Legal
Privacy Policy
Effective date: May 13, 2026 · CytoHub Inc.
CytoHub Inc. (“CytoHub”, “we”, “us”, or “our”) operates the BioEngineAI Intelligence Platform (CytoRNA) (“Platform”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Platform. Please read it carefully. If you disagree with its terms, please discontinue use of the Platform.
1. Scope
This Policy applies to all personal information collected through the Platform, including information provided during registration, subscription management, and use of analytical features. It does not apply to third-party websites or services that may be linked from the Platform.
The Platform is designed for research use only. Users are responsible for ensuring that any human-subject data uploaded complies with applicable consent requirements, IRB approvals, and data-protection regulations prior to upload.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, institution, and password (stored as a salted hash).
- Billing information: payment card details and billing address, processed by our payment processor (Stripe). CytoHub does not store raw card numbers.
- Research datasets: genomic files (h5ad, 10x MTX, H5) and metadata you upload for analysis. You are responsible for ensuring these files comply with applicable privacy and consent requirements.
- Communications: emails, support tickets, and other messages you send to us.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, analysis jobs run, error logs, and timestamps.
- Device and browser information: IP address, browser type, operating system, and referring URL.
- Cookies and similar technologies: session tokens, preferences, and analytics identifiers. See Section 8 for details.
2.3 Information from Third Parties
- If you access public datasets via NCBI/GEO integration, we may record the accession identifiers you query.
- If you use AI-assisted interpretation features, query content may be transmitted to our AI inference partners (see Section 5).
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account and authenticate your identity.
- Process transactions and send related information (receipts, invoices, renewal notices).
- Provide, operate, and improve the Platform and its analytical pipelines.
- Generate aggregated, anonymised usage statistics to understand how the Platform is used and to improve it.
- Send administrative communications (security alerts, policy updates, maintenance notices).
- Send marketing communications about new features or plans — only with your consent or where permitted by law. You may opt out at any time.
- Respond to customer support inquiries.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not use your research datasets or analysis results to train, fine-tune, or benchmark any machine-learning model without your explicit, informed consent.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing your personal data are:
- Contract performance: processing necessary to provide the Service you have requested.
- Legitimate interests: platform security, fraud prevention, and product improvement, where these interests are not overridden by your rights.
- Consent: where we ask for and receive your consent (e.g., marketing emails).
- Legal obligation: compliance with applicable law.
5. Sharing and Disclosure
We do not sell your personal information. We may share it in the following circumstances:
5.1 Service Providers
We share data with vetted third-party vendors who process it on our behalf, under contractual data-processing agreements:
- Amazon Web Services (AWS) — cloud infrastructure, file storage (S3), and compute.
- Supabase — managed PostgreSQL database and authentication.
- Stripe — payment processing.
- Anthropic / OpenAI / Google — AI inference for the optional AI interpretation feature. Only query text and relevant analysis summaries are transmitted; raw genomic files are never sent to AI providers.
- Vercel — web application hosting and edge delivery.
- Resend / email delivery providers — transactional email.
5.2 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect rights, property, or safety of CytoHub, our users, or the public.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred to the acquiring entity. We will notify you via email and/or prominent notice on the Platform at least 30 days prior to any such transfer.
5.4 With Your Consent
We may share your information for any other purpose with your explicit consent.
6. Research Data — Special Considerations
Genomic and biological datasets are sensitive by nature. We apply the following protections specifically to your uploaded research data:
- Research files are stored encrypted at rest (AES-256) in AWS S3 and in transit (TLS 1.2+).
- Access is restricted to authenticated users; files are served via short-lived presigned URLs.
- CytoHub staff access to raw research data is limited to authorised personnel for the purpose of debugging, security investigation, or legal compliance, and is logged.
- We do not share, sell, or otherwise make your research data available to any third party except as necessary to provide the Service (e.g., cloud storage).
- Users are solely responsible for ensuring compliance with applicable data-protection regulations, IRB protocols, and patient-consent requirements before uploading human-subject data.
- If you believe you have uploaded data that may contain identifiable human-subject information in error, contact legal@cytohub.com immediately.
7. Data Retention
- Account information is retained for the duration of your account and up to 3 years after termination for legal and compliance purposes.
- Research datasets and analysis results are retained until you delete them. Soft-deleted records may remain in our backups for up to 90 days before permanent deletion.
- Billing records are retained for 7 years as required by applicable tax and accounting regulations.
- Usage logs are retained for up to 12 months.
- You may request deletion of your personal data (subject to legal retention obligations) by contacting legal@cytohub.com.
8. Cookies and Tracking
We use the following types of cookies:
- Strictly necessary cookies: session authentication tokens required for the Platform to function. These cannot be disabled.
- Analytics cookies: anonymised usage statistics via Vercel Analytics. These help us understand feature adoption and improve the Platform. You may opt out by blocking analytics cookies in your browser.
- Preference cookies: theme (light/dark mode) and UI preferences stored locally.
We do not use third-party advertising or cross-site tracking cookies.
9. Security
We implement commercially reasonable administrative, technical, and physical safeguards to protect your information, including:
- TLS encryption for all data in transit.
- AES-256 encryption for data at rest in cloud storage.
- JWT-based authentication with RS256 signing.
- Role-based access controls and least-privilege infrastructure access.
- Regular dependency updates and security patching.
- Automated backups with point-in-time recovery.
No method of electronic transmission or storage is 100% secure. If you become aware of a security vulnerability or incident, please report it to legal@cytohub.com.
10. International Data Transfers
CytoHub is headquartered in the United States. If you access the Platform from outside the United States, your information may be transferred to and processed in the United States or other countries. We rely on appropriate safeguards — including Standard Contractual Clauses (SCCs) approved by the European Commission — for transfers of personal data from the EEA, UK, and Switzerland.
11. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure ('right to be forgotten'): request deletion of your personal data, subject to legal retention requirements.
- Restriction: request that we limit processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: with your local data-protection authority (e.g., the ICO in the UK, or a supervisory authority in your EU member state).
To exercise any of these rights, contact us at legal@cytohub.com. We will respond within 30 days (or as required by applicable law).
12. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Right to know what personal information we collect, use, disclose, and sell.
- Right to delete personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. We do not sell personal information.
- Right to non-discrimination for exercising your privacy rights.
To submit a verifiable consumer request, contact us at legal@cytohub.com.
13. Children's Privacy
The Platform is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a minor has provided us with personal information, contact us immediately at legal@cytohub.com and we will take steps to delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or prominent in-app notice at least 14 days before the changes take effect. The “Effective date” at the top of this page indicates when the current version was last revised. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
15. Contact and Data Controller
CytoHub Inc. is the data controller for personal information collected through the Platform. For privacy-related enquiries, requests, or complaints:
CytoHub Inc. — Privacy
Email: legal@cytohub.com
Website: www.bioengineai.com