Psichronize Open Beta

The short version

  • Your name, email and Google profile picture, from signing in. Your practice log and settings, from practising.
  • No advertising, no profiling, no data broker, no sale. There is nothing to sell you and nobody to sell you to.
  • No analytics on this site or in the app. No tracking cookies, because there are no cookies.
  • One invitation email carries our mark as an image, so opening it can be seen. It is the only such thing we do, and it is named below.
  • Four companies are involved: Google, Supabase, Cloudflare, Resend. Each is named, with what it sees.
  • Ask and we will send you a copy of everything, or delete all of it.

The short version is a summary. The sections below are the policy.

  1. Who is responsible

    Psichronize is operated by Psichronize, and we are the controller of the personal data described here. In this policy, “we” and “us” mean that entity, and “you” mean the person using the service. “The service” means the Psichronize app at app.psichronize.com and this website.

    For anything in this policy, write to help@psichronize.com. A person reads it.

  2. What we collect, and where it comes from

    From Google, when you sign in. Your name, your email address and your Google profile picture. We ask Google for those three things and nothing else — not your contacts, not your calendar, not your files, not anything else in your Google account. We do not keep a long-lived Google token, so we cannot go back to Google later and ask for more.

    From practising. Your practice log, and your settings. The log is the record of your sessions and what happened in them. It is append-only: entries are added and nothing rewrites them, which is the point of keeping one at all.

    From asking for access. Psichronize is invite-only, and you request access by signing in. That request — your address, and when you made it — sits on a list a person reviews.

    Incidentally, from serving the site. The companies below keep ordinary server logs, which include IP addresses, for the usual reasons: keeping the service up and keeping it from being abused. We do not build anything on top of those logs, and we do not use them to work out anything about you.

    That is the whole list. We do not ask for your date of birth, your location, your phone number, or anything about your health.

  3. Why we hold it

    Your name, email and picture identify your account and let us reach you about it — your address is also how we tell you an invitation has come through. Your log and settings are the service: without them the app has nothing to show you and no way to tell whether anything is improving. The access list is how a person decides whether to let you in.

    We hold all of it because it is necessary to provide a service you asked us for. Where the law where you live requires your consent instead, signing in is that consent, and you can withdraw it by asking us to delete your account.

  4. What we do not do

    We do not sell, rent, trade or share your personal data for anyone else’s purposes. We do not advertise to you, we do not let anyone else advertise to you, and we do not build a profile of you for either.

    We run no analytics on this website and none in the app. There is no Google Analytics, no tag manager, no third-party pixel, no heatmap, no session recorder. Nothing on this page is counting you.

    We do not make automated decisions about you with legal or similarly significant effects. The decision to grant access is made by a person.

  5. Cookies, and what sits on your device

    We set no cookies, for any purpose, on this website or in the app.

    The app does keep things in your browser’s local storage: your sign-in session, and a local copy of your settings and recent practice so the app works quickly and survives a reload. That is on your device, not ours, and nothing in it is sent anywhere except to our own database as part of the service. Logging out erases the local copy on that device. It does not touch your log on our servers.

  6. The mark in the invitation email

    When an invitation goes out, the email shows the Psichronize mark, and that mark is an image loaded from our own domain rather than embedded in the message. If your email client loads it, we can see that the message was opened, roughly when, and from what IP address.

    We are telling you this because it is true and because a privacy policy that omitted it would be a worse document. It is not a tracking pixel in the usual sense: it is a visible part of the card, it is not a hidden 1×1 image, it goes to our own domain rather than to an analytics company, and nothing downstream consumes it. Most email clients block remote images until you allow them, and if yours does, this does not happen at all.

    It is the only thing of its kind anywhere in the service. If it ever stops being worth it, the answer will be to take the image out, not to move it somewhere less visible.

  7. Who else sees it

    Psichronize runs on services other companies operate. These are all of them, and what each one handles:

    • Google — sign-in. Google tells us your name, email and profile picture, and knows that you signed in to Psichronize.
    • Supabase — the database and the authentication service. Your account and your practice log live here.
    • Cloudflare — serves this website and the app, and sees the requests that come with that.
    • Resend — sends invitation email. It handles your address and the message.

    Each has its own privacy policy and its own terms, and your data passes through them as a consequence of using the service. We choose them deliberately and we are answerable for choosing them, but we do not control how they run.

    These companies operate internationally, so your data may be processed outside the country you live in, under the transfer safeguards each of them maintains.

    We will also disclose data if the law genuinely requires it. If that ever happens and we are permitted to tell you, we will.

  8. How long we keep it

    We keep your account and your log for as long as you have an account. The whole value of a practice log is that it is long, so we do not expire it for you.

    Ask us to delete it and we remove it from live systems within 30 days. Backups age out on their own cycle; we do not reach into them to delete individual records, and we will not restore deleted data from them.

    An access request that is never granted is kept on the list, or archived. Ask and we will remove it.

  9. Your rights, and how to use them

    Email help@psichronize.com from the address on your account. One message is enough for any of these:

    • A copy. We will send you everything we hold, in a machine-readable format.
    • Deletion. The app has no delete-my-account button; this is how you do it. We remove the account and everything in it.
    • Correction. We will fix wrong details on your account. Note that your practice log is append-only and cannot be edited, by you or by us — that is a design decision described in the terms, and it is what makes a result worth anything later.
    • Objection, restriction, or withdrawing consent. Tell us and we will act on it.

    Deleting your account removes what we hold. It does not withdraw the permission you gave Google to share your name and email with us — that lives in your Google account, under third-party apps with account access, and you can revoke it yourself. We deliberately do not keep the token that would let us do it for you, because keeping one would mean holding a long-lived key to your Google account.

    Depending on where you live you may have further rights, including the right to complain to your data protection authority. Email us first if you are willing — we would rather fix it — but you are not obliged to.

  10. Keeping it safe

    Your data is held in a database that enforces, row by row, that an account can only read its own. Everything travels over TLS. Access to production is limited to the people who need it.

    No service is perfectly secure and we will not pretend otherwise. If a breach affects you, we will tell you and the relevant authority as the law requires, and we will tell you what actually happened.

    Found a security problem? help@psichronize.com. We would rather hear it from you.

  11. Children

    The service is for adults. You must be at least 18 to use it, as the terms set out, and that covers supervised use: an adult may not open an account for a child or hand one over to a child.

    We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete it and withdraw access to the account. If you believe a child has an account here, email us.

  12. Changes to this policy

    If we change this policy we will update the date at the top. If a change actually matters — something new collected, a new company involved, a new purpose — we will email the address on your account rather than quietly editing the page and hoping you re-read it.

  13. Talk to us

    Any question about this policy, a request about your data, or anything that reads wrong to you: help@psichronize.com.