Legal

Privacy Policy

Version 2026-09-22In force from 22 September 2026Covers holoprism.ai and platform.holoprism.ai

The short version

  • We use your Google account only to sign you in. We keep your email address and your name, and nothing else from Google.
  • The areas you set up belong to your account. Other users cannot see them.
  • No advertising, no analytics, no tracking cookies. We do not sell data.
  • The words you type to set up an area go to the guide (Claude on Amazon Bedrock, in the EU) and to search services, without your name or email address.
  • You can download everything we hold about you, or delete your account, at any time under Account in the platform.

1Who we are

Holoprism is operated by Metamatics Ventures, Prague, Czech Republic (“we”, “us”). We are the controller of the personal data described in this policy.

Contact for anything about privacy: support@metamatics.ventures.

2The website

The website at holoprism.ai sets no cookies, runs no analytics and has no form that sends anything to us. The box that asks what you want to follow stays in your browser: it only changes the page you are reading.

The website is delivered by Amazon CloudFront. We do not keep access logs for it.

It loads nothing from other services: its text uses your device’s own system font, and its images come from holoprism.ai itself.

3What the platform keeps

The platform at platform.holoprism.ai requires signing in with Google. It keeps the following:

DataWhyKept
Email address and name, from Google when you sign inTo sign you in, tell accounts apart, show you who you are signed in asUntil you delete your account
Account record: a random account id, when the account was created and last used, which version of the terms you accepted and whenTo run the account and to show what you agreed toUntil you delete your account
What you set up: the areas you describe, their scope, terms, signals and questions, the sources you choose, and your setup searchesThis is the service: it is what Holoprism watches for youUntil you remove the area or delete your account
What your areas collect: items published by the sources (headlines, links, short excerpts, dates) and snapshots of what was readTo show you what changed and to trace every item to its sourceWhile an area follows the source
Signatures: the name you type when you sign a digest, the time, and a hash of what you signedA record of who approved what, and whenUntil you remove the area or delete your account
Usage counts: guide runs, runs by hand, and paid searches with their estimated costTo apply the limits of each account and to keep costs under controlUntil you delete your account
Audit record: what was done and when, under your random account id, never your email addressSo that evidence and decisions in Holoprism can be checked laterEntries stay, but lose everything that points to you when you delete your account
Technical logs on the server: time, page requested, browser type, and sign-in events with the account’s email addressSecurity and fixing faults30 days
Backups: a nightly copy of the databaseTo recover from a failure30 days

We do not ask for, and ask you not to enter, sensitive or confidential information. Areas are meant to describe public topics, not people.

4Your Google account

Signing in uses Google’s basic sign-in permissions: your email address and your basic profile. We do not request access to Gmail, Drive, Calendar, Contacts or any other Google service, and we never see your Google password.

From what Google sends, we store only your email address and your name. The sign-in token also carries your profile picture address and a Google account identifier; those stay inside the encrypted session cookie in your browser and are not stored on our servers.

We use this information only to sign you in and to identify your account. We do not use it for advertising, we do not sell it or transfer it to anyone, and nobody reads it except when you ask us for help, for security, or when the law requires it.

Holoprism’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5Cookies and browser storage

The platform uses only what signing in needs:

  • _holoprism: your sign-in session. Encrypted, sent only over HTTPS, unreadable by page scripts, and valid for up to 30 days or until you sign out.
  • _holoprism_csrf: set only while you sign in, to stop forged sign-ins. It expires within minutes.

The platform also keeps two things in your browser’s local storage, which never reach us unless you use them: the name you type under “Signing as”, and edits to an area you have not finished setting up. They are cleared when you delete your account, and you can clear them in your browser at any time.

Because these are strictly necessary for the service you asked for, there is no cookie banner.

6Who else receives data

Service providers that process data for us

  • Amazon Web Services (AWS EMEA SARL, Luxembourg) hosts the platform, its database and backups in Frankfurt, delivers the website, and runs the guide: Anthropic’s Claude on Amazon Bedrock, within the EU. The guide receives the words you type to set up an area, headlines found for it and your requests to it, never your name or email address. Amazon Bedrock does not use them to train models and does not share them with the model’s maker.
  • Google handles sign-in, under its own terms and privacy policy.

Search services

To find and watch sources for an area, our server sends its search terms to Google News, arXiv, Hacker News (through hnrss.org), Reddit and GitHub. Paid searches of the web, X and YouTube go through Apify (Apify Technologies s.r.o., Prague), which runs them on those services. These services receive the search terms from our server, not your name, email address or IP address. Some of them are in the United States, so do not put personal information in an area’s description or terms.

The sources your areas follow

Our server fetches them. They see our server, not you.

Administrators

Other users cannot see your areas. Our administrators can, to run the service, answer your requests and stop abuse.

Nobody else

We do not sell or rent personal data and work with no advertising networks. We disclose data to authorities only when the law requires it.

7Where data is kept

Your account, your areas and everything they collect are kept in the European Union, in AWS’s Frankfurt region, and so are the backups. The guide runs on Amazon Bedrock within EU regions.

Data leaves the EU in two cases: search terms sent to the search services above, which carry no personal data unless you type some into them; and sign-in with Google, which Google processes under its own safeguards for international transfers.

8Why we are allowed to

Under the EU General Data Protection Regulation (GDPR):

  • To provide the service you signed up for (Art. 6(1)(b)): your account, sign-in, your areas and what they collect, your signatures.
  • Our legitimate interests (Art. 6(1)(f)): keeping the service secure and working (logs, backups), applying fair-use limits, keeping an audit record that can be checked, and collecting publicly available information for the areas users follow.
  • Legal obligations (Art. 6(1)(c)): where the law requires us to keep or disclose data.

9How long we keep it

  • Your account and everything you set up: until you delete them. Deleting your account removes them from the live database at once.
  • A source that another user’s area also follows stays for them, without your name.
  • Audit-record entries keep their date and the kind of action, and lose everything that points to you.
  • Technical logs and backups: 30 days. Anything you delete disappears from backups within 30 days.

10People named in sources

Holoprism collects what public sources publish: news, registers, feeds, research. Headlines and excerpts can name people. We keep them only as part of an area that follows the source, always with a link to where they were published, and we do not build profiles of individuals.

If you are named in something Holoprism has collected and want to object or ask for removal, write to support@metamatics.ventures.

11Your rights

You have the right to access your data, get a copy of it, have it corrected or deleted, restrict or object to how it is used, and take it elsewhere. Two of these are built into the platform, under Account:

  • Download my data: a copy of everything we hold about you, as a JSON file.
  • Delete your account: removes your account, your areas, your searches and what they collected.

For anything else, write to support@metamatics.ventures. We answer within one month.

You can also complain to a data protection authority: in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or the authority where you live or work.

12Security

  • Every connection uses HTTPS. The platform cannot be reached without signing in, and the application itself accepts no connections from outside the server.
  • Each account reaches only its own areas.
  • Keys and secrets are kept in AWS’s parameter store, not in code. Administrators reach the server only through AWS’s managed access; remote shell logins are switched off.

No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities as the law requires.

13Age

Holoprism is for people aged 18 or over. If we learn that an account belongs to someone younger, we delete it.

14Changes to this policy

Each version is dated at the top of this page. When we change it, the platform asks you to read and accept the new version before you continue. Earlier versions are available on request.

15Contact

Metamatics Ventures, Prague, Czech Republic
support@metamatics.ventures

See also the Terms of Service.