Privacy policy
How Prism handles information
This policy explains what Prism collects, why it is used, when it is shared, and the choices available to people whose information is processed in the application.
Scope
Prism is an invite-only production operations application developed and operated by Wildlife AI for London Alley Entertainment. It is designed for authorized staff, collaborators, and production teams, not for general consumer use. In this policy, "Prism," "we," and "our" refer to Wildlife AI and London Alley Entertainment in their respective roles operating and sponsoring the service.
Information we collect
Prism may process the following categories of information:
- Account information: name, business email address, profile image, role, organization membership, and account status.
- Production records: project briefs, bids, budgets, estimates, schedules, documents, approvals, notes, and deliverables.
- Crew and vendor records: contact details, location, engagement history, union affiliation, rates, invoices, and related production information.
- Financial operations data: payroll entries, vendor charges, card and bank statement imports, purchase orders, accruals, and reconciliation records supplied by authorized users.
- Technical data: session data, IP address, browser and device information, error reports, security events, and feature preferences needed to operate and protect the service.
Prism does not currently offer a live connection to personal bank accounts. Any future bank-data integration will be documented here before it is enabled for real financial data.
Google account and Workspace data
Prism uses Google OAuth through Clerk to let authorized users sign in. For sign-in, Prism receives basic account information such as name, email address, profile image, and a Google account identifier. We use that information only to authenticate the user, apply access controls, display the user's account, and attribute work performed in Prism.
Prism is also being prepared for limited Google Workspace actions. If those features are enabled and separately authorized, Prism may use:
- Gmail send permission to send a production-related message initiated or approved by an authorized user. Prism does not use this permission to read the user's inbox.
- Google Calendar event permission to find suitable meeting times and create, retrieve, or update production-related calendar events for the authorized workflow.
Prism does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train general-purpose AI models. Human access is limited to what is necessary for support, security, legal compliance, or an action the user requests.
Prism's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
How we use information
We use information processed through Prism to:
- authenticate users and manage role-based access;
- operate production intake, bidding, budgeting, staffing, and closeout workflows;
- import, organize, match, and reconcile authorized business records;
- provide AI-assisted extraction, drafting, and operational recommendations;
- maintain security, diagnose errors, prevent misuse, and improve reliability; and
- meet contractual, accounting, tax, and legal obligations.
How information is shared
Prism does not sell personal information. Information may be shared with authorized London Alley personnel and service providers only as needed to operate the application. Current providers include Clerk for authentication, Google Workspace for authorized account features, Supabase for database hosting, Render for application hosting, Sentry for error monitoring, and OpenAI and Anthropic for specific AI-assisted workflows.
We may also disclose information when required by law, to protect the security or rights of users and the service, or as part of a business transfer subject to appropriate safeguards. Providers are permitted to process information only for the services they supply to Prism.
AI-assisted features
Some Prism workflows send relevant project text or documents to AI providers for extraction, summarization, drafting, or recommendations. Users should submit only information they are authorized to process and must review AI-assisted output before relying on it. Google user data is not used to train general-purpose AI models.
Retention and deletion
We retain information for as long as needed to operate Prism, support active productions, meet contractual requirements, and satisfy accounting, tax, legal, and security obligations. Production and financial records may need to be retained for up to seven years after the relevant production wraps or the record's last activity. Retention controls for the internal alpha continue to be hardened and will be reviewed before a public production launch.
Authorized users may disconnect Prism from their Google account through their Google Account connections page. Disconnecting stops future access but does not automatically delete records that must be retained for legitimate business or legal reasons.
Security
Prism uses managed authentication, encrypted network connections, hosted database protections, role-based controls, and operational monitoring intended to protect information. No system can guarantee absolute security. Users must protect their accounts and promptly report suspected unauthorized access.
Choices and requests
Depending on the circumstances and applicable law, a person may ask to access, correct, or delete personal information associated with them. Some requests may be limited by business-record retention, contractual, legal, or security obligations. Send a request to dirk@wildlifeai.co.
Children and international processing
Prism is a workplace application and is not directed to children under 18. Information may be processed in the United States and in other locations where our providers operate, subject to the safeguards and contractual terms applicable to those providers.
Changes and contact
We may update this policy as Prism's features and data practices change. The date at the top identifies the version in effect. Material changes will be communicated through the application or directly to authorized users when appropriate.
Questions about this policy or Prism's data practices can be sent to dirk@wildlifeai.co.