Privacy Policy
Effective: 29 September 2026 · Last updated: 5 October 2026
This policy explains how PlexusMD Viewer — the app for iPhone and iPad and the web viewer at viewer.plexusmd.org — handles information. In short: the images you open stay on your device. Nothing is uploaded unless you choose to share a study by link or to run a research model on our servers, and in both cases the images are anonymised on your device first.
1. Who we are
PlexusMD Viewer is provided by Dermatological Beauty LLC, the data controller for the information described here.
Dermatological Beauty LLC, 312 W 2nd St, Unit #A1452, Casper, WY 82601, USA
Contact: [email protected]
2. Images you open
DICOM files, folders and zip archives are read and displayed on your device. Viewing, measurements, reconstructions (MPR, MIP) and, on the web viewer, automatic measurements and segmentation all run on your device or in your browser. The one exception is a research model that runs on our servers, and only when you start it yourself (section 4). Otherwise we do not receive these images.
In the app, studies you open are kept in the app's library on your device until you delete them. The library is protected by the device's encryption while it is locked and is not included in iCloud or device backups. Measurements, notes and key images you add are kept with the study, on the device only. A study opened from someone else's share link is removed from your device when that link expires or its sender removes it.
iCloud (app). If iCloud Sync is on, which it is unless you turn it off in the app's settings, studies you have anonymized in the app are also kept in your own iCloud account, so they appear on your other devices signed in to the same Apple Account. They are stored by Apple under your account, not by us, and we cannot see them; their names and descriptions are end-to-end encrypted. Studies with patient details and studies opened from someone else's link are never sent to iCloud. Deleting a study in the app removes it from iCloud and your other devices.
On the web viewer, opened files stay in your browser and are cleared when you close the page.
3. Sharing a study by link
When you choose to share, the chosen series are anonymised on your device before anything is sent:
- Removed: patient name, ID, birth date and birth time, other patient names and IDs, address and telephone, accession number, study ID, institution name, address and department, referring, performing, reading and requesting physicians, operators, order numbers, admission ID, and the station, application entity and location fields where devices often record the hospital's name. Private fields that repeat the patient's name or ID are cleared too.
- Kept: the images, age, sex, study date, series descriptions, and technical and device information needed to display the study correctly.
Some images (for example ultrasound frames, scanned documents or screen captures) may have patient details drawn into the pixels. These cannot be removed automatically; you are asked to check such images before sharing.
The anonymised study is stored in secure cloud storage for at most 120 minutes and then deleted automatically. You can remove a link earlier at any time; the study is then deleted from storage at once. If you email a link, the recipient addresses are passed to our email service provider only to deliver that message and are not used for anything else.
You can also export an anonymised zip or a single image. These are made on your device and go only where you send them.
4. Research models on our servers
A few research tools of the web viewer are too heavy for a browser and run on our servers instead. The models that run this way are marked in the viewer (for example stroke lesions, brain volumes, MS lesions, spine structures, and lung and breast cancer risk). They run only when you press Run, and only on studies you have anonymised in the viewer, or on NIfTI files, which carry no patient identity; the viewer refuses any other study.
- What is sent: only the series the tool needs (the series the tool asks for, such as the diffusion and ADC series for stroke lesions, or the four screening views for breast cancer risk), anonymised as described in section 3, in one package over an encrypted connection.
- Where: the images are processed on processors rented from a cloud computing provider, in the United States.
- How long: the images are deleted as soon as the model has used them. The result (the outline of a lesion or of brain structures, and their volumes) is deleted when the viewer has fetched it; anything not fetched is deleted within two hours at the latest. We keep no copy.
- No other use: the images are not used to train models, are not looked at by us and are not shared with anyone else.
- Access: these tools need an account (below) or an access code we have given you. Neither is stored with the images or passed to the model.
Accounts. The web viewer itself needs no account. To run a research model on our servers you sign in with an email link, a Google account or an Apple account; the sign-in itself is handled by an authentication service provider. We then keep your account id, email address, how you signed in, when you signed up and last signed in, your prepaid usage and research support and every change to them (usage bought, runs, refunds, support granted), and a record of each run: which model, when, the size of the anonymised package sent, how long the model ran, what it cost and whether it finished. We keep this record so that you and we can always see what usage was spent on. We do not keep which study or images a run used, or its result. A single cookie keeps you signed in for 30 days; it is needed for the account to work and is not used for anything else. Payments are handled by Paddle.com as merchant of record; we receive the amount and the payment's reference, never card details. Messages asking for research support reach us by email with your account address.
5. Preventing misuse
To prevent misuse of sharing and email, the number of shares, the declared size of shares and the emails sent from each network address are counted per hour and per day. We never store the address itself: it is turned into a fingerprint with a secret key that changes every day, and the counts are deleted after two days.
6. Messages to us
If you write to us from the app, your message, your reply address, the app version and the device model are emailed to [email protected] so we can answer. Please do not include patient details in messages.
7. Analytics and advertising
The app has no account, no analytics, no advertising and no tracking; the web viewer's optional account is used only for the research models (section 4). The web viewer keeps anonymous daily counts (for example visits and studies opened by modality and country) that cannot identify a person or a patient, and uses cookieless, privacy-friendly web analytics. We do not sell or rent any information, and we do not share it for advertising.
8. Service providers and international transfers
We rely on a small number of carefully chosen service providers for hosting, temporary storage of shared studies, computing for the research models, sign-in, payments, network protection and email delivery. They process information only on our instructions and under data processing terms with appropriate safeguards for international transfers, including standard contractual clauses where required.
9. How long information is kept
- Studies in the app's library: until you delete them (studies from others' links: until the link ends).
- Anonymized studies in your iCloud: until you delete them in the app or turn iCloud Sync off and delete them.
- Shared studies on our storage: at most 120 minutes, or until you remove the link.
- Images sent to a research model: deleted as soon as the model has used them; its result when the viewer fetches it, and at the latest after two hours.
- Accounts: until you ask us to delete yours; the record of runs and usage is deleted with it, except what tax or accounting law requires us to keep after a purchase.
- Misuse counters: two days.
- Messages to us: as long as needed to answer and keep a record of the conversation.
10. Your rights
Depending on where you live (for example under the GDPR, the UK GDPR, Turkey's KVKK or US state privacy laws), you may have the right to access, correct or delete information about you, to object to or restrict its processing, and to complain to a data protection authority. Because the app keeps your studies only on your device, you control them directly and can delete them at any time. For anything else, write to [email protected].
11. Security
Connections to our servers use TLS encryption. Share links are long random identifiers, and only the sender's device holds the key that can remove a link. No system is perfectly secure; please share studies only with people who should see them.
12. Children
PlexusMD Viewer is intended for healthcare professionals and is not directed at children.
13. Changes
We may update this policy as the service changes. The date at the top shows the latest version; important changes will be announced in the app or on the website.