How ReadingScan collects, uses, and protects your personal and medical imaging data
2026/04/09
Effective Date: April 9, 2026
This Privacy Policy describes how ReadingScan ("we," "us," or "our"), accessible at readingscan.com, collects, uses, stores, and protects your personal information when you use our AI-powered medical imaging report interpretation service (the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our Service.
When you create an account, we collect:
When you use our interpretation service, we collect:
Important: We do not require or collect any personally identifiable health information (such as your name, date of birth, or medical record number) in connection with image uploads. We strongly recommend that you remove any personal identifiers from images before uploading.
When you purchase credit packages, payment is processed by our third-party payment processor, Stripe, Inc. We do not store your credit card number, CVV, or full payment card details on our servers. We receive and store:
We automatically collect:
We use essential cookies for authentication, session management, and language preferences. For more details, see our Cookie Policy.
We use the information we collect to:
Our Service uses artificial intelligence to interpret medical images. When you upload an image, it is processed through the following third-party AI services:
Your uploaded medical images are sent to the Lingshu API for professional medical image analysis. Lingshu processes the image and returns structured medical findings. The image data is transmitted securely and used solely for the purpose of generating your interpretation report.
The structured medical findings from Lingshu are sent to OpenAI's API (GPT-4o mini) to generate a patient-friendly report in your preferred language. The data sent to OpenAI contains medical findings only — your uploaded image files are not sent to OpenAI.
In addition to AI processors, we use the following third-party services:
| Service | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, transaction details |
| Amazon S3 | Cloud storage for uploaded images | Uploaded medical images |
| OAuth authentication | Email, name (only if you choose Google sign-in) | |
| Resend | Transactional email delivery | Email address, email content |
Each third-party service operates under its own privacy policy. We encourage you to review their policies.
We implement industry-standard security measures to protect your data:
While we strive to use commercially acceptable means to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Regardless of your location, you have the right to:
If you are in the EEA, you additionally have the right to:
Our legal basis for processing your data includes: performance of a contract (providing the Service), your consent (uploading images for AI processing), and legitimate interests (improving our Service and ensuring security).
If you are a California resident, you have the right to:
To exercise any of these rights, contact us at support@readingscan.com.
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that we have collected data from a person under 18, we will delete that information promptly.
Your data may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. By using our Service, you consent to such transfers. We ensure appropriate safeguards are in place for international data transfers.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page and updating the "Effective Date" at the top. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: