Privacy

Version 2026-08-27

Two kinds of data, two different roles

Your account. Your name, email, address, tax status and billing history. Prism is the data controller for these: it decides what they are for, and they exist so the platform can bill you and meet its own accounting obligations.

Your audience.The email addresses, purchases and download records of the people who buy from you. You are the controller for these; Prism only stores and processes them on your instructions. Prism will never repurpose them — it does not market to your audience, and it does not pool your audience with anyone else's.

Who else sees it

Prism runs on a small set of processors, each of which sees only what it needs: Neon (database), Cloudflare R2 (the files you upload), Resend (delivery and account email), Stripe (payments, which holds its own record of every transaction), Inngest (background jobs) and Vercel (hosting). No personal data is sold or shared for advertising.

Rights, and where to exercise them

If you bought something from a Prism store, the creator you bought from is your point of contact — they decide what happens to your data, and they have the tools in their dashboard to export or erase it. Write to them first. Prism will help them act on it.

If you are a Prism creator, your own account data is Prism's responsibility: you can export or delete your account from Settings.

One limit worth stating plainly: erasing a buyer removes their identity from the audience, from download records and from sales rows, but the sale itself is kept — amounts, currency, country and dates — because accounting records must be retained by law. Stripe also keeps its own copy of every payment, which has to be requested from Stripe separately.

Cookies

Prism sets a session cookie when you sign in, and nothing else. There is no advertising or cross-site tracking, so there is no consent banner to click through.

Related

The rules on what may be sold, and what happens when a product is taken down, are in the Terms of Service.