Privacy Policy
Last updated: 3 August 2026
Polysystems, Inc. ("Poly," "we," "us," or "our") operates the Poly AI platform. This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and how you access, export, and delete it. It applies to poly.inc, the Poly web application, and every section within it.
The short version
This summary is for orientation only — the numbered sections below are the binding text.
| Do you sell my data? | No. We do not sell or share personal information for cross-context behavioural advertising. |
|---|---|
| Do you train AI on my content? | Not without your explicit, separate opt-in. Opting in is never required to use Poly. |
| Who else sees my content? | The AI provider that serves the model you chose, plus the infrastructure providers listed in section 9. Local models never leave your machine. |
| Can I delete everything? | Yes — Settings > Account > Delete Account, or email us. Blockchain records are the one exception we cannot erase (section 10). |
| Where is it stored? | The United States. See section 12 for transfer safeguards. |
| Who do I contact? | privacy@poly.inc |
1. Who We Are
Polysystems, Inc. is the data controller for personal data processed through Poly. We are incorporated in Delaware and operate from the United States.
Where you use Poly as part of an organisation that has its own agreement with us, that organisation may be the controller and we the processor; in that case the data processing terms of that agreement govern, and you should direct data requests to your organisation first. Organisations that need a standalone data processing agreement can request one from legal@poly.inc.
2. Information We Collect
We collect what you give us and what your use of the service generates.
a. Account information
Email address, a hashed password, and — optionally — a display name and profile photo. If you enable two-factor authentication we store the secret needed to verify your codes. We keep a login history (time, IP address, device) so you can review access to your own account.
b. Content you create
Messages and prompts; uploaded files (documents, images, PDFs); research plans and sources; journal and notebook entries; office documents, spreadsheets and presentations; drawings and design systems; canvases; projects, boards and tasks; and any other content you create or submit. When you upload a file we process its contents server-side — text extraction and OCR — to make the relevant features work.
c. Section-specific data
Poly is a suite of workspaces, and some of them process categories of data the others do not:
- Psyche (psychological instruments): your responses to assessments and the scores derived from them. See section 3 — we treat this as sensitive data.
- Finance and Wallet: public blockchain addresses you link (proved by a signature — we never receive or store your private keys or seed phrase), watchlists, strategy configuration, and a record of transactions initiated through Poly. See section 10.
- Mail: the content, headers, recipients and attachments of messages you send or receive through Poly.
- Voice: audio you record for speech-to-text, and text you submit for speech synthesis. Audio is processed to produce the transcript or the audio output and is not retained for any other purpose.
- Build and Code: source code you write or generate, and the output of running it in our sandboxed execution environment.
- Studio: generation prompts and the images, video and audio produced from them.
- Agents and automations: the instructions, schedules and run history of any agent you configure, including agents that continue running while you are away.
d. Usage data
Which features you use, session timestamps, page views, actions taken, request volumes against your plan limits, and error logs.
e. Device and technical data
IP address, browser type and version, operating system, referring URL, and device identifiers — used for security, fraud prevention, rate limiting and service optimisation.
f. Payment data
Payments are processed by Stripe. We never receive or store full card numbers. We retain a payment method summary (last four digits, card type, expiry), subscription status, and billing history.
g. Connected accounts
If you connect a third-party account (GitHub, Google, X, LinkedIn, Telegram and similar) we store the access token and the profile information that provider returns, limited to the scopes you authorise. You can disconnect at any time, which revokes our stored token.
h. Communications
If you subscribe to our newsletter we store your email address for that purpose alone until you unsubscribe. Support correspondence is retained so we can answer you.
3. Sensitive Data (Psyche)
Psychological assessment responses and scores can reveal information about your mental health. We treat them as special category data under GDPR Article 9 and as sensitive personal information under the CCPA, which means:
- We process them only with your explicit consent, given by choosing to take an assessment. You can withdraw that consent at any time by deleting the results.
- Results belong to the person who took the assessment. We do not disclose individual results to an employer, insurer, or any other third party.
- Where Poly is used in a workplace context, aggregate reporting is subject to a minimum group size so that individual results cannot be re-identified, and inference of emotional state in a work context is not offered at all.
- We do not use this data for advertising, profiling unrelated to the feature, or model training.
Assessments provided through Poly are for self-understanding. They are not a diagnosis and are not a substitute for a qualified clinician.
4. How We Use Your Information
- Provide, operate, secure and maintain Poly and its features.
- Route your messages to the AI model provider you selected in order to generate a response.
- Authenticate you and manage sessions.
- Process payments, apply plan limits, and manage subscriptions and credit balances.
- Send transactional email — account confirmations, security alerts, receipts.
- Send the newsletter, if you asked for it.
- Detect and prevent abuse, fraud and security incidents, and enforce our Terms.
- Analyse aggregated, de-identified usage to improve the product.
- Answer your support requests.
- Comply with legal obligations.
We do not sell your personal data. We do not train AI models on your content without your explicit, separate opt-in, and opting in is never a condition of using Poly.
5. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the EEA, the UK or Switzerland, we rely on the following bases:
| Purpose | Legal basis |
|---|---|
| Providing the service, processing your requests, billing | Performance of a contract |
| Security monitoring, fraud and abuse prevention, aggregate analytics | Legitimate interests |
| Psychological assessments (section 3) | Explicit consent (Art. 9(2)(a)) |
| Newsletter, optional model-training opt-in, non-essential cookies | Consent — withdrawable at any time |
| Responding to lawful requests, tax and accounting records | Legal obligation |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights. You may object at any time (section 11).
6. AI Processing
Cloud models. When you send a message to a cloud-hosted model, the message and any attached context are transmitted to that provider (see section 9) and processed under that provider's own terms. Different sections of Poly may use different providers for different tasks.
Local models. When you select a locally-hosted model (for example Ollama or OMM running on your own machine), your messages are processed on your own infrastructure and are not sent to us or to any third-party model provider.
Training. We do not use your content to train our own models, and we do not grant providers the right to train on it, except where you have explicitly opted in. Providers may retain data briefly for their own abuse monitoring under their terms.
Provenance. Images generated through Poly carry embedded metadata recording that they were produced or substantially modified by a generative model, in line with transparency obligations for AI-generated content. This metadata describes the file, not you.
7. Automated Decisions and Autonomous Agents
Poly lets you configure agents that act on your instructions — including on a schedule and while you are not present. These agents act for you, on parameters you set; we do not use them to make decisions about you.
We do not make decisions producing legal or similarly significant effects concerning you by solely automated means, with one exception: automated abuse and fraud controls may rate-limit or suspend an account. You can contest such a decision and obtain human review by writing to privacy@poly.inc.
8. Data We Never Ask For
We never ask for, and you should never enter into Poly, your wallet private keys or seed phrase. No member of our team will ever request them, and we will never send you a contract address or a payment request by direct message.
9. Sharing and Sub-processors
We do not sell or rent personal information. We share it only with the categories of recipient below, each under a contract that limits them to processing on our instructions.
| Category | Examples | What they receive |
|---|---|---|
| AI model providers | OpenAI, Anthropic, DeepSeek, and other providers we route to | The prompt and context for the request you made |
| Media generation | Image, video and speech generation providers | Your generation prompt and any source media |
| Payments | Stripe | Billing details and subscription events |
| Hosting and storage | Cloud compute, database and object storage providers | Data at rest and in transit for the service |
| Operational infrastructure | Rate limiting, queueing and email delivery | Identifiers and message metadata |
| Analytics | Privacy-preserving product analytics | Aggregate usage events |
| Data sources | Web search, market data, blockchain RPC and research APIs | The query or address you asked about |
| Messaging | Telegram, where you connect it | The messages your agents send you |
A current list of named sub-processors is available on request from privacy@poly.inc. We may also disclose information where required by law, court order or governmental authority; where necessary to protect the rights, property or safety of Poly, our users or the public; and as part of a merger or acquisition, in which case we will notify you before your data becomes subject to a materially different policy.
10. Blockchain Data
Poly's finance features are non-custodial: you hold your own keys and sign your own transactions. Understand that public blockchains work differently from our systems:
- Transactions are public, permanent and irreversible. They are recorded on a network we do not control and cannot be edited or deleted by us or by you, including in response to a deletion request.
- A wallet address is a persistent identifier. Linking one to your Poly account may make your on-chain activity associable with you by anyone who learns that link.
- Deleting your Poly account removes the association we hold; it does not and cannot remove anything from a blockchain.
11. Retention and Deletion
| Data | Retention |
|---|---|
| Account and profile | Life of the account |
| Conversations, documents, files and other content | Until you delete them, or the account closes |
| Assessment responses and scores | Until you delete them, or the account closes |
| Voice recordings | Deleted after the transcript is produced |
| Server and diagnostic logs | Up to 90 days |
| Newsletter subscription | Until you unsubscribe |
| Billing and tax records | As required by law, typically 7 years |
| Backups | Purged within 30 days of deletion |
Delete your account and its data at any time from Settings > Account > Delete Account. Some records are retained for a limited period where the law requires it.
12. Your Rights
Depending on where you live, you may have the right to:
- Access — get a copy of the personal data we hold about you.
- Correct — have inaccurate or incomplete data fixed.
- Delete — have your personal data erased, subject to legal retention duties.
- Port — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests.
- Restrict — limit how we process your data in certain circumstances.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Not be discriminated against for exercising any of these rights.
Email privacy@poly.inc. We respond within 30 days (45 where the law allows an extension). We may need to verify your identity first. You may use an authorised agent where the law provides for one.
If you are in the EEA or the UK you also have the right to complain to your local supervisory authority. We would appreciate the chance to address your concern first.
13. California Privacy Rights
In the twelve months preceding the date above, we collect the categories of personal information described in section 2: identifiers, customer records, commercial information, internet activity, geolocation inferred from IP address, audio where you use voice features, professional information where you provide it, and — for Psyche — sensitive personal information. Sources, purposes and recipients are described in sections 2, 4 and 9.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We use sensitive personal information only to provide the feature you requested, which does not trigger a right to limit its use — you can nonetheless delete it at any time.
California residents may exercise the access, deletion, correction and non-discrimination rights in section 12 by the same route.
14. International Transfers
Poly is operated from the United States. If you use it from elsewhere, your information is transferred to and processed in the US, where data protection law differs from your own.
For transfers from the EEA, the UK and Switzerland we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism, together with supplementary technical measures including encryption in transit. A copy of the relevant clauses is available on request.
15. Cookies and Tracking
We use a deliberately small set of cookies and similar technologies:
- Essential — authentication and secure session management. Cannot be disabled without losing the ability to sign in.
- Preference — interface settings such as theme and sidebar state. Functional only; they do not track you across sites.
We do not use advertising trackers, cross-site tracking pixels, or third-party advertising cookies, and we do not sell cookie data. Because we do not sell or share personal information, there is nothing for a Global Privacy Control or Do Not Track signal to opt out of; we honour such signals as a preference not to be tracked regardless.
16. Security
We protect personal data with encryption in transit (TLS), hashed password storage, optional two-factor authentication, scoped access controls, isolated execution environments for user-supplied code, rate limiting, and a visible login history so you can audit access to your own account.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data we will notify you and the relevant supervisory authority without undue delay, and within 72 hours of becoming aware where the GDPR requires it.
Found a vulnerability? Report it to security@poly.inc. We will not pursue legal action for good-faith research that respects user privacy and does not degrade the service.
17. Age Requirement
Poly is for adults. You must be at least 18 (or the age of majority where you live, if higher) to hold an account — see our Terms of Service. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, write to privacy@poly.inc and we will delete it promptly.
18. Changes to This Policy
We may update this policy. Material changes will be posted at this URL and, where appropriate, sent to the email address on your account before they take effect. The "Last updated" date above reflects the most recent revision. Continued use after the effective date constitutes acceptance.
19. Contact
- Privacy and data requests: privacy@poly.inc
- Data protection / GDPR: dpo@poly.inc
- Security reports: security@poly.inc
- Everything else: hello@poly.inc
Polysystems, Inc. · Wilmington, Delaware, United States