Saywell is a product provided by PsycFin Pty Ltd (ABN 81 697 454 345), an Australian company (PsycFin, we, us). Saywell helps financial advisers prepare draft client emails, text messages and related communications. Saywell is not a separate legal entity and PsycFin does not trade under Saywell as a registered business name.
This policy explains how PsycFin collects, holds, uses, discloses, protects and deletes personal information through Saywell, its website, assessment pages, support, billing and related operations. It applies to adviser firms and their personnel, adviser clients, assessment-takers, website visitors and people who contact PsycFin.
Saywell is offered to eligible financial-adviser firms in the United States for US-resident clients and in Australia for Australian-resident clients. It is not directed to firms or individuals in the United Kingdom, European Union or European Economic Area. Do not use Saywell or submit personal information if you are in a prohibited market.
All privacy requests, learning opt-outs and privacy complaints use one channel: hello@saywellhq.com.
The adviser firm is Saywell’s customer. It decides why client information is used in its professional practice and instructs PsycFin to process that information to provide the service. The firm is responsible for its relationship with its clients, its lawful authority to provide their information and its professional records. PsycFin processes customer personal information under the Adviser Terms and Data Processing Addendum.
PsycFin also handles limited information for its own purposes, including account administration, billing, security, fraud prevention, support, legal compliance, privacy-request administration, service improvement and operation of standalone assessments. For those activities, PsycFin determines the relevant handling described in this policy.
For Australian clients, PsycFin supplies adviser firms with a short collection notice. The firm must include that wording in its existing privacy and collection materials, or give it separately, before or as soon as reasonably practicable after first entering the client’s information into Saywell. For US clients, firms must provide the notices required by applicable law and ensure their existing notices adequately cover service providers such as PsycFin.
We may collect and hold the adviser’s and firm’s name, work email, country, account settings, authentication records, clickwrap acceptance records, subscription and referral information, billing metadata, support communications, security events and service activity. Password credentials are handled through managed authentication and are not stored by PsycFin in readable form.
To adapt drafts to an adviser’s voice, Saywell may hold writing samples, a derived voice profile, drafts, edits, regenerations, approvals and related usage signals. Writing samples may be deleted through the available process.
Information supplied by an adviser firm may include a client’s name, email address, optional full date of birth, notes, communication history, pasted or forwarded correspondence and other context supplied for drafting. Saywell does not provide a client phone-number field at launch. A phone number or other information may nevertheless appear incidentally inside material an adviser supplies.
Saywell may derive communication profiles and working inferences, such as how a client appears to prefer information presented, the amount of detail or reassurance that may help, relevant communication context and the adviser’s estimate of those preferences. These are communication aids. They are not clinical, psychological, financial-risk or diagnostic assessments and are not used to make legally significant decisions.
A full date of birth is optional and is stored only on the client record. Saywell derives age or age band at request time. The full date is excluded from AI prompts, logs, analytics, error reports and learning datasets.
An adult may complete an optional communication assessment after an adviser invitation or through an available assessment page. We collect the person’s name, email address, confirmation that they are at least 18, assessment responses, resulting scores, communication profile, report, acceptance record and relevant delivery activity.
Raw assessment responses are not shown to the adviser firm. The firm receives only the resulting communication profile and report. If the assessment-taker requests access or export, PsycFin provides that person’s own responses in legible question-and-answer form, together with the profile and report, subject to any lawful exception.
The assessment page gives a short privacy notice explaining what is collected and shared. Where an assessment is linked to an adviser, the person is asked to confirm sharing with the named adviser before the profile and report are made available. Assessment emails record delivery and bounce events but do not use tracking pixels or per-recipient tracked links.
Adviser-supplied notes or correspondence may contain sensitive information, such as health information, where it is genuinely necessary for the communication and the firm has the required consent or other lawful authority. Such information may be processed by PsycFin and Anthropic to provide the requested service and may be used for private account-level drafting and calibration.
Do not enter government identifiers, authentication credentials, financial account numbers or payment credentials into Saywell, even with consent. Do not supply unnecessary sensitive information. Saywell does not claim to detect, redact or prevent prohibited or sensitive information from being entered. If an adviser supplies information in free text, it may be stored and processed as supplied.
When someone visits a marketing page, infrastructure and advertising services may process IP address, device and browser information, page activity, referring information, advertising identifiers, cookie information and conversion events. PsycFin may also record first-party campaign attribution, such as a campaign code or referral source, and information a person voluntarily submits through a form. Section 10 explains the strict separation between advertising tags and form contents.
We collect information directly from adviser firms and authorised users during signup, account use, support and billing; from adviser clients and assessment-takers through assessment pages and privacy requests; automatically from service, security and marketing technologies; and from service providers that support those activities.
Most client information is collected indirectly from the adviser firm. It may be entered manually, imported from a client list, pasted into a drafting request or forwarded to an approved intake address. Imported CSV or Excel files are processed to create client records and are not retained as uploaded files after processing, subject to verification before publication. Forwarded attachments are removed. The original correspondence and relevant headers are retained as provenance for the resulting draft under the retention rules below.
We use and disclose personal information only for the purposes described here, as reasonably expected for the service, with valid authority, or as otherwise permitted or required by law. These purposes include:
providing, personalising and supporting Saywell, including drafting and assessment functions;
creating and maintaining adviser voice profiles and client communication profiles;
private calibration within the adviser firm’s own account;
recording the inputs and versions needed to explain how a draft was produced;
administering accounts, subscriptions, annual and monthly billing, trials, referrals and payments;
delivering assessment invitations, reports, service notices and privacy communications;
protecting accounts, investigating misuse, preventing fraud and maintaining service reliability;
handling access, correction, export, deletion, opt-out and complaint requests;
producing de-identified and aggregated improvement information under section 8;
complying with law, legal process and enforceable requests, and establishing or defending legal claims; and
managing a genuine corporate transaction or orderly service wind-down under sections 9 and 15.
Saywell does not sell customer or client personal information. PsycFin does not permit identifiable client content to train a third party’s general-purpose AI models. Saywell does not send adviser drafts to clients and does not know whether, or in what form, a draft is sent outside the service.
Your adviser may use Saywell to prepare a draft communication in the adviser’s own voice and adapt its presentation to what may help you understand it. Your adviser must review and decide whether to change, reject or send every draft. Saywell does not provide financial, legal, tax, compliance, psychological or clinical advice.
Saywell may hold contact details, correspondence, adviser notes, drafts and working communication inferences about you. If you complete an assessment, your adviser receives the profile and report but not your raw answers. Your information may be processed in the United States by the providers identified below, including Anthropic for generation.
You may contact PsycFin directly about access, correction, export, deletion or future cross-customer learning. We normally coordinate requests concerning adviser-controlled records with the relevant firm. We may act independently where law requires, where you completed a standalone assessment without an adviser relationship, where the information is controlled by PsycFin for its own purposes, or where coordination would itself risk harm to you.
Saywell uses an Anthropic Claude model through Anthropic’s commercial API to generate drafts and reports. PsycFin does not name a model version in this policy. A model is adopted only after PsycFin’s documented retention and quality checkpoint, and a model change requires privacy re-verification.
Before transmission, Saywell deterministically replaces the client’s stored name and email address with neutral placeholders and replaces stored adviser and firm identifiers where they are not needed. Necessary names are restored locally after generation. Full dates of birth, account identifiers and raw assessment answers are excluded from AI prompts.
This process reduces directly identifiable information but is not complete automated redaction. Supplied notes and correspondence may still contain incidental names, nicknames, third-party details, personal information or sensitive information. Relevant supplied content and communication inferences may therefore be processed by Anthropic to produce the requested output.
Under Anthropic’s standard commercial API terms, inputs and outputs are automatically deleted from its backend within 30 days of receipt or generation. Anthropic may retain information longer where required to enforce its usage rules, comply with law or provide a feature with different retention. Commercial API content is not used to train Anthropic’s general models by default. Anthropic personnel may have limited access for safety, abuse investigation, support or legal compliance under Anthropic’s terms.
Saywell uses an adviser firm’s own voice samples, edits, approvals, regenerations and client information within that firm’s account to adapt its outputs for that account. This private calibration is part of the service. One firm’s identifiable data does not influence another firm’s outputs outside the de-identified process below.
After beta, PsycFin may use de-identified and aggregated patterns from edits, approvals, regenerations, approval patterns and assessment behaviour to improve the service across customers. De-identification occurs before information enters the learning dataset. Identifiers are removed or generalised, PsycFin does not attempt re-identification, and de-identified information may be retained indefinitely.
Sensitive information never enters the cross-customer learning dataset in identifiable form. Communication content cannot enter the pipeline until a written de-identification method explicitly addressing sensitive-content removal or generalisation has been tested. Assessment datasets use coarse categories and a minimum group-size rule designed to prevent combinations describing fewer than ten people.
An adviser firm may opt its account out of future cross-customer learning. A client or standalone assessment-taker may separately opt out their own future data without opting out the firm or any other person. Requests are made through hello@saywellhq.com and are recorded with an effective timestamp.
An opt-out is forward-only and applies to the cross-customer learning corpus. Data generated after the timestamp is excluded from extraction. Contributions already incorporated into genuinely de-identified aggregates cannot be isolated or withdrawn. The opt-out does not prevent the adviser firm’s ordinary use of information in its own account and does not stop private per-account drafting or calibration.
PsycFin uses service providers under contractual and operational controls to run Saywell. The current authoritative list is maintained at saywellhq.com/subprocessors. It identifies each provider’s purpose, information handled, processing location and whether the provider can access readable content. Providers not yet adopted are not listed as active.
Anthropic. AI draft and report generation. Data: Prompt content described in section 7. Location: United States or the location stated on the current list. Readable content: Yes, for prompt content under controlled commercial processing.
Supabase. Database, authentication, storage and backups. Data: Stored product and account data. Location: Production region stated on the current list. Readable content: The provider hosts the data and may have controlled access under its terms.
Vercel. Application hosting. Data: Service data in transit and technical logs designed to exclude personal content. Location: Production region stated on the current list. Readable content: Transit processing; readable client content is not intended to enter logs.
Stripe. Payments, billing and fraud prevention. Data: Adviser billing identity, card metadata, transaction, device and fraud information; no adviser-client data. Location: United States and Australia as applicable. Readable content: PsycFin does not receive full card numbers.
Resend. Transactional email. Data: Recipient name, email address, message content, delivery and bounce events. Location: United States. Readable content: Yes, for email delivery.
Cloudflare. DNS, marketing-site delivery and site analytics. Data: Marketing-site traffic and waitlist information in transit. Location: Global edge network and United States provider. Readable content: Transit and website processing only.
Sentry. Technical error monitoring. Data: Technical error context designed to exclude prompts, outputs and personal content. Location: United States. Readable content: No readable client content by design.
Google advertising services. Marketing-page advertising, analytics, conversion measurement and remarketing. Data: Marketing-site visitor and device information described in section 10, never customer or client information held for adviser firms. Location: United States and other locations described by Google. Readable content: No Saywell product or adviser-client content.
We may also disclose information where required or authorised by law, to protect people, rights or service security, to professional advisers under confidentiality, or as part of a genuine corporate transaction. In a corporate transaction, the recipient must assume applicable privacy obligations, and affected people will receive notice where required.
PsycFin is an Australian company and many providers process information in the United States. Stripe may also process adviser billing information in Australia, and Cloudflare uses a global edge network. The current provider list states other practicable locations. Overseas law may require a provider to disclose information to authorities. PsycFin uses contractual and other reasonable measures appropriate to the provider and processing.
At launch, Saywell’s marketing pages use Google Tag Manager to load active Google Ads conversion and remarketing tags while campaigns run. Marketing pages may also use advertising or analytics tags from platforms such as LinkedIn and Meta during campaigns. These technologies may use cookies, pixels, local storage and similar identifiers and may receive IP address, device and browser information, page activity, referral information, advertising identifiers, cookie information and conversion events.
Google Tag Manager and advertising tags are configured not to collect form-field values, names, email addresses or information visitors type into Saywell forms. A conversion event may record that an action was completed, not the contents submitted. Google Enhanced Conversions, Customer Match and similar features that transmit identifiable or hashed customer details are prohibited unless separately approved through a privacy review.
PsycFin may also use cookieless first-party or infrastructure analytics and first-party campaign attribution on marketing pages. The policy discloses these practices; it does not promise a cookie banner or general consent mechanism merely because a marketing tag is active. If law applicable to a particular activity requires another step, PsycFin will take that step.
Advertising and marketing analytics tags are not permitted on the logged-in Saywell product, assessment pages or checkout beyond Stripe’s own payment and fraud-prevention technologies. Google Tag Manager is confined to marketing pages. Product pages use only essential session and security technologies and technical error monitoring designed to exclude personal content.
A person may send an applicable direct-marketing objection to hello@saywellhq.com. PsycFin records and gives effect to the objection through its request process and suppression controls. Minimal information needed to honour an objection may be retained for that purpose.
PsycFin retains personal information only for the purposes described below, the adviser firm’s documented instructions, legitimate security and operational needs, and applicable legal requirements. Different categories have different periods.
| Category | Ordinary retention | After the period |
|---|---|---|
| **Active account | While needed for the active | Export, restricted |
| and client data** | account and client relationship, | hold or deletion as |
| subject to deletion requests and | applicable. | |
| the three-year review below. |
Standalone 18 months without meaningful Reminder at about 12 assessment activity. months, final notice about 30 days before deletion, then deletion within 35 days.
Support Two years. Delete within 35 records days unless law requires retention.
Application and 90 days; designed to exclude Expire under the error logs personal content. logging schedule.
Security and 12 months. Expire unless authentication required for an logs active investigation or law.
Operational 12 months. Expire under the analytics and
applicable schedule. email-delivery
events
Billing and Seven years or another period Delete when the statutory required by law; adviser billing statutory period financial data only. ends. records
De-identified Indefinite. Not restored or aggregate re-identified for a information request.
Backups Managed expiry within the overall Deleted through 35-day deletion completion backup expiry. window.
For a person with no adviser relationship, meaningful activity means opening the report, engaging with a reminder email, making a request or linking to an adviser. A reminder is sent at approximately 12 months and a final notice approximately 30 days before the 18-month deletion point. The person may use a one-click action to retain the information for another cycle. If the person links to an adviser, adviser-account retention applies from that time.
A client record is not automatically deleted merely because three years have passed. After three years without drafting, correspondence, assessment, profile update or other meaningful client activity, PsycFin asks the firm to confirm whether the relationship remains active. Confirmation restarts the three-year cycle.
If the firm marks the client inactive, the record enters a 90-day export window and is then deleted within 35 days. If the firm does not respond after two notices over 60 days, the record enters restricted hold and the firm receives a final 30-day notice before the export-and-deletion process begins.
A client’s own deletion request takes priority and follows the separate 35-day procedure in section 12. Information that law requires the firm or PsycFin to retain follows the documented restricted-hold process.
After an account is cancelled, including deemed cancellation after 60 days past due, the firm has a 90-day period to request or complete the available manual export. Export is provided in appropriate formats, including structured records, reports, drafts and correspondence. Raw assessment responses remain excluded from the firm export because the firm is not entitled to them. Deletion then begins and is completed across active systems and backup expiry within 35 days, subject to a valid restricted hold or legal requirement.
Identifiable contact data, correspondence, drafts, assessment content, profiles and related content are deleted. A restricted audit skeleton may retain only the event type, timestamp and non-identifying information needed to evidence that an action occurred. De-identified aggregate information already created is not re-identified or reversed. Limited provider-side retention described in section 7, such as safety-flagged content held by the AI provider under its terms, expires under the provider’s arrangement rather than this schedule.
PsycFin offers every individual the same practical process to request access, correction, export, deletion and future cross-customer learning opt-out. This is PsycFin’s commitment and is not an admission that a particular US state statute applies. Formal legal rights depend on the law applicable to the individual and operate in full where they apply.
Send a request to hello@saywellhq.com. PsycFin verifies identity and authority proportionately, records the request and completes the applicable access, correction, export, deletion or learning opt-out process within 35 days. PsycFin may ask only for information reasonably needed to verify or locate the relevant records. Requests are handled without discrimination.
PsycFin normally coordinates a request concerning adviser-controlled records with the relevant firm. If a client requests deletion, the firm has 14 days to give a specific, documented instruction identifying each category that must be retained and the legal or regulatory basis. Without that instruction, deletion proceeds on the standard schedule.
A validly retained category enters restricted hold. It is excluded from drafting, calibration and cross-customer learning and used only for the stated retention purpose. PsycFin records the basis and expected later deletion date and tells the client what was retained and why unless law prohibits that disclosure. Vague instructions to retain everything for compliance are returned for specificity. Information PsycFin controls independently is assessed separately and is not retained merely because the firm objects.
Verified factual errors are corrected directly. PsycFin reviews and corrects or deletes system-generated inferences that are inaccurate, outdated, incomplete or misleading. If the disputed communication profile was measured from the individual’s own assessment, the primary correction is a fresh assessment whose result replaces the profile in full; PsycFin does not manually edit measured results.
Adviser-authored notes and estimates are referred to the firm. If the firm declines to amend them, PsycFin attaches the individual’s correction statement or dispute notation. While under assessment, disputed information is placed in restricted hold and suspended from drafting, calibration and cross-customer learning. Drafting may continue using the adviser’s undisputed estimate or neutral defaults. Original values and correction history persist only in a restricted audit record where needed to explain the change.
If PsycFin refuses or limits a request, it provides written reasons, identifies the affected information, explains what was still provided, corrected or deleted and describes how to request reconsideration. PsycFin does not promise an independent internal reviewer while it has a sole administrator, but may obtain external advice where appropriate.
Send a privacy complaint to hello@saywellhq.com. PsycFin records the complaint, verifies the relevant identity or authority, investigates the facts and provides a written outcome. Complaints are acknowledged within five business days and receive a written outcome within 30 days.
If a complaint genuinely cannot be completed within 30 days, PsycFin explains the reason before the deadline, gives a revised date and continues to provide material updates. A complaint and any extension do not delay an underlying access, correction, export or deletion request beyond its separate 35-day commitment. A person may request reconsideration of the outcome.
Saywell’s client records, communication profiling and assessments are for people aged 18 or over. A date of birth showing a person is under 18 is refused at entry or import, and assessments require an 18-or-over confirmation. A minor may be mentioned incidentally in an adult client’s matter, but must not be created or profiled as the subject of a Saywell client record. If PsycFin learns that an under-18 person has been improperly profiled, it deletes or restricts the information as appropriate.
If Saywell is discontinued or PsycFin winds down, PsycFin gives notice to all adviser firms, provides a 90-day export window and then deletes all customer and client data within 35 days. PsycFin also notifies standalone assessment-takers at their email of record and deletes their identifiable information on the same schedule. Only PsycFin’s own statutory financial records are retained for the legally required period. Restricted legal holds remain only to the extent law requires.
If PsycFin undergoes a merger, financing, reorganisation or sale involving the service, personal information may be disclosed under confidentiality for evaluation and transferred where lawful. The recipient must assume applicable privacy and contractual obligations. PsycFin gives notice where required and does not treat a transaction as permission for an unrelated new use.
PsycFin gives at least 30 days’ advance notice before materially expanding how identifiable adviser or client information is used or disclosed. Notice is sent by recorded account email and a dated change note on the published policy. A material expansion applies prospectively. Updating this policy does not itself create consent or legal authority for a materially different use of previously collected information.
Routine clarifications, provider-detail updates and changes that reduce processing take effect on publication with a dated change note. Urgent security or legal changes may take effect sooner, with notice as soon as reasonably practicable. Subprocessor changes follow the separate DPA process. Inserting the prepared APP and NDB statements after confirmed OAIC registration, and activating features already disclosed, are not material expansions.
PsycFin Pty Ltd
ABN 81 697 454 345
Saywell privacy requests and complaints: hello@saywellhq.com
Postal: PsycFin Pty Ltd, PO Box 5294, Red Hill Rockhampton QLD 4701,
Australia
Current subprocessor list: saywellhq.com/subprocessors