PRIVACY BY SEPARATION

Student boundaries
cannot depend on a slogan.

PRISMSAI reduces backend access to student content through an on-device runtime, a separately deployed model data plane, and an isolated school control plane.

WHAT GOES WHERE

Each layer receives only
what its job requires.

01

Stays on the iPhone

Full conversations, source capsules, profile bodies, private personal knowledge, the task ledger, agent orchestration, and device-permission state.

02

Passes through the model path

The bounded model request and response needed for one inference pass through relay memory without a relay database or content log.

03

Enters the control plane

Authentication, agent and skill versions, structured knowledge locators, knowledge gaps, and anonymous technical diagnostics that exclude prompt and output bodies.

THE PRECISE PROMISE

Stateless does not mean
end-to-end invisible.

The relay can process plaintext while forwarding, and the selected model provider receives inference content. PRISMSAI’s promise is narrower and verifiable: the relay does not persist content, the management backend does not receive it, content logging is disabled, and student identity is not forwarded to the model provider.

DEVICE-ONLY REQUIREMENTUse an on-device model when content must never leave the phone

Encryption in transit protects network transport. It does not prevent the chosen cloud model provider from receiving the request it must process.

USER CONTROL

Permissioned, revocable,
and auditable.

Calendar, location, Health, camera, photos, speech, and files follow explicit student intent and iOS authorization.

OFFCROSS-DEVICE SYNC

The current iPhone remains authoritative.

Personal memory, private knowledge, and task bodies do not currently synchronize across devices. Future continuity requires explicit opt-in, encryption, revocation, and auditability.

APP STORE PRIVACY DISCLOSURE

Eight disclosed data types.
One bounded purpose.

PRISMSAI declares the following data types for App Functionality. It does not use them for third-party advertising or cross-company tracking.

LINKED

Account & diagnostics

Email address, user ID, device ID, and other diagnostic data may be associated with the signed-in account or device session for authentication, runtime delivery, reliability, and support.

NOT LINKED

Optional device context

Health, fitness, and coarse location are processed only after the student enables the corresponding iOS permission and are not linked to the student identity in the App Store disclosure.

NOT LINKED

Student-selected content

Other user content includes questions and student-selected text, links, photos, camera captures, and files needed for a requested task. It is not used for tracking.

RETENTION, PROVIDERS & CHOICES

Keep less.
Keep control.

LOCALDELETE ANY TIME

The student controls local state.

Local conversations, memory, personal knowledge, task history, and selected imports remain until the student deletes them or removes the App. iOS permissions can be revoked in Settings at any time.

CONTROL PLANEOPERATIONS ONLY

No student-content dashboard.

Account records, runtime versions, knowledge operations, gaps, and privacy-safe diagnostics may be retained to operate and repair the service. They exclude full prompt and model-output bodies.

REQUESTSACCESS OR DELETION

Questions have a human destination.

For privacy, access, correction, or deletion requests, email support@prismsai.org. Include only the account email and the request needed for us to locate the relevant account record.

PRISMSAI does not sell personal data, does not serve behaviorally targeted advertising, and does not track students across other companies’ apps or websites. Last updated: August 16, 2026.