Privacy Policy

Effective date: 2026-04-22 · Last updated: 2026-04-22

⚠ BETA — BAAs with OpenAI, Anthropic, Google, and Railway are pending as of 2026-04-22. Do NOT upload PHI until the subprocessor table below shows all four as executed. Use de-identified data only.

1. Data We Collect

2. PHI Handling

Text submitted for report generation is passed through an automated HIPAA Safe Harbor redaction pipeline before being sent to any third-party language model. Names, dates, MRNs, accession numbers, and other 18-identifier PHI are replaced with non-reversible tokens. Restored PHI (if any) is re-inserted client-side after generation; only redacted text is retained in our database.

Images submitted for vision analysis are forwarded to the vision-capable LLM vendor(s) selected for that study. Radiology images may contain burned-in PHI (overlays, annotations) that automated text redaction cannot remove. Users are responsible for pre-clearing burned-in PHI before upload or using our DICOM-aware import (which strips DICOM metadata).

3. LLM Subprocessors

We transmit redacted content to the following processors as needed to generate reports:

VendorPurposeBAA executed?
OpenAI (GPT-4.1, GPT-5.4, text-embedding-3-small)Primary report generation, embeddingsPending — in active negotiation as of 2026-04-22
Anthropic (Claude Opus 4.6, Sonnet 4.6)Consensus second-opinion, fallbackPending — in active negotiation as of 2026-04-22
Google (Gemini 2.0 Flash, 2.5 Pro)Vision analysis, consensus, Volume IntelligencePending — in active negotiation as of 2026-04-22
Railway CorpApplication hosting, database, logsPending — in active negotiation as of 2026-04-22
Stripe, Inc.Payment processing (billing data only)Not applicable — Stripe is a PCI DSS processor, not a BAA subprocessor. No PHI shared.

4. Data Retention

5. Your Rights

6. Security

7. Cookies and Tracking

We use first-party cookies and local storage only for authentication and UI state. We do not use third-party analytics or advertising trackers.

8. Children

The Service is intended for professional use and is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children.

9. Changes

We will notify you of material changes to this policy at least 30 days in advance by email or in-app notice.

10. Contact

Privacy questions: support@myradagent.ai