Privacy Policy
Effective: March 25, 2026 · Last updated: March 25, 2026
Oncofiles is operated by Instarea s.r.o. ("we", "us").
This policy describes how we handle your data when you use Oncofiles
(oncofiles.com).
1. What Data We Access
When you connect your Google account, Oncofiles accesses:
- Google Drive — files in your designated medical documents folder only
- Gmail (read-only) — emails matching medical keywords
to detect appointments and results
- Google Calendar (read-only) — events to identify medical appointments
We only access data you explicitly authorize through Google's OAuth consent screen.
You can revoke access at any time via
Google Account Permissions.
2. How We Use Your Data
Your data is used exclusively to:
- Organize and categorize your medical documents
- Extract metadata (dates, institutions, categories) using AI
- Make your records searchable through AI chat (Claude, ChatGPT)
- Track lab values and treatment timelines
We do not use your data for advertising, profiling, or any purpose
unrelated to your medical document management.
3. Where Data Is Stored
- Document metadata — stored in a Turso database
(SQLite-compatible, hosted in EU)
- Original files — remain in your Google Drive;
we do not copy them to separate storage
- OCR text — stored as companion files in your Google Drive folder
- AI-generated metadata — stored in the database alongside document records
4. Data Sharing
We do not sell, share, or transfer your personal data
to third parties, except:
- AI providers — document content may be sent to Anthropic (Claude) for metadata
extraction. This is governed by Anthropic's data processing terms.
- Infrastructure — Railway (hosting), Turso (database). Both process data
under their respective privacy policies and data processing agreements.
5. Data Retention
Your data is retained as long as your account is active. You can request deletion
of all stored data by contacting us. Original files in Google Drive are never deleted
by Oncofiles — only metadata in our database.
6. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Request correction or deletion
- Data portability (export your data)
- Withdraw consent at any time
- Lodge a complaint with your supervisory authority
7. Google API Services Disclosure
Oncofiles' use and transfer of information received from Google APIs adheres to the
Google API
Services User Data Policy, including the Limited Use requirements.
8. Contact
For privacy questions: peter.fusek@instarea.sk
Instarea s.r.o. · Bratislava, Slovakia