Privacy Policy
This policy explains what information MediSynth collects, why, how we protect it, and the rights you have over it — including your right to delete your data. MediSynth generates deterministic synthetic patient cohorts: the cohort data we produce and store contains no real patients, no real medical records, and no protected health information (PHI).
Effective date: July 18, 2026 · We do not sell your personal information.
Only what we need to run your account.
Account data you provide when you sign up: your name and email address. Billing data when you subscribe to a paid plan — handled by our payment processor (Stripe); we receive plan, status, and invoice metadata, never full card numbers. Usage data generated as you use the platform: cohort generations, API calls, export requests, and console activity, plus standard technical logs (IP address, timestamps, user agent) used for security, rate limiting, and troubleshooting.
We do not require a phone number, and we do not collect special-category (sensitive) personal data about you. The synthetic patient records the platform generates are fabricated by design and are not the personal data of any real person.
Why we are allowed to process your data.
Where the EU or UK GDPR applies, we process your personal data on these bases: performance of a contract (to provide the service you signed up for and to bill you); legitimate interests (to secure the platform, prevent abuse, keep the service reliable, and improve it — balanced against your rights); legal obligation (to keep records we are required to keep); and consent where we ask for it (for example, optional product-update emails, which you can withdraw at any time).
To operate and improve the service.
We use collected information to provide the MediSynth platform, authenticate you, process payments, respond to support requests, monitor and secure the service, enforce plan limits, and improve the product. We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing. We do not build advertising profiles or use your data for cross-site tracking.
Essential cookies and limited analytics.
We use cookies and similar technologies for authentication, security, and basic usage analytics. You can disable non-essential cookies through your browser settings.
The service providers we rely on.
We use a small number of trusted providers to run MediSynth, acting as our processors under contract: Amazon Web Services (cloud infrastructure and hosting), Stripe (payment processing), and an email-delivery provider for transactional messages. Each processes personal data only on our instructions and only as needed to provide its service; we do not authorize them to use your data for their own purposes.
Moving data across borders.
Our providers may process data in the United States and other countries. Where personal data is transferred out of the EEA or the UK, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses and equivalent UK mechanisms — to protect it to the standard the GDPR requires.
Stored only as long as needed.
Account information is retained while your account is active. Generated cohort artifacts expire after 30 days unless you regenerate them. When you delete your account, deletion begins after a short grace period (currently 30 days, during which you can cancel), after which we delete your account and associated personal data from our active production systems. We may retain a limited subset of information where necessary to comply with a legal obligation, resolve disputes, prevent abuse, or maintain the security of the service; we minimize such data and delete it when it is no longer needed. Some information may also persist in routine backups until they are rotated and expire on a regular schedule.
We protect your account data.
We use industry-standard security measures, including encryption in transit, access controls, and routine monitoring. Because generated cohorts are synthetic by construction, the cohort data we store contains no real patient records or PHI. Operational records such as logs, backups, and support communications are handled under this policy and our data retention practices.
Access, correction, deletion, portability, and more.
Subject to applicable law (including the EU and UK GDPR and similar frameworks), you have the right to access the personal data we hold about you, correct inaccurate data, delete your data (the right to erasure), restrict or object to certain processing, export your data in a portable format, and withdraw consent where processing relies on it (for example, optional product-update emails). Exercising these rights is free and will not disadvantage you. You also have the right to lodge a complaint with your local data-protection supervisory authority.
You can delete your account and data at any time.
You can request deletion of your account and its associated personal data directly from the console, or by emailing support@cloud.medisynth.io. Once confirmed, deletion begins after a short grace period (currently 30 days, during which you can cancel), after which we delete your account and the personal data associated with it from our active production systems. We may retain a limited subset of information where necessary to comply with a legal obligation (for example, tax and accounting records), resolve disputes, prevent abuse, or maintain the security of the service; we minimize such data and delete it when it is no longer needed, and residual copies may remain in routine backups until they expire on their normal rotation schedule. We honour verified deletion requests within the timeframe required by applicable law.
Not intended for children.
MediSynth is a business tool intended for organizations and professionals. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
Updates to this policy.
We may update this policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you. Continued use of the service after an update means you accept the revised policy.
Questions or requests.
MediSynth is the data controller for the personal data described in this policy. For any privacy question or to exercise a right, contact us at support@cloud.medisynth.io.