Privacy policy
How PsyShare handles your information
PsyShare is a private network for verified UK psychologists. This Privacy Policy explains what information we collect and use to operate PsyShare, including member accounts, referral sharing, discussions, and your choices about your information.
In short: PsyShare does not use advertising or cross-site tracking. Referral content must remain anonymised, and we work with trusted providers who help us securely operate the service.
Last updated 3 September 2026
Who we are and how to contact us
PsyShare is a private, invite-only network for verified psychologists in the UK. It allows members to share anonymised referral opportunities and take part in member discussions. PsyShare is designed for professional networking and referral sharing only. It is not a therapy service, a route for members of the public to access support directly, or a system for providing or coordinating emergency support.
PsyShare is operated by JP & RG Ltd (company number 15293777), a company registered in England and Wales with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We are the “data controller” for the personal information described on this page, which means we are responsible for how it is handled. We are registered with the UK Information Commissioner’s Office (ICO) under registration number ZB783589.
If you have any questions about this policy, want to exercise a right, or want to make a data protection complaint, email support@psyshare.co.uk or use our contact page. You do not need to use legal terminology, and we recognise requests however they reach us.
Member account information
When you register and use your account, we store the details you provide — such as your name, email address, professional and contact details, the outward part of your postcode, the languages you work in, your areas of clinical interest, your current capacity, the insurers you accept, and your profile and notification preferences.
We use this to operate the service, verify your professional eligibility as a UK psychologist, match referrals to suitable clinicians, and manage how we communicate with you. Providing your outward postcode is optional. It is used only to help identify in-person referrals within approximately 30 miles. If you choose not to provide this, referral matching will not include location-based filtering.
Because PsyShare is invite-only, we also record who invited you and keep short-lived records of invitation attempts so that invitation codes cannot be guessed or abused.
As you use PsyShare we necessarily record some information about your activity: which referrals you have expressed interest in or passed on, allocation decisions, whether a message has been read, forum votes and reactions, and any members you have blocked or muted. This information is part of how the features work and is visible only as each feature describes.
Referral and discussion content
Referral summaries shared through PsyShare must be anonymised. Members must not upload or disclose patient-identifiable information within the network. We process referral summaries, expressions of interest, referral comments, and discussion posts so that PsyShare can provide referral matching, professional discussions, notifications, and related platform features.
To maintain a trusted professional environment, we keep moderation records and administrative logs, such as records of reported content and key account actions. These may be retained where needed to administer the service, maintain a trusted professional network, or meet our legal and regulatory obligations.
Our lawful bases for using your information
UK data protection law requires us to have a lawful basis for each purpose. Ours are set out below.
Contract: creating and running your PsyShare account and membership, and providing the referral-sharing service you asked for. Without this information we cannot operate your account.
Legitimate interests: keeping the service and its members secure, maintaining the integrity of a verified professional network, keeping audit records of key account and moderation actions, and moderating content proportionately. We have assessed these uses and consider that they do not override your rights; you can ask us for our assessment, and you can object to processing based on legitimate interests.
Legal obligation: handling data protection rights requests, complaints, and our regulatory obligations, and keeping the records needed to show we have met them.
Consent: optional marketing messages, which you can withdraw at any time from your profile or by using the unsubscribe link. Withdrawing consent does not affect anything we did before you withdrew it.
PsyShare does not ask for patient-identifiable information or special-category data, and referral summaries must be anonymised. If such information is submitted by mistake, tell us and we will remove or restrict it promptly.
Contact enquiries
If you use the public contact form, your name, email address, and message are sent through Netlify Forms so that the PsyShare team can read, classify, and reply to your enquiry.
Please do not use the contact form to share patient-identifiable information, request clinical advice, or seek urgent support. PsyShare does not monitor contact messages as a safeguarding, crisis, or emergency response channel.
Prelaunch email updates
If you ask to hear about the PsyShare launch, we send your email address to EmailOctopus, our prelaunch mailing-list provider. We use it only for occasional emails about the launch and joining the network. Joining this list does not create a PsyShare account and does not replace the registration and professional verification required for access.
We rely on your consent for these messages. EmailOctopus records the subscription status and when the address was added. Together with the specific consent wording on the launch page, this allows us to show when and how you asked to hear from us. EmailOctopus also processes delivery information, such as whether an email was delivered, opened, or a link was followed, so that campaigns can be delivered and managed.
You can withdraw your consent at any time by using the unsubscribe link in an email or contacting support@psyshare.co.uk. We will delete the prelaunch list by 31 October 2026. EmailOctopus may retain limited suppression information where needed to make sure an address that has unsubscribed is not contacted again.
Push notification subscriptions
If you opt in to push notifications, we store the technical information needed to send notifications securely to your device, including a device-specific subscription and encryption details. We use this only to deliver notifications about network activity you have chosen to receive, such as referral interest, nominations, comments on your referrals, account review updates, and expiry reminders. We do not include patient names or referral content in push notifications.
You can turn push notifications off at any time from your profile, which removes the stored subscription for your devices. Device subscriptions are also deleted when you sign out.
Cookies and similar storage
PsyShare does not use advertising cookies or cross-site tracking.
We use essential browser storage to keep your account secure and allow the service to function, including keeping you signed in while you use the platform.
We may also store basic preferences on your device, such as whether you have dismissed the app installation prompt.
Error monitoring
PsyShare does not currently use product analytics, individual tracking, or session recording. PostHog is disabled in both the web and Android applications.
We use Sentry only to identify application errors. Before an error leaves the app, PsyShare removes the error message, user and request data, IP fields, emails, names, headers, cookies, query strings, form or page content, breadcrumbs, console logs, and any recording, profiling, or performance data.
The remaining error record is limited to a random event reference, environment and release, web or Android runtime and build, a generic error class, a route template without identifiers, and scrubbed code locations needed to diagnose the fault. We do not attach a member identifier to error reports.
Providers that help us run PsyShare
We use a limited number of service providers who process information on our behalf only where needed to operate PsyShare: Supabase (application database, authentication, file storage, and hosting of member data), Netlify (website hosting and contact form handling), Resend (sending account and notification emails), EmailOctopus (prelaunch mailing-list management and launch emails), and Sentry (minimised error monitoring). PostHog is disabled and collects nothing.
Push notifications to the PsyShare Android app are delivered by Google, through Firebase Cloud Messaging. Google receives the notification token for your device, a short notification title and body, and internal reference identifiers — never referral content or message text. There is currently no PsyShare iOS app; if we release one, push notifications on that platform will be delivered by Apple through the Apple Push Notification service, and we will update this notice before that happens.
When you enable push notifications in the mobile app, your device is issued a notification token which we store against your account so we can send alerts to that device. The token is an account-linked technical identifier and is deleted when you turn push notifications off, sign out, or delete your account. Notification content is kept deliberately brief and never includes referral details or message text.
To match referrals by distance we look up the approximate location of outward postcodes (for example "SW1A", which covers a wide area and does not identify an address) using postcodes.io, a free public UK postcode service. Your browser makes this request directly, so no name or account detail is sent — but, as with any web request, the service necessarily receives your device’s IP address and standard connection information.
Where PsyShare information is stored: the PsyShare database, member accounts, and uploaded files are held in the United Kingdom, in Supabase’s London region. EmailOctopus stores its contact lists in Ireland. Our providers are internationally operated, so their support, technical, and email-delivery providers may in some circumstances access or process information from outside the UK; where that happens the safeguards described below apply.
Our error monitoring records are stored in the European Union. Some email delivery and push notification delivery is provided from the United States, so an email address and message content, and the technical details needed to deliver a push notification, may be processed there. Where information is transferred outside the UK we rely on the protections in each provider’s data processing terms — an adequacy decision where one applies, and otherwise the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. You can ask us which safeguard applies to a particular provider and we will tell you.
How long we keep information
We keep information for the periods below, and delete or anonymise it afterwards. The only exception is where we must keep something longer for a legal claim, a regulatory obligation, or an ongoing investigation; where that applies we keep only what is necessary, for as long as the reason lasts.
Your account: your account and profile information is kept for as long as your account exists. When you delete your account we remove or anonymise your information as described in the section below.
Referrals and messages: closed, expired, or otherwise finished referrals and their messages are kept for 24 months from the point they finished. Reopening a referral genuinely restarts that period; simply archiving it in your own view does not.
Discussions: forum posts and threads are kept while they remain part of the discussion. Where content has been removed by a moderator, the original content, the report, and the resolution notes are kept for 12 months.
Notifications: 90 days. Push notification registrations: 90 days after a device was last seen, and immediately when you turn push notifications off, sign out, or delete your account.
Administrative and audit records: 24 months. Invitation attempt records: 90 days. Operational records of our scheduled jobs and message delivery, which hold counts and identifiers rather than content: 90 days.
Profile photographs: removed with your account. An uploaded file that is no longer attached to any profile is deleted within 24 hours.
Contact form messages: kept for as long as needed to respond to and manage your enquiry, and in any case no longer than 12 months. Minimised Sentry error records are kept for no more than 30 days. Email delivery logs held by our email provider are kept by them for 30 days.
Prelaunch email list: deleted by 31 October 2026. An address that unsubscribes may remain on a suppression list where necessary to ensure that we honour the request and do not add it back to launch campaigns.
Your rights
You have rights over your personal information under UK data protection law, including the right to access a copy of it, to have it corrected or deleted, and to object to or restrict certain uses of it. You can update most of your profile details yourself in the app at any time, and you can ask us to close and delete your account.
Where we rely on your consent or on our contract with you, and the information was provided by you and is handled automatically, you can also ask us to provide it in a structured, commonly used, machine-readable format, or to send it to another provider where that is technically feasible.
Where we rely on consent, you can withdraw it at any time. Where we rely on legitimate interests, you can object and we will stop unless we have compelling grounds to continue.
Deleting your account does not remove everything instantly or in every case. Content other members rely on — for example a discussion thread others have replied to — is kept but detached from you and shown as belonging to a deleted member. We also keep minimised administrative and audit records for the periods above, and anything covered by a legal hold, so that we can meet our legal obligations. We will explain what applies to your request.
To make a request, email support@psyshare.co.uk or use our contact page. We use proportionate identity checks only where needed. We respond to rights requests without undue delay and generally within one calendar month; if the law permits more time, we will tell you within the first month and explain why.
You can raise a data protection complaint through the same routes. We acknowledge these complaints within 30 days, investigate them, keep you appropriately informed, and explain the outcome. You also have the right to complain to the ICO (ico.org.uk), and you do not need to wait for our process to finish before doing so.
Changes to this policy
We may update this Privacy Policy as PsyShare develops. When we make significant changes, we will update the date shown on this page and, where appropriate, let members know.
