Privacy Policy

Last updated: March 2026

What Data We Collect

When you use OakPrism, we process the files you upload (CSV, TSV, or Excel). We also collect basic account information if you sign up: your email address and chosen plan. We do not collect data beyond what you explicitly provide.

How We Use Your Data

Your uploaded files are processed to detect data types, clean values, compute statistics, generate charts, and produce AI-powered narrative insights. We send aggregated statistics — never raw row-level data — to Anthropic's Claude API for narrative generation. Anthropic does not use API inputs for model training.

Who Can See Your Data

Only you can see your uploaded files and generated reports. If you share a report via link, recipients see charts and narrative only — raw data is hidden by default. You control password protection, expiration, and data visibility on shared links.

PII Detection & Protection

During analysis, OakPrism automatically detects columns that may contain personally identifiable information (PII) — such as email addresses, phone numbers, names, and government IDs. These columns are automatically excluded from AI narrative generation. You will see a notice when PII columns are detected.

Data Retention

Retention periods depend on your plan. Expired data is automatically and permanently deleted — no soft-delete period, no recovery.

PlanRaw FilesReports
Anonymous24 hours24 hours
Free7 days30 days
Pro30 days90 days
Business365 days365 days

Data Deletion

You can delete any report at any time using the Delete button on each report page. Deletion is immediate and permanent — we remove data from all storage systems, including cached data, shared links, and associated metadata. There is no undo.

To delete your account and all associated data, contact us at privacy@oakprism.com.

AI Data Handling

We never use your data to train AI models. Your data is sent to Claude (by Anthropic) solely for generating narrative insights for your report. Only pre-computed statistics are sent — never raw row-level data. PII columns (emails, phone numbers, government IDs) are automatically excluded from AI analysis. Anthropic's terms confirm that API inputs are not used for model training.

Shared Report Privacy

Recipients of shared reports see only the sections you choose to share. Raw data is hidden by default. You control password protection, link expiration, and section visibility for every shared link. You can revoke access at any time by deleting the shared link or the report itself.

Where Data Is Stored

Your data is stored on Supabase Cloud infrastructure (powered by AWS) with AES-256 encryption at rest and TLS 1.3 encryption in transit. All data is stored in the United States. Business customers can choose US or EU data residency.

Compliance

GDPR: If you are an EU resident, you have the right to access, correct, or delete your personal data. You can exercise these rights by contacting us or by using the in-app deletion features.

CCPA: If you are a California resident, you have the right to know what personal information we collect and to request its deletion. We do not sell personal information to third parties.

A Data Processing Agreement (DPA) is available on request for Business customers. Contact privacy@oakprism.com for details.

Contact

For privacy questions, data deletion requests, or DPA inquiries, contact privacy@oakprism.com.

Mea Global Inc · Delaware, United States