Privacy Policy
Last updated: March 1, 2026
1. Introduction
Aldaim Digital Ltd ("we", "us", "our"), a company registered in England and Wales (company number 17327688), operates RadReports ("Service"). This Privacy Policy explains how we collect, use, protect, and share your information when you use our Service.
By using RadReports, you consent to the practices described in this policy. If you do not agree, do not use the Service.
2. Information We Collect
- Account data: Email address, name, specialty, organization (provided at registration or via Google OAuth).
- Usage data: Features used, report count, decision analytics, session timestamps, modality preferences (no PHI).
- Style samples: If you paste sample reports into the Style wizard to teach the tool your reporting style, those samples are stored with your style profile so you can see and revisit what it learned from. You can clear them at any time by deleting your style profile. The separate "Use this to learn my style" action does not store report text: it extracts formatting patterns and keeps only those.
- Saved reports: Reports are stored only when you choose to save one to your library. Autosaved drafts stay on your device and are never sent to us. A saved report keeps its text, the AI draft it came from, and the study details you entered.
- Payment data: Processed exclusively by Stripe. We do not store, process, or have access to credit card numbers, CVVs, or full bank account details. We only store your Stripe customer ID for subscription management.
- Dictation audio: When you dictate, the audio is sent to our speech to text processor (Deepgram) and the transcript is returned to you. We do not store the audio, and the transcript is only ever the text you see in the findings box. Dictate no patient identifiers.
- Technical data: IP address (for rate limiting only, not stored long-term), browser type, device information (via standard HTTP headers).
3. Information We Do NOT Collect
- Protected Health Information (PHI): Medical images are stripped of EXIF/DICOM metadata on the client side before upload, processed ephemerally, and automatically purged from our servers within 24 hours.
- Patient-identifiable data: We never ask for patient names, MRNs, dates of birth or any other identifier, and you should not enter them. We do not extract or index identifiers. However, if you save a report to your library, the text is stored on our servers exactly as you wrote it, so anything you typed into it is stored too. Please de-identify before saving.
- Tracking data: We do not use Google Analytics, Facebook Pixel, or any third-party tracking cookies.
4. How We Use Your Information
- To provide, maintain, and improve the Service
- To process payments, manage subscriptions, and administer free trials
- To send transactional emails (verification, password reset, receipts, billing alerts)
- To send optional product updates and weekly usage digests (you can unsubscribe at any time)
- To enforce rate limits and prevent abuse
- To generate anonymized, aggregated analytics to improve the Service
5. Legal Basis for Processing (UK GDPR)
We process your data under the following legal bases:
- Contractual necessity: To provide the Service you signed up for (account management, report generation, billing).
- Legitimate interest: To improve the Service, prevent fraud, and ensure security.
- Consent: For optional communications (product updates, digests). You may withdraw consent at any time.
6. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with the following processors, strictly for service delivery:
- Stripe Inc. (San Francisco, CA) — Payment processing. Stripe Privacy Policy
- Resend Inc. — Transactional email delivery (verification, receipts). Resend Privacy Policy
- Cloudflare Inc. (San Francisco, CA) — Hosting infrastructure, CDN, edge computing. Cloudflare Privacy Policy
- Google LLC — OAuth authentication (only if you sign in with Google). Google Privacy Policy
- Deepgram Inc. — Speech to text for voice dictation, using a model trained for medical speech. Audio you dictate is sent to Deepgram both when a recording is uploaded and, on live dictation, while you speak; the transcript comes back to you. We do not store the audio and we do not select a processing region, so it is handled on Deepgram default infrastructure. Dictate no patient identifiers. Deepgram Privacy Policy
- AI providers — Image analysis and report generation via API. Images are not stored by these providers and are processed under data processing agreements.
We may also disclose data if required by law, court order, or governmental authority.
7. Data Security
- All data transmitted via TLS 1.3 encryption
- Authentication via signed JWT tokens (HMAC-SHA256)
- Passwords hashed with PBKDF2 over SHA-256, 100,000 iterations, each with its own random 16-byte salt (never stored in plaintext)
- Rate limiting on all authentication endpoints
- Account lockout after repeated failed login attempts
- EXIF metadata stripped from images before upload (client-side)
- Images automatically purged from storage within 24 hours
- Hosted on Cloudflare's global edge network with enterprise-grade DDoS protection
8. HIPAA Notice
RadReports is not a HIPAA-covered entity. The Service is not designed to receive protected health information: we never ask for patient names, MRNs, dates of birth or any other identifier, we do not extract or index identifiers, and you should not enter them. Images are stripped of EXIF/DICOM metadata on your device before upload and are purged from our servers within 24 hours.
Saved reports are the one exception, and it is under your control. If you save a report to your library, we store its text on our servers exactly as you wrote it — so anything you typed into that report, including anything identifiable, is stored with it. De-identify before you save. You can delete any saved report at any time, and unpinned reports are deleted automatically 12 months after you last edited them.
Users are solely responsible for ensuring their use of the Service complies with their institution's HIPAA policies and applicable regulations. Do not upload images containing visible patient-identifiable information.
Enterprise customers requiring a Business Associate Agreement (BAA) should contact support@reportsrad.org.
9. Your Rights
GDPR (EEA/UK users) and CCPA (California users):
- Right to Access: Download all your data in JSON format via Settings > Export My Data.
- Right to Rectification: Update your account information at any time in Settings.
- Right to Erasure: Permanently delete your account and its content (reports, images, style profile, templates, usage and decision history) via Settings > Delete Account. Deletion is completed within 72 hours and is irreversible. We keep no usage log, no de-identified event log and no copy of any kind behind — except payment records, which UK tax law requires us to retain for 6 years; see Data Retention, below.
- Right to Portability: Export your data in a machine-readable JSON format.
- Right to Object: Unsubscribe from optional emails at any time.
- Right to Withdraw Consent: Contact us to withdraw consent for any processing based on consent.
To exercise any of these rights, use the in-app Settings or email support@reportsrad.org. We respond to all requests within 30 days.
Complaints. If you are in the United Kingdom and you believe we have mishandled your personal data, you may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. We would ask you to raise it with us first so that we can put it right.
California Users (CCPA): We do not sell personal information. You have the right to know what data we collect, request deletion, and opt out of any future sale (though we do not sell data).
10. Data Retention
- Account data: Retained while your account is active. Deleted within 72 hours of account deletion request.
- Medical images: Automatically purged within 24 hours of upload.
- Usage analytics: Feature-use counts, report counts and decision timings. They record what was used and when, never patient identifiers. We keep them for as long as the account exists and there is no scheduled anonymization pass; when you delete your account both your per-day analytics rows and the underlying usage event log are deleted with it, and nothing de-identified is kept behind.
- Audit records: A log of security and report actions, including the modality and body part of a report you delete. It outlives the report it describes and is deleted only when you delete your account.
- Style samples: Retained until you delete your style profile or your account.
- Saved reports: Kept for 12 months from the last time you edited them, then deleted automatically. Pin a report to keep it indefinitely. You can delete any saved report at any time.
- Payment records: Retained for 6 years as required by UK tax law.
- Session data (localStorage): Stored on your device only, auto-cleaned after 30 days of inactivity.
11. Cookies & Local Storage
We use only essential localStorage entries (not HTTP cookies) for authentication and session persistence. No tracking cookies, no third-party analytics scripts. See our Cookie Policy for full details.
12. International Data Transfers
Aldaim Digital Ltd is established in the United Kingdom and is the controller of your personal data. The Service is hosted on Cloudflare's global edge network, and our processors may handle data in the United States and other countries. Where personal data leaves the United Kingdom we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply.
13. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect data from minors. If we become aware that a minor has provided personal data, we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 14 days before they take effect. The "Last updated" date at the top indicates the latest revision.
15. Contact & Data Protection
Aldaim Digital Ltd
Registered in England and Wales, company number 17327688
Email: support@reportsrad.org
Data Protection Inquiries: support@reportsrad.org
Founder: a UK CCT trained radiologist