Who we are
srcprism is made by Apparition Dev LLC (“we”, “us”), which controls the personal data described here. Contact: support@srcprism.com.
What stays on your machine
Your sessions stay on your machine: the transcripts srcprism records, and everything the Prism shows. The command-line tool sends no analytics, telemetry or crash reports.
Anything that calls a model (readings, consult, recall --answer) uses your own model keys. Text goes straight from your machine to the provider you configured. We are not in that path. srcprism pr writes to your git remote through your gh.
The tool itself contacts us only for your licence and, if you turn them on, cloud backup and Team (all below). It contacts GitHub when you run srcprism update. Nothing readable from your sessions goes to either.
What we collect
- Your account. Your name, email address and profile image from GitHub or Google sign-in. Used to run your account.
- Your machines. When the tool checks your licence: a random install id, the hostname, operating system, processor type, srcprism version, the machine's public key, and whether it has captured anything yet (yes or no). Used to grant your plan and hold one trial per machine. API keys are stored only as hashes.
- Your subscription. Payment goes through Polar, our merchant of record; your card details never reach us. We keep your subscription status, seats and paid-through date.
- Cloud backup, if you turn it on. Your record is encrypted on your machine before upload, under a key that never leaves it. We store only the encrypted copy. We cannot read it, and cannot recover it if you lose your key.
- Team, if you use it. The team's name, members' public keys, and invited email addresses.
- This website and the dashboard. Cookieless visit counts (Vercel Web Analytics) and page-speed measurements (Vercel Speed Insights), neither of which identifies you. The dashboard reports only which kind of page was viewed: a PR viewer address goes without its repository name, and no page sends its query string.
- Email to us. Kept so we can answer it.
Where the GDPR or UK GDPR applies, we process this to perform our contract with you, and for security and site analytics on our legitimate interests.
Cookies and Do Not Track
We use no advertising, analytics or tracking cookies. What we do store in your browser is only what a page needs to work:
- This website sets no cookies. The film keeps your scroll position in the tab's session storage, so the Back button returns you to the same place. It never leaves your browser and is gone when you close the tab.
- The account dashboard sets the cookies that keep you signed in and protect sign-in against forgery.
- The PR viewer, if you sign in with GitHub to read a private repository, sets a cookie for ten minutes to check that GitHub's reply is to your sign-in. Your GitHub token then lives in that tab's session storage. Your browser uses it to read the pull request from GitHub, and it is gone when you close the tab. The token passes our server once, during sign-in, and we do not keep it.
Because all of this is strictly necessary and none of it tracks you, we don't ask for cookie consent and there is no cookie banner. We do not track you across other sites, so we treat every visit the same whether or not your browser sends a Do Not Track or Global Privacy Control signal.
Who processes it
Service providers that work for us under contract: website and account hosting, the account database, encrypted backup storage, payment (Polar), and sign-in (GitHub, Google). We do not sell or share personal information, and never have.
How long we keep it
Account, machine and subscription data: while your account exists. Cloud backups: until you delete them, or 30 days after your paid-through date. Deleting your account cancels your subscription, erases your backups, and deletes everything tied to it. Polar keeps its own payment records as the law requires.
Your rights
You can see, download, correct and delete what we hold from your account, and object to or restrict processing. Where the GDPR, UK GDPR or California law gives you these rights, you can also complain to your data-protection authority. We will not treat you differently for using them. For anything else, write to support@srcprism.com; we answer within 30 days.
We are based in the United States, and our providers process data there. Data leaving the EEA, UK or Switzerland moves under the European Commission's Standard Contractual Clauses.
Children
srcprism is not meant for anyone under 16.
Changes
When this policy changes, its date moves, and we email account holders before a material change applies.