Privacy Policy
Last updated: August 28, 2026
1. Overview
iPSYC (“we”, “us”) is committed to protecting your privacy. This Privacy Policy describes what data we collect, how we use it, and the rights you have under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.
2. Data We Collect
Account data: Name, email address, password (hashed), role, and subscription tier.
Assessment data: Your responses to personality assessments, calculated scores, AI model parameters (when testing AI), and timestamps.
API keys: Your AI provider API keys (OpenAI, Anthropic, Hugging Face), stored encrypted at rest using AES-256-GCM.
Usage data: Feature usage counts for quota enforcement (e.g., number of AI tests per month).
Technical data: IP address (for rate limiting and audit logging), user agent, and session tokens.
Shared results: If you generate a share link, the linked assessment results are publicly accessible via that URL until revoked.
3. How We Use Your Data
- To provide, maintain, and improve the Service.
- To authenticate you and manage your account and sessions.
- To store and display your assessment results and history.
- To enforce subscription tiers and usage limits.
- To send transactional emails (verification, password reset).
- To monitor for security issues and fraud (audit logging).
- To produce aggregated, anonymized research data that cannot identify you.
4. Legal Bases (GDPR)
We process your personal data under the following legal bases:
- Contract: Providing the Service you requested (account, assessments, results).
- Consent: You consent to assessment data collection via the informed consent flow before each assessment.
- Legitimate interest: Security monitoring, fraud prevention, and service improvement using anonymized data.
- Legal obligation: Retaining audit logs for security and compliance.
5. Data Retention
- Account & assessment data: Retained until you delete your account or request erasure.
- AI test results: Retained until account deletion or per your request.
- Audit logs: Retained for 1 year for security analysis and compliance.
- Shared results: Accessible until you revoke the share token or delete the underlying assessment.
- Anonymized aggregate data: May persist indefinitely but cannot be linked back to you.
6. Your Rights
Under GDPR, CCPA, and similar regulations, you have the right to:
- Access: Request a copy of your personal data (export from Settings → Profile).
- Rectification: Correct inaccurate data (edit your profile).
- Erasure: Delete your account and all associated data (from Settings → Profile).
- Portability: Export your data in a machine-readable format (JSON).
- Object: Object to processing based on legitimate interest.
- Withdraw consent: Withdraw consent for assessment data processing at any time by deleting the data.
- Restrict: Request restriction of processing in certain circumstances.
To exercise these rights, use the in-app tools in Settings → Profile, or email cole@ipsyc.io. We respond to verified requests within 30 days.
7. Data Sharing
We do not sell your personal data. We share data only with:
- Service providers: Stripe (payments), Resend (email delivery), Sentry (error monitoring) — each under their own privacy policies.
- AI providers: When you test an AI model, your assessment items are sent to that provider’s API. This is necessary to provide the feature.
- Legal compliance: When required by law or to protect rights and safety.
You may voluntarily share results via share links — this is your decision and under your control.
8. Data Security
We use HTTPS for all connections. Passwords are hashed with scrypt. User-provided API keys are encrypted at rest with AES-256-GCM. Session cookies are HTTP-only and secure in production. We conduct regular security reviews. No method of transmission or storage is 100% secure.
9. Children’s Privacy
The Service is not directed to children under 13. We do not knowingly collect data from children under 13. If you believe we have, please contact us for immediate deletion.
10. International Transfers
Your data may be processed in countries other than your own (e.g., the United States). We rely on appropriate safeguards for such transfers under GDPR.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated via the Service or email. The “last updated” date above reflects the most recent revision.
12. Contact
Privacy questions or data requests? Email cole@ipsyc.io.