Data We ProcessAccount and usage data
CliniAtlas uses sign-in data such as email address, account identifiers, and session tokens to authenticate users and protect access. The app stores chat titles, user questions, generated answers, source metadata, and timestamps so signed-in users can review their previous evidence searches.
VerificationHCP review data
If a user submits a medical ID, professional registration number, diploma, or credential image for verification, the data is used only to assess professional access eligibility. Credential images are stored in EU AWS infrastructure and configured to expire after 24 hours.
InfrastructureEU processing
CliniAtlas is hosted on AWS infrastructure in the EU region. Retrieval and model calls process user questions and retrieved source excerpts to generate citation-grounded answers. Literature and web retrieval services receive search terms, not CliniAtlas account credentials.
RetentionHow long data is kept
Chats and saved reports remain available until the user deletes the account. Deep research working files expire after 180 days. Credential images and verification review records are configured to expire after 24 hours. Security and access logs are retained for limited operational periods, up to 365 days for production access logs.
Service providersAuthentication and evidence processing
AWS provides EU hosting, authentication, storage, and model inference. Google and Apple process information when their optional sign-in methods are used. PubMed, Europe PMC, guideline, regulatory, and web-search services process evidence search terms.
Operational dataSecurity and usage records
CliniAtlas records timestamps, request outcomes, account identifiers, quota usage, and infrastructure access information to operate the service, prevent abuse, investigate failures, and understand aggregate product usage. These records are not used for advertising or cross-app tracking.
Public trialTwo-question landing preview
The public landing-page trial processes the submitted question but does not add it to a CliniAtlas chat history. To enforce the two-question allowance and prevent automated abuse, CliniAtlas stores a pseudonymous browser identifier for up to 30 days and a salted one-way hash of the source network for up to three days. The quota record does not store the raw IP address.
ControlsAccess and deletion
Users can permanently delete their account and associated chats, reports, verification records, quota records, and sign-in identity from the mobile app or the account deletion page. For access, correction, or other privacy requests, contact hello@discensmachina.com.