Privacy
Privacy Policy
Read how PRISM handles account data, lesson content, browser storage, integrations, and third-party classroom media services.
Last updated: September 12, 2026
This Privacy Policy explains how PRISM handles information in the current version of the service. It is written for the actual architecture currently used by PRISM and may be updated as the product changes.
Information PRISM handles
When you use PRISM with an account, PRISM may process account information such as your email address, authentication session information, saved lessons, class names, student names entered by you, rewards data, seating layouts, theme preferences, and other workspace content you choose to create or save. PRISM also handles subscription status and identifiers needed to associate your account with a paid plan.
PRISM also uses limited browser storage for device and interface preferences, such as navigation layout, visualizer preferences, timer sound choice, and temporary canvas clipboard data. A temporary session storage key may be used during an email change flow.
Previous interest-list submissions
If you previously joined PRISM’s interest list, PRISM stores your email address to manage that request and contact you about availability. PRISM may also store limited referral, source, or campaign information supplied with the request.
A separate optional checkbox allows you to receive occasional PRISM development updates and feature previews. You could join the interest list without choosing those additional updates, and you may withdraw that optional consent at any time by contacting support@prismclassroom.com.
Supabase stores interest-list records and Resend delivers related email. This information is retained until you create an account, withdraw, ask for deletion, or the information is no longer needed. PRISM does not sell these email addresses to third parties for advertising.
Core service providers
Supabase provides account authentication, database storage, and file storage. It may process account details, authentication data, lessons, boards, classes and student names, rewards, seating layouts, settings, uploaded assets, and subscription metadata so PRISM can save and restore your workspace.
Vercel hosts PRISM and runs its server-side routes. Vercel may process ordinary request information such as IP addresses, request headers, timestamps, and diagnostic logs. PRISM also uses public content-delivery networks and Google Fonts for interface assets; those providers receive ordinary browser request information when their assets load.
If you continue with Google, Google handles the authentication interaction and PRISM receives the account and profile information Google authorises for sign-in. PRISM does not receive your Google password.
Resend delivers certain transactional or service email, including previous interest-list confirmations. It processes the recipient address, message content, and delivery metadata needed to send those messages. Cloudflare Turnstile provides bot and abuse protection where it appears, currently including the previous interest-list form, and may process a verification token plus browser, device, network, and request information.
Payments and subscriptions
Creem is the merchant of record for paid subscriptions. At Creem checkout, Creem collects and processes the buyer name, email address, billing and payment details, tax information, and order information needed to complete the purchase, issue invoices or receipts, and handle applicable taxes. PRISM receives and stores the identifiers, product, billing interval, status, dates, and transaction or subscription information needed to associate and manage your plan. PRISM does not store your full payment-card number. Creem may retain transaction records under its own legal and operational obligations.
Media, embeds, and third-party content
For a Pexels image search, PRISM sends the search query and pagination details from its server to Pexels. For a KLIPY media search, PRISM sends the search query, pagination, locale, and content-filter details from its server to KLIPY. PRISM does not intentionally include account or student information in either search request. Search results use provider-hosted image or media URLs, so Pexels or KLIPY may receive ordinary browser and request information when previews or media load. Do not put personal or student information in media-search queries.
PRISM includes integrations, embeds, or links for services such as YouTube, Google Slides/Docs, Canva, and Substack. If you load, interact with, or follow third-party content, its provider may receive browser and request information under its own privacy practices.
Student avatars use open-source DiceBear software bundled into PRISM. Avatar images are generated locally in the app; PRISM does not send the avatar seed to a DiceBear-hosted service.
Email sent to support@prismclassroom.com is processed by the sender's email provider and PRISM's configured email routing or mailbox provider.
Optional analytics and marketing measurement
With your analytics consent, PRISM uses the EU-hosted PostHog product analytics service to understand a limited set of product actions. PostHog may use an anonymous first-party browser identifier, but PRISM does not identify your account in PostHog. PRISM does not send names, email addresses, Supabase or Creem identifiers, lesson or Board content, class names, or student information to PostHog.
With your separate marketing consent, public pages may load Meta Pixel for advertising measurement. Meta may receive browser and device information under its own privacy practices. Optional analytics and marketing services stay off unless you enable them. You can reopen Cookie settings in the footer to change or withdraw consent at any time.
These providers may process limited technical information internationally under their own safeguards. PRISM retains analytics information only for as long as reasonably needed to understand product use and operate the service.
Lesson and classroom content
You control the lesson and classroom content you enter into PRISM. Because PRISM is an online workspace, that content may be stored and processed by PRISM's service providers so the app can save, restore, display, and export your work.
Retention and deletion
PRISM keeps account, workspace, and subscription information while your account is active and for as long afterward as reasonably needed to operate the service, resolve disputes, prevent abuse, meet legal obligations, and maintain appropriate records. Different records may have different retention periods, and backups or provider logs may persist for a limited time after deletion.
You can request account and workspace deletion through PRISM’s account controls or by contacting support. Account deletion does not by itself cancel a paid subscription; cancel the subscription separately before deleting the account. Providers such as Creem may retain payment, invoice, tax, or transaction records when legally or operationally required.
Questions and requests
For privacy questions, account questions, or requests related to your PRISM data, contact support@prismclassroom.com.