Privacy Policy
Last updated: 1 September 2026
NNC Prism (“Prism”, “we”, “us”) is a social media analytics and reporting tool operated by National Network Communications (FZE), Sharjah Publishing City, L03, Sharjah, United Arab Emirates. We use Prism to produce monthly performance analytics and client-ready reports for the social media accounts that our agency manages on behalf of its clients.
This policy explains what data Prism handles, where it is stored, who we share it with, and how it can be removed. It describes Prism specifically — the internal application at prism.nncpr.com — and not NNC’s wider services.
1. Whose data this policy covers
Prism is a business-to-business tool. It does not collect personal information from members of the public who visit the application, and it has no public sign-up. The data it handles falls into two groups:
- Managed client accounts. Published content and performance metrics belonging to the social media accounts NNC manages for its clients (for example a client’s Facebook Page, Instagram, X/Twitter, LinkedIn or TikTok account). This is the account’s own published material and its analytics — not data gathered from individual followers or commenters. Published posts and images may nonetheless reference or depict individuals; we process that content only as part of the account’s own published output.
- NNC staff users. The email address and authentication credentials of NNC employees who log in to Prism, and a log of the actions they take in the tool.
2. What we collect and where it comes from
Prism does not scrape or gather data directly from individuals. It retrieves analytics and published content for the managed accounts from the following sources, using credentials that NNC or its clients have authorized:
- Emplifi Public API — the primary source. Post content (captions, links, media type, publish time), post-level engagement metrics, daily account metrics, and Instagram stories and their metrics.
- Meta Graph API (Facebook & Instagram) — account-level reach figures, Instagram reposts, and a reconciliation of which posts still exist on the platform, used to keep our records accurate. Accessed through an NNC-owned Meta system-user credential.
- X (Twitter) API — for client X accounts that have been connected to Prism: tweet text, tweet engagement and video-view metrics, and account statistics such as follower and verified-follower counts. Connecting an account is an explicit, consent-based step (see section 6).
- Platform data exports — spreadsheet exports (e.g. an Emplifi “Feed” export for X) uploaded by NNC staff, and occasional metric values entered by hand where an API does not provide them.
For each post we store, we keep the caption text, permalink, media/content type, publish time, the platform’s own quality grade where provided, and the raw metric response for auditability. We do not collect the contact details, profiles, or private messages of the people who follow, like, or comment on these accounts; social-listening features are not enabled.
3. What we store
Prism stores, per managed account:
- Posts and stories — the post/story record including caption text, permalink and metadata (
posts,stories). - Engagement metrics — dated snapshots of post and story metrics (
post_metrics,story_metrics) and daily account metrics (metrics_daily). - Calculated monthly figures — the derived monthly totals used in reports, stored with their formula and component breakdown for audit (
calculated_monthly). - Cached post & story images — because platform image links expire, we download post and story thumbnails at sync time and keep our own copy in private storage.
- Generated reports and exports — the composed monthly report, including the AI-written narrative, and the exported PDF/PowerPoint files.
- Connected-account tokens — for connected X accounts, an encrypted refresh token (see section 6).
We also keep operational records: the client and account registry, NNC staff accounts and an activity log, and sync/import audit logs.
4. How we use the data
We use the data solely to operate Prism’s purpose: to calculate performance metrics and month-over-month comparisons, and to compose monthly analytics reports for the client whose accounts we manage. All figures in a report are computed by our own software; where a report includes written commentary, that narrative is generated by a third-party AI service as described next. We do not sell data, and we do not use it for advertising or profiling.
5. AI-generated report narrative (Google Gemini)
To write the narrative commentary in a report, Prism sends report data to a third-party large-language-model service. By default this is Google’s Gemini API (a model in the Gemini Flash family), operated by Google LLC. Prism can be configured to use Anthropic’s Claude API (Anthropic, PBC) instead; when it is, the same data is sent to Anthropic rather than Google.
The data sent for narration includes, for the report being generated:
- the client / account name and social handles;
- calculated performance metrics and their month-over-month history;
- post caption text and permalinks for the posts featured in the report; and
- any business-context notes that NNC account staff have entered for the client (e.g. campaign context or seasonality notes).
This data is sent only to generate the report’s written text. We do not send the raw authentication tokens or the underlying database to the AI provider.
Prism currently uses the free tier of the Gemini API. Under Google’s free-tier terms, Google may use the content submitted to the API — including, as listed above, post captions and business-context notes — to provide and improve its services, which can include human review and using the content to train Google’s models. If you would prefer that your data not be processed on these terms, contact us using the details in section 15.
6. Connected social accounts and access tokens
Some data is retrieved using NNC-owned platform credentials (Emplifi and the Meta system user); for these, no per-account login tokens are stored — Meta page tokens are held only in memory for the duration of a sync.
For X (Twitter), a client account can be connected to Prism through an explicit OAuth authorization (initiated by an NNC administrator or by the client via a single-use link). We store only the long-lived refresh token, and it is encrypted at rest (AES-256-GCM); short-lived access tokens are generated in memory when needed and are never written to the database. A connection can be revoked at any time from the portal, which deletes the stored token.
7. Where data is stored
- Database: a managed PostgreSQL database hosted on Supabase, in the Sydney, Australia region (ap-southeast-2).
- File storage: cached post/story images and exported report files are stored in private Supabase Storage buckets, served only via short-lived signed URLs.
- Application hosting: the Prism application runs on Vercel.
- Exported reports: when a report is exported as slides, the PowerPoint is uploaded to a Google Workspace shared drive (as a Google Slides file) so NNC staff can deliver it to the client.
8. Service providers we share data with
We share data only with the service providers that operate or support Prism. We do not sell data or share it with advertisers.
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, file storage, authentication | All stored data (see sections 3–7) |
| Vercel | Application hosting | Data in transit as the app runs |
| Google LLC (Gemini API) | AI report narrative | Report metrics, post captions, handles, context notes (section 5) |
| Google Workspace (Drive/Slides) | Delivering exported report decks | The exported report: name, metrics, post images, captions, links |
| Anthropic, PBC (Claude API) | AI report narrative (alternative to Gemini, when configured) | Same as Gemini (section 5) |
| Meta Platforms | Recovering expired post thumbnails (oEmbed) | The public post permalink only |
| X Corp. | Retrieving tweet metrics / recovering tweet images | Tweet identifiers; account authorization |
| Inngest | Background job scheduling | Job identifiers and dates only — no post content or metrics |
| Resend | Internal operational email | Internal import-review emails to NNC (post identifiers + counts; no captions) |
9. Cookies and tracking
Prism uses only strictly-necessary, first-party cookies: a session cookie to keep NNC staff signed in, and a short-lived state cookie used during the X account-connection handshake. We use no third-party analytics, advertising, or tracking technologies, and set no advertising cookies. Fonts are served from our own infrastructure, so viewing the app does not send requests to font or analytics providers.
10. How long we keep data
We retain the stored social media data (posts, metrics, daily and monthly figures, cached images, and generated reports) for as long as NNC manages the relevant client account. This is so we can produce month-over-month comparisons and keep an auditable record of how each reported figure was calculated. Prism does not automatically delete this data on a fixed schedule; where a post is removed from a report it is flagged as excluded rather than erased, so the audit trail is preserved.
When NNC stops managing an account, or on a verified deletion request, we remove the associated data as described in the next section.
11. Security and access
Access to Prism requires an individual authenticated account; administrative functions are restricted to staff with an administrator role. The database enforces row-level security, connected-account refresh tokens are encrypted at rest, and cached images and exported files are kept in private storage reachable only through short-lived signed links. Only authorized NNC staff can access client data — clients do not have direct logins to Prism.
12. Your choices and how to request removal
Because NNC manages these accounts on behalf of its clients, requests to access, correct, or delete data are normally made through the client’s NNC account manager, or by contacting us at m.omar@nncpr.com. A client can also disconnect a connected X account at any time, which deletes the stored access token immediately.
On a verified request, we will delete the associated posts, metrics, cached images, generated reports, and any stored access tokens from our systems within 30 days, except where we are required to retain certain records to meet a legal or contractual obligation.
13. International data transfers
Prism’s database is hosted in Australia, and several of our service providers (including Google, Vercel, Anthropic, Inngest, and Resend) operate in the United States and other countries. Where the managed accounts and their data originate outside these locations, operating Prism involves transferring that data internationally to the providers listed in section 8.
14. Changes to this policy
We may update this policy as Prism changes. Material changes will be reflected in the “Last updated” date above.
15. Contact
Questions about this policy or about how Prism handles data can be sent to m.omar@nncpr.com, or by post to National Network Communications (FZE), Sharjah Publishing City, L03, Sharjah, United Arab Emirates.