Effective from first publication.
This page explains what psychegraph.ai collects, why, who else receives it, and what you can do about it. PsycheGraph is a research project, not a shop: we do not sell anything on this site, and we do not sell your details or share them with anyone for their own marketing.
Who is responsible
This site is operated by Coupled Logic. Contact: [email protected].
How to contact us about your data
Email [email protected].
What this page covers
This notice covers the public landing page at psychegraph.ai and its two forms: the contact form and the “get in touch” pop-up.
Everything at a glance
This table is the short version. Each row is explained underneath.
| Data | When it happens | Held by this website | Sent to | Purpose | How long |
|---|---|---|---|---|---|
| Ordinary web-request data (IP address, browser user-agent, requested URL, timing) | Every visit | The application stores none of it. What the access logs of the Cloudflare edge, of Traefik and of the application server retain is set outside this code | Cloudflare (edge/CDN, in front of the whole site) | Delivering and protecting the site | Not yet established |
| Your IP address | Every submission of either form | Counted in memory for a 60-second window; not written to our application log | Cloudflare Turnstile, as remoteip, whenever Turnstile is configured |
Rate-limiting abuse; verifying you are not a bot | The in-memory count is deleted at the end of its 60-second window; Cloudflare’s retention is set outside this code |
| Your privacy choice | When you answer the banner | Stored in your browser only | Nobody | Honouring your choice | Until you clear or change it |
| First-touch attribution (landing path + campaign tags) | First page view in a tab | Stored in your browser | Sent onward with a form submission: our server → lead-relay → Airtable | Knowing which campaign or page an enquiry came from | In your browser: until the tab closes. In Airtable: 24 months |
| Analytics events (the four listed below) | When the action happens, and only once you have accepted Analytics | Nothing — an event that happens before you accept is discarded | Google (GA4) — only if you grant Analytics | Measuring page and form usage | At Google: governed by the GA4 property configuration |
| Advertising events | Only if you accept Marketing and a vendor is configured | — | The configured vendor | Advertising measurement | Vendor’s retention. No advertising vendor is configured today |
| Your form submission (name, email, message, and on the contact form organisation and area of interest) | Only when you submit a form | Field names logged, values not stored | Our server → lead-relay (in-memory transit) → Airtable | Replying to you | Airtable is the system of record: 24 months |
We describe which system holds what, and for how long, rather than making a blanket claim that we keep nothing: there are recipients — notably Cloudflare at the edge — that such a claim would hide.
What we collect, and when
Four things collect data on this site.
1. Serving the site at all (always). psychegraph.ai is served through Cloudflare, which sits in front of the whole site. Every request — including this page — reaches Cloudflare before it reaches us, so Cloudflare receives the ordinary network and request data any web server or CDN receives: your IP address, your browser’s user-agent, the URL you asked for, and timing. This is true whether or not you accept anything in the privacy banner and whether or not you ever use a form. Cloudflare also terminates the HTTPS connection, which means anything you send us, including a form submission, passes through Cloudflare’s network before it reaches our server.
2. Your privacy choice (always). When you answer the privacy banner, your choice is stored in your own browser. Nothing about it is sent to us. If you make no choice, the banner keeps asking and no analytics or marketing service loads.
3. Analytics and marketing (only if you say yes). Nothing in this group loads until you consent to that category, and each service additionally stays off unless we have configured it. Until you choose, all four Google consent signals are set to “denied” by default.
4. If you contact us through a form (only if you choose to). There are two forms and they do not collect the same things.
Both the contact form and the “get in touch” pop-up send:
| What | Notes |
|---|---|
| Your name | Required. |
| Your email address | Required. |
| Your message | Required on the contact form, optional in the pop-up. |
| Which form you used | contact or modal. |
| Whether you agreed to be emailed back | Recorded as the answer you gave; never assumed. |
| The page you first landed on, and any campaign tags in the link you followed | See what the site stores in your browser, below. |
The contact form only also sends:
| What | Notes |
|---|---|
| Your organisation | Optional, free text. |
| Your area of interest | Optional. One of: discovery, safety and translational, research, data contribution, other. |
The pop-up does not ask for, and cannot send, organisation or area of interest.
Our server adds one constant marker to every submission before passing it
on: the source label psychegraph.ai. It identifies which site a
record came from in a table shared with other Coupled Logic sites. It says
nothing about you.
There is also a hidden field that real people never fill in. It exists to catch automated spam, and a submission that fills it in is discarded without delivery.
Your IP address
Your IP address is used for two purposes, both connected to abuse prevention.
- Rate limiting, by us. Our server counts submissions per IP address in a 60-second window (10 by default) so that one source cannot flood the forms. The count is held in the server’s memory. It is not written to our application log. The entry is deleted at the end of its 60-second window.
- Bot verification, by Cloudflare. When Cloudflare Turnstile is configured, your IP address is sent to Cloudflare along with the challenge token as part of verifying that a submission is not automated.
Separately from both, Cloudflare receives your IP address for every request to the site, simply because it serves the site (see above).
Our own application log records field names, error classes and the site identifier — never field values and never your IP address. The Cloudflare edge, Traefik, and the application server each have their own access-log configuration and retention, which this codebase does not determine. We would rather leave that gap visible than promise something we have not verified.
What the analytics events contain
If you accept Analytics and Google Analytics is configured, the site sends Google four events of its own, in addition to the page views GA4 collects automatically:
| Event | When |
|---|---|
lead_modal_shown | The “get in touch” pop-up was displayed to you |
lead_modal_dismissed | You closed the pop-up without submitting |
lead_modal_submit | You submitted the pop-up form |
contact_form_submit | You submitted the contact form |
We attach no parameters of our own to these events. They carry no name, no email address, no message text and no field values of any kind — only the fact that the action happened. Google adds its own automatic information to any event, such as the page, the referrer, device and browser details, and an approximate location derived from your IP address.
How consent interacts with these events, precisely. We record these events only after you accept Analytics. Something you do before that is not held for later: the event is discarded at the moment it happens, and nothing about it is sent to Google if you accept afterwards.
What we do with a message you send us
- Your browser sends the form to this website’s server, through Cloudflare.
- This website’s server checks the message is
well-formed, writes the names of the fields you filled in to its
log — never their contents, never your IP — adds the
psychegraph.aisource marker, drops the Turnstile token, and passes the rest straight on to an explicitly allow-listed HTTPS destination. It does not keep a copy. - Our lead-relay service holds it in memory for the length of that one request and delivers it onwards. It stores nothing: no database, no queue, no files. Its logs, and its optional server-side error reporting, record the site identifier, the destination type and the error class only — never a name, an email address, or your message.
- Airtable receives it, and that is where it stays. Airtable is our record of the conversation.
If the final step fails, the message is not queued for later — delivery is attempted during your request, with retries, and if every attempt fails the message is lost and you see an error asking you to try again. We would rather lose a message than hold your details somewhere they are not properly protected.
We use what you send to reply to you and to have the conversation you started. We do not add you to a mailing list.
Why we are allowed to do this (lawful bases)
| Activity | Basis |
|---|---|
| Storing your privacy choice in your browser | Strictly necessary — it exists only to honour your choice |
| Analytics (GA4), including the four events above | Your consent |
| Advertising vendors | Your consent |
| Replying to your enquiry | Legitimate interests or consent |
| Anti-spam: hidden field, IP rate limit, Turnstile (including sending your IP to Cloudflare) | Legitimate interests / strictly necessary |
| The “don’t show the pop-up again” markers | Strictly necessary |
| First-touch attribution: storing the landing path and campaign tags, and forwarding them to Airtable with a submission | Under review |
| Serving the site through Cloudflare (edge request data) | Legitimate interests / necessary for the service |
Services that may load in your browser
Two states matter, and this page separates them.
Active in the launch configuration
| Service | Provider | What it is for | Loads when |
|---|---|---|---|
Google Analytics 4 (G-K480L70HTE) |
Google — privacy notice | Understanding which pages are used and whether the forms are used | You accept Analytics |
| Cloudflare Turnstile | Cloudflare — privacy notice | Checking form submissions are not automated | Always, when configured — this one is not covered by the consent banner, because it is a security measure |
| Cloudflare edge/CDN | Cloudflare — privacy notice | Serving the site, TLS, protection | Always. It is not a script in your browser; it is the network path to the site |
Built but switched off (no identifier configured, so nothing loads)
Google Ads, Meta (Facebook) Pixel, LinkedIn Insight Tag, X (formerly Twitter) Pixel, TikTok Pixel. Each has a code path gated on both Marketing consent and its own configured identifier. None is configured, so none loads, no matter what you consent to — there is no tag sitting dormant. If any of them is switched on, this page is updated first.
Once a service loads, it sets its own identifiers and cookies under its
own policy. Google Analytics, when loaded, typically sets _ga
and _ga_G-K480L70HTE in your browser. Our code does not set
those, and their exact lifetime depends on the GA4 property
configuration.
Who receives your data
| Recipient | Entity | Role | What it receives | Purpose | Retention |
|---|---|---|---|---|---|
| Cloudflare (edge/CDN, TLS) | Cloudflare, Inc. / Cloudflare Ltd | Processor for site delivery; Cloudflare also operates its own security network | Every request: IP, user-agent, URL, timing; form bodies pass through in readable form after TLS termination | Serving and protecting the site | Edge log settings and retention are set outside this code |
| Cloudflare Turnstile | as above | as above | The challenge token and your IP (remoteip) |
Verifying a submission is not automated | Per Cloudflare’s Turnstile configuration |
| Google (GA4) | Google Ireland Limited / Google LLC | Under review | Page views and the four events above, plus Google’s automatic event data including approximate location from IP | Understanding site usage | Governed by the GA4 property configuration |
| lead-relay (our own service) | The operator named above | Operator-run transit; not a third party | The full submission for the duration of one request | Delivering the submission to Airtable | Nothing persisted: no database, no queue, no files |
| Airtable | Airtable, Inc. — privacy notice | Processor | Name, email, message, form type, email-reply consent, source marker, first-touch page and campaign tags; and on the contact form, organisation and area of interest | Our record of the enquiry and the conversation | 24 months |
There is no browser-side error-reporting or session-recording tool on this site.
What the site stores in your browser
Beyond anything the services above set once they load, the site itself stores four small items. This site sets no cookies of its own — no first-party cookie is written anywhere in the landing code. All four items below are browser storage, not cookies, and none is a tracking identifier.
| Name | Where | What it holds | How long it works | How long it is stored | Sent anywhere? |
|---|---|---|---|---|---|
psychegraph.consent.v1 |
Local storage | Two true/false values: analytics, marketing | Until you change it | Until you clear or overwrite it | No — never leaves your browser |
psychegraph.first_touch.v1 |
Session storage | The path you first landed on, plus up to five campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content), each truncated to 200 characters |
For the tab | Until you close the tab | Yes — if you submit a form. It is attached to the submission and reaches Airtable |
psychegraph.lead_submitted.v1 |
Local storage | A timestamp of when you submitted | 24 months — the pop-up does not reappear in that time | 24 months, then deleted when the site next reads it | No |
psychegraph.modal_snooze_until.v1 |
Local storage | A timestamp 30 days in the future | 30 days — after that the pop-up may appear again | 30 days, then deleted when the site next reads it | No |
Each of these stops working and is deleted at the same point: neither the snooze value nor the submitted marker outlives the period in its row.
You can clear all four at any time through your browser settings. Clearing them resets your privacy choice, and the banner will ask again.
You can also change your mind at any time using the Privacy choices button on the site. Turning a category off takes effect immediately: the page reloads so that anything already loaded under the old choice is gone.
How long we keep things
The application and our relay store nothing about you persistently. The site holds a per-IP counter in memory for abuse prevention and writes field names and error classes to its application log; the relay holds a submission in memory for one request. Neither keeps your details.
That statement is about the application layer, which is what this code determines. Underneath it, the Cloudflare edge, Traefik and the application server each keep their own access logs on their own settings, which this codebase does not determine. We would rather leave the gap visible than promise something we have not verified.
Enquiries live in Airtable, in a single shared Leads
table used by Coupled Logic sites, with each row marked
psychegraph.ai as its source. Airtable is the intended
persistent system of record for them.
We keep an enquiry for 24 months, reviewed annually: once a year the table is reviewed and records past that age are deleted. Access to that table is limited to the operator’s account.
Sending data outside the UK
The services above, and Airtable, are provided by companies based in or operating from the United States, so using them involves your data being transferred there.
Your rights
You can ask us to give you a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, or to provide it in a portable form. Where we rely on your consent, you can withdraw it at any time — for analytics and marketing, the Privacy choices button does this immediately and takes effect on the spot.
To make a request, email [email protected]. In practice, for most people, everything we hold is the message you sent us, the details that came with it, and our reply — all of it in Airtable.
Changes to this page
If we change how any of this works, we will update this page before the change goes live.