Privacy Policy
Last updated: 26 July 2026
Prisma Connect is operated by Coco and Jay LLC, a limited liability company registered in Wyoming, United States (“we”, “us”). This policy explains what we do with your data when you use the service at prismaconnect.me. Prisma Connect lets you connect your own accounts to an AI agent for analysis. We are built around data minimization: we pass your data through, we do not stockpile it.
1. Who is the controller
For your account data (your email and the access tokens for services you connect), Coco and Jay LLC is the data controller. For the underlying content in your connected accounts, you are the controller and Coco and Jay LLC acts as your processor, handling that content only to fulfil the requests your AI agent makes.
2. What we collect
- Account: your email address, from Google sign-in.
- Connection tokens: OAuth refresh tokens for each provider you connect, encrypted at rest.
- Preferences: enabled connectors and privacy settings, plus encrypted API credentials you enter.
- Operational metadata: request method, redacted path, status, latency, tool name — never content.
We do not store the content of your connected accounts. See our Data Retention Policy for the full picture.
3. How we use it
Solely to operate the service: authenticate you, connect the providers you choose, and fetch data live so your AI agent can answer your requests. When you enable pseudonymization, personal identifiers are replaced with tokens before any data leaves for the AI provider.
4. Google user data (Limited Use)
Prisma Connect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice:
- Only what you switched on. Google user data is used solely to provide the actions you explicitly enabled for a connector, and only when your agent invokes one of them.
- Never for advertising. We do not sell Google user data, do not transfer it for advertising purposes, and do not use it to build advertising or marketing profiles.
- Never for model training. We do not use Google user data to develop, improve, or train generalized AI or machine-learning models.
- No human reading. Our staff do not read your Google user data, except with your explicit consent for support you have asked for, to investigate a security incident or abuse, when the data is aggregated and anonymized, or where we are legally required to.
- One recipient, chosen by you. Google user data is transferred only to the AI assistant you connected, and only to fulfil a request you made with it. We recommend a zero-data-retention tier with that provider, and pseudonymization can replace personal identifiers before anything leaves.
- Nothing kept. We retain no Google source content. It passes through to answer your request and is then discarded.
5. Legal bases (GDPR)
We rely on performance of a contract (to provide the service you signed up for) and your consent (each provider you connect, and each request you run through your agent). You can withdraw consent by disconnecting a provider or deleting your account.
6. Sharing and sub-processors
When your agent runs a request, the resulting data (pseudonymized if you enabled it) is sent to the AI provider you use — such as Anthropic (Claude) or OpenAI (ChatGPT) — to produce the answer. We recommend using those providers' zero-data-retention tiers. We do not sell your data and do not share it with any recipient you have not connected.
7. Retention
Your account row persists for the life of your account and is deleted immediately on request. Source data is never retained. Logs are metadata-only and size-capped. Full detail: Data Retention Policy.
8. Your rights
You may access, correct, export, or erase your data, and object to or restrict processing. Erasure is self-service via Connect → Delete account, which also revokes your provider tokens. For any other request, contact us below. You may also complain to your local data protection authority.
9. Security
OAuth tokens and connector API credentials are encrypted with AES-256-GCM. Traffic is served over HTTPS. Session pseudonymization maps live only in memory and are destroyed at session end.
10. International transfers
Your AI provider may process data outside your country. Those providers offer Standard Contractual Clauses and equivalent safeguards; using pseudonymization further limits what crosses a border.
11. Changes & contact
We will update this page and its “last updated” date when practices change. Questions or requests: [email protected].
Coco and Jay LLC
30 N Gould St Ste R
Sheridan, WY 82801, USA