Privacy Policy
Last updated: July 2, 2026
???? Your Health Data Privacy Is Our Top Priority
AI Doctor implements HIPAA-like data handling standards to ensure your medical information remains confidential. We use encryption, secure API key storage, role-based access control, and audit logs. This Privacy Policy describes in detail how we collect, use, protect, and process your data — with special attention to health-related information as required by GDPR Article 9 (special category data).
1. Data Controller
The data controller responsible for your personal data is Colbex SRL, registered in Romania with CIF: RO50325335, Reg. Com.: J40/13183/2024, address: Str. Izvorul Muresului, Nr. 8, Camera 1, Bl. A4, Sc. B, Et. 4, Ap. 30, Sector 4, Bucuresti. For privacy inquiries, contact: info@ai-doctor.ai.
2. Data We Collect
2.1 Account Data
- Name — the name you provide during registration
- Email address — used for account login and communication
- Password — stored as a salted MD5 hash (never in plaintext)
- Account status — credits balance, purchase history, subscription tier
2.2 Health Data (Special Category — GDPR Art. 9)
Health data is classified as "special category" data under GDPR Article 9. We process this data only with your explicit consent. Health data collected includes:
- Symptom descriptions — text you enter in the chat describing your symptoms, conditions, or health concerns
- Uploaded images — photos of skin conditions, wounds, medical scans, or other health-related images you voluntarily upload for AI analysis
- AI consultation history — the full conversation thread between you and the AI specialists, including AI-generated responses and web search results
- Chat metadata — timestamps, AI specialist selected, language preference, and session information
2.3 Technical Data
- IP address and browser type (for security and abuse prevention)
- Cookies and session data (for authentication and user experience)
- reCAPTCHA data (for spam prevention, processed by Google)
- Google Analytics data (anonymized usage statistics, processed by Google)
2.4 Payment Data
We do not store your credit card or payment credentials. All payment processing is handled by certified third-party providers:
- Stripe — card payments (PCI-DSS Level 1 certified)
- PayPal — PayPal account and card payments
- Bank transfer — processed via our bank account at Unicredit Bank SA
We only store transaction records (order ID, amount, date, status) for accounting purposes.
3. Legal Basis for Processing (GDPR Art. 6 & Art. 9)
| Data Type | Legal Basis |
| Account data (name, email) | Art. 6(1)(b) — Contract performance |
| Health data (symptoms, images) | Art. 9(2)(a) — Explicit consent |
| Technical data (IP, cookies) | Art. 6(1)(f) — Legitimate interest (security) |
| Payment records | Art. 6(1)(b) — Contract performance + Art. 6(1)(c) — Legal obligation |
| Analytics data | Art. 6(1)(a) — Consent |
4. How We Use Your Data
Your data is used exclusively for the following purposes:
- Providing AI consultations — processing your symptoms and images through AI models to generate informational responses
- Account management — authenticating your login, managing credits, and processing payments
- Improving AI quality — anonymized conversation data may be used to improve AI response quality (see Section 5 for anonymization details)
- Security and fraud prevention — monitoring for abuse, unauthorized access, and malicious activity
- Legal compliance — maintaining records as required by applicable law
- Communication — sending essential account notifications (email confirmation, password reset)
We do NOT use your data for:
- Selling or sharing your health data with third parties for marketing
- Training external AI models without your explicit consent
- Sharing your data with insurance companies or employers
- Profiling or automated decision-making with legal effects
5. Data Processing — AI and Third-Party Processors
To provide AI consultations, your data is processed by the following subprocessors under Data Processing Agreements (DPAs):
5.1 AI Model Providers
- Ollama Cloud — processes text prompts and images through AI models (LLM and Vision models) to generate responses. Data is transmitted via encrypted API calls. Ollama's processing is governed by their privacy policy and our API agreement.
- OpenAI — may process text prompts through GPT-4o models for certain AI specialists. Governed by OpenAI's API data usage policies (no training on API data).
5.2 Web Search Provider
- Brave Search API — receives anonymized search queries (your symptoms + AI-generated search terms) to retrieve medical literature. No personal identifiers are sent to Brave.
5.3 Infrastructure Providers
- Hosting provider — servers at 92.205.187.30 (Plesk-managed) store your account data, chat history, and uploaded images
- Google reCAPTCHA — spam prevention (processes IP address and interaction data)
- Google Analytics — anonymized usage analytics (property G-L18V925XC3)
5.4 Anonymization
When your conversation data is used for quality improvement, all personally identifiable information (name, email, IP) is removed. Only the symptom description and AI response quality are analyzed in aggregate form.
6. Data Security — HIPAA-like Standards
We implement the following security measures to protect your data:
6.1 Encryption
- Transport encryption: All data transmission uses HTTPS/TLS 1.2+ encryption
- Password hashing: Passwords stored as salted MD5 hashes (never plaintext)
- API key security: All third-party API keys stored in encrypted server-side configuration files, never exposed client-side
6.2 Access Control
- Role-based access control (RBAC): Admin access restricted to authorized personnel only
- Admin authentication: Separate admin login with token-based session validation
- Server access: SSH key-based authentication (no password login)
6.3 Audit and Monitoring
- Audit logs: Admin actions logged for accountability
- Server monitoring: 24/7 service health monitoring with automated alerts
- SSL certificate monitoring: Automated daily SSL expiry checks
- Disk usage monitoring: Hourly checks with alerts at 80% threshold
6.4 Data Minimization
- We collect only the data necessary for providing the service
- Uploaded images are stored in a restricted directory with no public directory listing
- Vision images are cleaned up periodically to reduce stored health data
7. Data Retention
| Data Type | Retention Period |
| Account data | Until account deletion or 3 years after last login |
| Chat history & health data | 12 months after last activity, then automatically deleted |
| Uploaded vision images | Automatically deleted after 90 days |
| Payment records | 10 years (legal obligation for accounting) |
| Server logs | 30 days |
| Analytics data | 26 months (Google Analytics default) |
8. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of access (Art. 15): Request a copy of all personal data we hold about you
- Right to rectification (Art. 16): Correct inaccurate or incomplete personal data
- Right to erasure (Art. 17): Request deletion of your account and all associated data
- Right to restrict processing (Art. 18): Request that we limit processing of your data
- Right to data portability (Art. 20): Receive your data in a machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to withdraw consent (Art. 7): Withdraw consent for health data processing at any time
- Right to lodge a complaint (Art. 77): Complain to your local data protection authority
To exercise any of these rights, contact us at info@ai-doctor.ai. We respond to all requests within 30 days.
9. Cookies
We use the following cookies:
| Cookie | Purpose | Duration |
| PHPSESSID | Session authentication | Session (deleted on browser close) |
| _ga | Google Analytics | 2 years |
| _gid | Google Analytics | 24 hours |
| reCAPTCHA | Spam prevention | 6 months |
You can manage cookie preferences through your browser settings. Essential cookies (PHPSESSID) cannot be disabled as they are required for the platform to function.
10. International Data Transfers
Your data is primarily stored on servers located in the European Union (Germany). However, some subprocessors may process data outside the EU:
- OpenAI (USA) — Standard Contractual Clauses (SCCs) in place
- Google (Analytics, reCAPTCHA) (USA) — Google's EU-US Data Privacy Framework certification
- Stripe (USA/EU) — PCI-DSS compliant, EU data residency available
- PayPal (USA/EU) — Data Privacy Framework certified
All international transfers are governed by Standard Contractual Clauses or equivalent safeguards as required by GDPR Chapter V.
11. Children's Privacy
The Platform is not intended for children under 18. We do not knowingly collect health data from minors. If you believe a minor has provided us with personal data, please contact us immediately at info@ai-doctor.ai, and we will promptly delete such data.
12. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33)
- Notify affected users without undue delay if the breach is likely to result in high risk to their rights and freedoms (GDPR Art. 34)
- Document the breach, its effects, and remedial actions taken
13. Automated Decision-Making
AI Doctor uses AI models to generate informational responses about your symptoms. However, these responses do NOT constitute automated decision-making with legal or significant effects as defined by GDPR Art. 22. All AI-generated content is informational only and does not result in any action being taken without your explicit human decision to seek or not seek medical care.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. We will notify you of significant changes by posting a notice on the Platform or sending an email. Your continued use of the Platform after changes constitutes acceptance of the updated policy.
15. Contact
For any privacy-related questions, data subject rights requests, or concerns:
- Email: info@ai-doctor.ai
- Company: Colbex SRL
- Address: Str. Izvorul Muresului, Nr. 8, Camera 1, Bl. A4, Sc. B, Et. 4, Ap. 30, Sector 4, Bucuresti, Romania
- CIF: RO50325335
- Reg. Com.: J40/13183/2024
You also have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP) at www.dataprotection.ro.
By using AI Doctor, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your data as described herein. Your health data is processed with your explicit consent under GDPR Article 9(2)(a) and is protected by HIPAA-like security standards.