Legal draft

Privacy notice

This notice explains the intended data flows in the localhost application. A data-protection professional must review it before public use.

Data we use

Account identity, roles, eligibility profile details, study activity, messages, support requests, consent history, security signals, and payment records are processed to operate the marketplace. For account security, we also retain a one-way IP fingerprint, a masked network range, country-level access location, limited device information, and request metadata. When optional VPN detection is configured, a public IP address is sent to IPinfo for VPN, proxy, Tor, and relay classification; Voxa stores the classification and provider status, not the raw IP address. These results are signals for human review and do not automatically restrict an account. Sensitive profile questions should remain optional and minimised.

How matching works

The platform evaluates eligibility rules on the server. Researchers receive study submissions and relevant participant identifiers, not the participant's complete matching profile or hidden answers from unrelated studies.

Retention and deletion

Account access-location events are automatically removed after 90 days. Account holders can export linked data and request deletion. Identity, credentials, profiles, preferences, and authored message content can be removed or anonymised after review. Limited financial, audit, consent, dispute, and research-integrity records may need documented retention.

Your choices

Account settings control research invitations, message emails, product updates, and optional analytics. A deletion request has a grace period and can be cancelled before administrator completion.