DeciTerra by PrismLab

Privacy Policy

Effective date:

DeciTerra is a structured decision-support app developed and operated by Shuo Li under the PrismLab brand. This policy explains how local decision data, optional product analytics, subscriptions, and correspondence are handled in the current V1 release.

1. Local project and decision data

DeciTerra does not require or provide a user account in the current V1 release.

DeciTerra processes project and decision content locally on your device for the product workflow. Local content may include project and case names, descriptions, decision facts, evidence, financial or operating values, generated risk outputs, responses, revisions, and other information you choose to enter.

This project and decision content is not sent to PostHog. Decision cases and generated responses remain in the app’s local storage. The current V1 release does not provide a DeciTerra-operated project-data backend or cloud synchronization service.

2. Optional product analytics

DeciTerra uses PostHog Cloud US for optional product analytics. Analytics is off by default: no optional analytics is sent while your choice is Not Chosen or Disabled. Optional analytics begins only after you explicitly choose Enabled in the app.

When enabled, DeciTerra may send an app-specific anonymous analytics identifier, fixed allowlisted product events, and coarse allowlisted properties such as Scenario Pack, broad team-size or role categories, decision stage, coarse commitment band, conversion basis and table version, fixed paywall entry point, and a Sandbox or Production environment label.

Optional analytics is not required for the app. Turning it off does not affect the core Free flow, purchased Pro functionality, or subscription entitlement processing. Analytics delivery failures do not prevent the Free or Pro workflow; failed optional events are discarded.

3. Analytics exclusions and safeguards

Optional analytics does not include project names, case names, descriptions, free text, evidence, complete cases, detailed risk outputs, exact local financial values, exact purchasing-power-equivalent values, email addresses, or personal identity. RevenueCat and PostHog do not receive project or decision content through this analytics flow.

DeciTerra does not use optional analytics for advertising, does not sell user data, does not use IDFA profiling, and does not track you across other companies’ apps or websites. The V1 analytics implementation does not use session replay, screenshots, screen recording, autocapture, advertising identifiers, or broad location collection.

Production validation has confirmed that retained approved events do not contain raw IP addresses or GeoIP/location enrichment.

4. RevenueCat and Apple App Store

RevenueCat is used narrowly to support DeciTerra Pro subscription and entitlement processing. RevenueCat does not receive your project or decision content through that integration.

Purchases and subscription payments are processed through Apple’s App Store infrastructure. PrismLab does not directly process your App Store payment-card information. Apple and RevenueCat handle purchase and entitlement information needed to provide purchased access under their respective terms and privacy practices.

Necessary subscription and entitlement processing is separate from optional analytics. Turning analytics off does not cancel an Apple subscription or disable entitlement verification.

5. Support and privacy correspondence

If you contact support@prismlab.studio or privacy@prismlab.studio, the information you choose to send is received and used to handle your support or privacy request. Send only the non-sensitive diagnostic or contextual information needed for the request. Do not send passwords, authentication codes, payment details, Apple credentials, private keys, confidential case content, or exact financial values.

6. Retention, choices, and deletion

Anonymous product analytics may be retained for up to 7 years, unless deleted earlier in response to a valid privacy request. Irreversibly aggregated, non-user-level statistics may be retained longer.

Analytics deletion is located using the DeciTerra app-specific anonymous analytics identifier—not your email address. A valid and locatable analytics deletion request targets processing within 30 days after the identifier is received. This is a processing target, not an unconditional guarantee.

Turning analytics off stops future optional analytics but does not automatically delete analytics previously collected. Resetting the anonymous analytics identifier creates a new identifier for future events; it is not deletion of historical analytics and does not delete local cases.

For instructions, visit Privacy Choices or email privacy@prismlab.studio.

7. Local retention and security

Local case data remains until you remove it, reset local content where available, or delete the app and its local data. Device or operating-system backups may retain copies according to your Apple and device backup settings.

DeciTerra relies on Apple platform protections, the app’s local sandbox, and HTTPS transport where network services are used. No storage or transmission method is risk-free. Avoid entering information you are not authorized to use or store.

8. Changes and contact

If DeciTerra’s features, processors, or data practices change, this policy will be updated and the effective date will identify the current version. Any notice or consent required by applicable law or Apple policy will be handled before a materially different practice takes effect.

Operator and developer: Shuo Li
Product: DeciTerra by PrismLab
Privacy contact: privacy@prismlab.studio

See also Privacy Choices and DeciTerra Support.