Privacy Policy · version 2026-08-13.v1

How Prismatics handles early-access data

Prismatics is a read-only marketing decision-intelligence product. It imports authorised marketing and analytics data so users can review source-labelled reporting, insights, recommendations, and exports.

Release status: this product-policy text is ready for engineering and provider-review preparation, but final legal approval is still required before external early access.

Data you provide

Prismatics stores the account identity needed to operate the product, workspace and client settings, reporting timezone and currency, business-goal context, selected source accounts/properties, outcome mappings, and product feedback or support context you choose to provide.

Connected-source data

When you explicitly connect a supported source, Prismatics requests only the access required for the approved read-only product path. Google Ads data can include account, campaign, delivery, spend, conversion, and conversion-value fields available to the authorised account. Google Analytics 4 data can include property, traffic-source, user, session, engagement, key-event, and observed-revenue fields available to the authorised property.

Prismatics does not ask for your advertising-platform password and does not use connected-source access to create, edit, pause, publish, or delete campaigns, budgets, targeting, ads, analytics properties, or conversion definitions.

How data is used

Authorised data is used to provide dashboards, source-labelled metrics, data-quality states, insights, recommendations, CSV/PDF exports, refreshes, troubleshooting, security controls, and product measurement for the controlled early-access experience. Prismatics keeps analytics-observed outcomes separate from advertising-platform attribution unless an approved product rule explicitly states otherwise.

Storage and credentials

OAuth access and refresh tokens are stored server-side in encrypted form. Tokens are not placed in browser storage, exports, analytics events, support tickets, or user-facing error messages. Product records retain only the data required for the approved product and operational purposes.

Sharing

Prismatics does not sell connected-source data. Data may be processed by infrastructure and service providers used to operate Prismatics only for the service purposes described here and subject to the final approved legal/data-processing terms. Connected-source data is not used to operate source-platform write actions.

Disconnect and deletion

Disconnecting a source deletes Prismatics' stored authorisation and stops future refreshes using that authorisation. Previously imported facts remain available until they are removed under the account-retention policy. A confirmed account-deletion request stops source access immediately and schedules the account and imported product data for deletion within 30 calendar days. Minimal credential-free security/audit evidence may be retained for up to 90 days after deletion completion where needed for security, abuse investigation, or an applicable legal obligation.

Your choices

You choose whether to connect each source, which eligible account/property to map, and whether to export product output. You can disconnect supported sources from Prismatics. Account deletion is available from the protected Account page and requires an explicit destructive confirmation.

Policy changes

Material changes receive a new policy version. Prismatics requires a fresh acknowledgement before a later external source authorisation relies on the changed policy.

Connected-source data-use notice · Early-Access Terms · Support · Home