Stays on the iPhone
Full conversations, source capsules, profile bodies, private personal knowledge, the task ledger, agent orchestration, and device-permission state.
PRIVACY BY SEPARATION
PRISMS AI reduces backend access to student content through an on-device runtime, a separately deployed model data plane, and an isolated school control plane.
WHAT GOES WHERE
Full conversations, source capsules, profile bodies, private personal knowledge, the task ledger, agent orchestration, and device-permission state.
The bounded model request and response needed for one inference pass through relay memory without a relay database or content log.
Authentication, agent and skill versions, structured knowledge locators, knowledge gaps, and anonymous technical diagnostics that exclude prompt and output bodies.
THE PRECISE PROMISE
The relay can process plaintext while forwarding, and the selected model provider receives inference content. PRISMS AI’s promise is narrower and verifiable: the relay does not persist content, the management backend does not receive it, content logging is disabled, and student identity is not forwarded to the model provider.
Encryption in transit protects network transport. It does not prevent the chosen cloud model provider from receiving the request it must process.
USER CONTROL
Calendar, location, Health, camera, photos, speech, and files follow explicit student intent and iOS authorization.
PRISMS AI may use current coarse location for a requested task but does not build a continuous location trail. Health access is read-only for authorized step and sleep summaries.
Personal memory, private knowledge, and task bodies do not currently synchronize across devices. Future continuity requires explicit opt-in, encryption, revocation, and auditability.