Privacy Policy
Updated September 5, 2026
Plain-language summary
We process account identifiers, company and product facts, customer inquiries, analyses, replies, follow-ups, and limited security and usage metadata to provide and protect the service. Free-allowance protection uses account, random device, session, weak hashed network, and explainable behavior signals; a shared IP never triggers a restriction by itself. Necessary AI content may be sent over HTTPS after email and phone redaction. We do not use advertising trackers.
Complete policy
1. Data
Account identifiers, business records, inquiries, analyses, replies, follow-ups, usage records, billing identifiers, amounts, currency, status, and limited security metadata are collected when needed. PrismSino does not store full card numbers or CVV.
2. Free allowance
Protection uses account, a random first-party device identifier, session, weak hashed network data, and explainable behavior signals. A shared IP, VPN, or company network never causes restriction by itself, and no invasive fingerprinting SDK or AI similarity model is used.
3. Purposes
Data supports authentication, SaaS functions, AI processing, support, quota calculation, abuse prevention, and reliability.
4. Service providers
Necessary AI content may be sent over HTTPS after email and phone redaction. Waffo Pancake receives the account identity, email, selected plan, and server metadata needed for checkout and returns verified order, subscription, and refund events. Provider handling remains subject to provider terms.
5. Retention
The device identifier lasts up to 180 days and risk signals up to 90 days. Business and billing records remain while the account exists or as needed for support, audit, disputes, and legal duties.
6. Access
Account data is isolated by owner. Privileged content access is locked by default and requires MFA, reason, time limit, read-only access, redaction, and audit.
7. Choices
Account settings provide correction, Excel/CSV/JSON export, session revocation, and irreversible deletion. You may request manual review of a free-allowance link.
8. Security
Production uses HTTPS, password hashing, hashed tokens, authorization, rate limits, and server-only secrets.
9. Contact
Email [email protected] for access, correction, export, deletion, or policy questions.
PrismSino Inbox and Gmail
Inbox processes only the visible thread you explicitly choose to analyze. It previews extracted text, does not scan your mailbox in the background, does not read attachments, and never sends email. Necessary text is redacted before transmission to the configured AI provider. The inquiry and thread are saved to your PrismSino account under the business-data retention and account-deletion rules. Extension tokens live only in extension session memory for up to one hour and are revoked when the linked website session ends. Edited drafts remain in extension session storage until browser shutdown or extension sign-out. Persistent extension storage contains only language preferences and account-scoped thread digests and task identifiers. Logs exclude full email bodies, replies and tokens.
Google third-party sign-in
Only when you choose Google sign-in or account linking, PrismSino receives Google-verified basic account information, which may include your name, email, and profile picture. We use it to create your account, sign you in, protect the account, and provide the service. Signing in does not let us read Gmail, Google Drive, contacts, or calendars. You can review connected methods in account settings, disconnect Google when another sign-in method remains, or request deletion of your account and related data.