How your data is used
What we collect, what we don't, and who sees it — in plain English.
PRISM collects only what's needed to build your report — your responses to assessment items and the timing data the cognitive games require to score correctly. Your responses are encrypted at rest in Firebase Firestore.
What we store
- Your email address (for sign-in and report delivery).
- The name you typed during sign-up, used to greet you.
- Your answers to the assessment items.
- Your scored report (29 dimensions + 5 career matches).
- An audit log of share events (created, viewed, revoked).
What we never store
- Identity documents, passport numbers, national IDs.
- Mouse-movement or eye-tracking data.
- Network identifiers beyond what Firebase needs for auth.
- Anything we'd be embarrassed to explain to your mom.
Who sees what
By default, only you see your report. Firebase Security Rules are enforced server-side and audited per release — even our engineers can't read your responses without going through an admin tool that logs every access. When you share your report with an employer, they see the scored report (dimensions + career matches), never your raw item-level responses.
You can revoke any share at any time from your dashboard. Revocation takes effect on the next page load by the recipient.