← Back to home

Privacy Policy

Last updated: July 30, 2026

Physis ("we", "us", "our") is an AI implementation studio operating the physislabs.ai website and the client portal at physislabs.ai/dashboard. This Privacy Policy explains what information we collect, how we use it, and what you can do about it.

1. Information We Collect

We collect only what the client portal needs in order to work:

  • Account information: Your name, email address, and the company name you give us during sign-up.
  • Requests: The engagement track you select, the description of the work you write, and the status of that request.
  • Messages: The message thread between you and Physis on each request.
  • Documents: Files you choose to attach to a request, and their filenames.
  • Billing records: Payment status and Stripe identifiers for your engagement. We never see or store your card details.

We do not collect analytics, behavioural tracking, advertising identifiers, or location data.

2. How We Use Your Information

We use your information to:

  • Operate your client portal account and show you your own requests.
  • Communicate with you about the work, on the request thread and by email.
  • Scope, price, and deliver the engagement you asked for.
  • Process payments for that engagement.

We do not sell your information, share it with advertisers, or use the contents of your requests, messages, or documents to train any AI model.

3. Third-Party Services

Three services are involved in running the portal:

  • Supabase: Database, authentication, and document storage. Every portal table is protected by row-level security, so a request, its messages, and its attachments are readable only by the account that owns them.
  • Stripe: Payment processing. Card details go directly to Stripe and never reach our servers or our database.
  • Vercel: Website and application hosting.

Your requests, messages, and documents are not sent to any third-party AI provider. If a specific engagement ever requires that, we will tell you and agree it in writing first.

4. Data Retention

We retain your account, requests, messages, and documents for as long as your account is active, and afterwards only as long as we need to for tax and accounting obligations on work you paid for. When you delete your account, your account data and requests are permanently removed. Deleting your account does not delete the system we built for you — that lives in your own environment, on your own accounts, and we have no access to it.

5. Your Rights

You have the right to:

  • Access your data: Everything we hold about you is visible in the portal — your requests, their message threads, and your uploaded documents.
  • Correct your data: You can edit your own request descriptions and your account details from the portal.
  • Delete your account: You can permanently delete your account and its data from the Settings page. This is irreversible.
  • Export your data: Email us and we will send you everything we hold about you.

6. Cookies

Physis uses essential cookies for authentication and session management only. We do not use tracking cookies, advertising cookies, or third-party analytics. Your session is managed by Supabase's secure tokens.

7. Security

We implement industry-standard security measures including encrypted connections (HTTPS), row-level security on our database, rate limiting on API endpoints, and input sanitization. However, no method of electronic storage is 100% secure, and we cannot guarantee absolute security.

8. Age

Physis sells professional services to businesses. The portal is not intended for use by anyone under 18, and we do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us at support@physislabs.ai.