Privacy Policy

Last updated: 13 September 2026

Health data at Sera

Sera is a practitioner tool. Most of the health data in it describes your clients, not you: you decide what to record about them and why, and Sera stores and processes it on your instruction. Under UK/EU GDPR that makes you the controller of your clients' data and Sera the processor — which means the duty to obtain their consent, answer their access and deletion requests, and tell them their data is held here sits with you, and Sera's job is to give you what you need to do it.

  • Stored encrypted at rest on our database provider (Neon Postgres), using standard AES-256 encryption.
  • Never sold, shared, or used for advertising.
  • Used only to provide the service — parsing lab reports, reading values against ranges, and showing trends over time.
  • Isolated to your workspace. Every query is scoped to your account, and no other practitioner can reach your clients' records.
  • Processed by Anthropic's Claude API during PDF parsing, under terms that prohibit training on your data (see below).
  • Deleted immediately and irreversibly when you delete a client or delete your account. Archiving a client is the separate, reversible option — an archived record leaves your caseload but is kept in full.
  • Exportable at any time as a single JSON file covering your whole workspace, so you can answer a client's portability request.
  • Under UK/EU GDPR, you can request access, portability, or deletion at any time.

Sera is a small business run by Alina Radu. We take privacy seriously not because of any zero-knowledge cryptographic guarantee, but because health data is personal and we believe in treating it that way.

What we collect

  • Account information: Your email address, a securely hashed password (bcrypt), and optionally your name. We also record your plan, whether you joined as a founding member, and the time you last signed in.
  • Client records: For each client, the first name and optionally a last name, biological sex, full date of birth, and any notes you write. Sex and date of birth are required because they are direct inputs to the ranges and calculations — age feeds eGFR and FIB-4 rather than serving as a label.
  • Client health data: Blood work values and their units, panel names, collection dates and times, notes on a panel or on an individual result, and, where a panel includes cycle-dependent hormones, the menstrual cycle day the sample was drawn. This is what powers the overview, insights, trends and reports.
  • Interventions: The changes you record against a client — diet, supplementation, medication, exercise, stress, sleep, environment or other — with their description and dates, so a movement in a marker can be read beside what preceded it.
  • Consent records: When you accept these terms at registration, we store what you agreed to, the version of each document, the time, and the IP address the request came from, as a record that consent was given.
  • Technical and diagnostic data: Errors and notable events (including the request path and, where applicable, your account), kept for 90 days; the times you upload a lab report, used to enforce upload limits; a record that a client report was generated, with its date range; and any biomarker name or unit from an uploaded report that Sera did not recognise, which we review to add support for more laboratories.

Sera does not ask for a postal address, a phone number, or payment details, and has no way to accept them.

How your data is stored and protected

Your data is stored in a PostgreSQL database hosted by Neon and served through Vercel. It is encrypted at rest by the database provider using AES-256, and transmitted over encrypted (HTTPS/TLS) connections. Access to the production database is restricted to what is needed to operate Sera.

International data transfers. Our infrastructure providers (Neon and Vercel) operate from the United States, which means data from UK and EU users is transferred outside the UK/EEA. These transfers are protected by the Standard Contractual Clauses (SCCs) included in our Data Processing Agreements with Neon and Vercel, providing the legal basis for the transfer under UK GDPR and EU GDPR.

PDF parsing and Anthropic's Claude API

When you upload a client's lab report PDF, Sera extracts the text from that PDF and sends the extracted text — not the PDF file itself— to Anthropic's Claude API, which reads it and returns the structured biomarker values for you to review before saving.

Under Anthropic's commercial API terms, data you submit through the API is not used to train Anthropic's models. Anthropic retains API inputs and outputs only for a limited period to operate the service and guard against misuse, and for no other purpose. Sera itself does not keep the uploaded PDF or its full extracted text after parsing — we store only the structured biomarker values you choose to save, together with any biomarker name or unit from the report that Sera did not recognise, which we keep in order to add support for more laboratories.

Anthropic operates from the United States. Data sent to their API is covered by the Standard Contractual Clauses in Anthropic's commercial terms, providing the legal basis for the transfer under UK/EU GDPR.

What we do not do

  • We do not sell or share your data with anyone
  • We do not show you advertisements
  • We do not use tracking pixels or third-party advertising analytics
  • We do not use your clients' health data to train AI or machine learning models, and our AI provider does not either
  • We do not build advertising profiles about you

Your rights

  • Access: Everything you enter — your clients, their results, notes and interventions — is visible to you in the app at any time. The consent, diagnostic and upload records described above are not shown on a screen, but they are included in full in the export below, which is the complete picture of what we hold about you.
  • Export: You can export all of your data in a standard JSON format from the Settings page.
  • Deletion: You can permanently delete your account and all associated data from the Settings page. Deletion is immediate and irreversible — your clients, their results, your notes, interventions and consent records are all erased at once. Diagnostic event records are the one exception: they are retained for the remainder of their 90-day window with your account no longer named on them.
  • Portability: Your exported data is in a standard format that you can use however you wish.

Cookies

Sera uses only essential cookies required for authentication (session management). We do not use tracking cookies, advertising cookies, or third-party cookies.

One other thing is kept in your browser rather than on our servers: the questions you tick to take into a consultation are stored in your browser's local storage, on that device only. They are never sent to us and are not part of your account.

Changes to this policy

The date at the top of this page indicates when the policy was last updated, and it is recorded against your consent when you register, so what you agreed to is always identifiable. Sera does not currently send email of any kind, so we cannot notify you of a change — please check this page if you want to know whether it has moved.

Contact

If you have questions about this privacy policy or how your data is handled, contact us at transcedentalia@gmail.com.