Privacy Policy
Last updated: September 4, 2026
PsyHome is built on one simple idea: your clinical material belongs to you. This policy explains what we collect, what the architecture makes impossible for us to see, and the choices you have. The short version: the system is designed so that most of this document describes what we don’t do.
1. Who we are
PsyHome is operated by Changsha Geili Information Technology Co., Ltd. ("we"), which is the data controller for personal information. Contact: support@geilixinli.com. This policy covers the PsyHome iOS app, the PsyHome Android app, the websites psyhome.geilixinli.com and psyhome.ai, and the platform API (api.psyhome.geilixinli.com / api.psyhome.ai).
2. The architecture, in plain words
- Local-first. Case archives — notes, transcripts, conceptualization cards, reports — live in an encrypted database on your device and are never uploaded to us.
- BYOK. With your own AI key, supervision conversations go straight from your device to the provider. We are not in the loop and cannot see them.
- Platform API (optional, paid). With the platform API, requests pass through our relay. They are forwarded byte-for-byte to the upstream model provider; we only record usage metadata (account, model, token counts, timestamps). Request and response content is never written to disk.
3. What we collect
- Account data (optional): your email, or your Apple Sign-In identifier. Only needed for the platform API.
- Order & points status: platform top-up order numbers, tiers, amounts paid, payment channel (WeChat Pay / Alipay), and points balance. We never see your bank card or payment credentials — payments are handled by WeChat Pay / Alipay.
- Usage metadata: model names, token counts, timestamps of platform API calls. Never content.
- What you actively submit: feedback messages, and crash logs, diagnostic files or screen recordings you explicitly upload.
- Website logs: standard web server logs (IP, user agent), kept at most 30 days, for security and abuse prevention.
4. What we never collect
- Archive contents, supervision conversations, client names or clinical details
- Original recordings and photos (materials you import stay in your device’s encrypted storage; cloud recognition forwards them to the provider you chose per section 6 — never to us)
- Analytics, advertising identifiers, tracking pixels — none whatsoever
- Contacts, location, or any device identifier not named in this policy
5. On-device processing & app permissions
Speech recognition, OCR, name scanning and redaction matching run on your device by default; you can opt into cloud recognition item by item (the audio/image then goes to the recognition provider you selected). Alias registration on the input side is yours to drive: originals are stored locally as-is, and everything sent to an AI passes a redaction gate first (registered real names are silently replaced with their aliases).
The alias mapping table lives only in your device’s encrypted database and is never uploaded. One exception: when you deliberately export a local backup via “Backup & Restore”, the mapping table travels inside the backup package (it’s your own data moving house; choose encrypted export to avoid plaintext exposure).
- Camera: photographing paper files, handwritten notes and other materials.
- Microphone: recording sessions and voice input.
- Photo library: importing material images you pick.
- Notifications: local reminders (e.g. backup freshness) and essential status notices.
- Network: requests to the AI provider you configured, the platform API (sign-in/top-up/usage), and version checks.
6. Third-party processors
- Apple — App Store distribution, TestFlight beta, Apple Sign-In. Apple’s privacy policy applies.
- DeepSeek — text-model upstream of the platform API. Requests are relayed byte-for-byte; per our agreement, content is not used for training.
- Alibaba Cloud DashScope (Qwen) — image and speech model upstream of the platform API. When you choose cloud recognition, your audio/images are forwarded to this service.
- WeChat Pay, Alipay (in-app SDKs in the China Android build) — platform top-ups. The SDKs collect device and transaction data needed for payment per their own privacy policies.
- The AI provider you choose (BYOK) — your conversations are governed by your agreement with that provider.
7. Retention & deletion
Account data, order records and usage metadata are kept while your account exists. You can delete your account anytime in the app (Me → cloud account card → Delete account) or via the deletion page: we delete account records and subscription links within 30 days. For abuse prevention and payment reconciliation, the following may be retained after deletion: content-free usage metadata, trial-claim records (including email), feedback messages you submitted, and crash/diagnostic/screen-recording files you uploaded. Local data on your device is deleted when you delete the app or a case.
8. Your rights
Depending on your jurisdiction (GDPR, CCPA, PIPL, etc.), you may have rights to access, correct, export and delete your personal data. Because your clinical data never reaches us, the personal data we hold is limited to section 3 — email support@geilixinli.com to exercise any of these rights.
9. Minors
PsyHome is a professional tool for practicing counselors and is not directed at minors. We do not knowingly collect data from minors.
10. Changes
Changes will be posted on this page with the date above updated. Material changes will be announced in the app before they take effect.