Privacy Policy
Short version: Without an account, your audio is analysed entirely in your browser and never leaves your device. With an account (or for link analysis), it's sent to our analysis server, processed transiently, and deleted immediately — never stored. We collect only what's necessary to run the Service, and we don't sell your data.
This Privacy Policy explains how PRISM ("we", "us") collects, uses, and protects information about you when you use our Service.
1. Information We Collect
Account information. When you create an account, we collect your email address. If you sign in via Google OAuth, we receive your email address and display name from Google.
Audio files. Without an account, your audio is analysed locally in your browser (Web Audio API) and never leaves your device. With an account — or when you analyse a link (Spotify, YouTube, SoundCloud) — the file (or the track fetched from the link) is sent to our analysis server (Railway) to extract DSP features (LUFS, BPM, spectral data, etc.). It is written to a temporary file, processed, and deleted immediately afterwards. We never archive or listen to your audio; only the numerical features are kept.
Analysis data. For authenticated users, we may store the numerical results of your analyses (scores, feature values, timestamps, filenames) to provide scan history. No audio data is included.
Usage data. We collect basic, anonymised usage data (page visits, scan counts) to improve the Service. This data is not linked to your identity.
2. How We Use Your Information
- To provide and improve the Service
- To authenticate you and manage your account
- To display your scan history and progression (if you have an account)
- To send you product updates or critical service notices (you can opt out at any time)
3. Data Storage and Security
Account data and analysis results are stored in Supabase, a hosted PostgreSQL service with row-level security, hosted in the EU (AWS eu-west-1). Some processors (analysis server, payments, email) are located outside the EU — see "Data Sharing" below. We implement reasonable technical measures to protect your information, but no system is 100% secure.
Audio files are processed transiently in a temporary file that is deleted immediately after analysis; they are never archived or written to object storage.
4. Data Sharing
We do not sell, rent, or trade your personal information. We may share data with:
- Supabase — database & authentication (AWS eu-west-1, EU)
- Railway — audio analysis server (backend); transient audio processing, not stored (US)
- Vercel — website hosting
- Stripe — payments; processes your email and payment details (US)
- Resend — transactional email delivery (US)
- Sentry — error monitoring; technical data only, no audio (EU region)
- PostHog — product analytics (usage funnel); pseudonymous events only, no audio, EU region — loaded only after you accept the consent banner
- Spotify — only when you analyse a Spotify link: the URL is sent to Spotify's API to fetch the track
- Legal authorities — if required by applicable law
All sub-processors are contractually bound (Data Processing Agreements) to handle your data in accordance with applicable data protection law.
International transfers. Some processors (Railway, Stripe, Resend) are located in the United States. Transfers to them are covered by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, ensuring an adequate level of protection.
5. Cookies and Local Storage
PRISM uses browser localStorage to store your scan history locally on your device (no server involved). We use a session cookie set by Supabase to maintain your authentication state. We do not use tracking or advertising cookies.
6. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict processing of your data
- Data portability
To exercise any of these rights, contact us at contact@prism-audio.app. We will respond within 30 days.
7. Data Retention
Account data is retained until you delete your account. Analysis results stored server-side are deleted when your account is deleted. You can also delete individual scans from your account page at any time.
8. Children's Privacy
PRISM is not directed to minors under 15 (the age of digital consent in France; 16 in some EEA countries). We do not knowingly collect personal information from children. If you believe a minor has provided us with personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this Policy from time to time. We will notify you of material changes via email or a notice on the Service. Continued use after changes constitutes acceptance.
10. Contact
Privacy questions or requests: contact@prism-audio.app.