Your workspace.
Your control.

This notice explains how the Prism Android application handles information when you pair it with a Prism community.

Who is responsible

Prism Labs provides the mobile application and operates the notification gateway described below. The organization operating or selecting your Prism community controls the workspace relay, media service, its members, and its retention rules. Contact your organization for workspace-data requests. Contact [email protected] about the app or Prism notification gateway.

Information the app handles

Paired workspace identity

When you pair Prism, the app stores the community address and cryptographic credentials needed to act as that paired identity. Credentials are kept in the device's secure storage. The app sends the corresponding public identity and signed requests to the community you selected.

Workspace content

The app sends and receives the content needed for features you use, including profile information, channels, direct messages, replies, reactions, presence, activity, and Vault history. This content is processed by the selected community relay, not by a general Prism-hosted AI service.

Photos, videos, and files

Prism accesses only media you choose through Android's picker or camera flow. Selected attachments are uploaded to the media service associated with your community. Prism does not request microphone permission. Files you explicitly save or share outside Prism are then controlled by the destination you choose.

Notifications and device integrity

If you enable notifications, Google Firebase processes a messaging token. The Prism notification gateway processes that token, a pseudonymous installation handle, a device public key, delegation details for your selected relay, and Play Integrity evidence used to protect enrollment. Notification alerts use generic text; the wake payload does not contain message content.

Local app data

Prism stores preferences, recent searches, unsent drafts, cached content, and push-registration state on the device so the app can work. We do not include advertising SDKs or third-party analytics in the audited Android release.

Purposes and disclosures

Information is disclosed to the customer-selected relay and media service as necessary to provide workspace features, and to Google Firebase and Google Play Integrity when optional Android notifications are configured. We do not sell personal information or share it for targeted advertising.

Retention and deletion

In Settings, Erase local data removes paired community credentials, local drafts, preferences, caches, Android push authority, and the stored Firebase token from that device. Prism also attempts to revoke the remote push installation; if the device is offline, it expires automatically.

Local erasure does not delete messages, files, or other workspace records already retained by a community relay. The organization controlling that relay determines its retention and deletion process. The mobile app does not create an independent Prism account.

Security and transfers

Prism requires encrypted network transport for production community connections and uses signed workspace events. Information may be processed where the selected organization and its providers operate. No system can guarantee absolute security.

Children and changes

Prism is intended for professional and organizational use and is not directed to children under 13. An organization must configure access consistently with its obligations. Material changes to this notice will be posted here with a new effective date.