Data We ProcessAccount and usage data
CliniAtlas uses sign-in data such as email address, account identifiers, and session tokens to authenticate users and protect access. The app stores chat titles, user questions, generated answers, source metadata, timestamps, and attachment metadata so signed-in users can review their previous evidence searches.
Chat imagesImage attachments
Signed-in users may attach images to Fast or Full chat. Images are stored in encrypted EU AWS storage, sent to the selected AWS Bedrock model to create the answer and search context, and configured to expire after 30 days. Users should not upload names, identifiers, or other unnecessary personal data. Image chat is for professional evidence discussion and is not a diagnostic medical-imaging service.
VerificationHCP review data
If a user submits a medical ID, professional registration number, diploma, or credential image for verification, the data is used only to assess professional access eligibility. Credential images are stored in EU AWS infrastructure and configured to expire after 24 hours.
InfrastructureEU processing
CliniAtlas is hosted on AWS infrastructure in the EU region. Retrieval and model calls process user questions and retrieved source excerpts to generate citation-grounded answers. Literature and web retrieval services receive search terms, not CliniAtlas account credentials.
Report exportsPDF and Word files
When a user exports a completed answer or Deep Research result, CliniAtlas creates the PDF or Word file on demand from the already saved answer and source metadata. The generated download is returned directly to the user and is not stored as a separate report file by CliniAtlas. The user controls copies saved or shared from their device.
RetentionHow long data is kept
Chats and saved reports remain available until the user deletes the account. Deep research working files expire after 180 days. Credential images and verification review records are configured to expire after 24 hours. Chat image objects expire after 30 days. Security and access logs are retained for limited operational periods, up to 365 days for production access logs.
Service providersAuthentication and evidence processing
AWS provides EU hosting, authentication, storage, and model inference. Google and Apple process information when their optional sign-in methods are used. PubMed, Europe PMC, guideline, regulatory, and web-search services process evidence search terms.
Operational dataSecurity and usage records
CliniAtlas records timestamps, request outcomes, account identifiers, quota usage, and infrastructure access information to operate the service, prevent abuse, investigate failures, and understand aggregate product usage. These records are not used for advertising or cross-app tracking.
Public trialTwo-question landing preview
The public landing-page trial processes the submitted question but does not add it to a CliniAtlas chat history. To enforce the two-question allowance and prevent automated abuse, CliniAtlas stores a pseudonymous browser identifier for up to 30 days and a salted one-way hash of the source network for up to three days. The quota record does not store the raw IP address.
ControlsAccess and deletion
Users can permanently delete their account and associated chats, chat attachments, reports, verification records, quota records, and sign-in identity from the mobile app or the account deletion page. For access, correction, or other privacy requests, contact hello@discensmachina.com.