Legal
Privacy policy
This policy covers spinesense.ai, the education library on it, and the SpineSense assessment at app.spinesense.ai. It describes what we collect, why we collect it, and the things we do not do with it.
Effective 4 August 2026
The short version
Reading the education library requires no account and no personal information. The assessment does, because it cannot describe your problem back to you without knowing what your problem is. Everything you enter there is held to protect your health information, it is never sold, and it is never used to target advertising at you. You can ask for a copy of it or have it deleted at any time.
What we collect
If you only read the library. No account, no name, no email. We record anonymous page measurements so we can tell which articles are useful and whether the site is working. Those measurements carry no cookie, no durable browser storage, and no identifier that survives closing the tab, so they cannot be linked to you or to a later visit.
If you create an account and start an assessment. Your email address and, if you choose to sign in with Google, the account identifier Google returns. Then the things you tell us about your problem: your description in your own words, your answers to the questionnaire, where your symptoms are, and any imaging report or clinical document you choose to upload. This is health information, and it is treated as such throughout.
Operational records. Sign-in events, security events, and an audit trail of access to health information. These exist because a system holding health records has to be able to show who looked at what, and they are kept whether or not anything goes wrong.
What we use it for
To produce your assessment and show it back to you. To keep your account secure and your session protected. To maintain the audit trail described above. To fix faults and improve how the product works. That is the list.
What we never do
- We do not sell your information. Not to insurers, not to employers, not to data brokers, not to anyone.
- We do not use it for advertising, and we do not let anyone else use it for advertising. There are no advertising or tracking cookies on this site or in the app.
- We do not share your health information with third parties for their own purposes. The only outside parties who touch it are the infrastructure providers described below, who process it on our instruction and are contractually barred from doing anything else with it.
- We do not report you to anyone. Using the assessment does not put anything on a medical record, and nothing you enter is sent to your insurer or your employer.
Who processes it on our behalf
The platform runs on Microsoft Azure in the United States, and the language model that helps produce your summary is Azure OpenAI, running inside that same Microsoft boundary. Both are covered by a Business Associate Agreement, which is the contract that binds a service provider handling health information to the same protections we are held to. Your health information is not sent to any consumer AI service, and it is not used to train anyone else’s model.
Cookies
The assessment sets essential cookies only. They sign you in, keep your session protected against cross-site request forgery, and support the audit trail. They hold no health information, and there is no version of a signed-in, protected session that works without them, which is why they are not presented as a choice. The education library sets no cookies at all.
How it is protected
Health information is encrypted in transit and at rest. The browser reaches the backend only through a server-side layer that holds the session token, so no backend credential is ever readable by JavaScript in your browser. The app keeps nothing durable in browser storage, which is what stops your health information being left behind on a shared or borrowed device. Access is scoped per patient at the database level rather than by application code alone.
How long it is kept
Assessment data is kept while your account is open, so you can come back to a result rather than start again. If you ask for deletion we remove your health information. Security and audit records are kept for the period we are required to keep them, because their whole purpose is to be a record that cannot be edited away.
Your choices
You can ask for a copy of the information we hold about you, ask us to correct something that is wrong, or ask us to delete your account and its contents. Uploading a document is always optional, and you can use the assessment without uploading anything. Ask through the contact page and tell us which of these you want.
Children
SpineSense is built for adults and is not intended for children under 18. We do not knowingly collect information from them. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
If this policy changes in a way that affects what we do with your information, we will change the effective date at the top and, where the change is significant, tell account holders directly rather than relying on you to notice.
Contact
Questions about this policy, or about the information we hold on you, go through the contact page. See also the HIPAA notice for how health information specifically is handled, and the terms of service for the rules of using the product.