Statement on non-storage of patient data
This service displays DICOM radiographs in your browser. It is designed not to store patient data on the server. Here we explain what happens to your file and what we do keep.
What happens when you upload a file
- The file travels to the server over an encrypted connection (HTTPS).
- The server reads only the file header (the first 4 MB) to check that it is DICOM and to build the study card. It does not decode or store the image pixels.
- While the request lasts, PHP keeps the file in the system temporary folder and deletes it automatically when the request ends. Our code does not copy or move it anywhere else.
- The study card (name, ID, dates, equipment, etc.) goes back to your browser in the same response and is not stored.
- The image is drawn in your browser from the file on your own device. The JPG download is also generated in your browser.
- If the file arrives from an authorized third-party system (integration API, with its own key), it goes through the same process: it is not stored, and the study card is sent back to whoever requested it in the same response.
What we do keep
- Your account
- Email and whether you have confirmed it, password (only its encrypted hash), plan and validity, date you accepted the consents, sign-up date and last sign-in.
- Integration API keys
- For each key: the name of who uses it, their contact email, the key's irreversible fingerprint (not the key itself), when it was created, who created it and when it was last used. The full key is only shown once, when it is created; we do not keep it.
- Email links
- When you ask to recover your password or confirm your email we keep the irreversible fingerprint of the link code, when it was requested and when it expires. The link cannot be rebuilt from that fingerprint. They are deleted after 7 days or when you close your account.
- Query counter
- To apply the daily limit we keep the day, an irreversible code of who is querying (your account id, or for people without an account a code derived from the IP address, not the IP itself) and an irreversible code of the study identifier. That code cannot be used to recover the study or the patient. It is deleted automatically after 48 hours (no account) or 35 days (with an account).
- Sign-in attempts
- A code derived from the IP and the time, to stop repeated sign-in attempts. A 15-minute window is used and expired records are deleted automatically.
- Recorded payments
- Date, amount, method and reference of each payment (those the team records and those Wompi confirms, with the transaction identifier), and until when it covers. They are kept for accounting even if you delete your account (then without your email). They carry no patient data or card data.
- Payment orders
- When you press "Pay" an order is created with your account, the plan, the amount and our own reference, so the payment can be credited when Wompi confirms it.
- Administration changes
- Account creation, plan and settings changes, blocks, with date and who made them. No patient data.
What we do not keep on our server
- The DICOM file or any copy of it.
- The image pixels, or the image as JPG or in any other format.
- Name, ID, sex, date of birth or any other patient or study data.
- The study card.
Technical logs and cookies
- Like any site, the web server may log the IP address, date, requested address and size of each request. It never logs the file contents. If an unexpected error happens, only the error type and its technical message are recorded.
- We use a session cookie only if you sign in, and we keep your language in the browser. We use no advertising or third-party analytics.
- We do not send patient data to third parties.
Email and online payments
- We email you only to confirm your address and to recover your password, with a link that works for 1 hour (recover) or 48 hours (confirm) and can be used only once. They never carry patient data. The email service the site uses sees your address and the message.
- If you recover your password by email, the sessions you had open are closed.
- If you pay online, you do it on the secure Wompi page (Banco Agrícola, El Salvador): we never see or store your card details. We send Wompi only the amount, the plan name and an order reference; we do not send your email or any patient data. Wompi tells us whether the payment was approved and we activate your plan with that. Wompi may send you its own receipt and handles your data under its own terms.
Deleting your account
- From My account you can delete your account whenever you want (we ask for your password to confirm). It is permanent.
- Your password, plan and consents are removed, and the record of your queries is deleted. Your email becomes anonymous and free in case you want to sign up again.
- Recorded payments and the change-log entries are kept, without your email. What you saved in your own Google Drive is not touched.
Google Drive (optional)
- In My account and in the viewer you can connect your Google Drive. It is optional and up to you. Google's script is only loaded when you use the "Save to my Drive" or "Connect Google Drive" button (or when you move toward that button while signed in, so the Google window opens without delay). Google asks permission only for the files this application creates in your Drive; it cannot see the rest of your Drive.
- If you press "Save to my Drive", your browser sends the original study file straight to a folder called Mediclad in your Drive: it does not pass through our server. Next to the file, some data the study itself carries (patient name, document number, sex, age, date of birth, date, modality and description) is noted as private properties of the file in your Drive, to build your history. That data stays only in your Drive; we neither receive nor store it.
- The study history in My account is read by your browser directly from your Drive each time you open it; our server is not involved. We do not receive or store the access key: it stays only in your browser, in the session storage of the tab, and lasts about an hour; it is erased when you close the tab, sign out or disconnect. That way you do not have to reconnect when moving from the viewer to My account. In the permanent storage of the browser only your Google email is remembered, to suggest reconnecting, and it is forgotten when you sign out. You can disconnect at any time; that also revokes the permission at Google.
- What you save in your Drive stays in your custody and under Google's terms. Personal Google accounts do not have a health-data agreement; if you save patient studies, consider a Google Workspace account.
What this statement is not
It describes how the service works. It is not a certification or a guarantee of compliance with HIPAA, GDPR or local laws. If your organization must comply with any regulation, review this document with your advisor. The service is for viewing only: it is not a diagnosis and does not replace a certified diagnostic viewer.
Questions about this statement: desarrollo@gruponetblu.com
Version 6, September 27, 2026.
