Skip to content
Mediora
For patients For doctors For students Second opinion Pricing
RU EN HE
UploadLogin
  • How it works
  • Pricing
  • FAQ
  • For doctors
  • For students
  • Upload
  • Login
RU EN HE

Privacy Policy

Effective date: 22 July 2026
Version: 3

1. Introduction

Mediora is an AI-powered tool that helps adults understand their personal lab test results.
The service is operated by SLAtech Ltd, an Israeli company (company number 515518926)
with registered offices at HaShayetet 8, Rishon LeZion, Israel. References in this policy
to "we", "us", "Mediora", or "the service" mean SLAtech Ltd acting as the controller of
your personal data.

This policy explains what personal data we collect when you use Mediora, why we process it,
who we share it with, and which rights you have under the EU General Data Protection
Regulation (GDPR) and the Israeli Privacy Protection Law, 5741-1981 (PPL).

2. What data we collect

Account data. Email address, preferred language, optional first / last name, date of
birth, sex, phone number, chronic conditions and medications you choose to share in your
profile. Your date of birth is required by our 18+ age gate.

Health data (GDPR special category under Article 9). Lab reports you upload
(PDF / images), lab markers we extract from them, AI-generated analyses and trend
narratives, messages you exchange with the AI assistant, and the record of whether a
message triggered one of our safety filters.

Technical data. IP address, browser user agent, browser language, approximate
geolocation inferred from IP, and the session cookies listed in our Cookies Policy.

Usage data. Which features you use (uploads, report views, chat interactions), email
delivery history (welcome, analysis-ready, critical-alert), and admin audit log entries
that relate to your account when a staff member interacts with it.

Funnel and abandonment data. When you begin one of our forms — in particular the doctor
application — and enter an email address but do not complete and submit it, we retain that email
address together with the step you reached and the language you used. We use this only to
understand where people stop, to send a single short "what got in the way" survey, and to improve
the flow. You can ask us to delete it at any time (see Section 8).

Study materials (section for medics). If you create a student account and upload
study material — lecture notes, a summary, a handout — we store the file itself, the text
extracted from it, the fragments that text is split into, and the numeric vector
representations of those fragments used for search. The file is kept in a storage bucket
separate from medical reports, because the two have different retention periods and
different grounds for processing. Your material is visible only to you: it is not
published, not shown to other users, and never added to a shared question bank. No health
data is involved unless you choose to upload a lab report, which is covered above.

3. Legal basis for processing (GDPR Article 6 + Article 9)

We process your personal data on the following legal bases:

  • Contract performance — Art. 6(1)(b). Delivering the core product: parsing your
    reports, generating analyses, emailing you when they're ready, maintaining your history.
  • Consent — Art. 6(1)(a). Analytics cookies, marketing emails (opt-in in Profile),
    non-essential features such as similar-case comparison, and early-access signup for the
    section for medics — given by its own checkbox and confirmed through a link we email you.
  • Vital interests — Art. 6(1)(d). Sending "critical marker" alerts when one of your
    results is clinically significant — we treat these as a safety issue, not a marketing
    channel.
  • Special-category explicit consent — Art. 9(2)(a). Processing your health data
    requires a separate affirmative consent, captured on signup as part of the "I accept
    the Privacy Policy" checkbox. You can withdraw this consent at any time by deleting
    your account (see Section 8).

Under the Israeli PPL we rely on §11 for processing with the data subject's consent and on
§2(9) for processing that is necessary to provide the service you requested.

4. How we use your data

  • Run the analysis pipeline that processes your lab reports and produces the report you
    see in the app.
  • Send transactional emails: account welcome, analysis-ready notification, critical-marker
    alert, re-engagement nudge if you never returned after signup.
  • Track longitudinal trends across multiple uploads for the same marker.
  • Improve the service using aggregated, de-identified metrics. We do not use your
    identifiable data to train AI models.
  • Detect abuse (rate limits, spam, repeated safety-filter triggers).

5. Recipients of your data (processors)

We share the minimum necessary personal data with the following processors to provide the
service. This is the full list of recipients required by GDPR Article 13:

Processor Purpose Location Safeguards
OpenAI AI analysis of lab reports, chat responses, and reading the text out of study material you upload United States Data Processing Agreement with a no-training-on-your-data clause; Standard Contractual Clauses for EU personal-data transfers
Amazon Web Services — S3 Secure storage of your uploaded files — lab reports and study materials, in separate buckets United States (AWS, us-east-1) Server-side encryption at rest; Data Processing Agreement; Standard Contractual Clauses
Amazon Web Services — Textract Redaction of patient identifiers before AI processing United States (AWS, us-east-1) Data Processing Agreement; Standard Contractual Clauses
Amazon Web Services — SES Delivery of transactional email United States (AWS, us-east-1) Data Processing Agreement; Standard Contractual Clauses
Qdrant (vector search) Semantic similarity search over the text of your reports, your analysis history and your study materials Germany (Contabo GmbH) Data Processing Agreement + Standard Contractual Clauses (Module 3); stored and processed within the EU (Germany); user-level isolation — every query is strictly filtered to your data
Primary application database, application and background processing Storing and processing your account and analysis data United States (Contabo Inc., US-East) Data Processing Agreement + Standard Contractual Clauses (Module 3); access controls, encryption at rest
Cloudflare Content delivery, DDoS protection and cookieless aggregate performance analytics United States (Cloudflare, Inc.; global edge network) Data Processing Addendum; Standard Contractual Clauses

All processors are contractually bound to:

  • Process your data only to provide the service to you.
  • Implement appropriate technical and organisational security measures.
  • Never use your health data to train AI models.
  • Return or delete your data when our contract with them ends.

We do not sell personal data, and we do not share it with advertisers.

6. International data transfers

When we use processors located outside your country, we apply the safeguards required
by GDPR and the Israeli Privacy Protection Law:

  • EU users: transfers to the United States are covered by the European Commission's
    Standard Contractual Clauses (SCCs).
  • All users: Israel is currently recognised by the European Commission as providing
    an adequate level of data protection (Decision 2011/61/EU).
  • Processors in other countries: bound by our Data Processing Agreement with
    equivalent safeguards.

You can request the specific transfer mechanisms in use by emailing support@mediora.ai.

7. Retention

  • Account active: we retain your data while your account is active.
  • Account deleted (user-initiated): 30-day grace period during which you can cancel,
    then permanent hard delete (see Section 8). The only data we retain after hard delete
    are aggregated, irreversibly de-identified metrics.
  • Chat history: retained while your account is active; you can soft-delete
    individual messages from the sidebar.
  • Early-access signups: retained while we prepare the launch of the educational
    section. There is no scheduled auto-deletion — we delete the record when you ask us to
    (support@mediora.ai) or when you create an account.
  • Study materials: retained while your account is active. Deleting a material
    removes the file, the text extracted from it, its fragments and their search vectors.
    Deleting your account removes all of them.
  • Backups: rolling 90-day encrypted backups; hard deletes propagate into the current
    backup within 24 hours and drop out of rotation within 90 days.

8. Your GDPR rights

You can exercise the following rights at any time, free of charge:

  • Access (Art. 15). The Profile page includes a "Download my data" button that
    exports a machine-readable JSON bundle of everything we hold about you, including
    the specific names of the processors we have shared data with.
  • Rectification (Art. 16). Edit your profile directly; lab-marker values can be
    corrected in the analysis editor.
  • Erasure (Art. 17). The Profile page includes a "Delete my account" button that
    triggers the 30-day deletion flow described in Section 7.
  • Restriction (Art. 18). Contact support@mediora.ai.
  • Portability (Art. 20). Same export button as for Access.
  • Object (Art. 21). Contact support@mediora.ai.
  • Withdraw consent. Any consent you gave (analytics cookies, marketing emails) can
    be withdrawn from the Profile page without affecting the lawfulness of prior processing.

9. Israeli PPL rights

Israeli data subjects have equivalent access rights under §13 of the PPL and may request
correction of inaccurate data under §14. To exercise these rights, email
support@mediora.ai from the address on your Mediora account.

10. Security measures

  • Transport: industry-standard encryption in transit for every browser-to-server
    connection.

  • Authentication: short-lived session tokens + one-time-passcode login (no password
    stored on your device).

  • Infrastructure: private network segmentation, firewalled database, least-privilege
    service accounts, encrypted logs.

  • Chat safety: a multi-layer content filter (input screening, refusal templates,
    output review) so the assistant cannot produce prescriptions or diagnoses.

  • Encryption at rest: extracted patient identifiers (name, date of birth, ordering
    doctor) are encrypted at rest in our primary database under a managed-key scheme.

11. Children

Mediora is a service for adults. We do not knowingly collect personal data from anyone
under 18. You must tick an explicit "I am 18 or older" checkbox on signup, and the
service will refuse to save a profile whose date of birth corresponds to an under-18 age.
If you believe a minor has created an account, please email support@mediora.ai and we
will delete it.

12. Changes to this policy

We will notify you by email at least 30 days before a material change takes effect. For
changes that affect the legal basis of processing or add a new category of data, we will
ask for your fresh consent before continuing to process your data under the new terms.

13. Contact

  • Controller: SLAtech Ltd, company number 515518926, HaShayetet 8, Rishon LeZion, Israel.
  • Privacy contact: support@mediora.ai.

14. Supervisory authority

EU-based users have the right to lodge a complaint with the national data-protection
authority where they live or work.

Israeli users may contact the Privacy Protection Authority (Ministry of Justice).

Document version 6 - last updated 2026-09-14

Product

  • How it works
  • Pricing
  • FAQ
  • Upload a test
  • My History

Features

  • Document analysis
  • Biological age
  • Lab trends over time
  • Family profiles
  • Which specialist

Catalog

  • Lab markers (254)
  • Conditions (191)
  • Symptoms (184)
  • Health Score (free)
  • Trajectory tracking
  • Pick your tests
  • Reference ranges
  • Health topics
  • Unit converters
  • Which tests for you

Resources

  • Marketplace
  • Our doctors
  • Articles
  • How to read results
  • Free AI analyzer
  • Contact

For agents

  • MCP server
  • llms.txt
  • llms-full.txt
  • Discovery manifest
  • Public data API

For medics

  • For students
  • Study materials
  • For doctors

For business

  • For laboratories
  • For clinics
  • For hospitals

Documents

  • Privacy
  • Terms
  • Medical Disclaimer
  • Cookies Policy
Mediora

We read your lab results and explain them in your language. Your data stays yours. From SLAtech LTD.

support@mediora.ai
© SLAtech LTD 2026
SLAtech LTD · Company No. 515518926 · HaShayetet 8, Rishon LeZion, Israel
We use cookies
Only the cookies required to run Mediora safely. See our Cookies Policy for details. Read

Cookie preferences

Essential cookies are always on - they're required for login and language.