Privacy Policy
This Privacy Policy explains how we handle your data on the Pythia platform. For privacy queries: privacy@getpythia.co.uk.
What we collect
When you use Pythia, we collect your email address and company name for account management, and the financial models and context you upload for evaluation.
How we process it
Uploaded models via Excel, Google Sheet or the dashboard are analysed to produce structured feedback. Model contents are processed by Anthropic's Claude API for evaluation under zero-data-retention terms: Anthropic does not store your data after processing and does not use it to train models. AI outputs are advisory and are surfaced for you to review in your dashboard; Pythia does not carry out automated decision-making that produces legal or similarly significant effects. Pythia's use of information received from Google Workspace APIs, and its transfer to any other application or service, adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and sub-processors
Primary storage and processing are hosted within the EU (Supabase on AWS eu-west-1; Google Cloud europe-west1). Anthropic (USA) processes data for AI evaluation under zero-data-retention terms. International transfers to sub-processors outside the UK/EEA are governed by EU Standard Contractual Clauses with the UK Addendum. A full sub-processor list is maintained in our Data Processing Agreement, available on request. We do not sell your data or share it for marketing purposes.
Retention
Your data is retained for the duration of your account. On closure, all data is deleted within 30 days. Model files and evaluation outputs can be exported before deletion.
Your rights
Under UK and EU GDPR, you have the right to access, correct, delete, or export your personal data. Contact us at abel@getpythia.co.uk. You may also lodge a complaint with the ICO.
Security
Pythia implements technical and organisational measures to protect personal data appropriate to the risk, including:
- Encryption in transit: TLS 1.2+ on all connections between your browser, our backend, and our sub-processors
- Encryption at rest: AES-256 server-side encryption for all stored data and files (Supabase/AWS S3)
- Access control: Role-based access control with row-level security enforced at the database level; all queries are scoped to the authenticated user's company
- File access: Model files are stored in private buckets and accessible only via short-lived signed URLs (1-hour expiry), generated after verifying company membership
- Authentication: JWT-based authentication with short-lived access tokens; passwords hashed by Supabase Auth and never stored in plaintext
- Rate limiting: Applied to authentication, submission, and upload endpoints
- Secrets management: API keys and credentials stored in GCP Secret Manager; not stored in source code
Full detail of our technical and organisational measures is available to customers on request under our Data Processing Agreement.
Changes
We will notify you of material changes to this policy by email.