Privacy Policy
Last updated October 10, 2026
1. Who We Are
Prisma is operated by Carajillo Solutions LLC, a Texas limited liability company ("we," "us," or "our"). Contact: privacy@caraji.io | Carajillo Solutions LLC, 13423 Blanco Rd, San Antonio, Texas 78216, USA.
2. What We Collect
Prisma is a publishing tool: you connect your social media accounts, and Prisma adapts and publishes your content to them. To run it, we process:
- Account information: your email address, used to sign you in and to send transactional email, plus your language and theme preferences
- Connected channel information: the identifiers and names of the social accounts, pages, and profiles you connect through each network's official API
- Access tokens: the credentials each network issues so Prisma can act on your behalf; stored encrypted at rest and never shown to anyone
- Your content: the posts, captions, and media you compose, schedule, and publish, plus each network's response (post ID, link to the published post, publish status)
- Engagement automations: the keyword rules and reply templates you set up on Facebook Pages and Instagram, and a record of each automated reply Prisma sends (see section 5)
- Payment information: processed by Stripe, Inc.; we receive a customer ID and payment metadata, never your full card number
We access only the data needed to provide the features you use. We never sell personal data, never use your content or your audience's data for advertising, and never access more of your social accounts than those features require.
3. The Waitlist
If you join the Prisma waitlist, we keep the email address you submit and the language you signed up in. We use it only to send you news about Prisma, and we don't sell it or hand it to anyone for their own marketing. You can have your email removed at any time: write to privacy@caraji.io or follow the instructions on our data deletion page.
4. The Social Networks You Connect
Prisma works through each network's official API, and only with the accounts you personally connect and authorize: Instagram, Facebook, and Threads (operated by Meta Platforms, Inc.), X, LinkedIn, TikTok, YouTube (operated by Google LLC), Bluesky, and Pinterest. The same rules apply to every one of them:
- We use each network's API only for the features you use. That means publishing for you, identifying the account you connected, and, on Facebook Pages and Instagram, running the engagement automations you set up. Prisma's use of information received from a network's API is limited to those features, and complies with that network's developer and platform terms, including any "limited use" requirements.
- We are independent. Prisma is not endorsed by, certified by, affiliated with, or sponsored by Meta Platforms, X Corp., LinkedIn Corporation, TikTok, Google LLC or YouTube, Bluesky, Pinterest, Inc., or any other network. All product names, logos, and trademarks belong to their respective owners and are used only to identify the networks you can connect.
- We never resell or redistribute network data. We do not sell, rent, license, share, or otherwise redistribute any network's content, or any data we derive from a network's API, to any third party, and we never use it for advertising or to build advertising profiles.
- When you disconnect, we delete the credentials. When you disconnect a channel, Prisma immediately deletes the credentials it holds for that account (such as OAuth access and refresh tokens, or app passwords) and stops publishing and running automations on it. The account's identifiers and name, and the record of what Prisma published there, stay in your workspace so your post history stays intact and you can reconnect later; they are permanently deleted when your workspace is deleted (section 8). Content you already published to a network stays on that network and is governed by the network's own terms and privacy policy.
5. Connected-Network Data: Meta and TikTok
This section sets out, for each platform, exactly what Prisma reads through the platform's API, what it stores, how long it keeps it, and how it is deleted.
5.1 Meta: Facebook Pages, Instagram, and Threads
Permissions we request. Facebook Pages: pages_show_list, pages_read_engagement, pages_manage_posts, pages_manage_engagement, pages_messaging, pages_manage_metadata. Instagram (Instagram API with Instagram Login): instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments, instagram_business_manage_messages. Threads: threads_basic, threads_content_publish.
What we read.
- When you connect: on Facebook, the list of Pages you manage (each Page's ID, name, and username) and an access token for each Page you choose; on Instagram, your professional account's ID, username, name, account type, and profile picture link; on Threads, your account's ID, username, and name.
- When you publish: the processing status of each upload and the link to the published post.
- When you use engagement automations (Facebook Pages and Instagram only): Meta sends Prisma notifications (webhooks) about comments on your posts and messages sent to your account, and on Instagram also new followers and story mentions, as well as the messages your account sends. From them Prisma reads the person's ID and username and the text of the comment or message, to check it against your keywords, send the reply you configured, and pause an automated conversation once someone on your team replies personally.
What we store.
- For each connected account: the network, the account ID, username, and display name, the access token (encrypted at rest), and the date it expires. On Facebook we store the Page's access token; the personal token Facebook issues is held only in your encrypted session while you choose Pages, then discarded. On Instagram and Threads we store the long-lived account token. We do not store profile pictures.
- For each published post: the post ID the network assigns and the link to the post, alongside the content you wrote.
- For each automated reply: the commenter's or sender's ID and username, the keyword that matched, the ID of the post that was commented on, the text of the public reply and private message Prisma sent, and the IDs Meta assigned to them.
- For message automations: for each conversation, the other person's ID and the time someone on your team last replied personally.
- Raw notifications: the webhook notifications Meta sends, exactly as received, which can include IDs, usernames, and the text of comments and messages.
How long we keep it.
- Access tokens: until you disconnect the channel, reconnect it (the new token replaces the old one), or your workspace is deleted.
- Account identifiers, post IDs and links, automation records, and conversation records: for as long as your workspace exists, including after a channel is disconnected. Deleting an automation deletes its record of replies.
- Raw notifications: deleted automatically 7 days after Prisma processes them, or after 30 days if one could not be processed. We delete the ones relating to your accounts sooner when you ask us to, as described below.
How it is deleted.
- Disconnecting a channel (Channels, then Disconnect) deletes its access token immediately and stops all publishing and automations on it.
- Deleting your account permanently deletes everything above, including the raw notifications relating to your accounts. Request it by email at support@prisma.onl and we complete it within 30 days; if your subscription ends instead, your workspace is deleted automatically 90 days later.
- Removing Prisma in your Facebook, Instagram, or Threads settings stops Prisma's access on Meta's side, but does not by itself delete what Prisma already stores; use the options above for that. Step-by-step instructions are on our data deletion page.
5.2 TikTok
Permissions we request. user.info.basic and video.publish.
What we read.
- When you connect: your TikTok account's open ID and display name.
- When you prepare and publish a video: your creator settings (the privacy levels available to your account, whether comments, Duets, and Stitches are turned off, the longest video you can post, and your username), plus the processing status of the upload. These settings are used in the moment to show you the right options and check the video; they are not stored.
What we store.
- For the connected account: the open ID, the display name, the access and refresh tokens (encrypted at rest), and the date they expire.
- For each published video: the privacy level and the comment, Duet, and Stitch settings you chose, the video ID TikTok assigns, and the link to the video (which contains your username), alongside the video and caption you uploaded.
Prisma does not run automations on TikTok and receives no notifications from it.
How long we keep it. Access and refresh tokens are kept until you disconnect the channel, reconnect it, or your workspace is deleted. The account's identifiers and the record of published videos are kept for as long as your workspace exists, including after a channel is disconnected.
How it is deleted. Disconnecting the channel (Channels, then Disconnect) deletes its tokens immediately and stops publishing to it. Deleting your account permanently deletes everything above: request it at support@prisma.onl and we complete it within 30 days, or, if your subscription ends, your workspace is deleted automatically 90 days later. Removing Prisma from your TikTok app permissions stops Prisma's access on TikTok's side but does not by itself delete what Prisma stores. Step-by-step instructions are on our data deletion page.
6. How We Share Information
We share personal data only with the service providers below, and only to operate Prisma:
| Provider | Location | Purpose |
|---|---|---|
| DigitalOcean LLC | United States | Cloud hosting and media storage |
| Stripe, Inc. | United States | Payment processing |
| Anthropic, PBC | United States | AI caption assistance (your draft content is sent solely to generate suggestions for you) |
| The social networks you connect | Varies | Recipients of the content you choose to publish and the automated replies you set up through Prisma |
Subprocessors are contractually prohibited from using your data for any purpose beyond providing services to Prisma. The social networks process the content you publish under their own terms and privacy policies.
7. Security
All traffic is encrypted in transit (HTTPS/TLS). Network access tokens and application credentials are encrypted at rest. Access to production systems is restricted and authenticated. No security measure is absolute; if we become aware of a breach affecting your personal data, we will notify you as required by applicable law.
8. Data Retention
- Waitlist emails: kept while the waitlist runs; removed sooner on request
- Active accounts: retained for the life of the workspace
- After your subscription or free trial ends: your workspace is retained for 90 days (so you can reactivate without losing your work), with email reminders along the way, then permanently deleted with everything in it
- Access tokens: deleted immediately when you disconnect a channel or your workspace is deleted
- Connected-account identifiers, published post records, and automation records: retained for the life of the workspace, as detailed in section 5
- Raw Meta webhook notifications: 7 days after processing, 30 days at most (section 5.1)
- Stripe payment records: retained as required by tax law
- Server logs: rolled after 90 days
9. Cookies
Today we use only first-party functional cookies: a session cookie (which also remembers your language choice) and a CSRF token. There are no advertising cookies or behavioral tracking. If we adopt analytics or similar tools later, we will list them here and update this policy.
10. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by writing to privacy@caraji.io. We acknowledge requests within 5 business days and fulfill them within 30 days. California residents: we do not sell or share personal information for cross-context behavioral advertising, and we will not discriminate against you for exercising your privacy rights.
11. International Data Transfers
Our servers are located in the United States (DigitalOcean). If you use Prisma from outside the United States, your data is transferred to and processed in the United States, protected by the safeguards described above.
12. Changes to This Policy
If we make a material change, we will notify registered users by email at least 30 days before it takes effect. For minor updates (such as adding a new service provider or tool), we will update this page and the "Last updated" date.
13. Contact
- Privacy: privacy@caraji.io
- Product support: support@prisma.onl
- Mailing address: Carajillo Solutions LLC, 13423 Blanco Rd, San Antonio, Texas 78216, USA