Trust & security
Plain answers, dated and versioned. Where something is not done yet, we say so. Every statement on this page has a matching piece of evidence in our repository.
Extracted values are stored in your browser, not on our servers. The file itself is only passed through for reading.
E-mail, password hash, sex and birth year live in a database in Western Europe. Nothing else is required.
TLS 1.3 in transit, encryption at rest, passwords hashed with PBKDF2, one-time codes and session tokens stored only as hashes.
Account deletion removes the account, sessions and entitlements at once and anonymises the security log.
What we process, where and for how long
| Data | Where | Why | Retention | |
|---|---|---|---|---|
| Report file (PDF or photo) | In transit only: our AI worker (Cloudflare) and Anthropic, for reading the values | To extract markers, units and ranges from the report | Not stored by Blood Lab 360. Anthropic keeps API inputs up to 30 days for abuse monitoring and does not train on them. | in place |
| Extracted values, age band, sex | Your browser (local storage); sent to the AI worker only when you ask for an explanation or chat | Explanations and answers for your age and sex | Never with your name or date of birth. Not stored on our servers. | in place |
| Account: e-mail, password, sex, birth year, contexts | Cloudflare D1 database, Western Europe region | Login on every device, correct reference ranges | Until you delete the account. Password only as a salted PBKDF2-SHA256 hash. | in place |
| Security log | Same database | Rate limits, abuse detection, incident reconstruction | Event type and a daily hash of the IP address, never the raw IP or browser fingerprint. Rows are anonymised when you delete the account. | in place |
| Anonymous usage events | Cloudflare D1 | To learn which explanations people need | No user or session identifier, no IP, no free text: events cannot be linked to a person. | in place |
| Website analytics | Cloudflare Web Analytics | Page views and speed | No cookies, no cross-site tracking, no advertising identifiers. | in place |
| Messages you send us (feedback, business enquiry) | Cloudflare KV and the info@ mailbox | To answer you | Until handled; business enquiries until the offer is closed. | in place |
Sub-processors
We keep the list short. Each provider is bound by a data processing agreement and, where data leaves the EU, by standard contractual clauses.
| Provider | Purpose | Location | Notes | |
|---|---|---|---|---|
| Cloudflare, Inc. | Website hosting, application workers, database (D1), key-value store, DNS, web analytics | Global edge; database placed in Western Europe | DPA with SCCs; encryption at rest and in transit | in place |
| Anthropic, PBC | AI model (Claude) for reading reports and writing explanations | United States | DPA with SCCs; no training on API data; inputs kept up to 30 days for abuse monitoring | in place |
| Resend, Inc. | Transactional e-mail (login codes) | EU region (Ireland) | Only your e-mail address and the code | in place |
| Webtasy d.o.o. (controlpanel.si) | Company mailbox info@ and domain registration | Slovenia | E-mails you send to us | in place |
| Google LLC | Only if you choose “Continue with Google” | United States | We receive your verified e-mail and a stable Google ID, nothing else | in place |
| Payment provider | Premium purchases | — | Not active yet. Card data will never touch our servers. | not yet |
Encryption and application security
- in placeTLS 1.3 on every request, HTTP Strict Transport Security enabled.
- in placeData at rest is encrypted by Cloudflare (D1, KV, Pages).
- in placePasswords: PBKDF2-SHA256, 100 000 iterations, 16-byte random salt, plus a server-side secret for one-time codes.
- in placeOne-time codes: 6 digits, 10 minutes, 5 attempts, at most 5 per day; session tokens stored only as SHA-256.
- in placeContent Security Policy and full set of security headers on the website and the application; Mozilla Observatory B+ (80/100) on 15 Sep 2026.
- in placeRate limits on the AI service: 20 requests per minute and 60 per day per address, 1 500 per day in total; bot check (Turnstile) ready to switch on.
- in placePDF parsing runs in your browser with a self-hosted library; no third-party script can read your report.
- in placeSecrets live only in Cloudflare’s secret store, never in code; every commit is scanned.
Access, backups and continuity
- in placeAdministrative access is limited to the company’s founders; source code is in private repositories with automated tests on every change.
- in placeDatabase point-in-time recovery for the last 30 days (Cloudflare D1 Time Travel).
- in placeEvery website and application release is kept; rollback to a previous release takes one command.
- in progressNightly off-site database exports to separate storage.
- in progressHardware-key two-factor authentication on all administrator accounts.
Monitoring and incidents
- in placeIf a breach affects your data, we notify you and the Slovenian Information Commissioner within 72 hours, with what happened and what we did.
- in placeTraffic and errors are visible in Cloudflare analytics; releases are verified with an automated live check (46 tests) before and after deployment.
- in progressAutomated uptime monitoring with alerts and a public status page.
How the AI is used (EU AI Act, Article 50)
- in placeExplanations and the chat are generated by an AI model (Claude by Anthropic) and are labelled as such wherever they appear.
- in placeThe model is constrained to our knowledge base: reference ranges, marker facts and sources are written and reviewed by us; the model may not add medical claims of its own.
- in placeEvery reference range shows its source. Values are rated by a deterministic engine, not by the language model.
- in placeBlood Lab 360 does not diagnose, treat or replace a doctor. When a value needs a doctor, we say so clearly.
- in progressMedical device status: Blood Lab 360 is offered as an educational tool. A formal regulatory classification review is scheduled before paid features launch.
Your rights
- in placeAccess and export: write to info@bloodlab360.com and you receive your account data within 30 days; an in-app export button is coming.
- in placeCorrection: sex, birth year and contexts can be changed in your profile at any time.
- in placeDeletion: immediate and complete on the server (account, sessions, entitlements); your report values stay only on your device and you can clear them there.
- in placeComplaint: Informacijski pooblaščenec Republike Slovenije, Dunajska 22, 1000 Ljubljana, gp.ip@ip-rs.si.
Reporting a security issue
- in placeWrite to info@bloodlab360.com (details in /.well-known/security.txt). We acknowledge within 72 hours and keep you informed until the fix is live.
- in placeGood-faith research that avoids privacy violations, data destruction and service disruption will not be pursued legally. There is no paid bounty programme.
What we do not have yet
We would rather list it than let you assume it.
- not yetSOC 2 or ISO 27001 certification.
- not yetIndependent penetration test (planned before paid launch).
- in progressSigned-off data protection impact assessment (DPIA) for health data (in progress).
- in progressAutomated uptime monitoring and public status page (in progress).
- in progressNightly off-site backups (in progress).
- not yetAutomatic purge of the security log after 12 months.
- not yetPayments, invoicing and Premium (not live).
- in progressIn-app buttons for data export and account deletion (today by e-mail).
Changes
- 1.02026-09-15 · First publication.
Questions about this page: info@bloodlab360.com · security.txt · Privacy
