Privacy Policy

Last Updated: 27 January 2026


1. Introduction

Mycelia Labs ("Company", "we", "us", or "our") operates SIQ("Platform", "Service"), a quantitative financial analysis platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.

We are committed to protecting your privacy and ensuring transparency about our data practices. This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), and the California Consumer Privacy Act (CCPA).

Data Controller

Mycelia Labs is the data controller responsible for your personal data under the UK GDPR and EU GDPR. As the data controller, we determine the purposes and means of processing your personal data.

Data Protection Contact: For any questions about this Privacy Policy, our data practices, or to exercise your data protection rights, please contact us at privacy@thesiq.ai.

Note: We are in the process of appointing a formal Data Protection Officer (DPO) and will update this policy with their contact details once appointed. In the meantime, all data protection enquiries should be directed to the email address above.

Important Notice About Financial Data

SIQ processes financial information that you voluntarily provide, including portfolio holdings, transaction history, and investment data. This information may be considered sensitive and is treated with additional care.

We do not:

  • Connect directly to your brokerage accounts or financial institutions
  • Store your banking credentials or account passwords
  • Have the ability to execute trades or move funds on your behalf
  • Access financial accounts beyond the data you explicitly upload

All financial data you provide is processed solely to deliver quantitative analysis and insights through the Platform.

2. Information We Collect

2.1 Information You Provide

Data CategoryExamplesPurpose
Account InformationEmail address, name (via WorkOS authentication)Account creation and authentication
Portfolio DataHoldings, transactions, financial positions you uploadProviding quantitative analysis services
Chat HistoryMessages, queries, and conversations with the PlatformProviding AI-powered analysis, improving services
CommunicationsEmails, support requests, feedbackCustomer support and service improvement

2.2 Information Collected Automatically

Data CategoryExamplesPurpose
Usage DataFeatures used, pages visited, session durationService improvement and analytics
Device InformationBrowser type, operating system, device identifiersSecurity, compatibility, troubleshooting
Log DataIP address, access times, error logsSecurity, debugging, fraud prevention

3. Legal Basis for Processing (GDPR)

Under the UK GDPR and EU GDPR, we process your personal data based on the following legal grounds:

Processing ActivityLegal Basis (Article 6)
Account creation and authenticationContract performance
Portfolio data analysisContract performance
Chat history storage and AI processingContract performance
Service improvement and analyticsLegitimate interests
Security monitoring and fraud preventionLegitimate interests / Legal obligation
Marketing communications (if opted in)Consent
Responding to legal requestsLegal obligation
Error monitoring and crash reportingLegitimate interests

Legitimate Interests Assessment: Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may request details of this assessment by contacting us.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Platform
  • Process and analyse your portfolio data to deliver quantitative insights
  • Respond to your enquiries and provide customer support
  • Send service-related communications (e.g., updates, security alerts)
  • Detect, prevent, and address security issues, fraud, and abuse
  • Comply with legal obligations and respond to lawful requests
  • Develop new features and improve our AI analysis capabilities
  • Conduct internal research and analytics to improve service quality

What We Do Not Do: We do not sell your personal information to third parties. We do not use your data for targeted advertising. We do not share your financial data with third parties for their own marketing purposes.

AI Processing and Automated Decision-Making (Article 22 GDPR)

SIQ uses artificial intelligence and machine learning to analyse your data and provide quantitative insights. This constitutes "profiling" under GDPR, as we process personal data to analyse and make predictions about your financial information.

Nature of AI Processing:

  • We use large language models (LLMs) provided by Anthropic to process your queries
  • Your chat messages and uploaded data are sent to AI systems for analysis
  • AI-generated outputs include portfolio analysis, risk assessments, and visualisations
  • No automated decisions are made that produce legal effects or similarly significantly affect you

Your Rights: The AI analysis provided is informational only. All investment decisions remain entirely with you. You have the right to:

  • Request information about the logic involved in the AI processing
  • Express your views about the AI analysis
  • Request human review of any AI-generated insights
  • Object to AI processing based on legitimate interests

5. Third-Party Service Providers (Sub-processors)

We share your information with trusted third-party service providers ("sub-processors") who assist us in operating the Platform. We have entered into Data Processing Agreements (DPAs) with each of these providers that include appropriate data protection obligations.

ProviderPurposeData SharedLocationTransfer Mechanism
WorkOSAuthentication and identityEmail address, name, authentication tokensUSASCCs + DPA
AnthropicAI/LLM processingChat messages, queries, uploaded data for analysisUSASCCs + DPA
RailwayCloud infrastructure and hostingAll application data, session state, databaseUSASCCs + DPA
CloudflareContent delivery and securityIP addresses, request metadataGlobal (USA HQ)SCCs + DPA
SentryError tracking and user feedbackError logs, stack traces, device/browser information, screenshots (if submitted via feedback)USASCCs + DPA

Sub-processor Updates: We may update our list of sub-processors from time to time. Material changes to sub-processors will be notified through updates to this Privacy Policy. You may subscribe to sub-processor update notifications by contacting us at privacy@thesiq.ai.

Transfer Safeguards: For transfers to countries outside the UK and EEA that do not have an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office, supplemented by additional technical and organisational measures where necessary.

6. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Our retention periods are based on business needs and legal requirements:

Data CategoryRetention PeriodBasis
Account DataDuration of account + 2 yearsLegal obligations, dispute resolution
Chat HistoryDuration of account or until deletion requestService provision, user convenience
Portfolio DataUntil deletion request or account terminationService provision
Log Data90 daysSecurity, debugging, fraud prevention
Backup Data30 days after primary deletionDisaster recovery

After the retention period expires, we will securely delete or anonymise your personal data. In some cases, we may retain anonymised data for statistical purposes indefinitely.

7. Your Rights

7.1 Rights Under UK GDPR and EU GDPR

If you are in the UK or European Economic Area, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction: Request limitation of processing
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, please contact us at hello@thesiq.ai. We will respond within one month as required by law.

7.2 Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of personal information collected, used, disclosed, or sold in the preceding 12 months
  • Right to Delete: Request deletion of personal information we have collected from you
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: Opt out of the sale or sharing of personal information (Note: We do not sell or share personal information for cross-context behavioural advertising)
  • Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information to purposes necessary to provide the services
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your privacy rights
CCPA/CPRA Notice

We do not sell your personal information. We do not share personal information for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA/CPRA.

Categories Collected (preceding 12 months): Identifiers (email, name), commercial information (portfolio data), internet activity (usage logs), and inferences drawn from the above.

Verification: When you make a request, we will verify your identity by matching the information you provide with information we have on file. For sensitive requests, additional verification may be required.

Authorised Agents: You may designate an authorised agent to make requests on your behalf. We may require written proof of the agent's authorisation and verify your identity directly.

7.3 How to Exercise Your Rights

To exercise any of your data protection rights, you may:

  • Email us at privacy@thesiq.ai with your request
  • Specify the right you wish to exercise and provide sufficient information for us to verify your identity

We will respond to verifiable requests within one month (GDPR) or 45 days (CCPA), with possible extensions for complex requests. We may request additional information to verify your identity before processing your request.

8. International Data Transfers

Your information may be transferred to and processed in countries outside the UK and European Economic Area, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses approved by the European Commission and UK ICO
  • Data processing agreements with all service providers
  • Assessment of the data protection laws in the destination country

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data in accordance with industry best practices and applicable legal requirements:

  • Encryption of data in transit (TLS 1.3/HTTPS) and at rest (AES-256)
  • Secure authentication through WorkOS (we do not store passwords)
  • Regular security assessments and vulnerability scanning
  • Access controls limiting employee access to personal data on a need-to-know basis
  • Secure infrastructure hosting with Railway in SOC 2 compliant data centres
  • Automated security monitoring and alerting
  • Regular security training for personnel with data access

Employee Access to Your Data: A limited number of authorised Mycelia Labs administrators may access your account data, including chat conversations and strategy configurations, strictly for the following purposes: investigating support requests you have raised, responding to security incidents, complying with legal obligations, debugging platform issues, and conducting SOC 2 compliance audits. All administrative access is logged in an immutable audit trail and reviewed quarterly. We do not access your data for marketing, analytics, or any purpose beyond platform operation and security.

While we strive to protect your personal data using industry-standard security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we commit to promptly investigating and addressing any suspected security incidents.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the supervisory authority: Within 72 hours of becoming aware of the breach, as required by UK GDPR and EU GDPR
  • Notify affected individuals: Without undue delay where the breach is likely to result in a high risk to your rights and freedoms
  • Document the breach: Maintain records of all breaches, including facts, effects, and remedial actions taken

10. Cookies and Similar Technologies

We use essential cookies necessary for the Platform to function, including authentication tokens and session management. We do not use third-party advertising or tracking cookies.

Cookie TypePurposeDuration
AuthenticationKeep you logged in securelySession / 7 days
PreferencesRemember your settings (e.g., theme)1 year

11. Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at hello@thesiq.ai.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

13. Complaints

If you have concerns about our data practices, please contact us first at privacy@thesiq.ai. We take all privacy concerns seriously and will do our best to resolve your concern promptly.

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:

  • UK: Information Commissioner's Office (ICO) - ico.org.uk | Tel: 0303 123 1113
  • EU: Your local data protection authority. A list of EU DPAs is available at edpb.europa.eu
  • California (USA): California Attorney General - oag.ca.gov/privacy/ccpa

14. California "Shine the Light" Law

Under California Civil Code Section 1798.83, California residents may request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes.

We do not disclose personal information to third parties for their direct marketing purposes. If this practice changes, we will update this Privacy Policy and provide you with an opportunity to opt out.

15. Contact Us

For any questions or concerns about this Privacy Policy or our data practices:

Mycelia Labs

Data Protection Enquiries

Privacy Email: privacy@thesiq.ai

General Email: hello@thesiq.ai

Website: https://thesiq.ai

For time-sensitive data protection matters, please include "URGENT" in the subject line of your email. We aim to respond to all enquiries within 5 business days.


Record of Processing Activities (GDPR Article 30)

As required under Article 30 of the GDPR, we maintain a record of all processing activities carried out under our responsibility. This record is available to the supervisory authority upon request and includes information about the purposes of processing, categories of data subjects and personal data, recipients of data, international transfers, retention periods, and security measures.

You may request a summary of our processing activities relevant to your personal data by contacting us at privacy@thesiq.ai.

This Privacy Policy is effective as of 27 January 2026.

Previous versions of this Privacy Policy may be requested by contacting us at privacy@thesiq.ai.

View Terms and Conditions