are the ones listed below that we need in order to run the service for you.

What we collect

Your account

Your name, email address, and timezone. Your password is stored only as a one-way hash — we cannot read it, and neither can anyone who obtained a copy of our database. If you turn on two-factor authentication, we store the secret needed to verify your codes and one-way hashes of your recovery codes.

Your content

The posts, captions, calendars, templates, and brand details you create or upload. This is yours. We use it to operate the service for you and for nothing else.

Connected social accounts

When you connect a social account we store the access token that platform issues us, encrypted at rest. We use it only to publish the posts you approve and to read the account’s name and profile picture so you can tell your accounts apart. We do not read your messages, your followers, or anything else the platform would let us.

Payments

If you subscribe, a payment processor handles the payment. Card numbers are entered on their systems and never reach ours. We store only your plan, its status, and the identifiers they give us so we can tell which subscription is yours.

Technical records

Server logs, and the IP address a message or sign-up came from. We keep these to diagnose faults and to stop abuse of the contact form and login. They are not used to track you across the web, and we do not use advertising or analytics cookies.

In your browser we store two things, both only on the device you are using: the token that keeps you signed in, and a note that you have seen our privacy notice. Clearing your browser data removes both.

Who else sees it

To run the service we use a small number of providers. They process data on our instructions and are not permitted to use it for their own purposes.

ProviderWhyWhat they see
Cloud infrastructure providerHosting and database storageEverything stored by the service
Content generation providerProducing draft captions, calendars, and templatesThe brief you provide and your brand details — never your credentials or connected-account tokens
Payment processorSubscription paymentsBilling details, which you enter on their systems directly. Card numbers never reach our servers.
Image storage providerHolding the photographs you upload to your libraryThe images you choose to upload, in a folder of your own
Email delivery providerTransactional email (password resets, replies to your messages)Your name and email address
The social platforms you connectPublishing the posts you scheduleOnly the posts you approve, sent to the accounts you connect

We describe these providers by category rather than by name. Publishing the list of vendors a service depends on mainly helps people trying to attack it, and it tells you nothing useful about how your data is handled — which is what the table above is for. If you need the specific providers — for a vendor review, a data protection impact assessment, or your own compliance records — email us and we will send you the current list.

Beyond these, we disclose data only where the law requires it — for example a valid court order — or where it is necessary to investigate abuse or protect someone’s safety.

Leads you collect

If you use lead capture, people who respond to your posts give you their details through a form, and we store them for you. This is the one kind of data here that belongs to someone who is not our customer, so it works differently from everything above.

You decide what that data is for; we only hold it on your instructions. In data protection terms you are the controller and we are your processor. That means:

  • we never contact your leads, market to them, or use their details for anything of our own;
  • we never combine or compare leads across different businesses;
  • you can export them at any time, and delete any of them permanently;
  • if one of your leads asks you to erase them, you can do it yourself and it is genuinely gone.

We store the wording of the consent shown on your form at the moment someone submitted it, because you may later need to show on what basis you were entitled to contact them. Making sure that wording is accurate, and that you have a lawful reason to hold the data, is your responsibility — see the terms.

Link clicks

When someone clicks a trackable link in one of your posts, we record that a click happened, which post it came from, and roughly where it came from. We do not set a cookie, we do not store the visitor’s IP address, and we do not build a profile of them. To tell twelve visitors apart from one visitor clicking twelve times we keep a one-way fingerprint that is re-salted every day, so it cannot be used to follow anyone from one day to the next.

Content generation

When you ask Prizm to draft a calendar, a caption, or a template, the brief you write and your brand details are sent to a content generation provider to produce that draft. Your password, your connected-account tokens, and your payment details are never included. Drafts are yours to edit, keep, or discard, and nothing is published anywhere until you approve it.

How long we keep it

Your content stays for as long as your account exists. Delete your account and we delete your content, your brand kit, and your connected-account tokens. Some records are kept longer where we have to: billing history for accounting, and abuse-related logs for a limited period. Password reset links expire within minutes, and unused ones are removed automatically.

Your choices

  • See your data. Ask us and we will send you a copy of what we hold.
  • Correct it. Most of it is editable in the app; ask us about the rest.
  • Delete it. Ask us to close your account and we will remove your data.
  • Disconnect a platform. Do this at any time from Accounts. We drop the stored tokens immediately, and you can also revoke access from the platform’s own settings.

Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA — including the right to object to processing, to export your data, and to complain to a regulator. Write to us and we will help.

Security

Passwords are hashed with a per-user salt. Connected-account tokens are encrypted at rest. Traffic to the service is encrypted in transit, as is traffic between the service and its database. No system is perfect, and we will tell affected users promptly if something goes wrong.

Children

Prizm is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.

Contact

Questions, requests, or complaints: prizm@buzzzillion.com, or use the contact form at the bottom of any page.

Prizm

A content engine for businesses that need to stay visible without hiring a marketing team.

Questions, or something not working?

© 2026 Buzzzillion. All rights reserved.

How it worksPricingPrivacyTerms