Privacy Policy
Last updated: 19 July 2026
We think a privacy policy should be something you can actually read, not a wall of boilerplate written to protect a lawyer rather than inform you. So this document explains, in plain language, what Phil collects, why, where it goes, how long it stays, and how you get rid of it. Every claim in it is checked against what the product actually does rather than copied from a template, and where we genuinely don't yet have an answer, we say so instead of guessing. By creating an account or using Phil, you agree to the handling of your information described here. This document is not legal advice, and if you need certainty about how it applies to your situation, a lawyer should review it.
Who we are
Phil is operated by Philosonic, a company incorporated and registered in South Africa at Rosebank, Gauteng. In this policy “we” and “Phil” mean that company, and “you” means the person or organisation using it.
For anything about this policy, your personal information, or how it is processed, contact adam.ismal1@icloud.com and we will get back to you as quickly as we can.
What Phil does
Phil is a platform that helps you understand information you already have. You upload files or connect a supported source, ask questions in plain English, and Phil reads what you gave it, works out what the columns and fields actually mean, and answers, surfaces things worth noticing on its own, and generates reports you can hand to someone else. It is built to read, organise, and explain your information, not to act as an independent decision maker on your behalf.
Phil only reads. It never writes back to Google Sheets or any other system you connect, and it never takes an action inside another tool for you. Anything Phil tells you, whether an answer, an insight, or a report, should be treated as informational and checked by you before you rely on it for a real decision. Every answer is meant to be checkable against your actual data, and Phil is built to say it does not have something rather than guess at it.
Information we collect
Your account. Your email address and a password. The password is hashed by our authentication provider using industry standard hashing, so we never see or store the password itself. If you sign in with Google instead, we receive your email address and basic profile information from Google, and no password at all.
Your workspace. The workspace name you choose and your retention setting, described below.
The data you give Phil. Files you upload, including CSV, Excel, PDF, images, text, JSON and Word documents, plus everything Phil extracts and derives from them, and any spreadsheet content pulled in from a Google Sheet you connect. This is whatever you put into it. If the files you upload contain personal information about your own customers, staff, or anyone else, we end up holding that information too, and you are responsible for having the right to share it with us in the first place.
What you and Phil say to each other.Your chat messages, Phil's replies, the insights it generates on its own, and any reports you create. We keep these so a conversation can continue where you left it, so reports stay available to download, and so your workspace behaves consistently across the files in it.
If you connect Google Sheets. Your Google email address, and access tokens allowing Phil to read your spreadsheets and see their names in your Google Drive. Those tokens are encrypted before they are stored. Phil requests only read only access, specifically permission to view spreadsheets and to see file names and metadata in Drive. It cannot edit, delete, or create anything in your Google account, and it never requests broader access than that.
If you connect Gmail. Your Google email address, and metadata for messages in your inbox, meaning the sender, subject, date, and a short snippet of each one. Phil requests metadata only access and never receives the message body or attachments, and it cannot read full messages, send email, or change or delete anything in your Gmail account. This is a separate, narrower permission from the one Google Sheets uses, requested and stored independently, so connecting one never grants access to the other.
If you connect Google Drive. Your Google email address, and the content of whichever specific file or files you choose to import (for example a CSV, PDF, Excel, Word, JSON, text, or image file already sitting in your Drive). This is a broader, read only permission than the one Google Sheets uses: it lets Phil list your Drive files by name so you can pick one, but it only downloads and imports the content of the file or files you actually choose to link, and it is requested and stored independently of the Sheets permission, so connecting one never grants access to the other. It cannot create, edit, or delete anything in your Google account.
If you connect Google Calendar.Your Google email address, and details of the events on your primary calendar, meaning each event's title, start and end time, location, description, attendee email addresses, and status. If your events include other people as attendees, we end up holding their email addresses too, through this connection. Phil requests read only access and cannot create, edit, delete, or respond to anything on your calendar. This is a separate permission from the ones Google Sheets, Gmail, and Google Drive use, requested and stored independently, so connecting one never grants access to the others.
If you connect Google Forms.Your Google email address, and whichever specific form or forms you choose to link: its title and questions, and every response submitted to it, meaning each answer and, when the form owner has that setting turned on, the respondent's email address. Response data belongs to whoever filled out the form, not just you, and you are responsible for having the right to collect and share it with us in the first place. Phil requests read only access and cannot create, edit, or delete forms or responses. This is a separate permission from the ones Google Sheets, Gmail, Google Drive, and Google Calendar use, requested and stored independently, so connecting one never grants access to the others.
If you connect Outlook Mail. Your Microsoft account email address, and metadata for messages in your inbox, meaning the sender, subject, date, and a short snippet of each one. Phil requests metadata only access and never receives the message body or attachments, and it cannot read full messages, send email, or change or delete anything in your mailbox. This is a Microsoft account connection, entirely separate from the Google-based connections above (Sheets, Gmail, Drive, Calendar, and Forms), it works with either a personal Outlook.com account or a work or school Microsoft 365 account, requested and stored independently, so connecting it never grants access to your Google account or vice versa.
If you connect Microsoft Teams.Your Microsoft account email address, and whichever specific channel or channels you choose to link: each message's sender name, date, and a truncated snippet, meaning it is not the full message text and never includes attachments. Phil never reads private or group chats, only channels you explicitly link. Message content in a channel may include things other people on your team wrote, not just you, and you are responsible for having the right to collect and share it with us in the first place. Phil requests read only access and cannot post, edit, or delete anything in Teams. This uses the same Microsoft account connection as Outlook Mail if you have that connected too, but a separate permission, requested and stored independently, so connecting one never grants access to the other. Microsoft only supports this connector for work or school accounts, not personal Microsoft accounts.
If you connect Excel. Your Microsoft account email address, and the actual content of whichever specific Excel file or files you choose to import from OneDrive. Phil requests read only access to your OneDrive files and cannot create, edit, or delete anything there. This uses the same Microsoft account connection as Outlook Mail/Teams if you have those connected too, but a separate permission, requested and stored independently, so connecting one never grants access to the others. Unlike Teams, this connector works with either a personal Microsoft account or a work or school Microsoft 365 account.
If you connect Outlook Calendar.Your Microsoft account email address, and details of the events on your primary calendar, meaning each event's title, start and end time, location, attendee email addresses, and free/busy status, never the event description. If your events include other people as attendees, we end up holding their email addresses too, through this connection. Phil requests read only access and cannot create, edit, delete, or respond to anything on your calendar. This uses the same Microsoft account connection as Outlook Mail/Teams/Excel if you have those connected too, but a separate permission, requested and stored independently, so connecting one never grants access to the others. Like Excel (and unlike Teams), this connector works with either a personal Microsoft account or a work or school Microsoft 365 account.
If you connect Luno. Unlike every connector above, this is not a sign in with Google or Microsoft: you create a read only API key yourself in your Luno account and paste it into Phil. We store that key, encrypted, along with the transaction ledger it gives us access to, meaning every deposit, withdrawal, trade, and fee across each currency wallet in your Luno account. We only ever ask you to grant balance and transaction history permissions, never permission to trade, send, or withdraw funds, and Phil cannot take any action on your Luno account through this connection.
If you connect Slack.The Slack workspace name, and whichever specific public channel you choose to link: each message's sender name, date, and a truncated snippet, meaning it is not the full message text and never includes threads or attachments. Phil never reads private channels or direct messages, only a public channel you explicitly link, and can only see channels its bot has been invited into. Because Slack limits how much message history an app like Phil can request, each sync only pulls the most recent messages in that channel rather than a full history. Message content in a channel may include things other people in your workspace wrote, not just you, and you are responsible for having the right to collect and share it with us in the first place. Phil requests read only access and cannot post, edit, or delete anything in Slack.
If you connect Xero. Whichever specific organisation you choose to link, and its invoices: invoice number, contact name, type, status, dates, total, amount due, and currency, capped at the 100 most recently updated invoices. Phil never sees line items, bank account details, or any contact information beyond a name. Because one Xero sign in can authorize more than one organisation, you choose which ones to link; Phil requests read only access to invoices and cannot create, edit, or delete anything in Xero.
If you connect Dropbox. Your Dropbox account email, and the content of whichever specific file or files you choose to import (for example a CSV, PDF, Excel, Word, JSON, text, or image file already sitting in your Dropbox). Phil lists your Dropbox files by name so you can pick one, but it only downloads and imports the content of the file or files you actually choose to link. It requests read only access and cannot create, edit, or delete anything in your Dropbox account.
If you connect Mailchimp.Whichever specific resource you choose to link: either your audience (each subscriber's email address, status, tags, and which list they belong to) or your campaign reports (subject lines, send dates, and open/click/bounce/unsubscribe counts), never both unless you choose to link each separately. Phil requests read only access and cannot create, edit, or delete anything in your Mailchimp account, including sending campaigns or editing your audience.
If you connect Notion.The name of your Notion workspace, and the rows of whichever specific database you choose to link, with each property (text, dates, tags, and so on) imported as a column. Notion only ever grants Phil access to the exact pages and databases you explicitly select on Notion's own sharing screen, never your whole workspace. Phil requests read only access and cannot create, edit, or delete anything in your Notion workspace.
If you connect GitHub. Your GitHub username, and the issues or pull requests (numbers, titles, states, authors, dates, labels) of whichever specific repository you choose to link, including private repositories if you grant access to one. Phil requests read only access and cannot create, edit, close, merge, or delete anything in your GitHub account.
If you connect Meta Ads.Your Meta account name, and the campaigns or performance insights (spend, impressions, clicks, CPC, CTR, reach) of whichever specific ad account you choose to link. Phil requests read only access to your ad accounts and cannot create, edit, or delete anything in your Meta Ads account. This connector is subject to Meta's App Review process and may not be available until that review is complete.
If you connect Google Ads.Your Google email address, and the campaigns or performance metrics (spend, impressions, clicks, CTR, average CPC, conversions) of whichever specific Google Ads account you choose to link. Phil requests read only access to your ad accounts and cannot create, edit, or delete anything in your Google Ads account. This connector requires a Google Ads API developer token and may not be available until Google's own access review is complete.
If you connect TikTok Ads. The campaigns or performance metrics (spend, impressions, clicks, CTR, CPC, conversions) of whichever specific TikTok Ads advertiser account you choose to link. Phil requests read only access to your ad accounts and cannot create, edit, or delete anything in your TikTok Ads account.
If you connect Stitch. Like Luno, this is not a sign in with Google or Microsoft: you create a read only Client ID and Secret yourself in your Stitch dashboard and paste them into Phil. We store those credentials, encrypted, along with whichever of PayIns (payments collected) or Refunds you choose to link. Phil only ever queries this data and cannot initiate a payment or refund through this connection.
If you connect PayFast. Like Luno and Stitch, this is not a sign in with Google or Microsoft: you create a read only Merchant ID and Passphrase yourself in your PayFast dashboard and paste them into Phil. We store those credentials, encrypted, along with the transaction history they give us access to, the last 90 days of payments collected, including amounts, status, item descriptions, and buyer email addresses. Phil only ever reads this history and cannot initiate a payment or refund through this connection.
Basic technical information. Standard server logs generated by running the platform, such as request timing and error information, kept only to operate and secure the service.
How we use what we collect
We use your information to operate Phil for you: to authenticate you, to store and organise the files and connections in your workspace, to answer your questions, to generate proactive insights and reports, and to enforce the retention setting you chose. We also use it to keep the platform secure, to diagnose and fix problems when something breaks, and to communicate with you about your account, for example a security notice or a change to this policy.
We do not use your information for advertising, and we do not build a profile of you for any purpose beyond running your own workspace. If we ever wanted to use your information in a new way that isn't covered here, we would update this policy first and, for anything significant, tell you directly rather than bury it in a changelog.
What we don't do
We do not sell your data. We do not share it for advertising.
We do not use your data to train AI models, and neither does our AI provider. Under Anthropic's commercial API terms, data sent through the API is not used to train their models.
Philosophies
A Philosophy changes the voice Phil answers in. It does not change what data is collected, where it is processed, or who can see it. Switching Philosophies is a setting on a data file, stored the same way any other data file setting is, and covered by the same rules as everything else in this policy.
Every Philosophy modeled on a real person, meaning all of them except Phil, is a persona inspired by that person's publicly known writing and interviews, or for historical figures, the historical record. None are affiliated with, endorsed by, or connected to the named individual, their estate, or their companies, and no personal data about any of them is collected or used to build these personas.
Who processes your data on our behalf
Phil is not built entirely from scratch, so running it means a small number of other companies handle your data for us, only to the extent needed to provide the service, and never for their own separate purposes.
Anthropicis the important one. The contents of your files, and the questions you ask, are sent to Anthropic's Claude API so Phil can read them, answer questions, and write reports. This is not optional. It is how Phil works at all. Data sent to the Claude API is processed in the United States.
Supabase is our database, file storage, and login system. Your files and everything derived from them are stored on servers in Paris, France.
Vercel hosts the platform and handles incoming requests, keeping standard server logs in the process.
Google is involved only if you choose to sign in with Google or connect a Google Sheet, and only receives what is needed to authenticate you or to let Phil read the spreadsheet you connected.
International transfers
Phil is based in South Africa, but as the section above shows, your data may be processed outside of South Africa, principally in the United States and the European Union. Where that happens, the transfer relies on Standard Contractual Clauses, and we take steps to make sure your information is protected to a standard consistent with where it came from, wherever it actually ends up.
How long we keep it
You decide this, and nobody else does. We keep your data for exactly as long as the retention period you set, and no longer. There is no separate schedule we apply on top of yours, and we do not hold anything back once yours has run out.
Your retention window is anything between 7 and 90 days, and it starts at 30 until you change it. When a file passes the window you set, Phil deletes it automatically: the file itself, everything extracted from it, and everything derived from it. This runs on a schedule whether or not you remember to ask.
A connected Google Sheet stays current for as long as it keeps syncing successfully, so its retention clock restarts on each successful sync. Stop syncing it and it expires like any other file.
You can also delete any individual file at any time, and you can delete your entire account from Settings. Deleting your account removes your workspace, your files, your chat history, your insights and reports, and your login. We do not keep a copy.
Deleted data is removed automatically as part of the same process, including from backups. We do not keep a separate backup copy of your data after it has been deleted.
How we protect it
Your data is isolated at the database level, so one account's queries cannot reach another's. File storage is private and scoped to your workspace. Access tokens for any service you connect are encrypted before being stored, so they are unreadable even to someone holding a copy of the database.
No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach affecting your data, we will tell you, and where the law requires it, we will also notify the relevant regulator.
Your rights
Deleting your data is self service. You can delete any file, or your whole account, from inside Phil at any time, without asking us.
Everything else, ask us and we will do it by hand. Phil does not currently have an export button, or a way to correct stored data in place. So if you want a copy of your data, or something in it corrected, email adam.ismal1@icloud.com and we will do it within 2 days at most.
If you are in South Africa, where Phil is based, you have rights under the Protection of Personal Information Act (POPIA), including the right to be told what personal information we hold about you, to have it corrected or deleted, to object to how it is processed, and to complain to the Information Regulator if you believe we have mishandled it. Our justification for processing your information is that it is necessary to perform the contract you enter into by signing up for Phil, and, for things like security logs, our legitimate interest in keeping the platform safe and working.
If you are in the UK or EEA, you have rights under the UK GDPR and the GDPR, including access, rectification, erasure, restriction, portability and objection. Our lawful basis for processing is the same one: performance of the contract you enter into by signing up for Phil, with legitimate interest covering things like security and abuse prevention. You can complain to your own country's data protection authority, the ICO if you are in the UK, if you think we have mishandled your data.
Wherever you are, these rights are not exclusive to any one law. If your local law gives you a right we haven't named here, ask us and we will honour it to the extent the law requires.
Cookies
Phil sets only the cookies needed to keep you logged in. No advertising cookies, no third party trackers, and no analytics that follow you around.
Children
Phil is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has created an account or given us information, contact adam.ismal1@icloud.com and we will delete it.
Changes to this policy
If we change how we handle your data, we will update this page and change the date at the top. If the change is significant, we will tell you rather than hope you notice.