Polycarp Privacy Policy
In force from 21 September 2026. Last updated: 28 September 2026 (customer records).
This policy explains what personal data Polycarp handles, why, and what your rights are. Polycarp is operated by GestureLoop Limited (company number 792165), 44 Cluain Droichead, Sixmilebridge, Co. Clare, V95 HD62, Ireland, which also operates the Yohanun platform that Polycarp runs on. If you have a question or want to exercise a right, write to privacy@yohanun.com.
There are two kinds of people this policy is written for, and the rules differ.
If you are a visitor talking to a Polycarp agent on someone's website
The business whose website you are on decides why the chat window is there and what happens to what you say. In data-protection terms, that business is the controller and we are its processor: we handle your data on its instructions and under a written agreement with it. Its own privacy notice applies to your conversation, and requests about your data should go to it first. We help it answer.
What we handle. The messages you type and the agent's replies; a random visitor identifier that the chat window keeps in your browser's local storage so that your conversation is still there when you come back; the pages the agent drew on for each answer; a thumbs-up or thumbs-down if you give one; and, if you ask to reach a person, the name, email address, organisation and message you enter in the handoff form. If you have signed in to the website and it chooses to attach your account to the conversation, we also hold the account identifier and any name or profile fields the website sends us. We use your network address to limit abuse: it is held in memory for about a minute to count requests, and it appears in our web server's logs, which are kept for fourteen days. We do not set cookies in the chat window and we do not run analytics in it. The visitor identifier is strictly necessary to give you the chat you asked for, which is why it does not need your consent under the ePrivacy rules; it is separate for each website's agent and is never used to recognise you on another website.
You are talking to an AI. The agent is an AI system, not a person, and the chat window says so. A person from the business may take the conversation over, and the chat tells you when that happens. The agent answers questions; neither we nor the agent make decisions about you that have legal or similarly significant effects.
What we do with it. We send your message, with the relevant pages from the website's content and the earlier turns of your conversation, to an AI model to produce a reply. We store the conversation so that the business can review it, answer a handoff request, and improve its agent. If you ask for a person, we email the business the conversation and your details. We do not use your conversation to train AI models, and we do not use it for advertising.
Customer records. If you have signed in on the website, or left your email in the handoff form, the business can see a record of you in Polycarp: your conversations with its agents, a one-line summary of each, labels such as "asked for a quote" or "unhappy", and short notes about what you told it about yourself, such as a preference or what you ordered. The summaries, labels and notes are drawn by an AI model from your own words once a conversation has gone quiet; the model is instructed never to record anything about health, religion, politics, sexuality, ethnicity or trade-union membership, anything about other people, or guesses. The business can correct or delete any note, and erasing you erases the record and the notes with your conversations. The agent uses the notes only when the website has signed you in, so it never mistakes someone else for you. If you have not signed in and have not left your email, there is no record of you.
Who else sees it. The AI models are provided by Anthropic and OpenAI under their API terms, which do not allow them to train on the data. Anthropic's models write the agent's replies. OpenAI's models turn text into the numerical form used to search the website's content, and extract and summarise content and conversations so that the agent can find them later. Email is sent through Resend. Everything is stored on servers we rent from Hetzner in Helsinki, Finland. The full list, with locations and safeguards, is in the Data Processing Agreement.
How long. The business decides. It can set a period (ninety days, six months, one year or two years) after which the conversations of visitors who have not signed in are erased automatically once they have gone quiet; if it sets none, they are kept for as long as it keeps its Polycarp account, so that its record of what its agent said is complete. If you signed in on the website, your conversations are kept while the business has its account, because remembering you is what signing in is for. The business can erase any conversation at any time, and must do so if you ask and the law gives you that right. The visitor identifier in your browser stays until you clear your browser's site data.
Your rights. You have the rights the GDPR gives you: to see the data we hold about you, to have it corrected or deleted, to restrict or object to its use, and to receive a copy. Ask the business first; if you cannot reach it, ask us at privacy@yohanun.com and we will help. You can complain to the Data Protection Commission in Ireland or to the supervisory authority where you live.
If you are a Polycarp customer
For your own account we are the controller.
What we handle. The email address and password of each person you let sign in (the password is stored only as a salted hash); the name and contact email of your organisation; the website you connect and the pages we read from it; your agents' settings; your usage, counted in conversations; billing details once you subscribe, which are held by Stripe and not by us (we hold your Stripe customer and subscription identifiers and the monthly overage we invoice); and the emails between us. We log sign-in attempts with the network address they came from to protect the account.
Why. To provide the service you asked for, to bill you for it, to keep your account secure, to tell you about changes that affect you, and to meet our legal obligations. The legal basis is the contract between us and, for security and service messages, our legitimate interest in running the service properly. We do not use your data for advertising and we do not sell it.
How long. For the life of your account and, after it closes, for as long as we must keep records for tax and legal purposes, which is six years in Ireland for financial records. Everything else is deleted as described in the Data Processing Agreement.
Your rights. The same rights as above, exercised by writing to privacy@yohanun.com. You can complain to the Data Protection Commission.
If you visit polycarp.yohanun.com
Our own website uses no advertising or analytics cookies. If you sign in as a customer we set one session cookie, which is strictly necessary to keep you signed in. If you ask to start your free month, the form sends us your email address, your website and your message by email, and we use them only to reply to you, on the basis of our legitimate interest in answering a request you made. The website loads its typefaces from Google Fonts, so your browser contacts Google and shares your network address with it when a page loads; the chat window on customers' websites does not. The chat on our own website is a Polycarp agent like any other, and the visitor section above applies to it, with us as the business.
Where data goes
Our servers are in the European Union. Two of our providers, Anthropic and OpenAI, process data in the United States. We rely on the EU–U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. Copies are available on request.
Security
Data is encrypted in transit. Each customer's content and conversations live in their own isolated tenant on the Yohanun platform, and that isolation is enforced by the platform, not by policy. Credentials for the platform are encrypted at rest. Access to production systems is limited to the people who run them. Backups are taken daily. If a breach affects you, we will tell you and, where the law requires, the supervisory authority, without undue delay.
Children
Polycarp is a business tool and is not directed at children. A business whose website is used by children is responsible for its own compliance.
Changes
We will post changes here and, for changes that matter to customers, email them at least thirty days in advance.
Contact
GestureLoop Limited (company number 792165, VAT IE4457373FH), 44 Cluain Droichead, Sixmilebridge, Co. Clare, V95 HD62, Ireland. privacy@yohanun.com.