# Prism privacy notice

Effective date: September 25, 2026

Thomas Brackin operates Prism under the Varitas brand. This notice explains how we handle personal information when you visit this website, contact us or use an authorized account.

The public demo contains fictional examples. It needs no account, accepts no interview uploads, saves no visitor edits and makes no live AI calls. Loading a page still sends ordinary request information to our hosting provider.

Customer workspaces are provisioned manually after you contact Varitas. No customer workspace is currently active. The customer-workspace practices below describe the conditions that must be confirmed before we activate that service.

## Who is responsible

We are responsible for personal information used for our website, account administration, security and correspondence. For interview content handled on an organization’s instructions, that organization is the controller and Varitas acts as its processor. Publishing this notice does not change those roles or replace the required customer and data-processing terms.

Organizations decide whose interviews to collect and why. They must provide participant notices and have authority to record, upload and analyze the material. Contact the organization that conducted your interview about its use of your information. We assist with requests according to our role.

## Information we handle

Website requests may include an IP address, browser and device information, the requested page, request time and response information. If you contact us, we receive your contact details and the information you send. Please do not send interview content, passphrases or recovery files by email.

For authorized accounts, we handle email addresses, account names, authentication records, session information, workspace memberships, roles and invitations. A sign-in passkey’s private key stays with your authenticator; we store the credential information needed to verify it.

We bill by invoice and handle the billing contact details, invoice amounts, payment status and transaction records needed to administer those invoices. Do not include interview content in billing correspondence.

An activated customer workspace processes uploaded VTT files or material imported from a customer-connected Zoom account. This can include meeting metadata, participant identifiers, speaker labels, recordings, original and edited transcripts, consent notes, analysis instructions, insights, citations, and saved questions and answers. Integration credentials and job and usage metadata support those features.

The service is intended for adults working with non-sensitive, non-regulated information. Do not upload children’s information, special-category or other sensitive information, or regulated information, including through Zoom imports, transcripts or prompts. These restrictions do not automatically detect or prevent prohibited uploads.

## How we use information

We use personal information to provide requested access and services, administer workspaces and invoices, send sign-in and invitation emails, secure and troubleshoot the service, answer requests and meet applicable legal obligations.

We use interview content exclusively to provide the service requested by the customer. We do not use it for model training, independent research, benchmarking or product improvement.

We do not sell personal information, share it for targeted or cross-context behavioral advertising, send marketing emails, or use advertising pixels, session replay or analytics for marketing or other independent purposes. Necessary disclosures to the service providers described below support the requested service.

Where the EU or UK GDPR applies to information for which we are the controller, we rely on steps you request before entering a contract or performance of a contract with you. Where you represent an organization, we rely on our legitimate interests in providing and administering its requested service. We also rely on legitimate interests to operate and secure the website and respond to enquiries, and on compliance with applicable legal obligations where required. For customer interview content, the customer determines the appropriate legal basis.

A customer’s in-app processing authorization controls future AI processing. It does not replace recording or upload permission, and turning it off does not delete information already stored.

## Service providers and AI

Railway hosts our website, application, database and files. Resend delivers sign-in and invitation emails and receives the recipient address and message, including a sign-in link when applicable. Your organization’s Zoom account supplies recordings and metadata when connected; Zoom’s handling of its own copy is separate.

In activated workspaces, AI features send text, such as relevant transcript passages, prompts and conversation context, through OpenRouter to the selected inference provider. We configure requests to require endpoints identified by OpenRouter as supporting zero data retention and to prohibit data-collection routing. Default Responses requests are stateless. Audio is not sent for AI transcription.

These routing controls concern inference, not all records held by the application or its providers. Before activating a customer workspace, we confirm the selected inference service, relevant providers and applicable processing arrangements with its administrator.

We may disclose information when required by applicable law or to address a security incident or protect legal rights. Customer content is not available through an operator support-entry workflow.

[Railway privacy policy](https://railway.com/legal/privacy)

[Resend privacy policy](https://resend.com/legal/privacy-policy)

[OpenRouter privacy policy](https://openrouter.ai/privacy)

[Zoom privacy statement](https://www.zoom.com/en/trust/privacy/privacy-statement/)

## Location and regional choices

The current public website is hosted in the United States. Account administration, email delivery and correspondence may also involve processing in the United States; a workspace region choice does not automatically apply to those records.

During purchasing and manual setup, the workspace administrator can request US or EU storage and US or EU AI inference. We confirm the available choices, actual deployment and provider arrangements before activation. We do not activate a customer workspace until we can meet its confirmed choices, and configured inference routing does not fall back outside the confirmed inference region.

Any required international-transfer arrangements must also be established before customer activation. This notice does not represent that an EU or UK customer deployment or a particular transfer safeguard is already in place.

## Customer-held encryption and access

New customer workspaces require encryption at rest using customer-held keys, unlocked with a passphrase or a compatible encryption passkey. Setup requires downloading a recovery file and reading it back successfully before completion. Ordinary account sign-in and workspace decryption are separate.

Authorized automated processing temporarily decrypts content on our servers. This is encryption at rest, not end-to-end encryption or a promise that the running service never sees plaintext. Account, membership and operational metadata are outside the content vault.

Workspace administrators manage membership and provide encrypted access to authorized members. We do not offer support access into a customer workspace or hold a recovery secret. If every customer unlock and recovery method is lost, we cannot recover the content, including during the seven-day recovery period. Removing a member prevents subsequent service access; it cannot revoke copies they already exported.

We use access controls and security measures appropriate to the service, but no system can guarantee complete security.

If a personal data breach affects customer information, we notify the relevant customer without undue delay after becoming aware of it and provide the information needed to help the customer respond. We make any additional notices required by applicable law.

## Retention and deletion

For activated customer workspaces, interviews remain until the customer deletes them or closes the workspace. Either action starts a seven-day recovery period. Recovery requires usable customer key material. At the deadline, recovery stops; the deletion worker removes covered live content on its next successful sweep. An outage or processing failure can delay completion, so the deadline is not a guarantee of instantaneous physical erasure.

Covered deletion includes source files, transcripts, insights and relevant saved answers. Final deletion of a meeting also removes workspace group-wide and all-meeting conversations because they may contain material from that interview. Removing membership only removes access. Deleting a source recording in Zoom is a separate action.

Final workspace erasure removes its content and workspace administration records. Accounts still needed for another active workspace remain; unneeded authentication records are cleaned up after workspace erasure. Application job and model-call metadata are removed after 30 days, and expired sessions are removed, with a maximum 30-day session-record lifetime.

The seven-day customer policy depends on a separately verified deployment and its provider copy-retention arrangements. We do not activate customers on the retained internal demonstration deployment or treat deletion of live rows as proof that provider backups or storage media have been erased.

We retain correspondence and privacy-request records as needed to resolve the matter and document our response. Website hosting, email delivery and other provider-held operational records have their own applicable retention arrangements; the application’s deletion schedules do not by themselves erase those records. We provide the confirmed customer arrangements before activation.

Invoice and transaction records are retained for as long as needed to administer payment, resolve billing matters and meet applicable accounting, tax or other legal recordkeeping obligations. These administrative records are separate from interview content and its deletion schedule.

## Cookies and browser controls

The public demo does not require sign-in cookies. Authorized account features use cookies for authentication, workspace selection and a temporary workspace-unlock session. Blocking these cookies may prevent sign-in or workspace access. Encryption keys are not saved in browser local storage.

## Your choices and privacy requests

Email thomas@varitas.io with privacy questions or requests. Thomas Brackin personally monitors this address. You do not need a Prism account to contact us. We may ask for proportionate information to verify identity and authority, without requesting your workspace passphrase or recovery file.

We aim to respond within 28 days and meet any earlier applicable legal deadline. If the law permits an extension, we explain why and when you can expect a response. If we deny a request, we explain the reason and how to seek review. Reply with “Privacy appeal” to have a denial reviewed; we respond within the applicable appeal deadline. You may complain to the relevant regulator if you disagree with the outcome.

Depending on applicable law and our role, you may have rights to access, correct, delete or obtain a copy of personal information, restrict processing, object to processing based on legitimate interests, or withdraw consent where processing relies on consent. Withdrawal does not affect earlier lawful processing. We do not discriminate against you for exercising applicable rights.

For customer interview information, contact the organization responsible for the interview. We route requests to that organization and assist as required, without exposing another person’s information. You may also complain to the privacy regulator responsible for your location.

[Contact Thomas about privacy](mailto:thomas@varitas.io)

## Changes to this notice

We update this notice when our practices change and show the effective date above. For material changes affecting customer workspaces, we email their administrators and provide any additional notice required by law. Customer activation requires confirming the applicable service and processing arrangements before interview content is accepted.
