MedQuiry
Legal

Privacy Policy

What MedQuiry collects, how it is used, and your controls.

Last updated: June 28, 2026

This policy describes what MedQuiry ("we," "us") collects, how it is used, and the controls available to you. MedQuiry is a scoring service for published medical studies and is not a healthcare provider. We are the data controller for the personal data described here. We do not solicit, store, or process patient-identifiable information.

What we collect

  • Account information you provide via Clerk (email address, name).
  • Token activity (issued, consumed, purchased) and payment metadata. Stripe handles card data; we never receive it.
  • Documents you submit for scoring. Uploaded PDFs and the text extracted from them are retained in private storage, associated with your account and accessible only to you, so that you can retrieve the document that was scored and so MedQuiry can re-score it under a later rubric version. We also keep the score report, an internal scoring artifact, and audit metadata for that submission (including a content hash). Submitted documents are never shared with other users and are not used to train or improve any model. You can delete any scored study at any time from your locker or its report page. Deleting destroys the stored document, its extracted text, and the score report. We retain a record of the scoring decision for that study — the score, band, rubric and model version, and the per-domain reasoning — so scores remain auditable after deletion; no part of the document itself is kept. Stored documents are also deleted when a study is removed under the dormancy policy or when your account is deleted.
  • Audit metadata for each scoring action (rubric version, model version, score, timestamps).
  • Aggregate, non-identifying usage logs (such as page views and device class) for service operation and security.

What we do not collect

  • Patient-identifiable information or protected health information. Do not submit any.
  • Clinical records of any kind.
  • Card or banking data.

How we use your data and our legal bases

We use account and token data to operate the service and process payments (performance of our contract with you); to send transactional email such as welcome, receipts, dormancy notices, and retraction notifications (performance of our contract and our legitimate interest in keeping you informed); and to secure the service and prevent abuse (legitimate interest and legal obligation). Submitted documents are used only to produce a score for that submission. We do not use the contents of your submissions to train or improve the rubric or scoring model, we do not sell your personal data, and we do not share it with advertising networks.

Subprocessors

We rely on the following service providers, each bound by its own data-processing terms:

  • Vercel — application hosting and transient file storage (Vercel Blob).
  • Neon — managed PostgreSQL database.
  • Clerk — authentication and account management.
  • Stripe — payment processing.
  • OpenAI — the scoring engine. The text of a submitted study is sent to OpenAI's API to generate the score. This is processed under OpenAI's API terms, which do not use API inputs to train their models.
  • Resend — transactional email delivery.

Data retention and account dormancy

We retain account, token, score-report, and audit records for as long as your account is active and as needed for governance, dispute review, and legal obligations. Inactive accounts move through a published lifecycle: after a sustained period without a paid purchase and with no token balance, locker items are read-locked; after a further period the account is scheduled for deletion; and the account is deleted after a notice window. We email you at each transition. Submitted documents are not part of this lifecycle because they are deleted immediately after scoring, as described above.

Cookies and tracking

We use strictly necessary cookies for authentication and session management (set by Clerk) and for core service operation. We do not use third-party advertising or cross-site tracking cookies.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Under U.S. state privacy laws you have the right to know what we collect, to request deletion, and to not be discriminated against for exercising these rights; we do not sell personal data or process it for targeted advertising. To exercise any right, email privacy@medquiry.co. You may also delete your account at any time from your account settings, which removes your locker, tokens, and submissions; audit metadata is retained in non-identifying form for governance. You have the right to lodge a complaint with your local data-protection authority.

International transfers

Our providers may process data in the United States and other countries. Where personal data is transferred internationally, it is protected by appropriate safeguards such as standard contractual clauses where required.

Security

We use industry-standard administrative and technical measures to protect personal data, including encryption in transit, scoped access, and minimization of what we retain. No method of transmission or storage is fully secure, and we cannot warrant absolute security.

Children

MedQuiry is intended for professional and adult use and is not directed to children under 18. We do not knowingly collect data from children.

Changes to this policy

We may update this policy. When we make material changes, we will update the date above and, where appropriate, notify you. Your continued use after a change takes effect constitutes acceptance.

Contact

Questions about this policy or your data: privacy@medquiry.co.