You trust us with the most personal things: test results, medical history, things people do not always say out loud. This document is written plainly and without generalities — it lists what exactly we keep, where, who sees it, and which services receive part of it. If a question remains after reading it, write to us and we will answer personally.
PRIVACY POLICY
Python Method — how we handle your data
Revision of 9 August 2026
1. Who is responsible for your data
The data controller is Pythons & Co, 1331 Amherst Ave, Apt PH5, Los Angeles, CA 90025, USA. For any question about your data: pythonsusa@gmail.com.
The platform is not a medical institution. The materials you upload are materials for your support programme, not a medical record.
2. What data we collect
We collect only what the work on your case needs. Nothing on this list is collected just in case.
- Registration: email and password (the password is held by our authentication provider as a hash — we never see it).
- Profile: name, phone number, interface language.
- Questionnaire: your goal, a description of your situation, who the support is for, age confirmation, and — where a minor takes part — the participant's name and date of birth together with the parent's or guardian's details.
- Documents: the files you upload — test results, discharge summaries, scans.
- Correspondence: the messages in your case, including voice messages and their attachments.
- Conversations with the AI assistant: your questions and its answers.
- Metrics, supplements and sleep: the values you enter yourself, your intake plan, and your sleep records — bedtime and wake-up time, duration, your own rating of how you felt, and notes. This also covers what you bring over as a file from the app of a watch, ring or bracelet.
- Payments: amount, plan, currency, date and a reference to the payment held by the payment provider. Card details never reach us and are never stored by us.
- Consents: the record that you accepted the offer and consented to the processing of your data — with the date, the version of the document and the language you read it in.
- Service records: the log of actions on your case, escalation events, and counters of assistant usage.
3. Why we do this
The basis for processing is your consent, given by a separate tick in the questionnaire, and the performance of the offer agreement you accept in the same place.
We process medical information only on the basis of your explicit consent and only to prepare and run your case. We do not use your data for advertising and we do not sell it.
4. Where the data is kept and who sees it
The database and the file storage are hosted on Supabase. Uploaded documents and voice messages sit in private storage: no direct link to a file exists, and access is granted through a temporary link and only to someone entitled to that case.
Access to rows is separated at the level of the database itself: a client sees only their own case, their own documents, their own correspondence and their own metrics. That rule lives in the database, not in the interface — it cannot be bypassed from a browser.
Within the team, Professor Python and the support staff have access to a case, to exactly the extent the work with you requires. Every action on a case is written to a log.
5. Who we pass data to
We do not sell data and do not pass it to third parties for their own purposes. Below is the complete list of services that receive part of the data so that the platform can work.
- Supabase (USA) — database, authentication and file storage. Receives all platform data.
- Vercel (USA) — website hosting. Processes network requests, including the IP address.
- Stripe (USA) — payment processing. Receives the amount, the currency, your email and your profile identifier. You enter your card details on Stripe's side, not ours.
- PayPal — an alternative payment route for countries where the main one is unavailable. Receives the same payment details.
- Anthropic (USA) — the model the AI assistant runs on. Receives the text of your message, the conversation history, the attachments to your message and a brief summary of your case.
- OpenAI (USA) — a second model used to review part of the answers. Receives the text of the enquiry and the prepared answer.
- Telegram — the team's alert channel. What exactly goes there is described in section 7.
- Public authorities — only where the law directly requires it.
6. How the AI assistant works
The assistant is a program, not a doctor. It does not diagnose and does not prescribe treatment; everything it says is a recommendation, and the decision stays with you and your treating physician.
For a visitor to the site, the assistant answers only questions about the centre and has no access to any personal data. After registration it sees your profile and your questionnaire. Once your support programme begins, it sees the materials of your case.
Your conversation with the assistant is stored in your case. The team can read it: the assistant is part of your support programme, not a separate anonymous chat.
7. Alerts about critical situations
If a conversation with the assistant contains a sign of a condition that needs a person's immediate attention, the platform creates an event and alerts the team through Telegram at once. This exists for safety, and we say so plainly, because part of the data leaves the platform when it happens.
The alert contains: the event identifier, your email (for a site visitor, a note that you cannot be contacted), the case identifier, the time, and an excerpt of your message no longer than 600 characters. The full message, your documents and your case history are not included.
The event itself and the same excerpt are stored in the database for the team to review.
8. Site visitors, counters and cookies
So that one visitor cannot exhaust the assistant on the front page, visitors' messages are counted. The IP address is not stored for that counter: it is irreversibly turned into a hash with a secret salt, and only the hash remains in the database. The address cannot be recovered from it, and it is not linked to any profile.
We use cookies: technical session cookies, so that you stay signed in, and a cookie for your chosen language. There are no advertising or tracking cookies on the platform, and no third-party analytics are connected.
9. How long we keep data
The data of your case is kept while the support programme runs, and afterwards — because people come back to the road they have travelled: you may return a year later, and the history should still be there.
Records of payments and consents are kept longer than the rest: they show on what terms and when you accepted the contract, and they are needed for accounting.
You can ask us to delete your data at any time — the next section explains how.
10. Your rights
Write to pythonsusa@gmail.com from the address your cabinet is registered to and tell us what you need. We answer within 30 days.
- Receive a copy of the data we hold about you.
- Correct an inaccuracy — part of the data you can correct yourself in your cabinet.
- Delete your data. We will delete it, other than the records of payments and consents that we are obliged to keep.
- Withdraw your consent to processing. Withdrawal means we cannot continue the support programme, because the programme rests on that data.
- Object to processing or ask for it to be restricted.
- Complain to the supervisory authority in your country if our answer does not satisfy you.
11. Participants under 21
Registration is completed by a person aged 21 or over. If the support is needed by someone younger, the questionnaire is filled in by a parent or legal guardian, who confirms this separately in the form and gives the participant's details. Consent to the processing of a child's data is given by the adult, and it is recorded as a separate entry.
We do not collect children's data directly and do not approach a child without the adult.
12. Security
The connection to the site is encrypted. Documents and voice messages sit in private storage and are served through temporary links. Access separation is enforced at the database level. Actions on a case are written to a log.
No system is absolutely secure. If a breach affecting your data occurs, we will tell you about it — through your cabinet or by email.
13. Changes to this policy
If this document changes, the revision date at the top of the page changes with it. We will announce material changes in your cabinet or by email.
14. How to reach us
For any question about data: pythonsusa@gmail.com. Postal address: Pythons & Co, 1331 Amherst Ave, Apt PH5, Los Angeles, CA 90025, USA.
If you have a question about your data, write to us.