Iatronix
Sign In

Privacy Policy

Last updated 25 July 2026

Draft pending legal review. This page accurately describes how Iatronix handles data today, but it has not been reviewed by a lawyer. Items marked [REVIEW] are still to be confirmed.

Who we are

Iatronix is an evidence-based clinical reference tool operated by [REVIEW: legal entity name and registered address]. For any privacy question or request, contact [REVIEW: contact email].

What we collect

Only what you give us, plus basic usage analytics:

  • Account — your email address. Your password is handled entirely by Google Firebase Authentication; Iatronix never receives or stores it. If you sign in with Google, we receive your email address and Google account identifier.
  • Profile you enter — username, full name, country, professional position, institution, institution type, specialty, age and gender. All of these are optional and can be changed or cleared at any time in Settings.
  • Newsletter consent — recorded only if you tick the box, and only used to decide whether to email you.
  • Your searches — clinical queries you run and the answers returned, stored so you can see your own search history.
  • API keys you supply — see "Your API keys" below.
  • Usage analytics — page views and interaction events via PostHog, to understand which features are used. Analytics are linked to your account identifier and email. Text content on pages is masked before capture.

We do not ask for, and you should not enter, any patient-identifiable information. Iatronix is a reference tool for clinicians, not a place to record patient data.

Your API keys

Iatronix is bring-your-own-key. When you supply an API key for an AI provider, it is encrypted before being written to our database (Fernet symmetric encryption) and is decrypted only in memory, at the moment a request is made on your behalf. Keys are never logged and are never returned to the browser — the interface only ever shows whether a key is set. You can delete a stored key at any time from Settings.

Your queries are sent to whichever AI provider your key belongs to (for example Cerebras, Anthropic, OpenAI or OpenRouter). Their handling of that data is governed by their own privacy policies, not this one.

Who we share it with

We do not sell your data. We share it only with the services required to run Iatronix:

  • Google Firebase — authentication (email/password and Google sign-in).
  • Google Cloud Platform — hosting, database and backups, in the us-central1 region.
  • PostHog — product analytics.
  • Your chosen AI provider — receives the text of your clinical query, authenticated with your own API key.

Iatronix also queries public medical databases — including PubMed/NCBI, openFDA, RxNorm, DailyMed, MedlinePlus, NICE, ClinicalTrials.gov, Semantic Scholar and ChEMBL — to retrieve evidence. These requests carry your search terms but no account information.

How long we keep it

Account and profile data are kept while your account exists. Older query and search-history records are periodically archived to encrypted cloud storage and then deleted from the live database. [REVIEW: state the exact retention period you want to commit to.]

Your rights

You can view and edit your profile, and add or delete stored API keys, at any time from Settings. To request a copy of your data, correction, or full deletion of your account, contact [REVIEW: contact email]. Depending on where you live, you may also have the right to object to processing, restrict it, or complain to a data-protection authority.

Cookies and local storage

Iatronix uses browser storage to keep you signed in and to remember interface preferences such as your theme. PostHog sets cookies to distinguish repeat visits. We do not use advertising cookies.

Changes

If we change what we collect or who we share it with, we will update this page and its "last updated" date.