PsyAgenda

Terms of Use

PsyAgenda — Important Information and Terms of Use

PsyAgenda is a professional tool designed to help therapists (psychologists, psychiatrists, counselors) manage appointments, client records, psychological tests, session notes, budgets, and encrypted cloud synchronization from a single application. The app is available on Android, iOS (iPhone, iPad), macOS, and Windows (Desktop) platforms. Please read the following important information carefully before you begin.

1. Data Stored in the App and Local Storage

  • The following categories of data, to the extent that you enter them and in order to support your professional practice (appointments, client records, session organization), are stored on your own device only and not on the developer's servers:
  • Client Information: Only first name and surname are required. All other fields — phone, email, date of birth, gender, marital status, education, profession, and therapist notes — are entirely optional. This information is stored only if you enter it; otherwise, the application does not request or collect it.
  • Appointment/Session Data: Date, time, duration, pre-session notes, session notes, next-session notes, AI session analysis, session images, and alarm settings.
  • Psychological Test Data: Rorschach test (card-by-card responses, AI and therapist evaluations, final reports), Projective Drawing Test (drawing images, AI and therapist analyses), and Manual Test (images, therapist reports).
  • Financial Data: Session fees, expenses, expense categories, and payment statuses.
  • Local Storage: All data is stored exclusively on your device's local storage, in an AES-256 encrypted SQLite database (detailed in Section 2). No data leaves your device outside the user-controlled channels listed in this agreement (cloud synchronization, AI analysis, license verification, support email). None of these channels delivers the client, appointment or financial data stored on your device to the developer; what each channel sends, and where, is described separately in the sections below.

2. Data Privacy and Device Responsibility

  • Data Security and Responsibility: Data stored in PsyAgenda may contain sensitive confidential information. The security and privacy of this data are entirely your responsibility.
  • Physical Security: It is your duty to ensure the physical security of your device (screen lock, password protection, preventing unauthorized access, etc.). In the event your device is stolen or falls into the hands of unauthorized persons, you are solely responsible for any legal and ethical consequences arising from the disclosure of confidential client information.
  • Digital Security: Ensuring the digital security of your device (malware protection, keeping operating system and security updates current, etc.) is also your responsibility. The developer cannot be held responsible for data breaches caused by malicious software that may infiltrate the device.
  • Data Loss: The developer is not responsible for data loss resulting from loss, damage, theft, or software failure of the device. Regular backups are recommended.
  • App Lock: The app lock (password + security question) is created during initial setup and is mandatory; your data is stored on your device in an encrypted database (AES-256 / SQLCipher) and your app lock password protects that encryption key. After setup you may, if you wish, turn off the password prompt at launch via Settings > Security > "Trust This Device"; in that case anyone who can access your device can open the app, so the level of protection is reduced. IMPORTANT: If you forget your app lock password and your security question answer, you will never be able to access your data again. No one, including the developer, can help you in this situation; your data becomes permanently inaccessible.

3. Cloud Synchronization (Google Drive)

  • PsyAgenda optionally allows you to synchronize your data across devices via Google Drive. This feature is available on all platforms, is entirely at the user's discretion, and is disabled by default.
  • Google Drive: You may optionally sign in with your Google account for synchronization. The application only requests the "drive.appDataFolder" scope (app-private, user-invisible storage). It does not access your personal Google Drive files, Gmail, or any other Google services.
  • End-to-End Encryption: All client, appointment, financial, test and image data uploaded to cloud services is encrypted on the client side with the sync password you define (PBKDF2 + AES-256-GCM). No third party, including Google, can decrypt this data. Only synchronization's own record file (device name and platform, last-seen time, file integrity digests and the text of your security question) is kept unencrypted; that record carries no client or session content.
  • Sync Password: During setup you are required to define a security question and answer; your sync password is stored, encrypted with that answer, in the synchronization file in the cloud. If you forget your password, you can recover it by answering the security question. However, if you lose both your sync password and the answer to your security question, you will never be able to access your encrypted data in the cloud again; keeping both in a safe place is vitally important.
  • Synchronized Data: Client records, appointments, expenses, expense categories, test data, app settings, and session images are synchronized in encrypted form.
  • Device Registry: The sync system records a device ID, device name, platform, and last-seen timestamp for each connected device. This information is written to the sync manifest.
  • Conflict Resolution: When multiple devices modify the same record, the most recently modified record prevails (last-write-wins). This may result in data loss in rare scenarios.
  • Disconnecting: You may sign out of your cloud account; however, this does not automatically delete existing encrypted data on the cloud.

4. AI Usage and Data Sharing

  • PsyAgenda uses the Google Gemini API for various AI-assisted analysis features that support the therapist's own professional evaluation. AI features are optional and require the user to provide their own Google Gemini API key.
  • AI-Assisted Features: Session note analysis, next session suggestions, handwriting recognition, Rorschach test card analysis and final report, Projective Drawing Test analysis, Manual Test correction, spelling correction in therapist reports and notes, hybrid reports that merge the AI and therapist reports, and the Overall Client Assessment.
  • Data Transmitted: During AI analysis, session notes (text), client age and gender, test responses (text), and drawing/handwriting images are sent to the Google Gemini API over HTTPS. This data is transferred to Google's servers, which may be located outside your country (cross-border data transfer).
  • API Key: You use your own Google Gemini API key. This key is stored encrypted (AES-256-GCM) on your device and is not transmitted to the developer. If synchronization is enabled, the key is transferred, together with your other application settings and encrypted with your sync password, only to the private application area in your own Google Drive account; it is sent to no other server. API calls are made directly from your device to Google servers.
  • Anonymity Responsibility: By default, the application sends only anonymous demographic information (age, gender) for AI analysis. However, free-text fields such as session notes, therapist notes, and client responses are also included in the analysis. It is entirely YOUR responsibility NOT to enter any personal information that could reveal your client's identity (name, surname, ID number, phone, address, etc.) into these fields.
  • Client Information: Informing your clients on the necessary matters and obtaining their consent is your responsibility.
  • Google Data Policy: Data sent to the Google Gemini API is subject to Google's AI terms of service and privacy policy. Google applies different data-use rules to its free and paid API tiers; these rules are set by Google, may be changed unilaterally, and PsyAgenda can give no undertaking regarding them. Google states that it may temporarily retain data for abuse detection. Given the sensitivity of confidential client information, we recommend using the paid tier and verifying the terms of your chosen plan in Google's current AI terms of service.
  • Professional Responsibility: All evaluations produced by AI (session analyses, test interpretations, reports) are solely supportive tools and preliminary analyses. They can in no way replace — and are not intended to replace — professional clinical judgment, supervision, or final therapeutic decisions. All professional responsibility rests with you.

5. Backup and Data Recovery

  • PsyAgenda allows you to export your data as an encrypted backup file (.thnbak).
  • Backup Encryption: Backup files are encrypted using the AES-256-GCM algorithm with the password you set. If you lose this password, you will not be able to restore your backup file.
  • Backup Contents: The backup file contains all client, appointment, expense and test data and session images, together with your application settings (including synchronization/API credentials, the master encryption key that decrypts them, and the digest of your app lock password); the entire file is encrypted with your backup password using AES-256. For this reason, anyone who holds both your backup file and your backup password can also access those credentials; keep both of them safe.
  • Backup Responsibility: Regular backups are entirely your responsibility. The developer is not responsible for data loss resulting from failure to back up.

6. Notifications and Communication

  • Local Notifications: Session reminder and alarm notifications operate locally on your device. No data is sent to an external notification server or third-party service.
  • Client Notifications: The app optionally makes it easier for you to send your clients appointment notifications and payment reminders (which may include the number of unpaid sessions and the total amount) via SMS, WhatsApp or e-mail. Messages are not sent directly by the app; it opens the SMS/WhatsApp/e-mail application on your device with pre-filled text, and sending occurs only with your manual confirmation. Automatic appointment notifications are disabled by default; a payment reminder is only ever an action you start yourself. Message contents depend on the templates you define in the app; sharing messages containing financial information with your client is your responsibility.

7. Device Permissions

PsyAgenda may request device permissions in order to provide certain features. All permissions other than internet access are optional, are requested only while the related feature is being used, and can be declined; a declined permission only disables the related feature. The internet permission is granted by the operating system at installation and is never requested separately; the purposes for which the app accesses the internet are explained below.

  • Internet (INTERNET): Used to connect to Google Drive sync and Gemini AI features. The internet is also used for a periodic connectivity check that carries no user data, and for verifying license status (RevenueCat) at app launch.
  • Camera (CAMERA): Used to attach photos to session notes or test records.
  • Notifications (POST_NOTIFICATIONS): Used to send appointment reminder notifications.
  • Exact Alarms (SCHEDULE_EXACT_ALARM): Used to trigger appointment reminders at the exact scheduled time.
  • Contacts (READ_CONTACTS): Used for the add-from-contacts feature. The contact list is shown by the operating system's own picker; the app reads only the name, phone number, and email of the contact you select. No other contacts in your address book are read, and no contact data is transmitted outside the device.
  • External Storage (WRITE_EXTERNAL_STORAGE — only on Android 9 and below): Used to save report downloads (PDF/DOCX) to the device's "Downloads" folder. This permission is not needed on Android 10 and later.
  • Biometric Authentication (Face ID / Touch ID / fingerprint): Used for optional quick unlock; biometric data stays within the operating system — the app never accesses, stores, or transmits it.
  • Photo Library: Only the photos you select are read, to attach images to session/test records; write access is used to save camera photos to your library.

8. License and Subscription

  • Trial Period: The application offers a 30-day free trial from the initial installation. All features are available during this period.
  • Expiration: When the trial period or subscription expires, the application switches to read-only mode. You can view and export your existing data but cannot enter new data.
  • Subscription Types: Monthly (1 month) and annual (1 year) subscription options are offered. Purchases are made through the Apple App Store on iOS, iPadOS and macOS. Your card and billing details stay with Apple and are never passed to the app. After a purchase, Apple gives the app only a receipt showing that your subscription is valid; this receipt is shared with RevenueCat to verify your subscription status. Apple also reports renewals and cancellations directly to RevenueCat (see Section 10). On other platforms, purchasing a subscription through a store is not yet offered. Lifetime or time-limited free full access may be granted by the developer as a gift (over the license verification infrastructure, assigned to your device's Installation ID), and this option is currently offered only on iOS and macOS; the app offers no code entry or direct Lifetime purchase option.
  • Auto-Renewal: Your subscription automatically renews unless cancelled at least 24 hours before the end of the current period. The renewal fee is automatically charged to your Apple ID or Google Play account after the current period ends. The renewed period is billed at the current price at the time of purchase.
  • Cancelling Your Subscription: You can cancel your active subscription at any time. On iOS devices: Settings → Apple ID → Subscriptions. On Android devices: Google Play Store → Subscriptions. On macOS: App Store app → Account → Subscriptions. Cancellation must be made at least 24 hours before the end of the current period; otherwise the subscription will renew for one more period.
  • Pricing and Duration: Current subscription prices and durations are displayed on the License page within the application and on the store purchase screen. Apple and Google may apply regional pricing variations; the price shown on the store purchase screen is the one that applies.
  • Billing and Refunds: Subscription fees are charged at the end of the free trial period (if any), or at the time of purchase if no trial applies. Refund requests are subject to the refund policies of the Apple App Store / Google Play; PsyAgenda cannot directly intervene in the refund process. You must contact the respective store's support channel for refunds.

9. Reports and Exports

  • PsyAgenda offers reports and data exports in DOCX (Word), PDF, and XLSX (Excel) formats. Optional password-protected ZIP encryption is offered during export (traditional ZIP protection for universal compatibility — it deters casual access but is not AES-grade); if you decline, the file is saved unprotected and its security is your responsibility.
  • Exportable content includes: Client profile reports, Rorschach test reports, Projective Drawing Test reports, Manual Test reports, and budget/income-expense lists.

10. Third-Party Services

  • PsyAgenda communicates with the following third-party services:
  • Google Gemini API: For AI analysis features (optional, with the user's own API key).
  • Google Drive API: For cloud synchronization (optional, appDataFolder access only).
  • Google Authentication: For optionally signing in with a Google account for Google Drive synchronization.
  • Google Play Store / Apple App Store: For subscription purchases.
  • RevenueCat: A device-specific random user identifier (App User ID) and the store purchase receipt are shared for the subscription purchase flow, receipt validation, and verification of subscription/license status at app launch. Apple also reports subscription renewals and cancellations directly to RevenueCat, without passing through the app. Gift licenses are also granted via this identifier. No personal data (name, email, session notes, confidential client information) is shared.
  • Bug Report Emails (info@psyagenda.app): When the user uses About > Support/Feedback > "I'm having a problem", the description they wrote and technical records (error messages, action types, platform/version info, the device-specific random Installation ID — so we can look up your subscription status for support — and browser/device info (User-Agent); contains no client/session content) are sent to the developer through the device's default mail app. This channel is fully under user control; the content can be reviewed, edited, or canceled before sending.
  • The app also performs a periodic reachability check, carrying no user data, to detect whether an internet connection is available. Beyond these, PsyAgenda does not communicate with any analytics service (Google Analytics, etc.), automatic error reporting service, ad network, or external server. Outside the user-controlled flows explicitly listed above (synchronization, AI, support emails), the developer has no access to any user data.

11. Disclaimer of Liability and Architectural Declarations

  • The developer is not responsible for user-error-related data loss, incorrect AI analyses, disruptions in API services, device failures, unauthorized access, or issues arising from password loss.
  • Service Continuity: The uninterrupted operation of third-party services (Google Gemini API, Google Drive) is not guaranteed. Changes to these services may affect certain features of the application.
  • Medical Device Notice: PsyAgenda is not a medical device. It is not designed as a diagnostic, treatment planning, or clinical decision-making tool. All content in the application (including AI analyses) is for informational and organizational purposes only.
  • No External Code Is Run: PsyAgenda never downloads, generates, or executes code from outside the app. The interface, the logic, and every feature ship with the installed app itself. AI produces text only — interpretations and reports; nothing it produces changes how the app works.
  • Rorschach Imagery: The original 10 inkblots published by Hermann Rorschach in 1921 have been in the public domain for 100+ years and are used in the application within this context.

12. Changes to Terms

  • The developer reserves the right to update these terms of use. When the terms are updated, the current version is published within the app (in the About section); continuing to use the app constitutes acceptance of the current terms. If you do not accept the updated terms, you must discontinue use of the application.

13. Account and Data Deletion

  • Account Structure: PsyAgenda does not require an in-app account to be created. Google sign-in is used only for optional synchronization and operates through the user's own Google account. Therefore, no separate "account deletion" process is needed; data deletion is directly under user control.
  • Deleting Local Data: Via Settings > Storage > Danger Zone > 'Delete All Local Data', all data on this device (clients, appointments, session notes, tests, financial records, attached files, settings and synchronization credentials) is permanently deleted. The action requires typed confirmation (DELETE ALL DATA) and cannot be undone. Your app lock password and the database encryption key are retained on the device; the app still opens with the same lock password after the deletion.
  • Deleting Drive Data: Via Settings > Sync > Danger Zone > 'Delete All Drive Data', encrypted backups, images, and the manifest on Google Drive are permanently deleted; this device's sync connection is disconnected. Local data is preserved. Other active devices on the same account may re-upload their own data on the next sync; to keep Drive permanently clean across all devices, you must repeat this action on each device.
  • Uninstalling the App: On iOS via Settings > General > iPhone Storage > PsyAgenda > Delete App, and on Android via Settings > Apps > PsyAgenda > Storage > Clear Data/Uninstall, all local data is deleted. On macOS and Windows, however, uninstalling the app may not automatically delete the encrypted database files in the operating system's application data folder; to permanently erase all local data on desktop, use Settings > Storage > Danger Zone > "Delete All Local Data" before uninstalling.
  • Backups Not Auto-Deleted: Encrypted .thnbak backups exported voluntarily by the user remain on the user's device or external media; managing these backups is the user's responsibility.

14. Terms Specific to App Store / Mac App Store Versions

This section applies only if you obtained the application through the Apple App Store or the Mac App Store.

  • Parties: This agreement is between you and the developer; Apple is not a party to it. The developer alone is responsible for the application and its content.
  • Scope of Licence: You are granted a non-transferable licence to use the application on Apple-branded devices that you own or control; use is also subject to the Apple Media Services Terms and Conditions.
  • Maintenance and Support: Responsibility for maintenance and support of the application rests solely with the developer; Apple has no obligation whatsoever to furnish any maintenance or support services.
  • Warranty: If you believe the application fails to conform to an applicable warranty, you may notify Apple; Apple's sole obligation, if any, is to refund the purchase price. All other warranty liability rests with the developer.
  • Product Claims: Any claims relating to the application — including product liability, conformity with legal and regulatory requirements, consumer protection, and intellectual property infringement claims — concern the developer alone; Apple is not responsible for such claims.
  • Legal Compliance: You represent that you are not located in a country subject to a U.S. embargo and that you are not listed on any U.S. government list of prohibited or restricted parties.
  • Third-Party Beneficiary: Apple and its subsidiaries are third-party beneficiaries of these terms and, upon your acceptance, have the right to enforce these terms against you directly.
  • Contact: For questions, requests and complaints regarding the application, you can write to info@psyagenda.app.

By using this application, you declare that you have read, understood, and agreed to all of the above terms.