Legal

Privacy policy

What Noosphere knows about you, why it knows it, how long it keeps it and who else sees it. Written to be read, not to cover our backs.

Last updated: 26 August 2026

1. Start with what we do NOT do

It is shorter than the list of what we do, and it explains the rest:

2. Data controller

ControllerRaúl del Pino
AddressLa Oliva (Las Palmas), Spain
Contactnoosphere@psiconautica.org · rauldelpino@gmail.com

3. What we process, what for, and on what basis

DataPurposeLegal basis
Email address Identify you, let you sign in, and tell you about your account and subscription Performance of a contract (art. 6(1)(b) GDPR)
Name (optional) Greet you by name in the interface and in emails Legitimate interest (art. 6(1)(f))
Password Protect your account. Stored hashed with scrypt and a per-user salt: nobody, not even the administrator, can read it Performance of a contract
Plan, billing period, status and Stripe identifiers Manage the subscription, its renewals and its cancellation Performance of a contract
Number of queries per day Apply your plan's daily quota Performance of a contract
Conversation history (Premium plan only) So you can return to an earlier chat. On the Free and Normal plans nothing is stored in the database Performance of a contract
IP address Contain abuse: limits on queries, sign-ups and login attempts. Held only in the server's memory, for a maximum of 24 hours, and gone on restart Legitimate interest — security (art. 6(1)(f))
Query text, with no user attached Know what people ask so the corpus can improve. We keep the text (up to 400 characters), the language and how many sources were used, with no link at all to your account, your session or your IP Legitimate interest — service improvement (art. 6(1)(f))
Web server access logs Security and fault diagnosis. Written by the web server, not by the application, and never cross-referenced with an account Legitimate interest (art. 6(1)(f))

We do not ask for, and do not need, your date of birth, postal address, phone number or country.

4. What you type into the question box

The question you write travels to the language model provider, together with the document passages retrieved to answer it. That is unavoidable: it is what makes the answer possible. What never travels is who you are: no email, no identifier, no IP address, no session data is sent. To the provider, every question arrives orphaned.

Even so, the advice is plain: do not put health data — yours or anyone else's — or anything that identifies you into a question. Ask about "the interaction between sertraline and MDMA", not "I have been on sertraline since March and I want to try MDMA".

If you do include health data anyway, it is processed only to answer you, on the basis of your explicit request (art. 9(2)(a) GDPR), and it is only stored if you are on the Premium plan — in your own history, which you can delete at any time.

5. How long we keep it

DataRetention
Account and subscriptionAs long as the account exists. Deleting it deletes them
Chat history (Premium)Until you delete it or delete your account. The 200 most recent chats are kept
Query counterAs long as the account exists
Anonymous query text60 days, deleted automatically every night
IP address24 hours maximum, in memory only
Web server logsWhatever the hosting provider's automatic rotation sets: weeks, not years
BillingThe mandatory tax and commercial periods (up to 6 years). Held by Stripe as the issuer of the charges
Backups5 days. Deleted data may survive in a backup until that backup rotates out

6. Who else sees your data

Only the providers this cannot run without. None of them uses it for anything else:

ProviderWhat forWhat it receivesWhere
Stripe Charging subscriptions and donations Your email, an internal identifier and the plan. Card details are collected by Stripe directly: they never touch our server Ireland / USA
Brevo Sending account emails (verification, password, notices) Your email address and the content of the message European Union
Language model providers
Google (Gemini) as primary and, if it fails, OpenRouter — which in turn routes to other providers — OpenAI and Groq
Writing the answer, translating the question and rewriting follow-up questions The question text and the document passages. No identifier of yours USA and other third countries
Hosting The server everything runs on Whatever appears in the access logs European Union

What stays at home. The engine that turns text into vectors and the one that re-ranks the results run on our own server. Your question does not leave the building to be searched: it only leaves to be written up.

7. International transfers

Some of those providers sit outside the European Economic Area. Those transfers rely on the safeguards in Chapter V of the GDPR — standard contractual clauses or an adequacy decision, depending on the provider — and are limited to what the table above describes. Remember that model providers receive no data that identifies you.

8. Your rights

At any time, and free of charge, you may exercise your rights of access, rectification, erasure, objection, restriction and portability. Just write to noosphere@psiconautica.org from your account's address. We reply within one month at most, usually within days.

9. Security

10. Minors

Noosphere is restricted to people aged 18 or over and is not aimed at minors. We do not knowingly collect data from minors; if we find an account belonging to one, it is deleted.

11. Changes to this policy

If something material changes — a new provider, a new purpose — this page is updated, and if the change genuinely affects you, account holders are told by email.

Cookie policy Legal notice