Optra Prism — Privacy Policy
Effective Date: September 14, 2026 Last Updated: September 14, 2026 Entity: Grumatic, Inc. ("Company," "we," "us," "our")
1. Introduction
This Privacy Policy describes how Grumatic, Inc. ("Optra Prism," "we," "us") collects, uses, shares, and protects information when you use the Optra Prism platform, website, dashboard, APIs, Claude Code Plugin, and related services (collectively, the "Service").
This Privacy Policy applies to:
- Website visitors who browse our marketing site and documentation
- Platform users who create accounts, install the Plugin, and use the Dashboard
- API consumers who interact with our Ingest Service or Prism API and Worker services endpoints
For the processing of Customer Data (as defined in our Terms of Service) — including telemetry, prompts, traces, logs, and metrics — a Data Processing Agreement (DPA) is available on request at legal@optra-prism.com for customers whose use of the Service is subject to data protection law. Where a DPA is in place, this Privacy Policy and the DPA should be read together.
2. Information We Collect
2.1 Information You Provide Directly
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | Name, email address, organization name, password | Account creation and authentication |
| Billing Information | Payment method, billing address | Subscription management, collected only if you subscribe to a paid plan. No payment processor is currently engaged, and we do not store full card numbers |
| Communications | Support requests, emails, feedback | Customer support and product improvement |
| Profile Preferences | Notification settings, dashboard preferences, theme | Personalization |
2.2 Information Collected Automatically
When you use the Service, we automatically collect:
| Data Type | Examples | Purpose |
|---|---|---|
| Device & Browser Data | IP address, browser type and version, operating system, device type, screen resolution | Service delivery, security, and analytics |
| Usage Data | Pages visited, features used, click patterns, session duration, timestamps | Product improvement and analytics |
| Product Analytics & Session Replay | Page views, clicks and interactions in the Dashboard, and a replay of your Dashboard session, collected through PostHog | Understanding how the Dashboard is used and fixing usability problems |
| Log Data | Server logs, error reports, API request metadata (endpoints called, response codes, latency) | Debugging, monitoring, and security |
2.3 Customer Data (Platform Data)
When you use the Platform (via the Plugin, SDK, or API), the following data is processed:
| Data Type | Examples | Source |
|---|---|---|
| Telemetry Data | OTLP traces, logs, metrics from AI coding sessions | Plugin / OTLP endpoints |
| Prompt Data | LLM prompts, completions, model metadata | Plugin / Prompt capture API |
| Project Context | Project and repository identity, branch, and commit identifiers used to associate activity with work | Plugin |
| Committed Changes | Commit metadata and change measurements, where supported | Plugin |
| Agent Activity | Occurrence records of agent messages used to associate work with the relevant prompt | Plugin |
| Developer Identifier | The user identifier sent by the Plugin; every record is attributed to the individual developer who produced it | Plugin |
| Prism Scores | Prompt Efficiency Scores, Sub-Session Efficiency Scores, Skill score, and coaching recommendations | Generated by Prism API and Worker services |
| Analytics Data | Tool usage, error rates, efficiency metrics, vibe metrics | Derived from telemetry |
Prompt and response content, and tool activity details, can contain source code, file paths, and any information you include in a conversation. Agent activity records capture that an agent message occurred; they do not by themselves mean every agent message body is collected.
Important: Customer Data is owned by you and processed solely to provide the Service. See Section 5 for our commitments regarding Customer Data.
2.4 Information from Third Parties
| Source | Data Type | Purpose |
|---|---|---|
| Authentication Providers | OAuth profile (name, email, avatar) from the sign-in provider you choose (e.g., Google, GitHub, Microsoft) | Single sign-on |
3. How We Use Your Information
We use collected information for the following purposes:
Service Operation
- Provide, maintain, and improve the Platform
- Authenticate users and manage accounts
- Process and display telemetry, analytics, and PRISM Scores
- Generate intelligence outputs (waste detection, throttle analysis, rightsizing)
- Respond to support requests
Security and Compliance
- Detect and prevent fraud, abuse, and security threats
- Monitor for unauthorized access
- Comply with legal obligations
- Enforce our Terms of Service
Product Improvement
- Analyze usage patterns to improve features (using Operational Metadata only)
- Create Aggregate Data for benchmarking and research
- Debug errors and improve reliability
Communications
- Send transactional emails (account verification, billing, security alerts)
- Respond to inquiries and support requests
We do NOT use your information for:
- Selling Personal Data to third parties
- Behavioral advertising or ad-tech profiling
- Training machine learning models on Customer Data (see Section 5)
4. Legal Basis for Processing (EEA/UK Users)
If you are in the European Economic Area or United Kingdom, our legal bases for processing are:
| Basis | Applies To |
|---|---|
| Performance of contract | Account management, service delivery, billing, Customer Data processing |
| Legitimate interests | Security, fraud prevention, product improvement (using Operational Metadata), analytics |
| Consent | Marketing emails, optional analytics, cookies beyond strictly necessary |
| Legal obligation | Tax records, law enforcement requests, regulatory compliance |
You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. Customer Data Commitments
Given that Optra Prism processes sensitive developer telemetry and AI interaction data, we make the following commitments:
5.1 No Model Training. We do not use Customer Data to train, fine-tune, develop, or improve any machine learning models — ours or any third party's. This applies during and after your use of the Service.
5.2 Purpose Limitation. Customer Data is processed exclusively to: (a) provide the Service to you, (b) generate PRISM Scores and intelligence outputs for your account, (c) comply with legal obligations.
5.3 Third-Party LLM Processing. When LLM-powered features are enabled (e.g., LLM PRISM scoring, insights reports), conversation data needed for evaluation and explanation, including developer prompts, assistant responses, and tool inputs, results, and errors, may be processed by:
- AWS (Amazon Bedrock) — Anthropic Claude and OpenAI-family models made available through Amazon Bedrock, processed within AWS Regions in the United States. Prompt data is not sent directly to Anthropic or OpenAI. This processing is governed by the AWS Service Terms and the applicable model's Amazon Bedrock terms. Under those terms and AWS's published Amazon Bedrock data policies, AWS does not use Amazon Bedrock inputs or outputs to train models and does not share them with the model providers. AWS may retain flagged inputs and outputs for a limited period for abuse detection, as described in those policies.
LLM-powered processing is an integral part of the Service and cannot currently be disabled on a per-account basis. You can stop new prompt data from being sent at any time by removing the Plugin from your installation; this does not delete data already collected.
5.4 Data Isolation. Customer Data is logically separated by organization, and access within the Platform is restricted to authorized members of that organization. Within your organization, authorized team viewers can see member-level activity, scores, grades, and reports as described in the Documentation; a personal report being separate does not mean all information about an individual is hidden from the team.
5.5 Encryption and Key Handling. Customer Data is encrypted in transit using TLS 1.2 or higher. Prism keys (prism_*), the per-developer credentials that authenticate the Plugin to the Service, are stored only as one-way cryptographic hashes; the plaintext is shown only in the creation or rotation response and cannot be retrieved later. Lost keys must be rotated. Existing authentication digests are preserved.
6. How We Share Information
We share information only in the following circumstances:
6.1 Service Providers (Sub-processors)
We use the following categories of service providers who process data on our behalf:
| Provider | Purpose | Data Processed |
|---|---|---|
| AWS (Amazon Web Services) | Cloud infrastructure, storage, and compute in AWS US West (Oregon), us-west-2; AI inference via Amazon Bedrock within the United States | Customer Data (encrypted), Operational Metadata |
| PostHog | Product analytics, interaction autocapture, and session replay in deployments configured for analytics; the default collection endpoint is in the United States | User and organization identifiers, account properties including email and name, product events, interactions, and masked session replay data |
All sub-processors are bound by data processing terms. The table above is our current list, and we update it when it changes.
6.2 Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request. We will notify you before disclosure unless legally prohibited, and will challenge overly broad requests.
6.3 Business Transfers
In connection with a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you before your information becomes subject to a different privacy policy.
6.4 With Your Consent
We may share information with third parties when you explicitly direct us to do so (e.g., integrations you configure).
6.5 Aggregate Data
We may share Aggregate Data (de-identified, anonymized, non-attributable) with third parties for research, benchmarking, or industry reports. Aggregate Data cannot reasonably be used to identify you or any individual.
We do NOT:
- Sell Personal Data
- Share Personal Data with advertising networks
- Provide Personal Data to data brokers
7. Data Retention
We retain Personal Data and Customer Data for as long as your account is active and as needed to provide the Service, resolve disputes, and meet legal, tax, and security obligations. When data is no longer needed for these purposes, or when you or your organization ask us to delete it, we delete or anonymize it without undue delay and within any period required by applicable law. Copies in backups are overwritten on our backup cycle and are not restored to production except for disaster recovery. Retention periods for specific data categories may be published as we formalize them.
Aggregate Data that cannot reasonably identify you or any individual may be retained indefinitely.
8. Your Rights
8.1 All Users
Regardless of location, you may:
- View your account data and Customer Data in the Dashboard
- Request a copy of your data, correction of inaccurate data, or deletion of your account and associated data by contacting privacy@optra-prism.com
- Stop new data collection at any time by removing the Plugin from your installation
We respond to verified requests without undue delay and within the period required by applicable law.
8.2 EEA/UK Users (GDPR)
If you are in the EEA or UK, you additionally have the right to:
- Access: Request a copy of your Personal Data in a structured, commonly used, machine-readable format
- Rectification: Request correction of inaccurate Personal Data
- Erasure: Request deletion of your Personal Data ("right to be forgotten")
- Restriction: Request that we limit processing of your Personal Data
- Portability: Receive your Personal Data in a portable format and transmit it to another controller
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time for consent-based processing
- Lodge a Complaint: File a complaint with your local supervisory authority
To exercise these rights, contact privacy@optra-prism.com. We will respond within the period required by applicable law.
8.3 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know: Request disclosure of Personal Information collected, used, and shared in the past 12 months
- Delete: Request deletion of your Personal Information
- Correct: Request correction of inaccurate Personal Information
- Opt Out of Sale/Sharing: We do not sell or share Personal Information for cross-context behavioral advertising. No opt-out is necessary
- Non-Discrimination: We will not discriminate against you for exercising your rights
Categories of Personal Information Collected (past 12 months):
| Category | Collected | Sold | Shared for Ads |
|---|---|---|---|
| Identifiers (name, email, IP) | Yes | No | No |
| Commercial information (billing) | Yes | No | No |
| Internet activity (usage data) | Yes | No | No |
| Professional information (organization) | Yes | No | No |
| Geolocation (IP-derived, approximate) | Yes | No | No |
To exercise these rights, contact privacy@optra-prism.com.
8.4 Other Jurisdictions
We respect privacy rights under applicable laws worldwide, including but not limited to Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act. Contact privacy@optra-prism.com to exercise your rights under local law.
9. Cookies and Tracking
9.1 Types of Cookies
| Type | Purpose | Examples |
|---|---|---|
| Strictly Necessary | Authentication, security, session management | Supabase auth cookies (sb-*-auth-token*), CSRF tokens |
| Functional | User preferences, theme, locale | Dashboard settings, theme preference |
| Analytics | Usage patterns, feature adoption, session replay | PostHog (ph_* cookies and browser storage; data hosted in the United States) |
9.2 Managing Cookies
- Browser Controls: You can block or delete cookies via your browser settings. Blocking strictly necessary cookies may impair functionality.
9.3 No Advertising Cookies
We do not use advertising cookies, tracking pixels for ad networks, or cross-site tracking technologies. We do not participate in real-time bidding or ad exchanges.
10. International Data Transfers
Customer Data is stored and processed in the United States. Its primary storage Region is AWS US West (Oregon), us-west-2. AI inference for LLM-powered features runs through Amazon Bedrock using a US geographic inference profile, which may route requests across AWS Regions within the United States. If you are located outside the United States:
- EEA/UK and other jurisdictions that restrict international transfers: We transfer Personal Data only where a lawful transfer mechanism applies, such as an adequacy decision or approved contractual safeguards, together with technical measures such as encryption in transit and access controls.
- Other Jurisdictions: We implement appropriate safeguards as required by applicable law.
We are evaluating EU data residency options. Contact sales@optra-prism.com for current availability.
11. Data Security
We maintain administrative, technical, and physical safeguards designed to protect Personal Data and Customer Data against unauthorized access, loss, or alteration. These include encryption of data in transit, role-based access to production systems, organization-level access controls within the Platform, storage of Prism keys as one-way hashes, and logging of security-relevant events. We review and update these measures periodically.
No system is completely secure. If you discover a vulnerability, please report it to security@optra-prism.com.
12. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children. If we learn that we have inadvertently collected Personal Data from a child under 18, we will promptly delete it. Contact privacy@optra-prism.com if you believe we have collected data from a minor.
13. Third-Party Links and Integrations
The Service may contain links to third-party websites or integrate with third-party services (e.g., GitHub, IDE extensions). We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website with a revised "Last Updated" date
- Sending an email notification to the address on your account, or displaying a notice in the Dashboard
Material changes take effect 30 days after notification. Continued use of the Service after the effective date constitutes acceptance. If you disagree with a material change, you may terminate your account.
15. Contact Us
For privacy-related inquiries, data subject requests, or complaints:
Grumatic, Inc. Email: privacy@optra-prism.com Legal documents: dashboard.optra-prism.com/terms, dashboard.optra-prism.com/privacy
For unresolved concerns, you may contact your local data protection authority.
Appendix: Data Flow Summary
Developer Machine
│
├── Claude Code Plugin ──→ Ingest Service (ingest.optra-prism.com)
│ (prompts, telemetry) │
│ ├── Auth: validates Prism key (prism_*)
│ ├── NATS JetStream (publish)
│ │ │
│ │ Prism API and Worker services (internal)
│ │ ├── NATS → S3 (NDJSON/Zstd raw archive)
│ │ ├── Scoring, identity, report state → Postgres
│ │ └── Raw signals → ClickHouse → Query API
│ │
└── Dashboard (dashboard.optra-prism.com) ◄──┘── API responses (scores, analytics)
(view scores, analytics)
Storage: AWS US West (Oregon), us-west-2. AI inference: Amazon Bedrock, US geographic inference profile.
All data encrypted in transit (TLS 1.2+) and at rest (AES-256).
Customer Data isolated per organization. No cross-customer access.
Change History
| Date | Summary |
|---|---|
| September 14, 2026 | Corrected data residency and AI processing descriptions (AWS us-west-2 storage; Amazon Bedrock in the United States); corrected the sub-processor table and authentication provider description; itemized Plugin collection (project context, committed changes, agent activity, developer identifier) and team-level visibility; disclosed PostHog product analytics and session replay; replaced the fixed retention table with purpose-based retention; revised rights-exercise methods and security description to reflect current practice; removed the Do Not Track statement, the LLM opt-out statement, and placeholders; updated international transfer wording and service domains. Effective immediately upon publication. |
| April 4, 2026 | Initial version. |