Legal

App Privacy Notice

1. Who we are

Prism Labs operates Toggle AI and is the controller (개인정보처리자 / controller) for everything described here.

Our Privacy Officer (개인정보 보호책임자, PIPA §31) is:

You can raise any question about this notice, or make any request under §9, at that address.

2. What this notice covers

This notice applies to the Toggle AI application served from toggle-app.prismlab.dev: signing up, logging in, and everything you do inside the product.

It does not cover the marketing website at prismlab.dev — the landing page, the team profiles and the privacy policy itself. Those are covered by the website privacy policy, which uses a different analytics setup and a consent banner this app does not have.

3. What we collect

3.1 Your account

To create an account we ask for an email address and a password, and you may be asked for an invite code while the product is closed. You may add a display name; it is optional and may be left empty.

We never store your password. What is stored is a scrypt hash of it, which cannot be turned back into the password you chose.

3.2 What you create in the product

Toggle AI exists to keep your thinking, so it keeps it. Stored against your account:

Quotes are not stored. A passage you stage to carry into your next question lives only in your browser and is consumed when you send. It is never written to our database.

3.3 How you use it

We record structural events — a Node created, a Thread opened, a Pin added, a quote used, navigation between Threads — with the ids of what you acted on and the time. These describe the shape of how you work, which is the thing Toggle AI is built to help with. They are stored now and analysed later; nothing in the product acts on them today.

3.4 What each answer cost

For every model call we record the model used and the number of tokens it consumed, and compute a price from them. This is how we know what the product costs to run. It is counts and names — no part of your conversation is kept in it.

3.5 Product analytics

Toggle AI is a closed beta, and while it is, usage analytics is part of taking part. Observing how the product is actually used is what a beta is for, so for participants this is a condition of the programme rather than a setting — we tell you, and leaving the programme is how you stop it. We are not asking for your consent to it, because a "choice" you cannot decline would not be one. Our basis is set out in §4.

When Toggle AI opens to everyone, this becomes a question instead. General users are asked, and may say no — the product works identically either way and no feature is withheld for refusing. Accounts that joined during the beta keep the basis they joined under.

Either way we use Mixpanel to count a fixed list of actions. The list is exhaustive — it is the whole of what we send, and it is set out here rather than summarised, because you are entitled to know precisely what is counted before you decide whether to take part.

Three things are true of all of it and worth stating plainly:

4. Why we use it, and on what legal basis

Where the basis is consent, refusing costs you nothing: the product works identically without analytics, and no feature is withheld for saying no. Where the basis is legitimate interests you may object (GDPR Art. 21) — write to us and we will stop, or you can leave the beta programme; a Global Privacy Control signal from your browser is treated as an objection automatically.

5. What is kept in your browser

The app sets no cookies. It uses your browser's local storage, which is not attached to any request and is not sent to us unless the app deliberately reads it:

Logging out removes the session token and your account details. Clearing site data in your browser removes all of it; you will be logged out and asked about analytics again.

6. Who else is involved

6.1 AI model providers — this is the important one

When you send a question, it is sent to the provider of the model you chose so that it can be answered. Today those are Anthropic and xAI.

What is sent is more than the sentence you typed, and you should know the shape of it:

Nothing crosses a Workspace boundary. A different Workspace's contents are never included.

We use each provider's commercial API, not its consumer product, and the two are governed by different terms. Under the API terms, as of 15 September 2026:

So the answer to the question people actually ask — is my conversation training someone else's model? — is no for Anthropic and xAI, by contract and not by courtesy. Neither keeps it beyond 30 days in the ordinary case.

These are their terms, not ours, and they can change them. This notice states what they said on the date above; the provider's current policy governs.

6.2 Everyone else

We sell nothing to anyone, and we run no advertising.

6.3 What the analysis copy contains, exactly

We copy part of the database to BigQuery so we can answer questions about how the product is used and what it costs. What crosses is deliberately narrow: ids, timestamps, tree depths, highlight offsets, counts, token usage, computed cost, statuses, colours, and the character lengths of text fields.

What never crosses, and cannot:

This is enforced by the shape of the code rather than by care: the types that describe an exported row have no field able to hold text content, so adding one would be a visible change to the program rather than a quiet widening of a query.

7. Sending data outside Korea

Toggle AI runs in the United States. If you are in Korea, everything in this notice is an overseas transfer under PIPA §28-8; if you are in the EEA or the UK, it is a transfer under GDPR Chapter V.

The safeguards. Each of these processors incorporates its data-processing terms into the agreement automatically, rather than by a separately negotiated signature, and each carries the EU Standard Contractual Clauses for transfers out of the EEA and the UK Addendum for transfers out of the UK:

Each of these keeps what it receives for as long as its own policy says — for the model providers, §6.1 has the figures. You may refuse the transfer to Mixpanel and keep using the product; you cannot refuse the transfer to AWS or to a model provider and still use it, because there is no product without them — under PIPA §28-8(1) those transfers are necessary to perform the contract you are entering.

8. How long we keep it

While your account exists, we keep what you made. That is the point of the product: a Thread you branched in March is expected to be there in September.

Deleting inside the product hides, it does not erase. When you delete a Workspace, a Node or a Pin, it is marked deleted and stops being shown to you, but the row remains in the database. We are telling you this because the word "delete" in the interface would otherwise imply something stronger than what happens.

Deleting your ACCOUNT does erase. Account → Delete account removes the account row and everything reachable from it — every Workspace, Node, Thread, Turn, Pin, attachment, produced file, structural event and usage record — permanently, in one transaction, with no soft-delete flag left behind and no backup to restore from. It asks for your password as well as your email address, because a signed-in session alone should not be able to do something irreversible. If you would rather we did it, ask (ringo@prismlab.dev) and we will do it by hand and confirm when it is done.

Two things are kept on their own clocks: a produced file that could never be fetched is given up on after 24 hours, and records of what each model call cost are kept for accounting.

9. Your rights

Whatever country you are in, you can ask us to:

Email ringo@prismlab.dev. We will answer within 10 days (PIPA) or one month (GDPR), whichever is shorter for you, and we will not charge you for it.

Asking us to erase your account does not reach the model providers: what was sent to answer a question is held under their terms, and we cannot delete it on your behalf. §6.1 says who to approach.

10. Children

Toggle AI is not for children. We do not knowingly create accounts for anyone under 14 (Korea) or under 16 (EEA). If you believe a child has an account, write to us and we will remove it.

11. Security

No system is perfect. If we ever lose control of personal data in a way that puts you at risk, we will tell you and the regulator, as PIPA §34 and GDPR Arts. 33–34 require.

12. Complaints

Tell us first — ringo@prismlab.dev — and we will try to put it right. You do not have to go through us, though:

13. Changes to this notice

If we change it we will post the new version here and move the "last updated" date. If a change means collecting something new, or sending it somewhere new, we will tell you in the product before it starts — not after.