Last updated · April 25, 2026
Varity is a workflow tool. We collect the minimum required to run that workflow for you, and we never sell your data — to anyone, ever.
We collect three buckets of data, and only those three.
We use your data only to operate Varity on your behalf — to publish posts, render clips, run AI tools, deliver analytics, and bill you. We do not sell, rent, or share your data with advertisers, data brokers, or training partners.
We use a small, vetted set of sub-processors. We list them below; we update this list at least 30 days before adding a new sub-processor that handles workspace content.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Connected-account tokens and bring-your-own-key secrets are stored in an envelope-encrypted vault and only decrypted at the moment they are needed by a worker.
Drafts, schedules, analytics, and brand data live for the life of your workspace. Job logs and event logs are retained for 90 days. Deleted workspaces are purged from primary storage within 30 days and from backups within a further 60.
You can export, correct, or delete any data you put into Varity at any time. For workspaces operating under GDPR or CCPA, you can also request a structured data export, restrict processing, or object to specific processing activities — write to privacy@prism.app and we will respond within 30 days.
Varity is a B2B tool. It is not directed at children under 16 and we do not knowingly collect data from anyone under 16.
Privacy questions, sub-processor concerns, or data subject requests: privacy@prism.app. Security issues: security@prism.app. We answer both inboxes within two business days.
This page is informational and reflects how Varity currently operates. It is not legal advice and does not replace a customer agreement; enterprise customers receive a signed DPA and order form alongside these public terms.