Skip to main content

Legal

Privacy & Security

How Medical Shield AI handles account data, sessions, payments, and imaging usage.

What we collect

Account details you provide (such as name, email, and username), authentication events, subscription and payment references, and usage metadata needed to operate credits and analyses. We do not ask you to paste secrets, private keys, or JWT secrets into the browser.

Medical Imaging AI content

Imaging uploads are processed to generate a research report. The product is designed so study files are not kept as a long-term imaging archive. Usage accounting (for example analysis status and credits consumed) is retained so your account balance stays accurate.

Authentication & sessions

Access tokens are short-lived. Refresh material is handled according to the API contract (including httpOnly cookie support where configured). Frontend route guards improve UX only — authorization is enforced by the backend.

Payments

Solana payments are verified server-side against a frozen quote. Transaction signatures and payment references are processed for settlement. We never ask for Solana private keys.

Security practices

Transport security, CORS allow-lists, rate limiting, password hashing, and signed Google OAuth flows are implemented on the API. Report suspected issues to our contact email.

Your choices

You can update profile details from your account, request password resets, and sign out to clear the local session. Contact us for account-related requests that require operator assistance.

Questions? [email protected] · Terms of Service