PrismLab

Privacy

A plain, honest account of what we collect, why, where it is processed, and the control you keep. For the technical detail on how it is protected, see our Security page.

Last updated 3 July 2026

Who we are

PrismLab is a personal-finance app operated by its founder, based in New Zealand ("PrismLab", "we", "us"). We are responsible for your data under this policy. You can reach us any time at admin@prismlab.app.

What we collect

  • Account details: your name, email and settings.
  • Financial data you add or import: accounts, transactions, budgets, goals, and asset records such as insurance, fixed deposits, property and family-vault entries.
  • Documents you upload: statements, receipts and files you attach to records.
  • Technical data needed to run and secure the service, such as log and error information.

How we use your data

We use your data only to provide PrismLab: to show your dashboard, run your budgets and FIRE projection, power Prism Intelligence, generate your reports, process your subscription, and keep the service secure. Our legal basis is performing our contract with you, our legitimate interest in operating and securing the service, and your consent where the law requires it. We do not sell your data or use it for advertising.

Prism Intelligence and AI

When you use quick entry, the bill reader, statement import or your monthly summary, the relevant content is sent securely to our AI provider, Anthropic, to produce your result.

  • Your content is not used to train AI models.
  • The provider may retain content briefly under its standard retention, for abuse-monitoring and legal compliance, and then deletes it; we do not operate a zero-retention arrangement.
  • AI output is always a suggestion you review, edit or discard before anything is saved.

Who processes your data

We rely on a small set of reputable providers (sub-processors), each bound by a data-processing agreement and using your data only to deliver PrismLab:

  • Supabase — database, authentication and file storage (Singapore).
  • Vercel — application hosting and global edge network (United States and edge locations).
  • Anthropic — the AI behind Prism Intelligence (United States).
  • Cloudflare — DNS and email routing.
  • Resend — transactional email delivery.
  • Our payment provider — subscription billing.

Where your data is processed

Running PrismLab means your data is processed in Singapore (our database) and the United States (hosting and AI), and may pass through global edge locations. Where data leaves your country, we rely on the providers' contractual safeguards and, where the law requires it, on your consent to the transfer.

How long we keep it

  • Active-account data: kept while your account is open.
  • After you close your account: personal data deleted within about 30 days, except where we must keep it longer by law.
  • Billing and tax records: retained for up to 7 years to meet financial-record obligations.
  • Backups: rotated and overwritten within about 30 days.
  • Technical logs: retained for about 90 days.

Sensitive information

Some records — insurance, family-vault documents, and identity or health-related details — are especially sensitive. They are protected the same way as the rest of your data: encrypted and isolated to your account, and visible only to you and anyone you explicitly invite. Please add only what you are comfortable storing.

Sharing

Your data is private to you. It is shared only with people you explicitly invite, at the access level you choose, and with the sub-processors above who help us run the service. You can revoke access at any time.

Your rights

You can ask us to access, correct, export or delete your data, and to object to or restrict certain processing. To exercise any right, email admin@prismlab.app; we aim to respond within 30 days.

  • New Zealand (Privacy Act 2020): access and correction, and the right to complain to the Office of the Privacy Commissioner.
  • India (DPDP Act 2023): access, correction, erasure, nomination, and grievance redress via the contact below.
  • Canada (PIPEDA and Québec Law 25): access, correction and data portability.
  • United States (CCPA/CPRA): to know, delete, correct, and opt out of sale — note that we do not sell data.
  • United Arab Emirates (PDPL): access, correction, deletion and objection.

Automated decisions

PrismLab does not make automated decisions that produce legal or similarly significant effects about you. Prism Intelligence is assistive: it suggests, and you decide.

Data breaches

If a breach affects your personal data, we will act promptly to contain it and will notify you and the relevant authority where the law requires — in New Zealand, the Privacy Commissioner as soon as practicable, and in other regions within their required timeframes.

Children

PrismLab is intended for adults. It is not for anyone under 18, and we do not knowingly collect data from children.

Cookies

We use only the cookies needed to keep you signed in and to run the app. We do not use third-party advertising cookies or cross-site tracking.

Business transfers

If PrismLab is ever transferred to a new operator, your data would move with it and remain subject to protections at least equivalent to this policy. We would tell you before any change of control affects your data.

Changes to this policy

We may update this policy as the product and the law evolve. Material changes will be reflected in the "Last updated" date above and, where appropriate, communicated to you.

Contact and complaints

Questions, requests, or a privacy grievance (including under India's DPDP Act)? Write to admin@prismlab.app. You also have the right to complain to your local data-protection authority.