Optra Prism — Privacy Policy

Effective Date: September 14, 2026 Last Updated: September 14, 2026 Entity: Grumatic, Inc. ("Company," "we," "us," "our")


1. Introduction

This Privacy Policy describes how Grumatic, Inc. ("Optra Prism," "we," "us") collects, uses, shares, and protects information when you use the Optra Prism platform, website, dashboard, APIs, Claude Code Plugin, and related services (collectively, the "Service").

This Privacy Policy applies to:

  • Website visitors who browse our marketing site and documentation
  • Platform users who create accounts, install the Plugin, and use the Dashboard
  • API consumers who interact with our Ingest Service or Prism API and Worker services endpoints

For the processing of Customer Data (as defined in our Terms of Service) — including telemetry, prompts, traces, logs, and metrics — a Data Processing Agreement (DPA) is available on request at legal@optra-prism.com for customers whose use of the Service is subject to data protection law. Where a DPA is in place, this Privacy Policy and the DPA should be read together.

2. Information We Collect

2.1 Information You Provide Directly

Data TypeExamplesPurpose
Account InformationName, email address, organization name, passwordAccount creation and authentication
Billing InformationPayment method, billing addressSubscription management, collected only if you subscribe to a paid plan. No payment processor is currently engaged, and we do not store full card numbers
CommunicationsSupport requests, emails, feedbackCustomer support and product improvement
Profile PreferencesNotification settings, dashboard preferences, themePersonalization

2.2 Information Collected Automatically

When you use the Service, we automatically collect:

Data TypeExamplesPurpose
Device & Browser DataIP address, browser type and version, operating system, device type, screen resolutionService delivery, security, and analytics
Usage DataPages visited, features used, click patterns, session duration, timestampsProduct improvement and analytics
Product Analytics & Session ReplayPage views, clicks and interactions in the Dashboard, and a replay of your Dashboard session, collected through PostHogUnderstanding how the Dashboard is used and fixing usability problems
Log DataServer logs, error reports, API request metadata (endpoints called, response codes, latency)Debugging, monitoring, and security

2.3 Customer Data (Platform Data)

When you use the Platform (via the Plugin, SDK, or API), the following data is processed:

Data TypeExamplesSource
Telemetry DataOTLP traces, logs, metrics from AI coding sessionsPlugin / OTLP endpoints
Prompt DataLLM prompts, completions, model metadataPlugin / Prompt capture API
Project ContextProject and repository identity, branch, and commit identifiers used to associate activity with workPlugin
Committed ChangesCommit metadata and change measurements, where supportedPlugin
Agent ActivityOccurrence records of agent messages used to associate work with the relevant promptPlugin
Developer IdentifierThe user identifier sent by the Plugin; every record is attributed to the individual developer who produced itPlugin
Prism ScoresPrompt Efficiency Scores, Sub-Session Efficiency Scores, Skill score, and coaching recommendationsGenerated by Prism API and Worker services
Analytics DataTool usage, error rates, efficiency metrics, vibe metricsDerived from telemetry

Prompt and response content, and tool activity details, can contain source code, file paths, and any information you include in a conversation. Agent activity records capture that an agent message occurred; they do not by themselves mean every agent message body is collected.

Important: Customer Data is owned by you and processed solely to provide the Service. See Section 5 for our commitments regarding Customer Data.

2.4 Information from Third Parties

SourceData TypePurpose
Authentication ProvidersOAuth profile (name, email, avatar) from the sign-in provider you choose (e.g., Google, GitHub, Microsoft)Single sign-on

3. How We Use Your Information

We use collected information for the following purposes:

Service Operation

  • Provide, maintain, and improve the Platform
  • Authenticate users and manage accounts
  • Process and display telemetry, analytics, and PRISM Scores
  • Generate intelligence outputs (waste detection, throttle analysis, rightsizing)
  • Respond to support requests

Security and Compliance

  • Detect and prevent fraud, abuse, and security threats
  • Monitor for unauthorized access
  • Comply with legal obligations
  • Enforce our Terms of Service

Product Improvement

  • Analyze usage patterns to improve features (using Operational Metadata only)
  • Create Aggregate Data for benchmarking and research
  • Debug errors and improve reliability

Communications

  • Send transactional emails (account verification, billing, security alerts)
  • Respond to inquiries and support requests

We do NOT use your information for:

  • Selling Personal Data to third parties
  • Behavioral advertising or ad-tech profiling
  • Training machine learning models on Customer Data (see Section 5)

4. Legal Basis for Processing (EEA/UK Users)

If you are in the European Economic Area or United Kingdom, our legal bases for processing are:

BasisApplies To
Performance of contractAccount management, service delivery, billing, Customer Data processing
Legitimate interestsSecurity, fraud prevention, product improvement (using Operational Metadata), analytics
ConsentMarketing emails, optional analytics, cookies beyond strictly necessary
Legal obligationTax records, law enforcement requests, regulatory compliance

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

5. Customer Data Commitments

Given that Optra Prism processes sensitive developer telemetry and AI interaction data, we make the following commitments:

5.1 No Model Training. We do not use Customer Data to train, fine-tune, develop, or improve any machine learning models — ours or any third party's. This applies during and after your use of the Service.

5.2 Purpose Limitation. Customer Data is processed exclusively to: (a) provide the Service to you, (b) generate PRISM Scores and intelligence outputs for your account, (c) comply with legal obligations.

5.3 Third-Party LLM Processing. When LLM-powered features are enabled (e.g., LLM PRISM scoring, insights reports), conversation data needed for evaluation and explanation, including developer prompts, assistant responses, and tool inputs, results, and errors, may be processed by:

  • AWS (Amazon Bedrock) — Anthropic Claude and OpenAI-family models made available through Amazon Bedrock, processed within AWS Regions in the United States. Prompt data is not sent directly to Anthropic or OpenAI. This processing is governed by the AWS Service Terms and the applicable model's Amazon Bedrock terms. Under those terms and AWS's published Amazon Bedrock data policies, AWS does not use Amazon Bedrock inputs or outputs to train models and does not share them with the model providers. AWS may retain flagged inputs and outputs for a limited period for abuse detection, as described in those policies.

LLM-powered processing is an integral part of the Service and cannot currently be disabled on a per-account basis. You can stop new prompt data from being sent at any time by removing the Plugin from your installation; this does not delete data already collected.

5.4 Data Isolation. Customer Data is logically separated by organization, and access within the Platform is restricted to authorized members of that organization. Within your organization, authorized team viewers can see member-level activity, scores, grades, and reports as described in the Documentation; a personal report being separate does not mean all information about an individual is hidden from the team.

5.5 Encryption and Key Handling. Customer Data is encrypted in transit using TLS 1.2 or higher. Prism keys (prism_*), the per-developer credentials that authenticate the Plugin to the Service, are stored only as one-way cryptographic hashes; the plaintext is shown only in the creation or rotation response and cannot be retrieved later. Lost keys must be rotated. Existing authentication digests are preserved.

6. How We Share Information

We share information only in the following circumstances:

6.1 Service Providers (Sub-processors)

We use the following categories of service providers who process data on our behalf:

ProviderPurposeData Processed
AWS (Amazon Web Services)Cloud infrastructure, storage, and compute in AWS US West (Oregon), us-west-2; AI inference via Amazon Bedrock within the United StatesCustomer Data (encrypted), Operational Metadata
PostHogProduct analytics, interaction autocapture, and session replay in deployments configured for analytics; the default collection endpoint is in the United StatesUser and organization identifiers, account properties including email and name, product events, interactions, and masked session replay data

All sub-processors are bound by data processing terms. The table above is our current list, and we update it when it changes.

6.2 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request. We will notify you before disclosure unless legally prohibited, and will challenge overly broad requests.

6.3 Business Transfers

In connection with a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity. We will notify you before your information becomes subject to a different privacy policy.

6.4 With Your Consent

We may share information with third parties when you explicitly direct us to do so (e.g., integrations you configure).

6.5 Aggregate Data

We may share Aggregate Data (de-identified, anonymized, non-attributable) with third parties for research, benchmarking, or industry reports. Aggregate Data cannot reasonably be used to identify you or any individual.

We do NOT:

  • Sell Personal Data
  • Share Personal Data with advertising networks
  • Provide Personal Data to data brokers

7. Data Retention

We retain Personal Data and Customer Data for as long as your account is active and as needed to provide the Service, resolve disputes, and meet legal, tax, and security obligations. When data is no longer needed for these purposes, or when you or your organization ask us to delete it, we delete or anonymize it without undue delay and within any period required by applicable law. Copies in backups are overwritten on our backup cycle and are not restored to production except for disaster recovery. Retention periods for specific data categories may be published as we formalize them.

Aggregate Data that cannot reasonably identify you or any individual may be retained indefinitely.

8. Your Rights

8.1 All Users

Regardless of location, you may:

  • View your account data and Customer Data in the Dashboard
  • Request a copy of your data, correction of inaccurate data, or deletion of your account and associated data by contacting privacy@optra-prism.com
  • Stop new data collection at any time by removing the Plugin from your installation

We respond to verified requests without undue delay and within the period required by applicable law.

8.2 EEA/UK Users (GDPR)

If you are in the EEA or UK, you additionally have the right to:

  • Access: Request a copy of your Personal Data in a structured, commonly used, machine-readable format
  • Rectification: Request correction of inaccurate Personal Data
  • Erasure: Request deletion of your Personal Data ("right to be forgotten")
  • Restriction: Request that we limit processing of your Personal Data
  • Portability: Receive your Personal Data in a portable format and transmit it to another controller
  • Object: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time for consent-based processing
  • Lodge a Complaint: File a complaint with your local supervisory authority

To exercise these rights, contact privacy@optra-prism.com. We will respond within the period required by applicable law.

8.3 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know: Request disclosure of Personal Information collected, used, and shared in the past 12 months
  • Delete: Request deletion of your Personal Information
  • Correct: Request correction of inaccurate Personal Information
  • Opt Out of Sale/Sharing: We do not sell or share Personal Information for cross-context behavioral advertising. No opt-out is necessary
  • Non-Discrimination: We will not discriminate against you for exercising your rights

Categories of Personal Information Collected (past 12 months):

CategoryCollectedSoldShared for Ads
Identifiers (name, email, IP)YesNoNo
Commercial information (billing)YesNoNo
Internet activity (usage data)YesNoNo
Professional information (organization)YesNoNo
Geolocation (IP-derived, approximate)YesNoNo

To exercise these rights, contact privacy@optra-prism.com.

8.4 Other Jurisdictions

We respect privacy rights under applicable laws worldwide, including but not limited to Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act. Contact privacy@optra-prism.com to exercise your rights under local law.

9. Cookies and Tracking

9.1 Types of Cookies

TypePurposeExamples
Strictly NecessaryAuthentication, security, session managementSupabase auth cookies (sb-*-auth-token*), CSRF tokens
FunctionalUser preferences, theme, localeDashboard settings, theme preference
AnalyticsUsage patterns, feature adoption, session replayPostHog (ph_* cookies and browser storage; data hosted in the United States)

9.2 Managing Cookies

  • Browser Controls: You can block or delete cookies via your browser settings. Blocking strictly necessary cookies may impair functionality.

9.3 No Advertising Cookies

We do not use advertising cookies, tracking pixels for ad networks, or cross-site tracking technologies. We do not participate in real-time bidding or ad exchanges.

10. International Data Transfers

Customer Data is stored and processed in the United States. Its primary storage Region is AWS US West (Oregon), us-west-2. AI inference for LLM-powered features runs through Amazon Bedrock using a US geographic inference profile, which may route requests across AWS Regions within the United States. If you are located outside the United States:

  • EEA/UK and other jurisdictions that restrict international transfers: We transfer Personal Data only where a lawful transfer mechanism applies, such as an adequacy decision or approved contractual safeguards, together with technical measures such as encryption in transit and access controls.
  • Other Jurisdictions: We implement appropriate safeguards as required by applicable law.

We are evaluating EU data residency options. Contact sales@optra-prism.com for current availability.

11. Data Security

We maintain administrative, technical, and physical safeguards designed to protect Personal Data and Customer Data against unauthorized access, loss, or alteration. These include encryption of data in transit, role-based access to production systems, organization-level access controls within the Platform, storage of Prism keys as one-way hashes, and logging of security-relevant events. We review and update these measures periodically.

No system is completely secure. If you discover a vulnerability, please report it to security@optra-prism.com.

12. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children. If we learn that we have inadvertently collected Personal Data from a child under 18, we will promptly delete it. Contact privacy@optra-prism.com if you believe we have collected data from a minor.

13. Third-Party Links and Integrations

The Service may contain links to third-party websites or integrate with third-party services (e.g., GitHub, IDE extensions). We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website with a revised "Last Updated" date
  • Sending an email notification to the address on your account, or displaying a notice in the Dashboard

Material changes take effect 30 days after notification. Continued use of the Service after the effective date constitutes acceptance. If you disagree with a material change, you may terminate your account.

15. Contact Us

For privacy-related inquiries, data subject requests, or complaints:

Grumatic, Inc. Email: privacy@optra-prism.com Legal documents: dashboard.optra-prism.com/terms, dashboard.optra-prism.com/privacy

For unresolved concerns, you may contact your local data protection authority.


Appendix: Data Flow Summary

Developer Machine │ ├── Claude Code Plugin ──→ Ingest Service (ingest.optra-prism.com) │ (prompts, telemetry) │ │ ├── Auth: validates Prism key (prism_*) │ ├── NATS JetStream (publish) │ │ │ │ │ Prism API and Worker services (internal) │ │ ├── NATS → S3 (NDJSON/Zstd raw archive) │ │ ├── Scoring, identity, report state → Postgres │ │ └── Raw signals → ClickHouse → Query API │ │ └── Dashboard (dashboard.optra-prism.com) ◄──┘── API responses (scores, analytics) (view scores, analytics) Storage: AWS US West (Oregon), us-west-2. AI inference: Amazon Bedrock, US geographic inference profile. All data encrypted in transit (TLS 1.2+) and at rest (AES-256). Customer Data isolated per organization. No cross-customer access.

Change History

DateSummary
September 14, 2026Corrected data residency and AI processing descriptions (AWS us-west-2 storage; Amazon Bedrock in the United States); corrected the sub-processor table and authentication provider description; itemized Plugin collection (project context, committed changes, agent activity, developer identifier) and team-level visibility; disclosed PostHog product analytics and session replay; replaced the fixed retention table with purpose-based retention; revised rights-exercise methods and security description to reflect current practice; removed the Do Not Track statement, the LLM opt-out statement, and placeholders; updated international transfer wording and service domains. Effective immediately upon publication.
April 4, 2026Initial version.