Privacy Policy

Effective: April 16, 2026

1. Who we are

TCM AI ("we", "us") operates the TCM AI web platform and desktop application. This policy explains what data we collect, how we use it, and the rights you have over it.

2. Data we collect

Account data: email, display name, hashed password, Stripe customer ID, subscription tier, credit balance, timestamps. Diagnosis and search requests: symptoms, tongue observations, pulse notes, chief complaint, duration, pregnancy status, allergies. Billing data: processed directly by Stripe; we receive subscription status and masked card metadata only. Technical data: IP address and request logs retained for 30 days for security and abuse prevention.

3. Data we do NOT collect

We do not receive patient names, dates of birth, national ID numbers, phone numbers, addresses, or any patient identifiers. The desktop app stores all patient personally-identifiable information in a local SQLite database on your device — it is never transmitted to our servers. Consultations sent to our AI backend contain only de-identified clinical observations.

4. How we use data

We use your account data to authenticate you, deliver AI services, process payments, and communicate service-related notices. Diagnosis content is passed to Google Gemini for inference and is not retained server-side beyond the request lifecycle except where you save consultation history to your own account.

5. Third-party processors

Google (Gemini API — AI inference; data is not used by Google to train models under the Vertex AI / Gemini API terms). Stripe (payment processing, billing records). Resend / SMTP provider (transactional email). Self-hosted PostgreSQL (account and history storage).

6. Your rights

Under GDPR, PIPL, and similar laws you may request access to, correction of, export of, or deletion of your account data. Email support and we will respond within 30 days. Deleting your account removes your history and personal data; backups are purged within 90 days.

7. Data retention

Active account data is retained while your account exists. Deleted accounts are purged from active systems within 30 days and from backups within 90 days. Payment records are retained for 7 years for tax and audit compliance.

8. Security

Passwords are hashed with bcrypt. TLS is required for all web and API traffic. The database is encrypted at rest and access is restricted to the application runtime. We do not sell your data.

9. International transfers

Our servers are located in [region]. If you use the service from another jurisdiction, your data is transferred there for processing under the lawful basis of contract performance.

10. Contact

For privacy requests or urgent security issues, email [email protected].