PsyProxy
MethodologyMCP/APIModel store
Sign in
Privacy

Privacy Notice

What PsyProxy collects, why it is processed, who receives it, how long it is kept, and the choices available to account holders and research participants.

Version 2026-07-10Effective July 10, 2026PsyProxy Limited, Colorado, USA
Legal and privacy
  • Policy center
  • Terms
  • Privacy
  • Data handling
  • Acceptable use
  • Consumer health

1. Who controls personal data

PsyProxy Limited, a Colorado limited liability company, Boulder, Colorado, USA is the controller of account, website, support, security, and billing data. When an organization directs PsyProxy to process personal data in submitted research material, that organization is normally the controller and PsyProxy acts as its processor under the Data Processing Addendum.

2. Information we collect

  • Account information, including name, email, authentication provider, role, and organization.
  • Waitlist and onboarding information you choose to provide.
  • Input, including uploaded text, dependent variables, filenames, and project settings.
  • Service records, including usage, credits, run status, model choices, errors, and support interactions.
  • Security and device records, including IP address, user agent, session, and legal-acceptance audit records.
  • Public Model Store information supplied by publishers.

3. Why we use it

  • Provide analyses, accounts, projects, downloads, APIs, support, and credits.
  • Secure the service; detect abuse, fraud, and failures; investigate quality problems.
  • Optimize service quality, reliability, capacity, and user experience.
  • Maintain required business, tax, legal, and acceptance records.
  • Comply with law and enforce our agreements.
We do not add customer text or dependent variables to a general training corpus, use them to build unrelated models, or share them with other customers.

4. Legal bases for international users

Where the GDPR or UK GDPR applies, we rely on contract to provide requested services, legitimate interests to secure and improve service quality, consent where specifically requested, and legal obligations for required records. Customers remain responsible for a lawful basis covering the Input they direct us to process.

5. Service providers and disclosures

We disclose personal data only as needed to vetted service providers, professional advisers, a successor in a corporate transaction, or authorities when legally required. Current infrastructure providers and roles appear on the Subprocessor List. We do not sell personal data or use it for targeted advertising.

6. Human access

Authorized personnel may access customer data only for support, quality investigation, security, and legal needs. Access is limited by role, logged where the platform supports it, and subject to confidentiality obligations.

7. Retention and deletion

Submitted project data is retained for six months after the project's last activity unless a separate contract provides a different period. Account holders may delete project data earlier. Automated cleanup removes eligible project containers and upload parts; limited backup or security copies age out under provider schedules.

Account, transaction, legal-acceptance, security, and audit records may be kept longer where needed for the contract, fraud prevention, legal claims, tax, or regulatory duties. Waitlist information is deleted or de-identified when no longer needed for access administration.

8. Your privacy choices and rights

Depending on where you live, you may ask to access, correct, delete, or obtain a copy of personal data, object to or restrict certain processing, withdraw consent, or appeal a decision. Use the authenticated privacy form or email privacy@psyproxy.ai. We may verify identity and authority before acting.

If PsyProxy processes data only for a customer organization, we may direct the request to that organization. You may complain to your local privacy regulator.

9. International transfers

PsyProxy operates from the United States and uses providers that may process data in other countries. Where required, organizational customers may enter the DPA, including the applicable EU Standard Contractual Clauses and UK transfer addendum. Users should not submit regulated or special-category data unless a separate written agreement expressly permits it.

10. Children and regulated data

PsyProxy accounts are for adults 18 and older. Self-service use must not include children's personal data, identifiable HIPAA-regulated health information, FERPA records, or identifying biometrics. See the Regulated Data Notice.

11. Washington consumer health data

Washington residents should also read the Consumer Health Data Privacy Policy, which explains the data in scope and additional rights.

12. Contact

Contact privacy@psyproxy.ai. Postal correspondence: PsyProxy Limited, Boulder, Colorado, USA — email is the reliable route and we answer statutory requests there.

© 2026 PsyProxy Limited. All rights reserved. PsyProxy™ is a trademark of PsyProxy Limited.B.0.3.5