Lab Readout

Legal

Privacy Policy

What we collect, what happens to a document you upload, and what you can ask us to do about it.

Draft pending legal review. The practices below describe how the system actually behaves. The operating legal entity, its jurisdiction, its data-protection representative and the statutory rights framework that applies to you still have to be filled in and reviewed by a qualified adviser before this page is published.

Scope

This policy covers the Lab Readout website, the document analysis application, and the educational resources delivered by email. It does not cover any third-party site you reach by following a link from a document you uploaded.

What we collect

  • Account information. Your email address, your first and last name, and authentication state. We do not collect a phone number.
  • Documents you upload and the analyses, readouts, corrections and conversations derived from them.
  • Resource requests. If you request the Reading Kit, your email address, an optional first name, and which resource version you requested.
  • Campaign attribution for a resource request, limited to standard UTM parameters, the landing page and the referring page.
  • Operational records. Rate-limit counters, audit entries for security-relevant actions, and error diagnostics.

We do not ask for and do not want health information, medical conditions, compound use, or patient information. Please do not put any of it into a document title, a correction note or a message.

Your documents

Uploads go to private object storage, in a bucket that is not publicly readable, under a workspace belonging to your account. Files are limited to 20 MB each and to PDF, JPEG, PNG and WebP.

Access is enforced on the server for every request. Knowing or guessing an identifier does not grant access to a document, and file URLs handed to your browser are short-lived and single-purpose.

Each upload is stored as an immutable version so that a report always points at the file it was actually produced from. Uploading a correction adds a version; it does not replace the earlier one.

AI processing

To produce an explanation, text extracted from your document is sent to an external AI provider over the provider's API. This is the core of how the product works, and it means the content of your document leaves our systems for the duration of that request.

If that is not acceptable for a particular document, do not upload that document. The methodology note describes exactly what the model is asked to do.

Email and consent

Account email — verification, password recovery, and a notice that a report is ready — is sent because you hold an account and asked for that action. It is not marketing and you cannot unsubscribe from it while keeping the account.

Educational newsletters are entirely separate and require you to tick a box and then confirm by clicking a link in a confirmation email. Until you confirm, you are not subscribed. Requesting the Reading Kit does not subscribe you. Creating an account does not subscribe you.

Unsubscribing is honoured permanently. A later resource request will not revive a subscription you withdrew, and a confirmation link issued before you unsubscribed cannot reverse it.

Retention

Documents, analyses and readouts are kept while your account holds them, until you delete them or ask us to. Short-lived items expire on their own:

  • a resource download link, about a week;
  • a newsletter confirmation link, about three days;
  • a signed file URL, minutes;
  • a generated report export, about a month.

Suppression records — the fact that an address unsubscribed — are kept indefinitely on purpose. Deleting that record is how people get re-subscribed by accident.

Who else sees data

We use these categories of processor, and no advertising network receives any of it:

  • a hosting and database provider, which stores your account, documents and reports;
  • an AI provider, which receives document text in order to produce an explanation;
  • an email provider, which receives the address a message is being sent to;
  • a payment provider, only if and when paid features exist.

Document contents, report contents, readout text and analysis results are never sent to advertising or analytics platforms. Download and confirmation tokens are never placed in analytics, referrers or logs.

We do not sell personal data.

Your choices

  • Delete an individual document, with a preview of which reports depend on it first.
  • Request an export of your data, or deletion of your account.
  • Change or withdraw newsletter permission without affecting your account.

Deleting your account and withdrawing email permission are separate actions, and we will tell you what happens to the other one when you do either.

Security

Authorization is checked on the server for every request rather than inferred from the URL. Sensitive operations require a fresh identity check. Rate limits apply to authentication, password recovery, contact messages and resource requests.

No system is perfectly secure. If you believe you have found a vulnerability, please contact us rather than testing it against other people's data.

Contact

Questions about this policy, or a request about your data, can go through the contact form. Email preferences can be changed from the email preferences page.