Last updated March 2026
Privacy Policy.
We built Simple Bloodwork with the belief that your health data is intensely personal. Here is exactly what we collect, how we use it, and what we will never do with it.
The short version
You upload a lab PDF. We extract your biomarker data, show you insights, and store the results under your account. We do not sell your data. We do not share it with third parties (except the providers listed below that are required to run the service). You can export or delete everything at any time.
The full version below is the binding document, but that summary is our genuine intent.
1. What we collect
Account information. When you create an account, we collect your email address and name associated with the account you used to authenticate. We do not collect your password.
Uploaded documents. PDFs and images you upload for analysis are temporarily stored during processing and then deleted from our processing queue within 24 hours. The extracted biomarker data (values, units, dates) is stored in your account for as long as you maintain it.
Payment information. Payments are processed by Stripe. We store only a Stripe customer ID and subscription status — we never see or store your full card number or any other payment information.
Usage data. We collect basic, anonymized analytics (page views, feature usage) to understand how the product is being used and how to improve it. This data is never linked to your name, email, or your health data.
2. How we use your data
We use your data for the following purposes only:
- To provide the core service: extracting biomarkers and generating your dashboard.
- To store your historical results so you can track trends over time.
- To process your payments and manage your subscription status.
- To send transactional emails (upload confirmations, billing receipts)
- To investigate abuse or security incidents if they occur.
We do not use your health data to run advertisements or for any purpose other than serving your account.
3. Who we share data with
We share your data with a minimal set of sub-processors required to operate the service:
- Vercel — hosting and edge infrastructure.
- Supabase — database storage for your account and extracted biomarker data.
- OpenAI / Anthropic — AI model inference for PDF extraction. Data sent is the raw PDF text only; it is not retained or used for training under our data processing agreements.
- Stripe — payment processing.
We do not sell, rent, or trade your data to any third party, advertiser, or data broker.
4. Data retention and deletion
Your biomarker data is retained for as long as your account is active. You can delete your entire history at any time from account settings. Deletion is permanent — we do not keep backups of deleted user data beyond a 30-day rolling window used for disaster recovery, after which it is purged.
Uploaded PDF files are deleted after their data has been extracted regardless of whether you delete your account.
5. Security
Access to production databases is restricted to a minimal set of authorized personnel and requires multi-factor authentication. We conduct periodic security reviews and will notify you of any breach that affects your personal data within 72 hours of discovery.
6. Your rights
Depending on where you live, you may have rights including: access to your data, correction of inaccurate data, deletion of your data, portability of your data, and the right to object to certain processing. To exercise any of these rights, email us at murphy.stude@gmail.com.
7. Cookies
We use only essential cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. You can disable cookies in your browser settings, but doing so will prevent you from staying logged in.
8. Changes to this policy
If we make material changes to this policy, we will notify you by email at least 14 days before the changes take effect. The “last updated” date at the top of this page reflects the most recent revision. Continued use of the service after that date constitutes acceptance of the updated policy.
9. Contact
For privacy-related questions, contact us at murphy.stude@gmail.com.