Privacy notice
This notice explains the intended data flows in the localhost application. A data-protection professional must review it before public use.
Data we use
Account identity, roles, eligibility profile details, study activity, messages, support requests, consent history, security signals, and payment records are processed to operate the marketplace. For account security, we also retain a one-way IP fingerprint, a masked network range, country-level access location, limited device information, and request metadata. When optional VPN detection is configured, a public IP address is sent to IPinfo for VPN, proxy, Tor, and relay classification; Voxa stores the classification and provider status, not the raw IP address. These results are signals for human review and do not automatically restrict an account. Sensitive profile questions should remain optional and minimised.
How matching works
The platform evaluates eligibility rules on the server. Researchers receive study submissions and relevant participant identifiers, not the participant's complete matching profile or hidden answers from unrelated studies.
Retention and deletion
Account access-location events are automatically removed after 90 days. Account holders can export linked data and request deletion. Identity, credentials, profiles, preferences, and authored message content can be removed or anonymised after review. Limited financial, audit, consent, dispute, and research-integrity records may need documented retention.
Your choices
Account settings control research invitations, message emails, product updates, and optional analytics. A deletion request has a grace period and can be cancelled before administrator completion.

