Legal

Privacy Policy

Last updated: May 2026

Plain-English summary: We process your account info, your search queries, and the documents you upload so that Symmathy can return results and AI summaries. Queries and document text are sent to third-party search APIs and AI providers. Do not upload identifiable patient information (PHI).

1. Data controller

Symmathy LLC is the data controller responsible for your personal data. We are a limited liability company organized in Wyoming, USA. Contact details are at the bottom of this page. If you are in the EU/UK and we do not have a local representative, Symmathy LLC is the controller of record.

2. What we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 What we do not collect

We do not knowingly collect protected health information (PHI) about identifiable patients. Symmathy is not a HIPAA-covered service and is not designed to receive PHI. Do not upload identifiable patient information.

3. Why we process it & legal basis

Under GDPR / UK GDPR Article 6, we rely on the following legal bases:

We do not use your data for automated decision-making with legal or similarly significant effects. We do not sell your personal data.

4. Who we share data with

We share the minimum personal data required with the following categories of processor:

Each processor is bound by its own published privacy and data-handling policies. We do not control how upstream AI providers retain or use prompts beyond those policies — this is one reason you must not submit PHI.

5. International transfers

Some processors are located outside the European Economic Area or the UK (including the United States). Where transfers occur, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision, as documented by each processor.

6. Retention

7. Your rights

Depending on where you live (GDPR in the EEA, UK GDPR, CCPA in California, and similar laws elsewhere), you may have the right to:

To exercise any of these rights, contact us using the details below. We will respond within the timeframes required by applicable law (generally one month under GDPR).

8. Cookies & local storage

Symmathy uses strictly necessary cookies and browser local storage to keep you signed in, remember UI preferences (e.g. dismissed banners), and protect against abuse. We do not use third-party advertising cookies. If we add optional analytics in the future, we will request your consent first where required.

9. Children

Symmathy is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided personal data, please contact us so we can delete it.

10. Contact

For privacy questions, data-subject requests, or to report a concern, contact Symmathy LLC at connect@symmathy.org. See also our Legal & Disclaimer page.

Important — operator notice

This Privacy Policy is generic boilerplate provided as a starting point. It is not legal advice and has not been reviewed by a qualified data-protection lawyer. Before deploying Symmathy to real users — particularly in the EU, UK, or California — you should have the document reviewed and adapted to reflect your actual operating entity, sub-processors, retention schedules, and DPA arrangements.

← Back to home

Report a problem