Privacy Policy
Last updated: 21 September 2026
Prisma Connect is operated by Coco and Jay LLC, a Wyoming limited liability company (“we”, “us”). This policy explains how we handle personal data when you use prismaconnect.me. Prisma Connect lets you connect accounts you control to an AI assistant and is designed to keep source content in motion rather than stockpile it.
1. Who is responsible for the data
Coco and Jay LLC is the controller of your Prisma Connect account, connection, billing, and service-usage data. For content in a business account you connect, you or your organization is normally the controller and we act as a processor, handling that content only on your instructions through the tools you enable.
2. Data we collect
- Account data: your email address from Google sign-in and account creation time.
- Workspace data: company or group names, connector-account names, enabled tools, privacy choices, and other settings you save.
- Connection data: OAuth refresh tokens and API credentials for services you connect, encrypted at rest.
- Billing data: plan and connector entitlements plus Stripe customer and subscription identifiers. Stripe processes payment details; we do not store full card numbers.
- Operational metadata: request method, redacted path, status, latency, connector and tool name, and error class. We do not put request or response bodies in application logs. Our hosting and edge-security providers can also process ordinary network data such as IP address, user agent, and request headers when delivering and protecting the service.
We do not store source content from connected accounts durably. The precise retention periods are in our Data Retention Policy.
3. How and why we use data
We use the data to authenticate you, maintain the companies and connections you configure, provide and secure the service, process subscriptions, respond to support requests, and fetch or change data only when an enabled tool is invoked by your connected AI assistant. Optional pseudonymization replaces selected personal details with tokens before results leave Prisma Connect for that assistant.
Our GDPR legal bases are performance of our contract with you, your consent to each provider connection, our legitimate interests in securing and improving service reliability, and compliance with legal obligations. You can withdraw a connection consent by disconnecting that provider or deleting your account.
4. Google user data and Limited Use
Prisma Connect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Depending on the connector and the actions you enable, Prisma Connect may access Google Analytics reports and configuration; Google Ads accounts, reports, campaigns, and conversion actions; Calendar events; Docs content and formatting; selected Drive files and metadata; Sheets values and formatting; Search Console sites, performance data, sitemaps, and indexing actions; and Gmail messages, drafts, labels, and sending actions when Gmail is available and enabled.
- Minimum access. We request the scopes needed for the specific actions you enable. Actions that create, send, edit, publish, or delete are separately controlled and off until you enable them.
- Only to provide your requested feature. Google user data is retrieved only when your connected AI assistant invokes an enabled action and is used only to complete that request.
- No sale, advertising, or generalized model training. We do not sell Google user data, use it for advertising or profiling, or use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
- Restricted human access. Our staff do not read Google source content except with your affirmative permission for support, when necessary to investigate abuse or a security incident, for aggregated and anonymized internal operations, or when legally required.
- User-selected recipient. A result is transferred only to the AI assistant you connected and only to carry out your request. That provider's handling of the result is governed by your account and agreement with it. Pseudonymization can reduce the personal details sent.
- No Google content cache. Google source content is fetched live for each request, is not cached by Prisma Connect, and is not written to our database, backups, or persistent logs.
A fuller, plain-language disclosure is available on our Google API Data Use page and is also linked directly before a user starts Google authorization.
5. Sharing and service providers
We do not sell personal data. We disclose only what is needed to:
- Your chosen services: the connected account provider and AI assistant needed to perform the action you requested.
- Amazon Web Services: application and database hosting.
- Stripe: checkout, subscriptions, and the customer billing portal.
- Cloudflare: DNS, edge delivery, traffic security, and network-error reporting; and, when configured, encrypted R2 disaster-recovery backups that are automatically rotated after approximately 14 days.
- Authorities or advisers: only where required by law or reasonably necessary to protect rights, users, and the service.
6. Cookies and similar technology
Prisma Connect uses one strictly necessary, signed session cookie (pc_sid) to keep you signed in. It is HttpOnly, SameSite=Lax, Secure on the live HTTPS service, and expires after 30 days. We do not use advertising cookies or third-party web analytics. Stripe may use its own technology on its hosted checkout and billing pages under Stripe's privacy policy.
7. Retention and deletion
Your live account, settings, billing identifiers, and encrypted connection credentials remain until you delete the account. Deletion revokes Google tokens on a best-effort basis, closes sessions, wipes temporary session caches, and removes the live database record. Encrypted disaster-recovery backups can retain that account record for up to approximately 14 days before automatic deletion; they are isolated, used only for recovery, and never contain connected source content. Non-Google connectors can use an optional RAM-only result cache for 15 minutes or one hour; it is off by default. Google results are never cached. Logs are metadata-only and size-capped. See Data Retention Policy.
8. Your choices and rights
You can turn off individual tools, disable or disconnect a connector, revoke access from the provider, or erase your live account through Connect → Delete account. Depending on your location, you may also ask to access, correct, export, delete, restrict, or object to processing of your personal data, and may complain to your local data-protection authority. Contact us below to exercise a right not available in the app.
We do not sell personal information or share it for cross-context behavioural advertising, and we do not discriminate against users for exercising privacy rights.
9. Security
OAuth tokens and connector credentials are encrypted at rest with AES-256-GCM; database backups are encrypted before leaving the server; traffic uses HTTPS; state-changing browser requests receive origin checks; and logs exclude payloads. Pseudonymization maps and optional non-Google result caches live only in memory. Connector content is marked as untrusted data for the AI client to reduce the risk of instructions embedded in emails, documents, files, and API results. No system can guarantee absolute security.
10. International transfers
We and the services you choose may process data outside your country. Where transfer safeguards are legally required, we rely on mechanisms such as contractual protections offered by our processors. Optional pseudonymization can further limit the personal data sent to your AI provider.
11. Children
Prisma Connect is a business productivity service and is not directed to children under 13. Do not use the service if you cannot legally agree to these terms or do not have authority to connect the relevant accounts.
12. Changes and contact
We will update this page and its “last updated” date when our practices change. If we materially change how Google user data is used, we will notify affected users and obtain any required consent before applying the new use. Privacy questions and rights requests: [email protected].
Coco and Jay LLC
30 N Gould St Ste R
Sheridan, WY 82801, USA