Legal / mobile privacy
Your workspace.
Your control.
This notice explains how the Prism Android application handles information when you pair it with a Prism community.
Who is responsible
Prism Labs provides the mobile application and operates the notification gateway described below. The organization operating or selecting your Prism community controls the workspace relay, media service, its members, and its retention rules. Contact your organization for workspace-data requests. Contact [email protected] about the app or Prism notification gateway.
Information the app handles
Paired workspace identity
When you pair Prism, the app stores the community address and cryptographic credentials needed to act as that paired identity. Credentials are kept in the device's secure storage. The app sends the corresponding public identity and signed requests to the community you selected.
Workspace content
The app sends and receives the content needed for features you use, including profile information, channels, direct messages, replies, reactions, presence, activity, and Vault history. This content is processed by the selected community relay, not by a general Prism-hosted AI service.
Photos, videos, and files
Prism accesses only media you choose through Android's picker or camera flow. Selected attachments are uploaded to the media service associated with your community. Prism does not request microphone permission. Files you explicitly save or share outside Prism are then controlled by the destination you choose.
Notifications and device integrity
If you enable notifications, Google Firebase processes a messaging token. The Prism notification gateway processes that token, a pseudonymous installation handle, a device public key, delegation details for your selected relay, and Play Integrity evidence used to protect enrollment. Notification alerts use generic text; the wake payload does not contain message content.
Local app data
Prism stores preferences, recent searches, unsent drafts, cached content, and push-registration state on the device so the app can work. We do not include advertising SDKs or third-party analytics in the audited Android release.
Purposes and disclosures
- Operate the paired workspace features you choose.
- Authenticate signed requests and protect workspace access.
- Upload and retrieve attachments at your direction.
- Deliver optional notifications and prevent fraudulent push enrollment.
- Troubleshoot, secure, and comply with legal obligations.
Information is disclosed to the customer-selected relay and media service as necessary to provide workspace features, and to Google Firebase and Google Play Integrity when optional Android notifications are configured. We do not sell personal information or share it for targeted advertising.
Retention and deletion
In Settings, Erase local data removes paired community credentials, local drafts, preferences, caches, Android push authority, and the stored Firebase token from that device. Prism also attempts to revoke the remote push installation; if the device is offline, it expires automatically.
Local erasure does not delete messages, files, or other workspace records already retained by a community relay. The organization controlling that relay determines its retention and deletion process. The mobile app does not create an independent Prism account.
Security and transfers
Prism requires encrypted network transport for production community connections and uses signed workspace events. Information may be processed where the selected organization and its providers operate. No system can guarantee absolute security.
Children and changes
Prism is intended for professional and organizational use and is not directed to children under 13. An organization must configure access consistently with its obligations. Material changes to this notice will be posted here with a new effective date.
Mobile privacy questions
[email protected] ↗