1. Who We Are
Custodian AI ("Custodian", "we", "us", "our") is a company incorporated under Swiss law, operating the Custodian employee wellbeing monitoring platform (the "Platform" or "Service"). Our platform helps organizations monitor the psychological impact of AI tool adoption on their workforce while protecting the privacy of individual employees.
For all privacy enquiries, contact us at: info@custodian.health
2. About This Policy
This Privacy Policy explains how Custodian collects, uses, shares, and protects personal data. It applies to:
- Business customers — HR teams and companies that subscribe to Custodian ("Customers").
- Employees — individuals employed by Customers who interact with Custodian's analysis pipeline through their workplace AI tools ("Employees").
- Website visitors — anyone visiting custodian.health or its subdomains.
Custodian acts as a data controller for account, billing, and website data, and as a data processor for Employee behavioral analysis data processed on behalf of Customers.
3. The Privacy-by-Architecture Guarantee
Employee data passes through these stages, in this order:
- Capture, in the employee's browser. The Custodian browser extension records what the employee and the assistant write on ChatGPT, Claude, Gemini and Microsoft Copilot, and only while the employee has capture switched on. The optional Custodian connector does the same for coding assistants used from the terminal (Claude Code, Codex CLI, GitHub Copilot CLI, Antigravity): it reads the session logs those tools keep on the employee's computer and takes only what the employee wrote and the text of the assistant's replies, never the commands run, the files read or the code produced. The text stays on the employee's computer until it is sent. Before sending, the employee can read the queue, remove a chat, exclude a chat for good, or delete everything. After sending, the browser keeps no readable chat text.
- De-identification, on arrival. The text travels over an encrypted connection to the Custodian service. There, before anything is written to storage, Presidio (an open-source library) detects and replaces names, email addresses, phone numbers, postal addresses, payment card and bank account numbers, national identification numbers, IP addresses, links and place names. The un-redacted text is never stored. Automatic detection is not perfect: a name typed without capital letters, for example, can be missed.
- Anonymous ID. Every record is stored under an anonymous ID assigned by the service. The username is never stored with the conversation records, and an ID supplied by the browser is ignored.
- Analysis. A model that runs on the service's own hardware reads the de-identified text and estimates mental states and the safety of the assistant's replies. No conversation text is sent to an external AI service.
The organisation view for HR combines the published results of the Customer's participants. It shows averages, weekly trends and mental states only where at least five participants contribute, and shows nothing while fewer than five have results. It never shows a name, an account, a conversation or one person's result, and it cannot be filtered down to a person.
Individual Employee dashboards display a summary of the Employee's own processed behavioral signals. This data is accessible only to the individual employee. HR, team leads and any other party within the organization never see it; it enters the HR view only as part of a group of at least five.
4. Data We Collect
4.1 Account and Platform Data (Controller)
When a Customer subscribes to Custodian, we collect:
- Company name, industry, and organization size
- Name, work email address, and job role of administrative contacts
- Billing information (processed by our payment provider; card numbers are not stored by Custodian)
- Communication records (support emails, onboarding interactions)
Legal basis: Performance of a contract (GDPR Art. 6(1)(b)).
4.2 Employee Behavioral Data (Processor)
When an Employee installs the Custodian browser extension or the Custodian connector and switches capture on, it collects the text of their conversations with the supported AI assistants (what they write and what the assistant answers), together with the time, the name of the assistant, and the conversation and message identifiers. The page address is reduced to the site and path; for coding assistants there is no page address, and nothing about the computer, the project or the files is sent. The extension or connector sends this data to the Custodian service at the interval the Employee sets (once a day by default), or when the Employee chooses to send.
For the account, the service stores a username, a password hash (Argon2), the anonymous ID and hashed session tokens. It does not ask for an email address.
Custodian processes this data on behalf of the Customer under a Data Processing Agreement (DPA) incorporated into the Customer's subscription. The Customer is the data controller for Employee data; Custodian is the data processor.
Legal basis (as processor): Legitimate interest of the Customer under its employment relationship with Employees (GDPR Art. 6(1)(f)), subject to the Customer's obligations as data controller and applicable employment law.
4.3 Technical and Log Data (Controller)
We automatically collect server logs, IP addresses (pseudonymized for analytics), browser type, operating system, pages visited, and error reports for the purposes of maintaining service security and performance.
Legal basis: Legitimate interests in maintaining service security, stability, and quality (GDPR Art. 6(1)(f)).
4.4 Cookie Data
See Section 11 (Cookie Policy) below.
5. Purposes and Legal Bases
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide and operate the Platform | Account data, behavioral data | Contract performance (Art. 6(1)(b)) |
| Billing and payment | Account data, payment data | Contract performance (Art. 6(1)(b)) |
| Employee personal wellbeing dashboard | Behavioral signals (own only) | Processor for Customer |
| HR organisation view | Results combined over at least five participants | Processor for Customer |
| Security and fraud prevention | Log data | Legitimate interest (Art. 6(1)(f)) |
| Service improvement (aggregate analytics) | Anonymized usage data | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Account email (opted-in contacts) | Consent (Art. 6(1)(a)) |
6. Data Sharing
We do not sell personal data. We share data only in the following circumstances:
- No AI provider. De-identification (Presidio, an open-source library) and analysis (a model built on Apertus, the open model of the Swiss AI Initiative) both run inside the Custodian service. Neither sends conversation text to a third party.
- Payment processors. Subscriptions are paid through Stripe or PayPal. Custodian does not receive or store payment card numbers.
- Hosting. The public website is served through Cloudflare. For each pilot, the location of the service that stores and analyses the conversation records is agreed in writing with the Customer; it can be a machine inside the Customer's own network.
- Legal Disclosure. We may disclose personal data if required by applicable law, court order, or valid government request, or to protect the legitimate rights of Custodian and its users.
All sub-processors are required to comply with GDPR and maintain appropriate security measures under written data processing agreements.
7. International Data Transfers
Custodian operates from Switzerland. Switzerland has been recognized by the European Commission as providing an adequate level of data protection for transfers of personal data from the EU/EEA (adequacy decision).
Analysis of conversation records is performed on the machine agreed with the Customer for the pilot. No conversation text is transferred to an external AI service.
For any residual transfers to sub-processors outside the EEA (e.g., support tooling), Custodian relies on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by appropriate technical safeguards.
8. Data Retention
| Data Category | Retention Period |
|---|---|
| Account and billing data | 3 years after contract termination, or longer if required by law |
| De-identified conversation records and the results derived from them | For the duration of the pilot, then erased, unless the agreement with the Customer sets a shorter period. An Employee can erase their own records at any time from their account. |
| Web server logs | 12 months |
9. Your Rights
Under the GDPR and the Swiss Federal Act on Data Protection (nFADP / revDSG, revised 2023), you have the following rights:
If you are an Employee (end user)
Because Custodian processes Employee data on behalf of the Customer (your employer), your employer is the primary data controller for your Employee data. You should direct your data rights requests to your employer in the first instance. You can also act yourself: your Custodian account lets you export everything the service holds about you and erase your account together with all its records, and the browser extension lets you delete what it still holds. You may also contact Custodian directly at info@custodian.health.
- Right of access — Request a copy of the personal data Custodian holds about you.
- Right to rectification — Request correction of inaccurate data.
- Right to erasure — Request deletion of your personal data, subject to legal retention obligations.
- Right to restriction — Request that we limit processing of your data in certain circumstances.
- Right to data portability — Receive your data in a structured, machine-readable format where technically feasible.
- Right to object — Object to processing based on legitimate interests.
If you are a Customer contact
You have the same rights in relation to your account and contact data held by Custodian as controller.
We will respond to requests within 30 days. Where requests are complex, we may extend this to 3 months with prior notification. To exercise your rights, contact: info@custodian.health
Right to lodge a complaint
If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with:
- Your national data protection supervisory authority (EU/EEA residents)
- The Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch (Swiss residents)
10. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include:
- Encrypted connections (TLS) between the browser extension, the website and the service
- Personal identifiers removed before conversation records are stored
- Passwords stored as Argon2 hashes; session tokens stored only as hashes
- Sign-up by invite code; the administration interface is reachable through the website only
- The administrator of a pilot sees participation counts under anonymous IDs, not conversation text or individual results
For a full description of our security practices, see our Security page.
11. Cookie Policy
The Custodian website sets no cookies. It uses no analytics, no advertising and no third-party trackers, so it shows no cookie banner. The pilot setup page remembers the pilot access code in the browser's session storage while the tab is open, so that a reload does not ask for it again.
The personal dashboard keeps the session token in the browser's session storage, which the browser clears when the tab is closed. The checkout page loads scripts from Stripe or PayPal, which may set their own cookies under their own policies.
12. Children and Minors
The Service is designed for professional workplace use by adults. We do not knowingly collect personal data from individuals under 16 years of age. If you believe we have inadvertently collected such data, please contact info@custodian.health immediately.
13. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last Reviewed" date at the top of this page. For material changes, we will provide advance notice to Customers by email or in-platform notification at least 14 days before the change takes effect.
Your continued use of the Platform after the effective date of any change constitutes acceptance of the revised Policy.
14. Contact Us
For all privacy-related enquiries, data subject requests, or to report a potential privacy issue:
Custodian AI
Switzerland
Contact: info@custodian.health