PIPER BY FOCENA — PRIVACY POLICY

Effective: August 28, 2026

This Privacy Policy explains what Focena, Inc. ("Focena," "we," "us") collects, why, and what we do and do not do with it, in relation to the focena.ai website and the Piper by Focena platform (together, the "Service"). It should be read with our Terms of Service and Acceptable Use Policy.


1. The short version

  • The public website sets no cookies, runs no analytics, and loads nothing from a third party. You can read every public page without being tracked, identified, or counted by any advertising or analytics service. We do not operate one.
  • The Service is designed not to collect personal or health information about patients. It is a research aid for professional and research use. We instruct users to submit only de-identified scientific information, and the Service does not need patient identifiers to function.
  • We do not sell personal, genetic, or health information. Not to anyone, for any purpose, ever. We do not share it for cross-context behavioural advertising.
  • We do not use anyone's information to train a general-purpose AI model, and the third-party model providers we use are configured not to train on what we send them.
  • You can reach a human. Write to focena@focena.ai with any question, request, or complaint about your data.

2. Who we are

Focena, Inc. is the controller of the personal data described in this policy. For any privacy question, or to exercise a right described in section 11, contact focena@focena.ai. We answer these ourselves; there is no ticketing system between you and us.


3. The public website

The pages at focena.ai that you can read without signing in — the home page, How it works, The programme, Resources and the guides under it, Access, and these legal documents — are built to collect as close to nothing as a website can.

When you visit a public page:

  • No cookies are set. We verified this against the live site: a first visit to any public page returns no Set-Cookie header at all. Because we set no cookies on these pages, there is no cookie banner and nothing for you to consent to or dismiss.
  • No analytics, no tracking pixels, no advertising. We do not run Google Analytics, Vercel Analytics, or any equivalent. We do not have an advertising account anywhere, and we do not build profiles of visitors.
  • No third-party requests. Typefaces are compiled into the site when it is built rather than fetched from a font service, so your browser does not contact Google or any other party when a page loads. The only server your browser talks to is ours.
  • No account required, and no sign-up form. The Access page gives an email address rather than a form, precisely so that reading about us does not require handing over anything.

What is unavoidably recorded. Our hosting provider (see section 8) keeps ordinary, short-lived server logs of requests — including the requesting IP address, the page requested, and the time — as every web host does. These exist for security, abuse prevention, and diagnosing faults. We do not use them to build visitor profiles, we do not join them to any account, and we do not attempt to identify visitors from them.


4. What we collect when you have an account

Accounts are created by us at the request of an organisation; there is no self-service sign-up. When your organisation has an account, we hold:

  • Account data — your email address, the display name you give us, the organisation ("tenant") you belong to, and your role within it.
  • Authentication data — sign-in records maintained by our authentication provider for security purposes. These include the IP address and browser user-agent associated with a sign-in, which is standard security logging for detecting account compromise.
  • Access records — an append-only log of which authenticated user viewed or requested which item, and when. This log deliberately records only the user, the organisation, the action, the item, and the timestamp: it does not store IP addresses or browser user-agents. It exists to detect misuse of licensed research material and to protect the corpus, not to observe you.
  • What you submit — de-identified scientific content you enter, such as a gene symbol or a variant notation, and any document you choose to submit for review.
  • Derived work product — the analyses the Service generates from those inputs.

Cookies in the signed-in Service. Once you sign in we set a session cookie so the Service knows it is you, and, for reviewers, a small preference cookie named focena_view that remembers which view of the portal you last chose. Both are strictly necessary to operate the Service. We set no advertising, analytics, or cross-site cookies anywhere.


5. Please do not send us patient identifiers

The Service is built for de-identified scientific information, and we ask you — in the product, in the Terms, and here — not to submit names, dates of birth, addresses, contact details, medical record numbers, photographs, or anything else that identifies a specific person.

One caution specific to rare disease, which we would rather state than let you discover. In a condition with a few hundred known patients worldwide, a specific variant combined with a couple of ordinary details — an age, a country, a clinical feature — can identify an individual even with no name attached. Please share the minimum necessary. This is not a formality; it is the realistic privacy risk in this field.

If you do send us information that identifies someone, tell us at focena@focena.ai and we will remove it. We do not want it, and nothing in the Service depends on having it.


6. How we use information

We use what we hold in order to:

  • provide the Service to you and to your organisation;
  • authenticate you and keep accounts secure;
  • detect, investigate, and prevent misuse, including misuse of licensed third-party research material;
  • diagnose faults and improve how the Service works; and
  • communicate with you about your account.

What we never do:

  • We do not sell personal, genetic, or health information, and we do not share it for cross-context behavioural advertising.
  • We do not use your information for advertising or profiling of any kind.
  • We do not use your information for any purpose connected with employment, insurance, or credit decisions.
  • We do not use content you submit to train a general-purpose AI model, and we do not permit our model providers to do so (see section 8).
  • We do not use one organisation's private content to serve another organisation (see section 9).

7. Genetic and health information

The Service is designed not to collect information about identifiable people. Nevertheless, some inputs — a gene, a variant notation, a clinical description in a document submitted for review — may constitute genetic or health information under laws such as the EU and UK GDPR (Article 9), the US Genetic Information Nondiscrimination Act, and state genetic-privacy and consumer-privacy statutes.

Where we hold such information, we use it only to provide the feature you asked for, within your organisation's isolated environment. We do not merge it into our shared research corpus, we do not sell or share it, and we do not use it for any discrimination-adjacent purpose. Where applicable law requires your explicit consent for us to process this category of information, we rely on the consent given when your organisation's users accept the Terms and the disclaimers at onboarding, and you may withdraw it at any time by contacting us (see section 11).


8. Who else processes data, and why

We keep this list deliberately short. Each provider processes data only to operate the Service, under contract, and none is permitted to use it for their own purposes.

  • Vercel — hosts and serves the website and application. Sees requests to the site, including IP address, in ordinary server logs.
  • Supabase — database, authentication, and file storage. Sees account data, authentication records, and the content described in section 4.
  • Cloudflare — DNS for focena.ai, and email routing for our contact address. Sees DNS queries, and the contents of email you send to focena@focena.ai.
  • Anthropic, OpenAI, and Google — large-language-model processing for analysis features. See only the specific content sent for a given request.

On the model providers, specifically. Where the Service sends content to a language model, we use configurations that do not train on inputs and that have zero or limited data retention, under terms that give the provider no right to retain, redistribute, or otherwise use the input or the output beyond returning the immediate response. This is a standing engineering rule for us rather than a preference, and a provider that does not meet it is not used. Consumer-tier or free-tier models that train on inputs are prohibited.

We may also disclose information where the law requires it, or where it is necessary to protect the rights or safety of a person. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.


9. Security and separation between organisations

  • Each organisation's data is held in an isolated tenant environment, enforced at the database by row-level security rather than by application logic alone. One organisation's private content is not available to another and is not merged into our shared research corpus.
  • Access to the Service is role-gated, and consumer-facing reads go through restricted, audited interfaces rather than direct database access.
  • The access log described in section 4 is append-only, so a record of access cannot be quietly removed.
  • We can suspend an individual account or an entire organisation immediately if we detect misuse.
  • Data is encrypted in transit, and at rest by our database and storage providers.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law.


10. How long we keep things

  • Account data is kept while your organisation's account is active.
  • Authentication and access records are kept for the life of the account, because their purpose is to make a historical pattern of misuse detectable. The access log is append-only by design.
  • Content you submit, and the work product derived from it, is kept while the account is active, or until you ask us to delete it.
  • Server logs held by our hosting provider expire on that provider's ordinary retention schedule.

When an account is closed, or when you ask us to delete your information, we delete or irreversibly de-identify it, except where we are required to keep it by law. Two honest limits: aggregated or de-identified statistics that can no longer be linked to you may remain, and where our own research conclusions have already been derived from a document you submitted, the conclusion may persist even after the document is deleted.


11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a portable copy, to object to or restrict certain processing, to withdraw consent, and to opt out of the sale or sharing of personal information — though as stated in section 6, we do not sell or share it in the first place.

To exercise any of these, email focena@focena.ai. We will acknowledge your request and respond within the time applicable law allows, and in practice much sooner. We may need to confirm your identity before acting on a request, and we will not treat you differently for making one.

If you are in the EU or UK and believe we have handled your data improperly, you may also complain to your national data protection authority. We would rather you told us first.


12. International transfers

We operate from the United States, and our providers process data in the United States. If you access the Service from outside the US, your information will be transferred there. Where we transfer personal data from the EU, the UK, or Switzerland, we do so using an appropriate legal transfer mechanism, including the European Commission's Standard Contractual Clauses where required.


13. Children

The Service is for people 18 or older acting in a professional or research capacity, and we do not knowingly create accounts for, or collect personal information from, children. Adults using the Service may discuss de-identified scientific information relating to children — that is the nature of paediatric rare disease — but a child is not a user, and identifiable information about a child should not be submitted (see section 5). If you believe a child has provided us with personal information, contact us and we will delete it.


14. Changes to this policy

If we change this policy we will update the effective date at the top, and for any change that materially affects your rights we will notify account holders directly rather than relying on you to notice. Earlier versions are retained in our version-control history and are available on request.


15. Contact

Focena, Inc.focena@focena.ai

Questions, requests, corrections, and complaints all go to the same address, and a person reads them.

Privacy Policy — Piper by Focena