Legal

Privacy policy

last updated SEP 03 2026

01

Who we are

Prism Revenue provides a done-for-you client acquisition service to business clients. We operate from California, United States.

This policy explains what personal information we collect, why we collect it, who processes it for us, and how you can have it corrected or removed. It covers prismrevenue.com and the Revenue Pilot application.

You can reach us about anything in this policy at richard@prismrevenue.com.

Effective date: August 11, 2026.

02

What we collect

When an account is created for you, we collect your name, your email address and a password. The password is stored only as a cryptographic hash by our authentication provider. We never see it, and it is never held in our own tables.

The interview is the substance of the service and the largest thing we hold. We keep the questions we ask, the answers you give in your own words, your website address if you give us one, and the classification our process produces from those answers.

If you log results from work you have put into market, we keep what you write and the date you attach to it.

We keep our own internal notes from reviewing your material, and any note you write when you tell us that something we recorded is wrong.

We keep technical records of the work our systems do for you: when a drafting run started and finished, how long it took, how much processing it consumed, and any error it returned. Those records name your account and the item being worked on. They do not contain your content.

At the end of the interview we ask for two practical things. The first is the link to a folder of documents we ask you to gather, such as adverts, contracts or posts. We keep the link, and whatever the folder holds is governed by the terms of wherever you store it, not by this policy. The second is whether you need us to build you a CRM. If you do, we keep the details that account is created with: your name, your phone number, your postal address and your business name, alongside the email address already on your account. If you do not, we keep only your answer, and those fields stay empty.

We do not collect payment information, because payment is not taken through this site. Apart from the setup details described above, which you give us only if you ask us to build your CRM, we hold no sensitive category of personal information, and we do not buy information about you from anyone.

03

Voice input

Where the application accepts spoken input, your browser records a short audio clip and sends it to us over an encrypted connection.

We forward that clip to OpenAI for transcription and send the text back to your screen. We do not write the audio to disk, to our database, or to any storage service, and we keep no copy of it. The only thing that survives on our side is the transcribed text, which lands in an editable field where you can change or clear it before you send it.

Your browser holds the clip in memory until transcription succeeds, so that a failed attempt can be retried without recording again. It is discarded when you leave the page.

How OpenAI handles the clip on their side is governed by their terms, not ours.

Voice input is optional. Typing does everything it does.

04

How we use AI, and where a person checks it

Your interview answers are processed by an AI system to draft your material. How that works is worth stating plainly, because the honesty of it is part of the product.

The questions we ask are fixed and written by us. The AI system reads your answers, may ask at most one clarifying follow up per question, plays your answers back to you at the end, and then drafts your material from the transcript.

Nothing the AI produces reaches you unreviewed. Every drafted item arrives in an internal queue marked pending, and a person at Prism Revenue reads it, corrects it and approves it before you ever see it. That gate is enforced in our database, not only in our interface.

Every fact we hold about your business is marked either verified, meaning you stated it, or assumed, meaning our process inferred it. We keep that distinction visible to you, and you can dispute any fact we have recorded.

No decision with a legal or similarly significant effect on you is made by an automated system. What the AI produces is business material, and a person signs off on it.

We do not use your interview content to train AI models, and we never use one client's material to produce another client's.

05

Who processes information for us

We keep this list short on purpose, and we name everyone on it.

Supabase provides our database and our authentication. Your account and everything described in section 02 is stored there, hosted by Supabase in the United States (Ohio).

OpenAI transcribes voice clips, as described in section 03. Audio is the only thing we send them.

Anthropic provides the AI model behind the drafting described in section 04. Your interview questions and answers are sent to that model to produce your material.

Hostinger provides the server infrastructure that runs our own software. As part of drafting your deliverables, interview content is processed and retained there in our system's working records. It is covered by the same deletion commitment as everything else, in section 09.

How each of these companies handles what we send them is governed by their own terms. We may change AI providers if a different one serves the work better, and if we do, we update this policy to name the new one.

Cloudflare runs the security check on our sign in and registration pages. To tell a person from a script it receives your IP address and signals about your browser. It sees only those two pages, it never receives your name, your email or anything you write in the product, and we do not receive a profile of you back.

Booking a call happens on TidyCal, a scheduling service, at a link that leaves our site. Anything you enter there is collected by TidyCal under their privacy policy, and no data comes back to us automatically.

06

Cookies

We set functional cookies only, and there are exactly two kinds.

Signing in sets session cookies from our authentication provider. They keep you signed in, and the application cannot work without them.

When someone on our team is reviewing a specific client's material, one additional cookie records whose material is on screen. It is readable only by our server, and on its own it grants no access to anything.

The sign in and registration pages carry one more thing, and it is the only third party script anywhere on this site: Cloudflare's security check, described in section 05. It may set a cookie of its own on those two pages to remember that the check already passed. Nothing like it runs on any other page.

Beyond that, the list is empty. We run no analytics, no advertising pixels, no tag manager and no cross-site tracking, and our fonts are served from our own domain rather than fetched from a font provider.

We checked this rather than assumed it: a visitor reading the site who is not signed in and has not opened the sign in or registration pages receives no cookies from us at all. What we do set is functional, so there is no cookie banner to dismiss.

07

Information about people who are not our clients

Part of the service is identifying and approaching the right companies on a client's behalf. That means we handle information about people who never signed up with us: a name, a job title, a work email address, the company someone works for, and public signals about why now is a sensible moment to make contact.

Part of it is also running advertising and a newsletter for a client, which invites people to subscribe. Where someone subscribes we handle what they give us and what their subscription produces: their email address, their name if they give one, where they subscribed from, and whether they opened or clicked what was sent. That is a different relationship from the one above, because the person asked to hear from the client rather than being approached, and we treat their request to stop as the same absolute instruction either way.

Our standard is narrow and we hold to it. We use professional and publicly available information only. Every message we send on a client's behalf, approached or subscribed, carries a way to opt out. When someone asks not to be contacted, we record that permanently and honor it from then on.

A suppression record exists precisely to prevent future contact, so we keep it even when we delete everything else. Deleting it would defeat its purpose.

We have not yet run outreach, advertising or a newsletter on behalf of a client. This is the standard we hold ourselves to when we do, and we will name the companies that process any of it for us in section 05 before it starts, not after.

If you think we hold information about you and you are not a client, write to richard@prismrevenue.com. We will tell you what we have and remove it on request.

08

We do not sell your information

We do not sell personal information. We do not share it for advertising, we do not rent or trade it, and we do not pass it to data brokers.

The companies named in section 05 process information because they run our infrastructure. Beyond them we share nothing, unless the law requires it of us.

09

How long we keep things, and how to have them removed

We keep your information while your account is active.

Anyone can create an account here, so some accounts are opened and never used. If an account never becomes a working engagement, what it holds is an email address, a name and whatever onboarding answers were written before it was abandoned. We remove those accounts when we notice them, and you can have yours removed sooner by asking.

We do not run an automatic deletion schedule today, and we would rather say so than publish a cycle we do not operate. Deletion is done by a person, on request.

Write to richard@prismrevenue.com and we will delete your personal information within 30 days. That covers your account, your interview and its transcript, your Prism and everything derived from it, the outcomes you logged, and the working records held on our own server infrastructure.

Two things survive a deletion request, both deliberately. We keep suppression and opt-out records, because their entire function is to remember that someone does not want to be contacted. And we keep anything the law requires us to keep, for as long as that requirement lasts.

Our database provider maintains backups on its own cycle. Deleted information leaves those backups as they age out.

There is no self-serve export button today. Ask us for a copy of what we hold and we will send it to you.

10

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, and ask us to delete it. Our service is aimed at businesses in the United States, and we honor these requests whoever you are and wherever you live.

Send any request to richard@prismrevenue.com. We may need to confirm your identity before we act, so that nobody else can make a request about you.

If you are a client, you can also dispute any individual fact in your Prism from inside the application. That flags it for a person to look at, and changes nothing until they do.

11

Security

Information travels over encrypted connections and is stored encrypted at rest by our database provider.

Access to client material inside Prism Revenue is limited to the people who need it to do the work. Separation between clients is enforced by our database itself, so one client's material is not reachable from another client's account.

The systems that process your content hold no database credentials. Our AI infrastructure cannot reach our database at all.

12

This service is not for children

Prism Revenue is a business service and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to richard@prismrevenue.com and we will remove it.

13

Changes to this policy

When this policy changes we update the date at the top of this page and publish the new version here. If a change materially affects how we handle information we already hold, we will contact account holders before it takes effect.

14

Contact

Prism Revenue, operating from California, United States.

richard@prismrevenue.com

Effective date: August 11, 2026. Last updated: September 3, 2026.

Privacy policy · Prism Revenue