Privacy Policy

What we collect, why we collect it, who else sees it, and how long we keep it.

Last updated: 18 August 2026

1. Who is responsible for your data

PneumonAI is run by two people, who are joint controllers of your data under Article 26 GDPR: Arsenii Ahamalov and Artem Romanov.

Between us, responsibility is divided as follows. Arsenii Ahamalov is responsible for the AI analysis layer — what is sent to Anthropic and how the report is written. Artem Romanov is responsible for the servers, deployment and database — where the data is stored and how it is secured. We have agreed this division between ourselves in writing.

This does not make your rights harder to use. You may contact either of us about any part of your data, and exercise all of your rights against either of us — you do not have to work out which of us holds what. Write to pneumonai@protonmail.com and it reaches both.

2. Health data — please read this part

A chest X-ray is data concerning health. If you also fill in the optional "about you" fields — age, sex, symptoms, how long you have had them, smoking status — that is health data too. Under Article 9 GDPR this is a special category of personal data, and we process it only on the basis of your explicit consent, which you give by ticking the consent box before you upload. The optional fields are separate: you give consent for those by choosing to fill them in.

You can withhold that consent simply by leaving the box unticked — without it the upload button stays disabled and nothing is sent. The optional fields can be left empty either way; the screening result does not depend on them.

3. What we collect and why

The image you upload. Processed to produce the screening result. Legal basis: your explicit consent, which you may withdraw at any time.

DICOM files. The file is opened and converted in your browser. Only the pixel data — with the window level stored in the study applied to it — is sent to us, as an ordinary PNG. The header never leaves your device: patient name, patient ID, accession number, study date, institution name and referring physician are not transmitted and we never receive them.

What that does not cover: text burned into the pixels themselves, which some equipment adds to the image. We cannot remove it, because to us it is part of the picture. If your films carry burned-in identifiers, crop them out on the framing screen before you submit.

The optional "about you" fields. Held in your browser tab only (sessionStorage) and transmitted to us solely if and when you request a report, where they are used to write the interpretation section. They are never used to identify you.

Server logs. Our web server records the timestamp, the URL requested, the response status and your browser's user-agent string for each request. It does not record your IP address — section 4 explains why. Legal basis: our legitimate interest in operating and securing the service.

No accounts, no tracking. We do not create user tier. We use no analytics, no advertising pixels and no tracking cookies, and we do not build profiles or sell data to anyone.

4. How long we keep it

Uploaded images and heatmaps: about 10 minutes. They are written to disk for processing and deleted automatically shortly after your result is produced.

Generated reports: 7 days. If you request a report, the report text, the heatmap images embedded in it and the numerical results are stored so you can reopen and re-download it. After 7 days they are deleted automatically, together with any questions and answers from the chat.

Server logs: 30 days. Our servers record the technical details of each request — the time, the page or endpoint requested, the response status and the browser's user-agent string — and delete them automatically after 30 days. We keep them to investigate errors and abuse, and for nothing else.

Because of the way traffic reaches our servers, these logs do not contain your IP address: our web server only ever sees the address of the machine that forwards requests to it. The hosting layer in front of it does record IP addresses, which is what allows attacks and abuse to be blocked before they reach us.

5. Who else receives your data

Anthropic PBC (United States) — only if you request a report. We send the numerical results of the analysis and, if you provided them, your optional "about you" answers, so that the explanation can be written. We never send your image. Transfers to the United States are made under the European Commission's standard contractual clauses and/or the EU–U.S. Data Privacy Framework.

Our hosting and DNS providers — operate the servers and domain on which the service runs.

We do not share your data with anyone else, and we do not sell it.

6. Your rights

Under the GDPR you may request access to your personal data, its correction or erasure, restriction of processing, portability, and you may object to processing based on our legitimate interests. Where processing rests on your consent, you may withdraw that consent at any time; withdrawal does not affect processing already carried out.

In practice, most of your data is gone within minutes or days by itself. To exercise a right sooner, write to pneumonai@protonmail.com.

You also have the right to lodge a complaint with the Czech data protection authority — Úřad pro ochranu osobních údajů, uoou.gov.cz — or with the supervisory authority of your own EU country.

7. Security

Traffic to this site is encrypted in transit. Results are reachable only through an unguessable random identifier and are not listed anywhere. Given the short retention periods above, we hold very little about you at any moment.

No system is perfectly secure. Do not upload images containing identifying details you would not want to leave your own device.

8. Changes

If this policy changes materially, the date at the top of this page changes with it.