1. Introduction
This Privacy Policy explains how PRISM Academic, Inc. ("PRISM," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website, mobile application, and services (collectively, the "Service").
By using PRISM, you agree to the practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide Directly
Account Registration:
- Full name
- Email address
- Password (encrypted)
- Educational institution name
- Academic level
Content You Create:
- Notes and study guides
- Custom tags and organization
- Saved research queries
- Calendar events and study plans
2.2 Information from Third-Party Services
When you connect PRISM to external services, we collect:
Learning Management Systems (Canvas, D2L, Google Classroom):
- Course names and codes
- Assignment titles, descriptions, instructions
- Due dates and point values
- Rubrics and grading criteria
We do NOT collect: Your grades, other students' information, private messages
2.3 Information Collected Automatically
- Usage data (features used, time spent)
- Device information (IP address, browser type, OS)
- Cookies (session, preferences, analytics)
- Error logs and performance metrics
3. How We Use Your Information
3.1 To Provide Core Services
- Fetch and organize assignments from your LMS
- Analyze assignment requirements
- Generate study materials tailored to your courses
- Create study schedules around your deadlines
- Send notifications and reminders
3.2 To Improve PRISM
- Fix bugs and optimize performance
- Develop new features based on usage
- Train AI models on aggregated, anonymized data
- Understand which features are most valuable
3.3 To Ensure Safety
- Detect patterns of misuse or cheating
- Prevent fraud and unauthorized access
- Comply with legal obligations
4. How We Share Your Information
4.1 Service Providers
We share data with third parties who help us provide PRISM:
- AI Providers (OpenAI, Anthropic, Google): Generate notes and analyze content
- Cloud Infrastructure (Supabase, Vercel, AWS): Store data and run our application
- Payment Processing (Stripe): Handle subscriptions and billing
- Analytics (PostHog, Sentry): Understand usage and fix bugs
4.2 What We Do NOT Do
We will NEVER:
- Sell your personal information to third parties
- Share your educational records with advertisers
- Use your assignments to train public AI models without consent
- Disclose your usage to your school without your permission
5. Data Retention
- Active Account: We retain your data for as long as your account is active
- Deleted Account: Your data is removed within 7-30 days after deletion
- Backups: May contain your data for up to 90 days after deletion
6. Your Privacy Rights
- Access & Portability: Request a copy of all data we have about you
- Correction: Update your profile information anytime
- Deletion: Delete your account and all associated data
- Objection: Opt out of marketing emails
Contact for Privacy Requests: privacy@prismacademic.com
7. FERPA Compliance
PRISM complies with the Family Educational Rights and Privacy Act (FERPA). We will not disclose your educational records to third parties without your consent, except as required by law.
8. International Users
PRISM's servers are located in the United States. By using PRISM, you consent to transfer of your data to the US.
GDPR Compliance (EU Users): You have additional rights under GDPR including access, erasure, and portability.
CCPA Compliance (California Users): You have the right to know what data we collect and request deletion.
9. Children's Privacy (COPPA)
- PRISM is designed for users 13 years and older
- We do not knowingly collect data from children under 13
- If you are under 18, you must have parental consent
10. Contact Information
PRISM Academic, Inc.
- Email: privacy@prismacademic.com
- Support: support@prismacademic.com
By using PRISM, you acknowledge that you have read and understood this Privacy Policy.