1. Introduction
PsychPal ("we," "our," or "us") is operated by Jules Poiron, located at 313 3rd Street, Box 291, Somerset, MB R0G 2L0, Canada. We are committed to protecting your privacy and complying with the Personal Health Information Protection Act (PHIPA) and the Personal Information Protection and Electronic Documents Act (PIPEDA). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal and health-related information when you use our mental wellness application.
By using PsychPal, you consent to the collection, use, and disclosure of your personal health information as described in this policy. You must be at least 16 years of age to use this Service.
2. Information We Collect
2.1 Personal Information
We collect the following personal information:
- Account Information: Name, email address, password (encrypted)
- Profile Information: Age, gender, location, occupation, education level
- Contact Information: Emergency contact details (optional)
2.2 Wellness Data
We collect data related to your mental wellness:
- Conversation history with the AI companion
- Daily emotional check-in responses
- Mood tracking data
- Personal notes and journal entries
- Appointment information
- Exercise completion data
2.3 Payment Information
Payment processing is handled by Stripe, our third-party payment processor. We do not store your complete credit card information. We only store:
- Subscription status (trial, active, expired)
- Billing cycle (monthly or yearly)
- Transaction IDs for record-keeping
Stripe collects and processes your payment card information securely. Please review Stripe's Privacy Policyfor more information.
2.4 Technical Data
- Device information (browser type, operating system)
- IP address and location data
- Usage data (pages visited, features used, time spent)
- Cookies and similar tracking technologies
3. How We Use Your Information
We use your information to:
- Provide the Service: Deliver personalized therapeutic support and track your progress
- Improve the Service: Analyze usage patterns to enhance features and user experience
- Process Payments: Manage subscriptions and billing
- Communicate: Send service updates, notifications, and respond to inquiries
- Ensure Safety: Detect and prevent fraud, abuse, or security issues
- Comply with Legal Obligations: Meet regulatory and legal requirements
4. AI and Data Processing
Our AI companion uses OpenAI for conversation processing. When you interact with the AI:
- Your messages are sent to OpenAI's servers for processing
- OpenAI processes data according to their privacy policy and data processing agreements
- We store conversation history in our secure database hosted in Canada (Montreal, ca-central-1) for continuity and personalization
- Your data is not used to train OpenAI's general AI models
- To make PsychPal a more attuned companion, we periodically run a private, automated analysis of your own saved journal entries (using Anthropic Claude Haiku) so the AI can sense your emotional rhythm over time. The result is used only to soften and personalize the AI's next replies to you — it is never shared, never sold, never shown to staff, and never used to advertise to you. There is no chart or score; the analysis simply helps the AI be more thoughtful.
Cross-border processing notice: While your primary record is stored in Canada, some of our service providers (OpenAI, Stripe, Twilio, Meta, Google) operate outside of Canada, primarily in the United States. Personal information transferred to these providers is protected by contractual safeguards (Data Processing Agreements and, where applicable, Standard Contractual Clauses) that require a level of protection comparable to Canadian law.
5. Data Sharing and Disclosure
We do NOT sell your personal information. We may share your information with:
5.1 Service Providers
- Stripe: Payment processing
- OpenAI: AI conversation processing, voice transcription (Whisper), and text-to-speech playback. Voice recordings are transcribed and discarded; only the transcript is retained.
- MongoDB Atlas: Database hosting (Canada — Montreal, ca-central-1, encrypted at rest with AES-256)
- Gmail SMTP (Google Workspace): Transactional email delivery (welcome emails, password resets, billing receipts)
- Twilio: SMS delivery, used only for emergency-contact and safety-team alerts triggered by a flagged safety event (see Section 6)
- FingerprintJS: Browser device fingerprinting used solely to enforce the one-per-device limit on the 7-day free trial and to detect trial abuse. We do not use the fingerprint for advertising.
- Meta (Facebook Pixel): Aggregate marketing analytics and conversion measurement (e.g. page views, sign-ups, subscription events). Pixel events are pseudonymous and never include the contents of your journals, conversations, or mood data. You can disable this tracking with any standard ad-blocker or browser tracking-protection setting.
5.2 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations (court orders, subpoenas)
- Protect our rights and property
- Prevent fraud or illegal activities
- Protect user safety in emergency situations
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new owner with prior notice to you.
6. Safety Event Data Handling
PsychPal's Safety & Crisis Protocol uses an AI classifier to recognize language indicating a credible threat of harm to yourself or to others. When a message is flagged, a "safety incident" record is created. Because this touches personal health information, we treat it with the following heightened privacy rules:
6.1 What a safety incident record contains
- Timestamp of the event.
- Severity tier (Concern / Specific / Mass).
- A trigger snippet — up to the first 500 characters of the flagged message. Your full conversation is not attached to the incident record.
- A sanitized copy of the AI's response (with safety marker tokens stripped).
- Your user ID and email, so a reviewer can identify and contact you.
- For "Mass" tier incidents only: the phone numbers of emergency contacts that were actually notified.
- Review metadata once an admin has acted: reviewer's email, timestamp, and any notes.
6.2 Who may review a safety incident
Safety incident records may be viewed only by members of PsychPal's safety team whose emails appear on a server-side allow-list. There is no shared password and no anonymous admin access. Every view and every action (marking reviewed, adding notes, manually unlocking the user's AI) is written to an immutable audit log with the actor's email, timestamp, and IP address.
Access to your broader conversation history beyond the 500-character trigger snippet is gated behind a separate, rarely used PHI-access credential that is itself audit-logged. Routine safety review does not expose the full conversation.
6.3 Third parties contacted on a safety event
- Twilio is used to deliver SMS messages. Admin alerts contain an incident ID and a review-page link — never raw user text. Emergency-contact alerts (Mass tier only) contain a short check-in message naming you, but not the content of the flagged message.
- Emergency contacts you have added to your profile may receive an SMS only in the Mass tier, and only after a 90-second user-controlled opt-out window has elapsed without cancellation.
- We do not autonomously contact law enforcement, emergency services, or any named third party (e.g. a threatened individual) based on a safety event.
6.4 Retention of safety incident records
Safety incident records are retained for two (2) years from the date of the event for audit, quality-assurance, and legal-defence purposes, after which they are permanently deleted. This retention period applies independently of general account closure; records from a closed account that contain safety incidents may be retained for the remainder of their two-year window before deletion.
6.5 Your rights regarding safety event data
Safety incident records are part of your personal health information. You may request access, correction, or a copy of any record relating to you under PHIPA / PIPEDA by contacting us at the address below. Note that audit-log entries (who reviewed and when) cannot be altered, but you can request a copy of them. Requests to delete safety incident records are honoured to the extent permitted by law and our legal retention obligations.
Safety incident data is never sold, never shared with advertisers, and never used to train AI models.
7. Data Security
We implement robust security measures to protect your personal health information:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (AES-256) for all stored data
- Data stored exclusively in Canada (MongoDB Atlas, Montreal ca-central-1 region)
- Secure password hashing (bcrypt)
- Regular security audits and updates
- Role-based access controls and authentication
- Secure session management with HTTP-only cookies
- Audit logging of all administrative access to personal health information
However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7.1 Data Breach Response & Notification
We maintain a formal incident-response plan that meets PIPEDA's Breach of Security Safeguardsrequirements (s. 10.1) and PHIPA equivalents. In the event of a privacy breach involving personal health information that creates a real risk of significant harm (RROSH):
- Containment & Triage: The Privacy Officer is notified within 24 hours of discovery; access is locked down and the breach is contained.
- Notification of Affected Users: Affected users will be notified as soon as feasible, and no later than 72 hours after we determine the breach creates a real risk of significant harm. Notice will describe the nature of the breach, the information involved, the steps we have taken, the steps you can take, and a contact for further information.
- Notification of the Privacy Commissioner: Where required, we will report the breach to the Office of the Privacy Commissioner of Canada and to the Information and Privacy Commissioner of the affected user's province within the same 72-hour window.
- Record-Keeping: We maintain a Breach Register of every breach (notifiable or not) for at least 24 months, available for review by the Privacy Commissioner on request, in compliance with PIPEDA s. 10.3.
- Post-Incident Review: Every notifiable breach triggers a root-cause review and update to our Privacy Impact Assessment (PIA) and security controls.
To report a suspected breach, contact our Privacy Officer immediately (see Section 16). We accept good-faith reports from users, researchers, and third parties.
8. Data Retention
We retain personal health information only as long as is reasonably necessary to fulfil the purposes for which it was collected, to deliver the Service, and to comply with our legal, regulatory, and clinical-records-keeping obligations. Specific retention periods are listed below.
- Active Accounts: We retain your data for as long as your account is active and the Service is being delivered to you.
- Closed Accounts — General Account & Wellness Data: Account information, conversation history, mood logs, journal entries, daily check-ins, notes, and appointment data are retained for seven (7) years following account closure. This period aligns with Canadian healthcare records-retention norms and our obligations under PHIPA / PIPEDA. After seven years, the data is permanently deleted from production systems.
- Safety Incident Records: Retained for two (2) years from the date of the event (see Section 6.4) regardless of account status.
- Audit Logs & Access Logs: Retained for seven (7) years for security, compliance, and legal-defence purposes. Audit log entries are immutable and cannot be edited or deleted on user request, but you may request a copy of entries that relate to you.
- Payment & Billing Records: Transaction IDs, invoices, and subscription history are retained for seven (7) years to comply with Canadian tax and accounting law.
- Marketing & Communication Preferences: Retained until you withdraw consent or close your account, whichever comes first.
- Encrypted Backups: Deleted data may persist in encrypted, access-restricted backups for up to thirty (30) days before being overwritten.
- Legal Hold: If we receive a valid legal request (e.g., court order, subpoena), relevant data may be retained beyond these periods until the legal matter is fully resolved.
You may request earlier deletion of any data not subject to a legal or clinical retention obligation by contacting our Privacy Officer (see Section 16). Where deletion is not possible, we will explain the legal basis for retention.
9. Your Privacy Rights
9.1 Rights Under PHIPA and PIPEDA (Canadian Users)
Under Canadian privacy legislation — including PHIPA, PIPEDA, and applicable provincial privacy statutes — you have the following rights with respect to your personal and personal-health information. We will respond to any verified rights request within 30 days. If we cannot fulfil the request within 30 days, we will explain the reason and the new expected response date in writing.
- Right of Access: Request confirmation that we hold information about you and a copy of that information in a usable format.
- Right of Rectification (Correction): Request correction of inaccurate, incomplete, or out-of-date personal health information. Where we agree, we will correct the record and notify any third party to whom the inaccurate information was disclosed in the prior 12 months.
- Right to Restrict Processing: Request that we limit the use or disclosure of your personal health information while a complaint or correction request is pending, or where the lawfulness of processing is contested.
- Right to Data Portability: Receive a copy of your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and have it transmitted to another service where technically feasible.
- Right to Object to Processing: Object to processing that is based on legitimate interests, including profiling, and to processing for direct marketing. We will stop the objected-to processing unless we demonstrate compelling legitimate grounds that override your rights.
- Rights Regarding Automated Decision-Making: PsychPal uses automated AI processing to (a) generate AI-companion responses, (b) classify messages for safety risk, and (c) personalize wellness content. Safety classifications and AI lockouts do not involve solely automated decisions with legal effect — every safety incident is reviewable by our safety team, and you may request human review of any AI-driven outcome that materially affects you. You may also request information about the logic of the automated processing and contest its results.
- Right to Withdraw Consent: Withdraw your consent to the collection, use, or disclosure of your personal health information at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal may limit or prevent your continued use of the Service.
- Right to Deletion (Erasure): Request deletion of your personal health information, subject to the retention obligations described in Section 8 and any applicable legal hold.
- Right to Lodge a Complaint: File a complaint with our Privacy Officer (Section 16), with the Office of the Privacy Commissioner of Canada (priv.gc.ca), or with the Information and Privacy Commissioner of your province (e.g., the Manitoba Ombudsman).
9.2 Consent
By creating an account and using PsychPal, you expressly consent to the collection, use, and disclosure of your personal health information as described in this Privacy Policy. You may withdraw your consent at any time by contacting us, though this may limit or prevent your ability to use the Service.
9.3 Exercising Your Rights
To exercise any of these rights, contact us at psychpal@outlook.com. We will respond within 30 days.
10. Cookies and Tracking
We use the following types of cookies:
- Essential Cookies: Required for authentication and core functionality
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how users interact with the Service
You can control cookies through your browser settings, but disabling essential cookies may affect functionality.
11. Age Requirement
PsychPal is not intended for individuals under 16 years of age. We do not knowingly collect information from anyone under 16. If you believe someone under 16 has provided us with personal information, please contact us immediately at psychpal@outlook.com.
12. Data Storage and Transfers
Your personal health information is stored on servers located in Canada (Montreal, Quebec) using MongoDB Atlas with AES-256 encryption at rest. In limited circumstances, your data may be processed outside of Canada by our third-party service providers (e.g., OpenAI for AI processing, Stripe for payments). Where data is transferred outside of Canada, we ensure appropriate contractual safeguards are in place to protect your information in accordance with PIPEDA requirements.
13. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification
- In-app notification
- Updating the "Last Updated" date
Continued use of the Service after changes constitutes acceptance of the updated policy.
15. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Province of Manitoba and the federal laws of Canada applicable therein, including PHIPA and PIPEDA.
16. Privacy Officer & Contact
PsychPal has appointed a designated Privacy Officer (also acting as our Data Protection Contact) who is accountable for our compliance with PHIPA, PIPEDA, and this Privacy Policy. The Privacy Officer is the primary point of contact for any access request, correction request, withdrawal of consent, breach report, or privacy complaint.
Privacy Officer: Jules Poiron
Privacy & Data Protection Email: privacy@psychpal.app
General Support Email: psychpal@outlook.com
Mailing Address: 313 3rd Street, Box 291, Somerset, MB R0G 2L0, Canada
We will acknowledge privacy requests within 5 business days and provide a substantive response within 30 days. To verify your identity, we may ask you to confirm account-related details before fulfilling sensitive requests.
If you are not satisfied with our response, you may escalate to:
- Office of the Privacy Commissioner of Canada — priv.gc.ca (toll-free: 1-800-282-1376)
- Manitoba Ombudsman (Access & Privacy Division) — ombudsman.mb.ca
- The Information and Privacy Commissioner of your province of residence, if outside Manitoba.
Your privacy is important to us. We are committed to transparency and giving you control over your personal information.