PRISM logo
Learn Practice Evaluate Roadmap ▶ Try live Demo
Log In Sign Up Back to Canvas
Learn Practice Evaluate Roadmap
Log In Sign Up Back to Canvas
PRISM › Privacy Policy
🔒 Legal Document

Privacy Policy

Last updated: 1 July 2026  ·  Effective: 1 July 2026

Contents

  • Overview
  • 1. Information We Collect
  • 2. How We Use Your Data
  • 3. Third-Party Sharing
  • 4. Data Retention
  • 5. Security
  • 6. Your Rights
  • 7. Cookies & Tracking
  • 8. Children's Privacy
  • 9. Policy Changes
  • 10. Contact
OVERVIEW

The Short Version

PRISM collects only what it needs to run the product. We do not sell your data. We do not run ads. AI features use OpenAI's API — your canvas designs and evaluation responses may be included in prompts.

This Privacy Policy explains what information PRISM ("we", "us") collects when you use prismhld.com, how we use it, and your rights regarding it. By using PRISM, you agree to the practices described here.


01

Information We Collect

Account data: When you register, we collect your email address, a username you choose, and a hashed password (or OAuth provider token if you sign in via Google or GitHub). We never store plain-text passwords.

Usage data: We record events as you interact with the product — opening modes, running simulations, submitting evaluations, generating MCQ questions, and switching between canvas states. These events are stored against your user ID and an anonymous session key.

Canvas designs & submissions: Workspace layouts, component configurations, and simulation results you create are stored in our database and associated with your account so you can access them across sessions.

Evaluation data: When you complete a formal evaluation, we store your answers to MCQ questions, trade-off responses, scoring breakdowns, and the AI-generated feedback report.

Payment data: Payments are processed by Razorpay. We do not store card numbers or payment credentials on our servers. We receive a transaction ID and plan metadata from Razorpay after a successful payment.

Technical data: Standard server logs may include your IP address, browser type, OS, referring URL, and request timestamps. We retain these for security monitoring and debugging.

Feedback: If you submit voluntary feedback (ratings, comments), we store that content linked to your account.


02

How We Use Your Data

  • Service operation: authenticating your account, persisting your workspaces, running simulations, and delivering evaluation results.
  • AI features: Your canvas graph, component parameters, and evaluation responses are sent to OpenAI's API to generate MCQ questions, trade-off evaluations, and design feedback. See section 3 for details.
  • Product improvement: Aggregated, anonymised analytics help us understand feature usage, improve the simulation engine, and prioritise development.
  • Security: IP addresses and usage patterns are used to detect abuse, rate-limit requests, and investigate incidents.
  • Communications: We may email you about significant account events (plan changes, password resets). We do not send unsolicited marketing without your explicit opt-in.

03

Third-Party Sharing

We share data with the following categories of third parties only to the extent necessary to operate the product:

  • OpenAI: Canvas design data, evaluation responses, and user prompts are sent to the OpenAI API to power AI features. OpenAI's Privacy Policy applies to data processed by their models. We do not use OpenAI's zero data retention API tier by default; data may be used by OpenAI to improve their models unless you are on a plan that uses the enterprise API.
  • Razorpay: Payment processing. Your card details are collected and stored exclusively by Razorpay and governed by their Privacy Policy.
  • Google Analytics & Microsoft Clarity: Anonymous event tracking and session recording to understand product usage. These tools may set cookies. You can opt out via your browser's privacy controls.
  • Hosting & Infrastructure: Our servers run on cloud providers (e.g., Render, AWS). Your data is hosted in regions subject to their data processing agreements.

We do not sell, rent, or trade your personal data to advertisers or data brokers. Ever.


04

Data Retention

We retain your account and workspace data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it longer (e.g., financial transaction records).

Analytics events are retained for 24 months in identifiable form, after which they are aggregated and the user ID link is removed.

Server access logs are retained for a maximum of 90 days.


05

Security

We take reasonable technical and organisational measures to protect your data, including:

  • Passwords hashed with bcrypt (no plain-text storage)
  • TLS/HTTPS enforced on all endpoints
  • JWT tokens with short expiry windows
  • HTTP security headers (HSTS, CSP, X-Frame-Options, etc.)
  • Rate limiting and anomaly detection on all API routes
  • Database access restricted to application-layer credentials

No system is perfectly secure. If you discover a security vulnerability, please report it to security@prismhld.com before disclosing publicly.


06

Your Rights

Depending on your jurisdiction you may have the right to:

  • Access a copy of your personal data
  • Correct inaccurate information via your profile settings
  • Delete your account and associated data
  • Portability — receive your workspace data in a machine-readable format
  • Restrict or object to certain processing activities

To exercise any of these rights, email us at privacy@prismhld.com. We will respond within 30 days.


07

Cookies & Tracking

PRISM uses the following types of cookies and local storage:

  • Session cookies: Maintain your login state across requests. These are HttpOnly, SameSite=Lax, and Secure in production.
  • localStorage: Your authentication token and canvas state are persisted in the browser's localStorage for a smoother single-page experience. This data stays on your device.
  • Analytics cookies: Google Analytics and Microsoft Clarity set tracking cookies to measure usage patterns. You can disable these in your browser settings or via browser extension.

We do not serve third-party advertising cookies.


08

Children's Privacy

PRISM is intended for users aged 16 and older. We do not knowingly collect personal data from children under 16. If you believe a minor has created an account, please contact us at privacy@prismhld.com and we will delete the account promptly.


09

Policy Changes

We may update this policy to reflect product changes or legal requirements. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, send a notice to registered users. Continued use of PRISM after changes become effective constitutes acceptance of the updated policy.


10

Contact

For privacy-related questions or to exercise your data rights, contact us at:

Email: privacy@prismhld.com
General: hello@prismhld.com
Website: prismhld.com/contact

PRISM

Product

Learn Mode Practice Mode Evaluate Mode Roadmap

Resources

Live Demo Mock Interview Contact Us

Company

Pricing Contact Privacy Terms

Simulation-driven system design practice.
Think in systems. Design with consequence.

© 2026 PRISM. All rights reserved. Design systems that survive scale.