Legal
Privacy Policy
Last updated 7 August 2026
Prism is built for motion designers, not to collect data about them. This policy sets out exactly what we handle and why. The data controller is Prism (oneprism.io), reachable at support@oneprism.io.
What we never do
- We do not use Google Analytics, Facebook Pixel, or any advertising tracker.
- We do not use advertising or retargeting pixels of any kind.
- We do not store your After Effects projects, compositions, footage or creative work, and we never use your work for anything other than running the request you made.
- We do not sell, rent or share your personal data with third parties for commercial purposes.
- We do not track you across other websites or services.
The MCP panel keeps your work on your machine: project files and compositions stay local. When your AI makes a request, the instructions for that request pass through Prism’s servers so the tool can run, and we record what was asked and how it went — see Product analytics below. Audio you submit for transcription is processed, then discarded. The panel contains no advertising trackers.
Your email and subscription record
When you buy a subscription, the transaction is handled entirely by Polar.sh, our Merchant of Record. Polar collects and holds your billing details and card information; we never see or store them. From Polar we receive only your email address and a subscription record, which we use to create your account, apply your plan, and support you.
Legal basis: contract performance, we need this to deliver what you bought.
Signing in
Signing in is handled by WorkOS, our identity provider. When you sign in with Google or an email code, WorkOS verifies it and returns your email address and an account identifier to us; we never see or store a password. Your session is held in an encrypted cookie on the Prism domain you signed in on, and signing out clears it.
The panel and your AI client are authorised by that same account. Each panel also generates a random identifier for itself so that requests reach the right open panel when you have more than one; it is not derived from your hardware and it identifies a panel, not a machine. You may use as many computers as you like.
Legal basis: contract performance, we cannot give you access to what you bought without knowing who you are.
Requests and usage counts
When your AI client asks Prism to act in After Effects, the request passes through our servers so the tool can run, and is counted against your plan’s allowance (MCP actions, and your Prism AI balance). The counts themselves are numbers attached to your account and contain none of the content of your work. What the request contained is covered separately under Product analytics below.
Legal basis: contract performance, running the tools you asked for and applying the limits you bought.
What you send to the generative tools
When you run a generative tool, your input goes to our servers to produce your result. Audio you submit for transcription, and the prompts you write for sound, music and images, are processed by Prism and our third-party AI infrastructure providers to generate what you asked for. Beat detection runs on our own servers and is sent to no third party. In every case the input is processed, then discarded. It is not stored and it does not train anything.
Legal basis: contract performance, you asked for the processing by running the tool.
Product analytics
We use PostHog, a privacy-focused analytics service hosted in the EU (Frankfurt), to see how the site and product are used: which pages are visited, which tools run, and where things fail. Session recordings, where enabled, mask what you type. Analytics identifiers live in your browser’s local storage rather than advertising cookies, and are never used for advertising or shared across sites.
When you use Prism inside a host application, we record what was asked of it and how it went: the instruction sent to Prism, the script Prism ran, the arguments and the result, any error, and what you searched the tool library for. This is how we find the failures nobody reports and build the tools people keep asking for. It is tied to your account.
What we never receive:your project file, your footage, your renders, or your conversation with your AI client — that conversation happens inside your own AI app and never reaches us. Credentials are stripped before anything is stored: session tokens are removed automatically and never retained.
Legal basis: legitimate interest, understanding how the product is used so we can improve it.
Server logs
Our web server keeps standard access logs (IP address, browser type and pages visited) for security monitoring and error diagnosis. They are rotated regularly and never used for marketing or profiling.
Legal basis: legitimate interest, keeping the site secure and diagnosing faults.
Who else processes your data
Data is processed on our behalf by Polar.sh for payments and subscriptions (their privacy policy), by WorkOS for signing you in and holding your account (their privacy policy), by PostHog for usage and product analytics in the EU, including the instructions and scripts described above (their privacy policy), and by our third-party AI infrastructure providers, which process the audio or prompt you submit in order to return your result and do not retain it.
Discordreceives a copy of any bug report or feedback you or your AI file through Prism’s support tool, so our team sees it. That copy carries your account and user identifiers, your plan tier, your current usage and balance, and the description of the problem. Nothing is sent there unless a report is filed.
No other third party receives your personal data. We use no advertising networks and no data brokers.
Cookies
We set no advertising cookies. Analytics identifiers are kept in your browser’s local storage, not cookies, and never follow you to other sites. The only cookies are functional: an encrypted session cookie once you sign in, without which you would not stay signed in, and cookies set by Polar.sh during checkout, which that flow needs to work. Neither is used to track you.
How long we keep things
We keep your email address and license record while your subscription is active, and for a reasonable period afterwards for accounting, legal compliance and support. You can ask us to delete it at any time. We remove everything we are not legally required to keep and confirm within 30 days.
Your rights
Depending on where you live you may have the right to see the personal data we hold about you, correct it, have it deleted, restrict or object to how we process it, receive it in a portable format, and withdraw consent where processing is consent-based.
To use any of these, email support@oneprism.io and we will respond within 30 days. If you are in the EU or UK you may also complain to your local data protection authority.
Children
Prism is not aimed at anyone under 16 and we do not knowingly collect personal data from minors. If you believe a minor has given us data, contact us and we will delete it promptly.
Changes to this policy
We may update this policy at any time. The date at the top shows when it was last revised, and we will email active subscribers about material changes before they take effect. Continuing to use the product after a change means you accept it.
Contact
Privacy questions or data requests: support@oneprism.io. We read and answer every message.