Privacy Policy — PharmaTools.AI
shield Privacy Policy

How we protect
your information

Updated September 14, 2026

PharmaTools.AI ("we", "our", or "us") is committed to protecting your privacy and handling data responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit www.pharmatools.ai, use our progressive web apps, mobile applications (e.g., Patiently AI, HushMap, Redacta), or interact with our AI-powered tools and services.

01

Introduction

Your privacy matters to us. This policy outlines how we handle data across our platforms, including Patiently AI and other AI-driven tools.

We design our products using privacy-by-design and data-minimisation principles, meaning we aim to collect the least amount of personal information necessary and apply safeguards such as on-device processing and temporary AI handling wherever possible.


02

Information we collect

2.1 Personal information

We may collect personal information you provide, including:

  • Name and email address when registering or subscribing
  • Payment details where applicable
  • Login credentials

2.2 Usage data

We automatically collect:

  • IP address, browser type, device type, and operating system
  • Interaction data relating to our website, PWAs, tools, or apps

This information helps maintain performance, security, and service reliability.

2.3 App-specific data (Patiently AI)

local_hospital Patiently AI data handling

This applies to the Patiently AI iOS app (version 2.0 and later) and the web app at getpatiently.ai. Patiently AI uses a third-party AI provider, OpenAI, to rewrite medical notes in plain language. Here is exactly what is sent, to whom, and what happens to it.

  • What is sent: the text of the note you submit, with personal identifiers (names, dates of birth, NHS numbers, phone numbers, email addresses, postal addresses and similar) replaced by placeholders on your device before anything leaves it, together with the options you chose (audience, tone, length and language). The real identifiers stay on your device and are put back into the result only on your screen.
  • Who receives it: our server (Google Cloud / Firebase) passes the de-identified text to OpenAI's API, which generates the plain-language version and, if you ask for them, suggested questions for your appointment. OpenAI processes the text to produce the response and does not use it to train its models; under its API data policy it may retain the text for up to 30 days for abuse monitoring, after which it is deleted.
  • What our server keeps: the de-identified reply for up to 24 hours, so that a retry after a lost connection doesn't cost you a free note, after which it is deleted; a count of simplifications per account (to apply the free allowance); and, if you unlock the app, the App Store transaction identifier used to verify the purchase.
  • Consent: the iOS app explains this and asks for your agreement before the first note is sent. You can withdraw agreement at any time by not using the simplification feature; the trackers work without it.
  • Cloud history (optional, iOS): if you sign in with Apple or Google, your simplified notes are also stored in your account so they appear on your other devices. They are stored in de-identified form; the map that restores the real identifiers is encrypted with a key held in your iCloud Keychain, which we cannot read. You can delete individual notes, all notes, or your whole account from within the app.
  • Trackers: symptoms, blood pressure readings, mood entries, medications, templates and appointment reminders are stored on your device only and are never sent to us or to any AI provider.
  • Dictation: in the iOS app, speech is transcribed on your device using Apple's on-device speech recognition; no audio leaves the device. In the web app, audio submitted for transcription is processed and deleted after processing.
  • Feedback: if you rate a result (thumbs up or down), we record the rating and the options used, never the note itself.
  • Analytics: the iOS app contains no analytics or advertising SDKs. The web app may collect aggregated, anonymised usage insights.

2.4 AI tool inputs and outputs

AI tools may process text or audio inputs and generate outputs such as summaries, explanations, or compliance feedback. Data is processed only to deliver the requested functionality and is not retained unless explicitly stated.

2.5 Security and abuse prevention

Security tools such as Captcha or rate-limiting systems may collect browser and IP information to prevent misuse.


03

How we use your information

We use information to:

  • Provide and improve services
  • Maintain platform safety and reliability
  • Respond to enquiries
  • Prevent fraud or abuse
  • Enhance product performance through aggregated analysis

3.1 AI processing

  • AI tools process data solely to deliver requested functionality
  • Identifiers may be removed locally before transmission where supported
  • For Patiently AI and LLMentor, the AI provider is OpenAI (API). Submitted content is processed by OpenAI only to generate the requested output; OpenAI does not use API content to train its models and retains it for at most 30 days for abuse monitoring
  • For RefCheckr, the AI provider is Perplexity (see the RefCheckr section below)
  • Outputs are generated automatically and may contain inaccuracies; they are designed to support, not replace, professional or clinical judgement

04

Legal basis for processing

Depending on the activity, processing may rely on:

  • Performance of a contract
  • Legitimate interests in operating and improving our services
  • User consent

05

Data retention

We retain data only as long as necessary:

  • AI tool inputs: Not stored after processing unless clearly stated
  • Patiently AI replies: Held on our server in de-identified form for up to 24 hours (to allow a retry without charge), then deleted
  • Patiently AI cloud history: Kept until you delete the note or your account in the app
  • Audio recordings (web app): Deleted after transcription; the iOS app sends no audio
  • Medications and symptoms: Held on your device only, until you delete them
  • Aggregated analytics: Fully anonymised and not identifiable

06

Disclosure of your information

We may share data with trusted processors including:

  • AI processing providers
  • Cloud hosting and infrastructure providers
  • Analytics or security services

We do not sell personal data. Data may also be disclosed where legally required.


07

Third-party services

Our platforms may use services such as:

  • OpenAI (API) — generates simplifications and suggested questions for Patiently AI, and outputs for LLMentor; receives de-identified text only; does not train on API content (OpenAI API data usage policy)
  • Perplexity (AI-powered search and reference verification)
  • Firebase / Google Cloud infrastructure
  • Railway (application hosting and deployment)
  • Resend (transactional email delivery)
  • Apple or Google authentication services
  • Mapping services for HushMap

These providers process data under their own privacy policies and, where they process personal data on our behalf, under data-processing terms that require protection at least equivalent to ours.


08

Data security and privacy by design

We apply layered safeguards including:

  • HTTPS encryption in transit
  • Secure cloud infrastructure
  • On-device redaction and data minimisation where available
  • Role-based access controls where applicable
  • Continuous review of privacy risks through internal assessments

Our design approach aligns with recognised privacy and security frameworks used in UK and international digital health environments.


09

Data Protection Impact Assessment

A DPIA has been completed for Patiently AI to evaluate risks related to processing health-related content and to implement appropriate safeguards.


10

Your rights

Depending on applicable law, you may have rights to:

  • Access, correct, or delete your data
  • Restrict or object to processing
  • Withdraw consent

Requests can be sent to: info@pharmatools.ai


11

Automated processing and AI transparency

Some tools use automated AI systems to generate outputs. These tools assist understanding or workflow support but do not provide medical diagnosis, regulatory determinations, or professional advice.

Users remain responsible for reviewing outputs and consulting qualified professionals where appropriate.


12

Children's privacy

Our tools are not intended for children under 13. If you believe personal data from a child has been submitted, please contact us so it can be removed.


13

International data transfers

Data may be processed internationally using trusted cloud infrastructure. Safeguards consistent with UK GDPR and applicable data protection standards are applied.


14

RefCheckr (web app & Word add-in)

fact_check RefCheckr data handling

Information we collect

  • Email address for authentication via magic link sign-in
  • Document text you select and submit for verification or search
  • Verification history and search queries
  • Subscription and billing information via LemonSqueezy
  • Usage counts for rate limiting

How we use it

  • Authenticate your session and manage your account
  • Process selected text through AI services (Perplexity) to verify claims against published evidence
  • Search PubMed, ClinicalTrials.gov, and drug labelling databases on your behalf
  • Track usage against plan limits

AI processing

  • Text you submit is sent to Perplexity AI for analysis and is subject to their privacy policy
  • RefCheckr does not store the content of your documents beyond the duration of the request
  • AI-generated outputs may contain inaccuracies and should be verified independently

Word add-in

  • The RefCheckr Word add-in reads only the text you explicitly select in your document
  • No document content is accessed, stored, or transmitted without your action
  • Authentication tokens are stored locally in your browser's localStorage

Data retention

  • Verification history is stored in your account for your reference
  • Document text submitted for verification is not retained after processing
  • Account data is deleted upon request

15

HushMap mobile app (iOS)

map HushMap data handling

Information we collect

  • Location data for venue mapping and reports
  • Sensory ratings, comments, and timestamps
  • Authentication data
  • Device performance information

How we use it

  • Provide personalised sensory insights
  • Share anonymised sensory reports globally with users
  • Improve features through aggregated analysis

Storage and sharing

  • Reports are stored on Google Firebase and visible to app users worldwide
  • Personal identity details are not displayed with reports
  • Authentication data remains private

Your controls

  • Location permissions can be revoked anytime
  • Data deletion requests can be submitted
  • Uninstalling removes local device data

Data retention

  • Local data removed upon uninstall
  • Community sensory reports retained to support the shared database
  • Account data deleted upon request

16

Redacta (iOS app)

shield Redacta data handling

Redacta runs entirely on your device. It collects no data — nothing you enter or process is transmitted off the device, stored on our servers, or accessible to us.

What we collect

  • Nothing. Redacta has no accounts, no analytics, no tracking, and no network connection

On-device processing

  • Clinical text you paste or type is redacted locally and is never transmitted or stored
  • Photos used for text recognition (Scan) are processed on-device with Apple's Vision framework and are not uploaded or retained
  • Clipboard contents used by the app, Shortcut, or widget are processed in the moment and not stored
  • Token maps for re-identification are held in memory only for the session and are never written to disk

Settings

  • Only non-identifying preferences (the selected redaction mode and light/dark appearance) are saved locally on your device

Your control

  • Because nothing leaves your device, there is no account or stored data for us to access or delete; uninstalling removes the app's local preferences
  • Questions: support@pharmatools.ai

17

OpenGATE (open-source framework, CLI & MCP server)

shield OpenGATE data handling

OpenGATE is an open-source evaluation framework. Its command-line tool and the @pharmatools/opengate-mcp server run entirely on your own machine and collect no data — nothing you pass to them is transmitted to us, stored on our servers, or accessible to us.

What we collect

  • Nothing. OpenGATE has no accounts, no analytics, and no tracking

On-device processing

  • The MCP server's check_grounding tool performs a deterministic, local text comparison — the answer and context you provide are processed in memory to produce a grounded/not-grounded result, and are never transmitted or stored
  • The tool makes no external network calls and uses no third-party model or service
  • When you evaluate your own AI system with OpenGATE, it calls your system's endpoint directly, using credentials you configure locally; those credentials and your data never reach us

Your control

  • Because nothing leaves your machine, there is no account or stored data for us to access or delete
  • Questions: support@pharmatools.ai

18

Updates

We may update this policy from time to time. The latest version will always be published on our website.

Questions about this Privacy Policy?

info@pharmatools.ai