Governed by HIPAA and applicable US state privacy laws (incl. CCPA/CPRA). Your data stays yours; consents below are explicit and revocable.
What AnXya does with your data (please read)
- We collect account details (name, email, phone) and the content you add — for patients this includes your Digital Twin health records; for organizations it includes uploaded files and study data.
- Sensitive free-text health fields and file titles/summaries are stored using field-level encryption; uploaded files are stored compressed in dedicated object storage, not in the main database.
- To provide AI features (document interpretation, health summaries, cohort signal briefs) the relevant content is sent to our AI sub-processor, Anthropic (Claude), in the United States, and is not used to train their models.
- Passwords are stored only as salted hashes; access is protected by authenticated sessions and role-based access control. Organizations and regulators only ever see de-identified, pseudonymous patient data.
- Your data may be transferred to and processed in other countries by the sub-processors listed above, under appropriate safeguards.
- We retain your data while your account is active. You can withdraw consent, export your data, or request erasure at any time from your account.
Sub-processors: MongoDB (managed database), Anxya Secure Cloud Storage, Anthropic (Claude), Resend, Infobip.
Your rights: Under HIPAA you may revoke this authorization in writing at any time (except where we have already acted on it). Where CCPA/CPRA applies, you may know, delete, correct and opt out of sale/sharing of your personal information without discrimination.
Grievance / Data Protection contact: Data Protection & Grievance Officer — grievance@anxya.health (responds within 90 days).