Effective: April 16, 2026
TCM AI ("we", "us") operates the TCM AI web platform and desktop application. This policy explains what data we collect, how we use it, and the rights you have over it.
Account data: email, display name, hashed password, Stripe customer ID, subscription tier, credit balance, timestamps. Diagnosis and search requests: symptoms, tongue observations, pulse notes, chief complaint, duration, pregnancy status, allergies. Billing data: processed directly by Stripe; we receive subscription status and masked card metadata only. Technical data: IP address and request logs retained for 30 days for security and abuse prevention.
We do not receive patient names, dates of birth, national ID numbers, phone numbers, addresses, or any patient identifiers. The desktop app stores all patient personally-identifiable information in a local SQLite database on your device — it is never transmitted to our servers. Consultations sent to our AI backend contain only de-identified clinical observations.
We use your account data to authenticate you, deliver AI services, process payments, and communicate service-related notices. Diagnosis content is passed to Google Gemini for inference and is not retained server-side beyond the request lifecycle except where you save consultation history to your own account.
Google (Gemini API — AI inference; data is not used by Google to train models under the Vertex AI / Gemini API terms). Stripe (payment processing, billing records). Resend / SMTP provider (transactional email). Self-hosted PostgreSQL (account and history storage).
Under GDPR, PIPL, and similar laws you may request access to, correction of, export of, or deletion of your account data. Email support and we will respond within 30 days. Deleting your account removes your history and personal data; backups are purged within 90 days.
Active account data is retained while your account exists. Deleted accounts are purged from active systems within 30 days and from backups within 90 days. Payment records are retained for 7 years for tax and audit compliance.
Passwords are hashed with bcrypt. TLS is required for all web and API traffic. The database is encrypted at rest and access is restricted to the application runtime. We do not sell your data.
Our servers are located in [region]. If you use the service from another jurisdiction, your data is transferred there for processing under the lawful basis of contract performance.
For privacy requests or urgent security issues, email [email protected].