Privacy Policy

Effective Date: March 1, 2026 · Last Updated: August 29, 2026

Table of Contents

  1. Introduction
  2. For Researchers: IRB-Ready Data-Handling Statement
  3. What Data We Collect
  4. How We Use Your Data
  5. Third-Party Services
  6. Data Retention
  7. Account Deletion
  8. Data Security
  9. Children's Privacy
  10. International Data Transfers
  11. Your Rights Under GDPR (EU Users)
  12. Your Rights Under CCPA (California Users)
  13. Cookies and Tracking
  14. Changes to This Policy
  15. Contact Us

1. Introduction

PsyStat Lab ("we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, web application, and related services (collectively, the "Service").

By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service. This Privacy Policy should be read in conjunction with our Terms of Service.

For Researchers: IRB-Ready Data-Handling Statement

The paragraph below is written to be pasted directly into an IRB protocol, DMP, or methods section. It describes actual system behavior, not marketing intent. If your IRB needs more detail, contact us and we will provide a signed data-processing addendum.

Statistical analyses in this study were conducted using PsyStat Lab (version [insert app version from the citation your analysis produced]). Raw participant data files were parsed on the researcher’s device and were not transmitted to the vendor. For each analysis, only the numeric columns being tested were transmitted over TLS 1.2+ to the vendor’s compute backend (Railway), which returned computed results and retained no dataset content after the request completed. Analyses the researcher explicitly saved were stored in the researcher’s vendor account (Supabase, row-level security, encrypted at rest by the provider) as numeric inputs, computed results, and any user-authored notes — never as raw participant rows.

Where the researcher used the in-app AI assistant, the vendor transmitted a bounded context bundle to Anthropic (Claude API) consisting of test type, variable names, and result summaries from prior saved analyses, capped at approximately 8 KB per prompt; raw participant rows were never included in this channel. Text-to-speech features, when used, transmitted only the plain-text string requested to be spoken to Modal (Kokoro TTS).

Subprocessors involved in delivering the Service: Supabase (authentication and encrypted storage of saved analyses), Railway (transient statistical computation), Anthropic (AI assistant), Modal (optional text-to-speech), Vercel (web hosting), Stripe and RevenueCat (billing), and Google Analytics (aggregate page-view metrics for the marketing site and web app only). The vendor does not sell participant data, does not use participant data to train machine-learning models, and does not display advertising on any tier.

If your institution requires a Business Associate Agreement (BAA) for HIPAA-covered data, please note that PsyStat is not currently HIPAA-BAA covered; do not upload identifiable protected health information.

2. What Data We Collect

2.1 Account Data

When you create an account, we collect:

Account data is stored in our Supabase database with row-level security policies ensuring that users can only access their own records.

2.2 Analysis Data

Raw files you upload (CSV, spreadsheets) are parsed on your device and are not transmitted to our servers as raw files. When you run an analysis, we transmit only the numeric columns you are analyzing to our compute backend (Railway) over TLS. That backend runs the computation and returns results; it retains nothing after the request completes.

If (and only if) you explicitly save an analysis, we store the following in your Supabase account, protected by row-level security:

Analysis data is stored in Supabase and is accessible only to you. We do not access, review, or use your analysis data for any purpose other than providing the Service, unless required by law.

2.3 Usage Data

We collect anonymized and aggregated usage information, including:

Some usage data may be stored locally on your device via AsyncStorage and periodically synced to Supabase for backup and cross-device continuity.

2.4 AI Conversation Data

When you use the AI Assistant feature:

To make the AI useful, we include a compact context bundle in each prompt: your recent saved analyses (up to 15) summarized as test type, variable names, and result numbers, plus your tier, ORCID, and institution if provided. This bundle is truncated to a hard ceiling (~8 KB) before it leaves our servers. Raw participant rows are never sent to the AI unless you explicitly paste them into a message yourself.

Please refer to Anthropic's Privacy Policy for information on how they handle data sent to the Claude API.

2.5 Device Information

We may collect basic device information, including:

2.6 Summary of Data Collection

Data Category Examples Storage Location Required?
Account Data Email, ORCID, institution Supabase Email required; others optional
Analysis Data Inputs, results, notes Supabase Created through use
Usage Data Module opens, analysis counts AsyncStorage / Supabase Automatic
AI Conversations Messages, AI responses Supabase / Anthropic Created through use
Device Info Device type, OS, app version Analytics service Automatic

3. How We Use Your Data

We use the information we collect for the following purposes:

3.1 Providing the Service

3.2 Personalizing Your Experience

3.3 Improving the Service

3.4 Advertising

PsyStat runs no advertising on any tier. Your participants’ data never shares a page with third-party ad or tracking scripts.

3.5 Communications

4. Third-Party Services

We use the following third-party services to operate PsyStat Lab. Each has its own privacy policy governing how they handle data:

Service Purpose Data Shared Privacy Policy
Supabase Database, authentication, file storage, real-time sync Account data, analysis data, AI conversation history supabase.com/privacy
Anthropic (Claude API) AI-powered statistical interpretation and assistance AI conversation messages, contextual analysis metadata anthropic.com/privacy
RevenueCat Subscription and payment management Purchase history, subscription status, anonymous user ID revenuecat.com/privacy
Vercel Web application hosting IP address, request metadata (standard web server logs) vercel.com/legal/privacy-policy
Railway Backend API and statistical computation hosting Numeric analysis inputs (transient; not retained after the request) railway.app/legal/privacy
Stripe Web subscription checkout and payment processing Email, plan identifier, payment method (handled directly by Stripe) stripe.com/privacy
Modal (Kokoro TTS) Text-to-speech for accessibility features (optional) The plain-text string you request to be spoken. Never analysis data or participant rows. modal.com/legal/privacy
Google Analytics Aggregate web analytics (marketing site and web app only) Page views, referrer, general geography. No analysis inputs, no results, no participant rows. policies.google.com/privacy

We carefully select third-party providers that maintain high standards of data protection. However, we are not responsible for the privacy practices of third-party services, and we encourage you to review their privacy policies.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service to you. Specifically:

When you request account deletion, all personally identifiable data is permanently removed from our active systems within 30 days. Backup systems may retain encrypted copies for up to 90 days before automatic purging.

6. Account Deletion

You can delete your account and all associated data at any time through the following methods:

Upon account deletion, the following data is permanently removed:

We will process deletion requests within 30 days and send a confirmation email upon completion.

7. Data Security

We implement industry-standard security measures to protect your data:

While we strive to use commercially acceptable means to protect your data, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Children's Privacy

PsyStat Lab is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and you believe your child under 13 has provided us with personal information, please contact us at moonlit-social-labs@proton.me.

If we become aware that we have collected personal information from a child under 13 without verification of parental consent, we will take steps to remove that information from our servers within 30 days.

Users between the ages of 13 and 18 may use the Service with the consent and supervision of a parent or legal guardian, in accordance with our Terms of Service.

9. International Data Transfers

PsyStat Lab operates globally, and your data may be processed and stored in countries other than your own, including the United States. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.

We take appropriate safeguards to ensure that your data is treated securely and in accordance with this Privacy Policy, regardless of where it is processed. These safeguards include:

10. Your Rights Under GDPR (EU Users)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

Our legal bases for processing personal data under GDPR include:

To exercise any of these rights, please contact us at moonlit-social-labs@proton.me. We will respond within 30 days.

11. Your Rights Under CCPA (California Users)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

Categories of personal information we collect: identifiers (email, ORCID), internet or other electronic network activity information (usage data), and professional or employment-related information (institutional affiliation).

We do not sell personal information as defined under the CCPA/CPRA, and we do not "share" personal information for cross-context behavioral advertising, because we do not run advertising on any tier.

To exercise your CCPA rights, contact us at moonlit-social-labs@proton.me or use the in-app account deletion feature. We will verify your identity before processing requests and respond within 45 days.

12. Cookies and Tracking

The PsyStat Lab web application may use the following tracking technologies:

We do not use advertising cookies. The mobile application uses AsyncStorage for local data persistence and does not use cookies.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this page periodically for the latest information on our privacy practices.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

PsyStat Lab — Privacy Team
Email: moonlit-social-labs@proton.me
General Support: moonlit-social-labs@proton.me

For GDPR-related inquiries, you may also contact our Data Protection Officer at the email address above with the subject line "DPO Request."

We will make reasonable efforts to respond to all privacy-related inquiries within 30 days.