What we do, what we don't, and what infrastructure providers cover. We do not claim certifications we haven't earned. Infrastructure attestations belong to Groq, Google Cloud, and Razorpay — not to OmniBioFex.
All traffic encrypted in transit; 1.3 negotiated wherever the client supports it.
Firestore + Cloud Storage encrypted with AES-256 by Google default.
Identity via Google. Zero passwords stored on our servers.
Session tokens issued and auto-rotated by Firebase Auth.
Firestore blocks all reads/writes unless explicitly permitted by rule.
Users may read only their own reports and wallet data.
Uploaded images are stored in your private Cloud Storage folder so they appear in your report history. You can request deletion at any time.
Your uploads are never used to train or fine-tune any model.
Account and history deletion completed within 30 days of a verified request.
Do not upload identifiable PHI. Use de-identified images unless you have independent legal authority.
Toggle that redacts history previews and signs you out after 15 min idle. Client-side only; no server-side tracking of the toggle.
If the inference step fails, the uploaded image is deleted immediately and the wallet charge is refunded automatically.
Every uploaded image lives under users/{uid}/chat/{sessionId}/. Firestore rules deny cross-user reads.
One Bearer key per wallet. Rotate any time from the API panel. Never exposed to the browser bundle.
OmniBioFex 1.0 47B served on Groq's LPU stack; up to ~450+ tps.
Attestation held by Groq, not OmniBioFex.
See groq.com/privacy for their current inference data-retention policy.
Held by Razorpay, our payment processor.
Held by Razorpay.
Razorpay holds a Reserve Bank of India Payment Aggregator license.
Held by Google Cloud.
Held by Google Cloud.
Design aligned. No independent audit.
Literacy obligations considered in product design. No independent audit.
Design aligned. No independent audit.
Full privacy policy and terms of service — written plainly, no hand-waving.