ZERO PHI RETENTION. EPHEMERAL INFERENCE STORAGE. TRANSPARENT THIRD-PARTY DISCLOSURE. TLS 1.3. AES-256 AT REST. ZERO PHI RETENTION. EPHEMERAL INFERENCE STORAGE. TRANSPARENT THIRD-PARTY DISCLOSURE. TLS 1.3. AES-256 AT REST.
PRIVACY POLICY

Our Commitment to Privacy

OmniBioFex.Cloud is built with strict data minimization principles. Because the platform is not clinical-grade and is intended only for educational and research use, we designed our infrastructure to keep uploaded medical data ephemeral by default.

Zero PHI retention Ephemeral inference storage Last updated: 2026-09-16

1. Zero PHI Retention Policy

Medical files uploaded to the platform are processed using ephemeral storage. Data is scrubbed from our servers immediately following the completion of the AI inference block.

WHAT THIS MEANS

UPLOADED FILES ARE NOT PERSISTED

Your uploaded images and histopathology slides are held in memory only for the duration of the inference request. Once the model returns a response, the original upload is discarded.

WHAT THIS MEANS

NO TRAINING ON YOUR DATA

We do not use your uploaded medical content to train, fine-tune, or otherwise improve Qwen 3.8 27B or any downstream model.

IMPORTANT — While we enforce zero PHI retention at the application layer, OmniBioFex is not a HIPAA-compliant or clinically certified system. Do not upload identifiable patient data unless you have independent legal authority to do so under your local jurisdiction.

2. Information We Collect

We collect the minimum amount of information required to operate the service, enforce fair usage, and provide you with a functional report history.

01

AUTHENTICATION DATA

Google OAuth provides your email address to create your account ID. We do not store passwords, phone numbers, or other personal identifiers.

02

PATIENT METADATA

When you generate a report, you provide a patient name, age, and gender. Stored alongside your report in your private history. Used only to populate the PDF letterhead.

03

REPORT OUTPUT

The structured clinical report is stored in Firestore to populate your historical dashboard. Original uploads are never stored — only the model's text response.

3. Third-Party Infrastructure

OmniBioFex is built on established cloud infrastructure. Each provider is governed by its own privacy policy and terms of service.

ProviderPurposeData Retained
GroqQwen 3.8 27B inferenceNone (processed in memory)
Google FirebaseAuthentication & FirestoreEmail, patient metadata, report text
RazorpayPayment ProcessingBilling details (no medical data)
ResendTransactional emailEmail address only
NOTE — Groq processes inference requests in memory and does not persist your uploaded medical files. Razorpay receives only billing information — no images, patient data, or report outputs are ever transmitted to our payment processor.

4. Cookies & Analytics

A

SESSION COOKIES

Required to keep you logged in after Google OAuth. Strictly necessary and cannot be disabled while using the platform.

B

NO TRACKING PIXELS

We do not use advertising pixels, cross-site tracking cookies, or third-party analytics that profile your behavior outside OmniBioFex.

C

AGGREGATE METRICS ONLY

Any analytics we collect are aggregate, anonymized, and used solely to monitor uptime, error rates, and API throughput.

5. Your Rights

01

ACCESS

Request a copy of the account data we hold for you — email address, patient metadata you entered, and the report outputs stored in your history.

02

DELETION

Request full deletion of your account and its stored report history. Deletion is irreversible and completes within 30 days.

03

CORRECTION

Request correction of inaccurate account information. Since we store limited data, this is typically limited to updating your OAuth-linked address.

EXERCISING YOUR RIGHTS — Contact privacy@omnibiofex.cloud from the email address associated with your account. We respond to all verified requests within 30 days.

6. Data Security

SAFEGUARD

TRANSPORT ENCRYPTION

All traffic between your browser, our servers, Groq, and Google Cloud is encrypted in transit using TLS 1.2 or higher.

SAFEGUARD

ACCESS CONTROL

Production credentials and Firebase access rules are restricted to a minimal set of authorized engineers under the VantyrixTek organization.

YOUR RESPONSIBILITY — You are responsible for ensuring that any data you upload complies with your local privacy regulations. Ensure you have legal authority to process any patient data you submit.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced on the main page and reflected in the "Last updated" date above. Continued use of OmniBioFex after changes constitutes acceptance.