PsyProxy
MethodologyMCP/APIModel store
Sign in
Trust

Data Handling Summary

A plain-language map of what happens to uploaded text and dependent variables from browser upload through computation, storage, download, and deletion.

Version 2026-07-10Effective July 10, 2026PsyProxy Limited, Colorado, USA
Legal and privacy
  • Policy center
  • Terms
  • Privacy
  • Data handling
  • Acceptable use
  • Consumer health

Before you upload

Remove direct identifiers whenever possible. Do not use self-service PsyProxy for regulated or restricted data listed in the Regulated Data Notice. Confirm that your research approval, participant notice, consent, license, or contract permits vendor processing.

Upload and computation

The browser uploads project data to PsyProxy's controlled storage using short-lived upload URLs. Analysis may run on PsyProxy-managed compute providers. Data therefore leaves your device; website analysis is not an on-device process.

PsyProxy processes text and dependent variables to compute the analyses you request, operate the project, investigate failures, secure the service, and optimize service quality. It does not place them in a general training corpus, build unrelated models from them, or share them with other customers.

Storage separation and access

Project containers are keyed to the account and project. Run access is checked against the owning account, and API keys are stored as hashes. Human access is limited to support, quality investigation, security, and legal needs.

Retention and deletion

Project data is scheduled for deletion six months after last project activity unless a separate contract extends or shortens the period. Account holders can request or initiate earlier project deletion. Never-run abandoned uploads are cleaned sooner.

Deletion removes the project container and known run-part objects. Database rows needed for billing, refunds, security, and audit remain without the submitted corpus. Provider backup copies may persist temporarily until their normal expiration.

No unsupported compliance claim

The self-service service is not offered as HIPAA-compliant, is not covered by a Business Associate Agreement, and is not approved for FERPA records or children's data. A custom agreement does not exist unless both parties sign one.

Questions and deletion requests

Use the authenticated account controls when available or contact privacy@psyproxy.ai before uploading if the handling described here does not meet your requirements.

© 2026 PsyProxy Limited. All rights reserved. PsyProxy™ is a trademark of PsyProxy Limited.B.0.3.5