1. Introduction

Rolepsy ("we", "us", "our") is a clinical training platform that uses AI to create realistic patient personas for therapy practice. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and application at rolepsy.com and app.rolepsy.com.

Rolepsy is operated from Sweden and complies with the General Data Protection Regulation (GDPR). For the purposes of the GDPR, Rolepsy is the data controller.

2. Data We Collect

2.1 Account Data

When you register, we collect:

2.2 Usage Data

When you use the platform, we collect:

2.3 Technical Data

2.4 Voice Data

If you use voice messaging features, audio is processed in real time for speech-to-text conversion and tone analysis. We do not store raw audio recordings after processing.

3. How We Use Your Data

We do not sell your personal data. We do not use your therapy session content to train AI models.

4. Legal Basis for Processing (GDPR)

5. Hosting & Infrastructure

All services are hosted in the European Union (Frankfurt, Germany) to ensure your data remains within the EU.

ComponentProviderLocationPurpose
Application serverRenderFrankfurt, DEBackend API and frontend hosting
DatabaseMongoDB AtlasFrankfurt, DEPrimary data store (accounts, sessions, personas)
Cache & sessionsRedis (Render)Frankfurt, DESession store, rate limiting, caching
DNS & CDNCloudflareGlobal edge (EU origin)DNS resolution, DDoS protection, TLS termination

6. Subprocessors

We share personal data with the following third-party subprocessors, each under a Data Processing Agreement (DPA):

SubprocessorPurposeData sharedLocation
OpenAIAI model provider for therapy chat and clinical analysisAnonymized session messages (PII stripped before transmission)USA (EU API endpoint)
AnthropicAlternative AI model providerAnonymized session messages (PII stripped before transmission)USA
DeepgramSpeech-to-text (voice messaging)Audio stream (real-time, not stored)USA
ElevenLabsText-to-speech (voice responses)AI-generated text (no personal data)USA
Hume AIVocal tone analysisAudio stream (real-time, not stored)USA
PostHogProduct analyticsAnonymized usage events (no PII)EU (Frankfurt)
RenderApplication hostingAll application data (encrypted)EU (Frankfurt)
MongoDB AtlasDatabase hostingAll stored data (encrypted at rest)EU (Frankfurt)
CloudflareCDN and securityIP addresses, request metadataGlobal (EU origin)

International transfers

Some subprocessors are based in the USA. For these transfers we rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses (SCCs) as adopted by the European Commission. We will notify you of any changes to our subprocessor list by updating this page.

7. Data Retention

8. Your Rights

Under the GDPR, you have the right to:

To exercise any of these rights, contact us at privacy@rolepsy.com. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (IMY).

9. Security Measures

10. Cookies

We use a limited number of cookies. For full details on what cookies we set, their purpose, and how to manage them, see our Cookie Policy.

11. Children's Privacy

Rolepsy is designed for licensed mental health professionals and is not intended for use by anyone under 18. We do not knowingly collect data from minors.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For privacy-related questions or requests: