Privacy notice · launch draft
How report data is handled
Last updated 6 September 2026. Have qualified counsel review this notice for every launch region before accepting customers.
Data used
Account identifiers, uploaded reports, OCR text, structured lab rows, conversations, subscription status, share settings, and pseudonymized access-log data are used to provide the service.
Current processors
The hosted application can send data to Clerk for authentication, Cloudinary for document storage, Mistral for OCR, Groq for hosted open-weight generation, MongoDB for persistence, Stripe for billing, and Cloudflare Workers AI for voice-agent inference, speech recognition, and session processing. Spoken responses use the speech-synthesis voice provided by the patient's browser or operating system. An Ollama deployment can keep text generation within customer-controlled infrastructure, but the other processors remain unless separately replaced.
Voice sessions
Voice processing starts only after you press the start button. During a session, microphone audio is transcribed and relevant account health records are supplied to the voice assistant. The bounded record snapshot is removed from the session store when the call ends; completed conversation turns can remain in the session's Cloudflare Durable Object until the production retention workflow removes them. Raw microphone audio is not intentionally stored by MediClarity application code.
Sharing and retention
Users can create revocable, expiring links. Access is logged. Database TTL removes expired share grants, but source-report, voice-session, and account deletion workflows must be configured in the production operating policy.
Claims we do not make
This code alone does not establish HIPAA, GDPR, DPDP, or regional data-residency compliance. Contracts, subprocessors, infrastructure, incident response, deletion operations, and legal review are required.
Do not upload emergency information. MediClarity provides health information, not diagnosis or emergency care.