OmniBioFex.Cloud is built with strict data minimization principles. Because the platform is not clinical-grade and is intended only for educational and research use, we designed our infrastructure to keep uploaded medical data ephemeral by default.
Medical files uploaded to the platform are processed using ephemeral storage. Data is scrubbed from our servers immediately following the completion of the AI inference block.
Your uploaded images and histopathology slides are held in memory only for the duration of the inference request. Once the model returns a response, the original upload is discarded.
We do not use your uploaded medical content to train, fine-tune, or otherwise improve Qwen 3.8 27B or any downstream model.
We collect the minimum amount of information required to operate the service, enforce fair usage, and provide you with a functional report history.
Google OAuth provides your email address to create your account ID. We do not store passwords, phone numbers, or other personal identifiers.
When you generate a report, you provide a patient name, age, and gender. Stored alongside your report in your private history. Used only to populate the PDF letterhead.
The structured clinical report is stored in Firestore to populate your historical dashboard. Original uploads are never stored — only the model's text response.
OmniBioFex is built on established cloud infrastructure. Each provider is governed by its own privacy policy and terms of service.
| Provider | Purpose | Data Retained |
|---|---|---|
| Groq | Qwen 3.8 27B inference | None (processed in memory) |
| Google Firebase | Authentication & Firestore | Email, patient metadata, report text |
| Razorpay | Payment Processing | Billing details (no medical data) |
| Resend | Transactional email | Email address only |
Required to keep you logged in after Google OAuth. Strictly necessary and cannot be disabled while using the platform.
We do not use advertising pixels, cross-site tracking cookies, or third-party analytics that profile your behavior outside OmniBioFex.
Any analytics we collect are aggregate, anonymized, and used solely to monitor uptime, error rates, and API throughput.
Request a copy of the account data we hold for you — email address, patient metadata you entered, and the report outputs stored in your history.
Request full deletion of your account and its stored report history. Deletion is irreversible and completes within 30 days.
Request correction of inaccurate account information. Since we store limited data, this is typically limited to updating your OAuth-linked address.
All traffic between your browser, our servers, Groq, and Google Cloud is encrypted in transit using TLS 1.2 or higher.
Production credentials and Firebase access rules are restricted to a minimal set of authorized engineers under the VantyrixTek organization.
We may update this Privacy Policy from time to time. Material changes will be announced on the main page and reflected in the "Last updated" date above. Continued use of OmniBioFex after changes constitutes acceptance.