Effective and last updated: 30 July 2026
Extension-specific privacy policy
Published by Selfhood Studios
Prism privacy policy.
This policy applies only to Prism — AI Website Audit & Inspector, version 1.0.0. It explains what user data the extension handles, how the data is collected and used, where it is stored, how long it is retained, and every party it may be shared with.
- Extension version
- 1.0.0
- Selfhood account
- Not required
- Policy scope
- Prism only
Scope
This page is the complete, extension-specific privacy disclosure for Prism. It does not describe another Selfhood Studios extension. The studio-wide policy remains available at /privacy.
Prism requires no Selfhood Studios account. Extension data is processed locally unless a feature you deliberately use needs to contact a destination identified in the sharing section below.
Prominent disclosure before page data is handled
Prism reads and analyses data from websites you inspect. Most auditing stays in your browser. Cloud AI is optional, but once valid cloud-provider credentials are configured, a user-started audit automatically sends audit and page context to that provider for an executive summary; other AI transfers occur when you send a chat or invoke an AI-labelled action.
Handled locally
- Current page address and title; visible text and metadata; headings, links, forms, selectors, attributes, DOM and HTML snippets.
- Accessibility roles, names and tree structure; computed styles, tokens and layout; resources, timing data and Core Web Vitals.
- Audit findings and scores, muted issues, preview edits, layout fingerprints, and optional screenshots or element crops.
- Audit history, settings, provider configuration, custom endpoint, model choice, and the API key you save.
Sent to your AI endpoint
- The prompt, conversation and system instructions for the AI action.
- The page address, title, compact page context, audit findings, selected DOM or accessibility evidence, style and token evidence, and tool results relevant to the request.
- Visible-page screenshots, viewport captures or element crops only for a vision, responsive, component-generation, or visual-comparison action that needs them.
- Your provider credential and ordinary connection metadata required to make the direct request.
When a transfer starts: Remote transfer begins after you configure a provider and take a related action: running an audit triggers the automatic AI summary; sending chat, choosing deep analysis, requesting vision or responsive critique, generating a component, or requesting an AI visual comparison triggers that specific request. Local audits still work without any AI provider.
Data collected or handled
Prism handles the address and title of the page being inspected; page text excerpts, headings, links, forms, metadata, structured-data types, selectors, attributes, DOM and HTML snippets, accessibility roles and names, computed styles, design tokens, layout fingerprints, resource and timing information, Core Web Vitals, and visible-page or element screenshots when the selected feature needs them. It also handles audit findings and scores, muted-issue rules, preview edits, fix packs, exported reports, audit-history metadata, chat prompts and responses, AI tool traces, provider and model settings, custom endpoint addresses, and any provider API key you choose to save.
How collection occurs
Prism's declared content scripts match ordinary pages at <all_urls>. The vitals script starts at document_start and observes current-page performance measurements in memory; the main page bridge loads at document_idle. A full audit, element inspection, accessibility-tree read, token extraction, viewport capture, screenshot, preview edit, export, or AI tool read occurs when you open Prism and invoke the relevant user-facing workflow. Prism reads active-tab details through the tabs capability and does not request the chrome.history API. Running an audit saves a local history entry unless storage fails. If usable AI credentials are already configured, completing that user-started audit also automatically requests an executive summary from the configured provider. Chat sends what you type and, while the Attach page context setting is enabled, a compact current-page context summary. Vision, deep-analysis, responsive-critique, component-generation, and visual-history actions can additionally attach screenshots, element crops, audit evidence, or tool results.
Permission-by-permission use
These are the Chrome capabilities declared by this extension and the narrow product purpose assigned to each one.
| Permission | Access and purpose | When used |
|---|---|---|
| Host access: <all_urls> | Allows Prism's page bridge and performance observer to run on ordinary websites and lets the extension read the rendered page needed for an audit or inspection. Audit the current site, inspect DOM and accessibility evidence, extract tokens, preview fixes, and collect current-page vitals. | The scripts load on matching pages; full page reads and changes are driven by the Prism workflow you invoke. Chrome-protected pages remain unavailable. |
| tabs | Reads the active tab identifier, address, title, window, and navigation state and coordinates actions with the inspected tab. Bind audits, history, inspection, screenshots, and page tools to the correct tab and update Prism after navigation. | Used while Prism is open or a Prism action needs the current tab. Prism does not request the separate browsing-history permission. |
| scripting | Can inject Prism's disclosed page bridge into the active page when it is not already available. Make user-requested audits and inspection tools work after extension updates, restricted injection failures, or page lifecycle changes. | Used as needed for a Prism action on the active tab. |
| storage | Stores settings, provider configuration and keys, muted issues, and audit-history metadata inside the extension's Chrome profile storage. Remember your setup and preserve local audit history and privacy controls. | Used when settings or history are read, changed, saved, or deleted. |
| debugger | Temporarily attaches through the Chrome DevTools Protocol to emulate requested device dimensions and capture viewport results. Provide the user-invoked multi-breakpoint Viewport Studio workflow. | Version 0.3.0 requests this permission at installation, but Prism attaches only while you run Viewport Studio and detaches after the capture workflow. |
| sidePanel | Displays Prism's audit and inspection workbench next to the page. Keep findings, chat, tokens, and tools visible while you work on the site. | Used when you open Prism from the toolbar, shortcut, or supported browser UI. |
How data is used
Prism uses this information only to audit accessibility, UX, SEO, performance, and security; measure page vitals; inspect elements and accessibility structure; extract and export design tokens; preview reversible fixes; generate and export audit reports or fix packs; preserve and compare audit history and visual regressions; emulate requested viewport sizes; and provide the AI summary, chat, vision, analysis, or code-generation action you request. It is not used for advertising, unrelated profiling, credit or eligibility decisions, resale, or data-broker services.
The data is not used for personalized advertising, unrelated profiling, credit or eligibility decisions, resale, or data-broker services.
Handling and storage
Rule-based analysis runs in the inspected page and extension contexts. Prism stores settings, provider configurations and API keys, muted findings, and up to 60 audit-history entries in chrome.storage.local in the Chrome profile where it is installed. Compressed visual-history screenshots are stored in the extension's IndexedDB database with a least-recently-used limit of 10 screenshots per website origin. Current chat state, tool traces, live performance readings, page context, element-inspection results, and unapplied preview state are generally held in extension or page memory for the active session. The theme bootstrap also reads the prism-theme value from extension localStorage. Prism has no Selfhood Studios application backend, account, sync, analytics, advertising, or telemetry service. API keys and other locally stored values are not separately encrypted by Prism; they rely on Chrome-profile, operating-system, and device security.
Selfhood Studios cannot inspect, recover, or restore data that remains only in your browser profile.
Retention and deletion
Audit history is capped at the newest 60 entries. Visual-history screenshots are capped at 10 per website origin and the least recently accessed capture is evicted when that limit is exceeded. You can delete an individual history entry, clear all history and its linked captures, clear muted issues, reset settings, or remove saved provider credentials in Prism. Session-only page context, chat state, tool traces, inspection data, and performance observations are discarded when the relevant extension or page context closes, reloads, or is replaced. Other local settings remain until you reset or delete them or uninstall Prism. A copy already sent to an AI provider or custom endpoint follows that recipient's account settings, contract, logs, and privacy and retention policies; Selfhood Studios cannot retrieve or delete that copy.
Before uninstalling, use the extension's delete, clear, reset, or export controls where available. Uninstalling normally removes browser-managed extension storage from that Chrome profile.
Your privacy controls
You control whether optional remote processing is configured and can reduce, remove, or avoid the data handled by the extension:
- Use Prism without adding an AI key to keep rule-based audits, inspection, tokens, exports, and history on-device.
- Choose a compatible local custom endpoint and enable local heavy mode to route AI calls to that local endpoint instead of a cloud provider.
- Turn off Attach page context before sending chat if you do not want the compact page summary included; avoid vision and screenshot actions when an image is not needed.
- Remove a saved API key, change the active provider or endpoint, clear muted issues, delete one history entry, clear all audit history, reset settings, or uninstall Prism.
- Do not inspect pages containing secrets or personal data you do not want Prism to handle, and review the receiving provider's policy before enabling cloud AI.
What the extension does not collect or do
- Prism does not create a Selfhood Studios account or send audit data, page content, credentials, or history to a Selfhood Studios backend.
- Prism does not include Selfhood analytics, advertising, telemetry, session replay, or cross-site tracking.
- Prism does not request Chrome's browsing-history permission and does not read a blanket list of previously visited pages.
- Prism does not sell data, share it with data brokers, or use it for personalized advertising, eligibility decisions, or unrelated profiling.
Security
Remote requests containing user data or credentials use secure transport such as HTTPS or WSS, except a user-configured service that is deliberately hosted on the same device or private network. Authentication information is not publicly disclosed.
Local data relies on Chrome's extension isolation and the security of your Chrome profile, operating system, and device. No security measure is absolute; protect your device account and revoke a provider credential if you believe it has been exposed.
Chrome Web Store Limited Use disclosure
User data is used only to provide or improve Prism's disclosed single purpose and user-facing features. Selfhood Studios does not permit personnel or contractors to read extension data. Routine human access is not possible because Selfhood Studios does not receive extension content.
The limited exceptions are when you explicitly send specific data for support, access is necessary to investigate security or abuse, disclosure is required by law, or data is first aggregated and anonymized for lawful internal operations.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Notice, choices, and contact
Where a feature sends data to a third party, the transfer must be disclosed before it begins and occur only after an affirmative user action. You can avoid the transfer by not invoking or enabling that optional feature, and you can remove local data through the controls described above.
Analytics on this marketing website are separate from the extension and cannot access its stored content. Website practices are explained in the studio-wide privacy policy.
For a privacy question, rights request, or security report, contact Selfhood Studios. Do not send API keys or unrelated private content.