ZERO PHI RETENTION. EPHEMERAL INFERENCE STORAGE. TRANSPARENT THIRD-PARTY DISCLOSURE. MEDGEMMA 1.5 4B IT — NOT CLINICAL-GRADE. ZERO PHI RETENTION. EPHEMERAL INFERENCE STORAGE. TRANSPARENT THIRD-PARTY DISCLOSURE. MEDGEMMA 1.5 4B IT — NOT CLINICAL-GRADE.

PRIVACY POLICY

OUR COMMITMENT TO PRIVACY

OmniBioFex.Cloud is built with strict data minimization principles. Because MedGemma 1.5 4B IT is not clinical-grade and is intended only for educational and research use, we designed our infrastructure to keep your uploaded medical data ephemeral by default.

Zero PHI retention Ephemeral inference storage Last updated: 2026-09-11

1. ZERO PHI RETENTION POLICY

Medical files uploaded to the platform are processed using ephemeral storage. Data is scrubbed from our servers immediately following the completion of the AI inference block.

WHAT THIS MEANS

UPLOADED FILES ARE NOT PERSISTED

Your uploaded images, DICOM volumes, PDFs, and histopathology slides are held in memory only for the duration of the inference request. Once the model returns a response, the original upload is discarded.

WHAT THIS MEANS

NO TRAINING ON YOUR DATA

We do not use your uploaded medical content to train, fine-tune, or otherwise improve MedGemma 1.5 4B IT or any downstream model. Model improvements come from the upstream Google MedGemma family only.

IMPORTANT — While we enforce zero PHI retention at the application layer, MedGemma 1.5 4B IT is not a HIPAA-compliant or clinically certified system. Do not upload identifiable patient data unless you have independent legal authority to do so under your local jurisdiction.

2. INFORMATION WE COLLECT

We collect the minimum amount of information required to operate the service, enforce fair usage, and provide you with a functional dashboard.

01

AUTHENTICATION DATA

Google OAuth provides your email address to create your account ID. We do not store passwords, phone numbers, or any other personal identifiers beyond what Google OAuth returns.

02

INFERENCE OUTPUT

The JSON text output is stored in Firebase Firestore to populate your historical dashboard. Original uploads are never stored — only the model's text response.

03

USAGE METRICS

We track API call frequency to enforce plan limits (Community: 10/month, Pro: unlimited, API: pay-per-request). No content of your requests is logged.

3. THIRD-PARTY INFRASTRUCTURE

OmniBioFex.Cloud is built on top of established cloud infrastructure. Each provider below is governed by its own privacy policy and terms of service.

Provider Purpose Data Retained
Google Firebase Authentication & Firestore Email, JSON text output
Vertex AI MedGemma 1.5 4B IT Inference None (processed in memory)
Razorpay Payment Processing Billing details (no medical data)
NOTE — Vertex AI processes inference requests in memory and does not persist your uploaded medical files. Razorpay receives only billing information — no images, DICOM volumes, EHR text, or JSON outputs are ever transmitted to our payment processor.

4. COOKIES & ANALYTICS

We use only the minimum set of cookies required to keep you authenticated and to protect the service against abuse.

A

SESSION COOKIES

Required to keep you logged in after Google OAuth. These are strictly necessary and cannot be disabled while using the platform.

B

NO TRACKING PIXELS

We do not use advertising pixels, cross-site tracking cookies, or third-party analytics that profile your behavior outside OmniBioFex.Cloud.

C

AGGREGATE METRICS ONLY

Any analytics we collect are aggregate, anonymized, and used solely to monitor uptime, error rates, and API throughput.

5. DATA SECURITY

We implement industry-standard safeguards to protect the limited data we do retain. However, no system is perfectly secure, and MedGemma 1.5 4B IT is not a clinical-grade system.

SAFEGUARD

TRANSPORT ENCRYPTION

All traffic between your browser, our servers, and Vertex AI is encrypted in transit using TLS 1.2 or higher.

SAFEGUARD

ACCESS CONTROL

Production credentials and Firebase access rules are restricted to a minimal set of authorized engineers under the VantyrixTek organization.

SECURITY LIMITATION

No system is perfectly secure — and this is not a clinical-grade platform.

You are responsible for ensuring that any data you upload complies with your local privacy regulations. Do not upload identifiable patient data unless you have independent legal authority to do so.

6. YOUR RIGHTS

Because we retain very little data, most privacy requests can be fulfilled immediately. You have the following rights regarding your account data.

01

ACCESS

Request a copy of the account data we hold for you — this is limited to your email address and the JSON text outputs stored in your Firestore history.

02

DELETION

Request full deletion of your account and its stored inference history. Deletion is irreversible and completes within 30 days.

03

CORRECTION

Request correction of inaccurate account information. Since we only store your email, this is typically limited to updating your OAuth-linked address.

EXERCISING YOUR RIGHTS — Contact privacy@omnibiofex.cloud from the email address associated with your account. We respond to all verified requests within 30 days.

7. CHILDREN & RETENTION PERIODS

AGE RESTRICTION

NOT FOR USE BY MINORS

OmniBioFex.Cloud is not intended for use by anyone under 18. We do not knowingly collect personal information from minors. If we become aware of such data, we delete it.

RETENTION

ACCOUNT LIFETIME + 30 DAYS

Your email and stored JSON outputs are retained while your account is active. After account deletion, all data is removed within 30 days. Aggregate usage metrics may persist longer, but contain no personal identifiers.

8. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Material changes will be announced on the main page and reflected in the "Last updated" date above. Continued use of OmniBioFex.Cloud after changes constitutes acceptance.

QUESTIONS?

Reach out to our team, or review the full terms governing MedGemma 1.5 4B IT access on OmniBioFex.Cloud.