Legal
Privacy Policy
What personal information Prizmal Inc. collects, why, and what you can do about it. It covers two things: information collected through our website, and data processed through the Prizmal Service, PrizmalSwitch, PrizmalRun, and Warden, when you use it.
- On the website, we collect what you send us and standard browser data. There are no ads, pixels, or cross-site tracking.
- In the Service, we process the requests you send in order to route them and return results. We do not store the content of your prompts, reasoning, or completions after your request is served, we do not sell your data, and we do not use that content to train our own or third parties' models.
- We use only operational metadata and telemetry (never your content) to improve the Service. This is on by default and you can opt out at any time.
- We use service providers, including third-party model providers, to operate the Service. They act on our instructions.
- You can access, correct, delete, or export your data. Questions: privacy@prizmal.ai
Scope
This policy applies to the website at prizmal.ai and to the Prizmal Service. Where you use the Service under a separate signed agreement, the data terms of that agreement control for the data it describes, and this policy applies to everything else.
Information we collect
On the website. Contact details you send us by email (name, company, role), the content of messages you send, and standard information your browser sends (browser, operating system, pages visited, time on page, referrer, and IP address, which may be anonymized).
When you use the Service.
- Account and billing data, the information needed to create and manage your account, keys, plan, prepaid balance, and payments. Payment card details are handled by our payment processor; we do not store full card numbers.
- Request and response content, the inputs ("prompts"), any intermediate reasoning, and the outputs ("completions") processed to serve your request. This may include personal information you choose to include; you are responsible for the content you submit. We process this content in transit to return your result and do not retain it afterwards (see Section 04).
- Operational and usage data, metadata and telemetry about your use of the Service: which model handled a request, timing, token and cost accounting, error and security signals, rate-limit and quota events, and audit records generated by Warden.
How we use information
- To deliver the Service, route your requests, run inference, return results, apply governance, and maintain availability and failover.
- To operate accounts and billing, provision keys, meter usage, draw down your prepaid balance, and process payments.
- To secure and protect the Service, detect and prevent abuse, fraud, and security threats, and enforce our Terms and applicable provider policies.
- To support and communicate with you, respond to inquiries and send technical and administrative updates.
- To operate and improve the Service, understand aggregate usage and keep the Service working well, using only operational and usage data (metadata and telemetry) and any feedback you choose to give us, never the content of your prompts, reasoning, or completions. This improvement use is on by default; you can opt out at any time at privacy@prizmal.ai or in your account settings, without affecting your access to the Service. Where the law requires your consent for this use (for example in the EEA, the UK, or Quebec), we rely on consent and will not use your data to improve the Service without it.
- To comply with law, meet legal, accounting, and reporting obligations.
We do not retain the content of your prompts, reasoning, or completions after your request is served, and we do not use that content to train our own or others' foundation models. We do not sell, rent, or trade your data.
Data in the Service
When you use the Service, your requests are processed to produce a result and are routed, on your behalf, to the model best suited to the work. Some models are operated by third-party model providers, who process your requests as our subprocessors, on our instructions, solely to return a result. We provision and pay for that access so that a single Prizmal key gives you access to open and frontier models.
- Custody. As between you and Prizmal, your inputs and the outputs generated for you are yours. We process them to provide the Service and for the purposes described in this policy.
- No retention of your content. We do not store the content of your prompts, reasoning, or completions after your request is served. It is processed in transit to return your result and is not retained afterwards. Where content is inspected in real time to keep the Service safe and secure, that inspection happens in-flight and does not create a stored copy.
- No training on your content. We do not use your prompts, reasoning, or completions to train our models, and we contract with providers on terms intended to prevent your content from being used to train theirs.
- Local and Enterprise deployments. Local (on-premises or self-hosted) and Enterprise deployments are governed by the data-handling terms of the applicable signed agreement, which may provide additional or different commitments, including on data residency, retention, isolation, and subprocessors, and which control over this policy for the data they describe.
- Subprocessors. We use third-party model providers and infrastructure providers to deliver the Service. A current list of subprocessors is available on request via privacy@prizmal.ai.
- Retention of metadata and audit records. We do not retain prompt, reasoning, or completion content (see above). Operational and usage metadata (for security, abuse prevention, billing, and improving the Service) and Warden audit records are retained for up to one year, or longer where the law requires. These records do not contain the content of your prompts or completions.
Cookies and tracking
Essential only. We use essential cookies for basic site function and local storage for display preferences on your device. No advertising networks, no social pixels, no cross-site behavioural tracking. Anything stored for preferences stays on your device and can be cleared from your browser at any time.
Legal basis (EEA, UK, Switzerland)
We rely on: consent for specific activities; performance of a contract to provide the Service you request; legitimate interests, balanced against your rights, to secure and improve the Service; and legal obligation where the law requires.
Sharing and disclosure
We do not sell, rent, or trade your data. We share it only:
- with service providers and subprocessors (including model and infrastructure providers) bound by confidentiality and acting on our instructions;
- where required by legal process or to comply with law;
- to protect rights, ours or others', and to prevent abuse or harm;
- in a business transfer such as a merger or acquisition; and
- with your consent.
Security
We protect data with encryption in transit (TLS), access controls that restrict who can view data, regular security review, and an internal register of privacy incidents. No method of transmission or storage is completely secure, and we do not claim absolute security.
Breach notification
If a breach creates a real risk of significant harm, we will notify affected individuals as soon as feasible, describe the nature of the breach and the data involved, outline mitigation steps and your options, and report to regulators where required.
Retention
We keep personal information only as long as necessary for the purpose it was collected for, including legal, accounting, and reporting requirements. Business contact data may persist through the relationship and for a reasonable period afterwards. Data in the Service is retained as described in Section 04.
International transfers
We operate from Quebec, Canada, recognized as adequate by the EU Commission. Data may be transferred to Canada and to jurisdictions where our service providers operate. For transfers outside an adequacy framework, we apply standard contractual clauses.
Your rights
Canada (PIPEDA and Law 25). Access your data, correct inaccuracies, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
United States (California, Virginia, Colorado, and others). Know what we collect, request deletion, opt out of sale (we do not sell), and non-discrimination for exercising your rights.
GDPR (EEA, UK, Switzerland). Access, rectify, erase, restrict, and port your data, object to processing based on legitimate interests, and complain to a supervisory authority.
To exercise any right, contact privacy@prizmal.ai.
Regulatory alignment
A SOC 2 examination is currently in progress. Our governance and data practices are otherwise mapped and aligned to recognized frameworks, including the EU AI Act, ISO/IEC 27001, 27701, and 42001, GDPR, PIPEDA, and Quebec's Law 25. Except for a certification or attestation we expressly state we hold, references to these frameworks describe the standards we align to and are not, on their own, a claim of certification.
Children
The Service and website are not directed at anyone under 18, and we do not knowingly collect information from children. Contact us if you believe a child's information has been collected and we will delete it.
Third-party links and services
The website links to third-party services and sources. We are not responsible for their privacy practices. Read their policies before you share anything with them.
Changes
Material changes update the effective date at the top of this page. Continued use after a change means you accept the updated policy.
Contact
You may also contact the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec. For use of the website and the Service, see the Terms of Service. For our position on custody and governance, see Trust.