QA environment · Draft study configuration. Changes here are not live until promoted to production.Go to production →

Privacy Notice

Version 1.0 · Effective 24 July 2026

This notice explains how Brainstorme Inc. ("Brainstorme", "we", "us") handles personal data in connection with the Brainstorme platform at https://portal-qa.brainstorme.com (the "Platform").

It is written for the people who use the Platform — readers, radiologists, site coordinators, monitors, sponsor staff and administrators. If you are a clinical trial participant looking for information about your own medical images, please read Section 9 — you should contact your trial site or study sponsor, not us.


1. The two roles we play

Your rights, and who you exercise them against, depend on which kind of data is involved. We handle two very different categories.

Platform account dataStudy and imaging data
What it isYour name, email, sign-in activity, product usageDICOM medical images, reader reports, trial results
Whose dataYours, as a Platform userClinical trial participants'
Our roleController — we decide how it is usedProcessor — we act only on the sponsor's documented instructions
Who to contactUs, at ryan@brainstorme.comThe study sponsor or your trial site

The rest of this notice is mostly about the first column. Section 9 covers the second.

2. Who we are and how to reach us

Brainstorme Inc. 745 Firth Ave, Los Angeles, CA 90049, United States

Privacy enquiries: ryan@brainstorme.com Data subject requests: https://grc.brainstorme.com/data-request

3. What we collect and why

3.1 Account and authentication data

What: your name, email address, the organisations, studies and sites you are assigned to, your role, sign-in timestamps, and — if you enrol one — a passkey credential identifier.

Why: to create your account, authenticate you, apply the right permissions, and keep the Platform secure.

Legal basis: performance of a contract (Art. 6(1)(b)) with your employer or sponsor, and our legitimate interests in securing the Platform (Art. 6(1)(f)).

Accounts are created by invitation from a sponsor or site administrator. We do not collect your date of birth, address, phone number, government identifiers, or payment details.

3.2 Product analytics and session recording

What: pages you visit, features you use, actions such as starting an upload or submitting a report, error events, and a session recording — a replay of your interactions with the Platform interface, including pages viewed, clicks and navigation.

By default this is linked to your account. Your usage events and session recordings are associated with your email address, so that we can support you and investigate problems you report. We discard your IP address. The identifier persists across visits so that a recording is not fragmented into disconnected pieces.

You can unlink it. Turning off "Link analytics to my account" (see Section 4) keeps analytics running against a random identifier instead, with no name or email — pseudonymous rather than identified. Turning analytics off entirely stops collection and clears the identifier from your device.

Why: to understand how the Platform is used, diagnose faults, and improve usability and reliability.

Legal basis: consent (Art. 6(1)(a)) where consent is required for the storage of identifiers on your device and for the associated analytics; otherwise our legitimate interests in operating and improving the Platform (Art. 6(1)(f)), against which you may object at any time using the controls in Section 4.

You can object to or switch off analytics and session recording at any time — see Section 4.

3.3 Access, security and audit logs

What: account identifiers, IP address, timestamps, and records of security-relevant and regulated actions (for example viewing an image, submitting or signing a report, exporting data).

Why: security monitoring, incident investigation, service reliability, and because regulated clinical research requires an attributable audit trail.

Legal basis: legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) in the security and integrity of a regulated system.

Audit records supporting the integrity of clinical research cannot be deleted on request — see Section 7.

3.4 Notifications and email

What: your name and email address, used to send transactional messages about Platform activity.

Why: to operate the service.

Legal basis: contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).

These are service messages, not marketing. We do not send marketing email and we do not sell, rent or share personal data for advertising.

3.5 AI-assisted features

Where the Platform offers AI assistance, the content you submit to it is sent to our AI provider under commercial terms that prohibit training on your data. It is processed transiently and not retained to build models.

4. Cookies, tracking and your choices

We store a small number of identifiers on your device. Some are strictly necessary to sign you in and cannot be switched off. Analytics and session recording are optional, and are linked to your account by default.

You can accept, decline or change your mind at any time:

  • via the banner shown when you first visit;
  • at any time afterwards under Your Data & Privacy on your profile page.

There are two separate controls:

  • Product analytics and session recording — turn this off to stop collection entirely and clear the analytics identifier from your device.
  • Link analytics to my account — on by default. Turn this off to keep analytics running pseudonymously, with no name or email attached.

Withdrawing is as easy as giving consent, and withdrawal does not affect processing carried out beforehand.

Full details of each cookie and identifier are in our Cookie Notice.

5. Who we share data with

We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and where legally compelled.

Our current sub-processors, what they do, and where they are located are published and kept current at https://grc.brainstorme.com/trust. They include our cloud infrastructure provider, authentication and database provider, application hosting provider, notification and email provider, analytics provider, and AI provider.

We may also disclose personal data where required by law, court order or a regulatory authority, and to professional advisers or an acquirer in connection with a corporate transaction.

6. International transfers

Brainstorme operates in the United States, and all of the providers listed at https://grc.brainstorme.com/trust process data in the United States.

If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with technical measures including encryption in transit and at rest and strict access controls. You may request a copy of the relevant safeguards at ryan@brainstorme.com.

7. How long we keep data

DataRetention
Account and profile dataFor the life of your account, then deleted within the window set in our retention policy
Analytics and session recordingsPer our analytics provider's retention configuration; recordings are retained for a limited period and then deleted
Transactional email logsPer the delivery provider's retention period
Security and access logsFor the period required by our Logging policy and applicable regulation
Regulated audit trails and electronic signaturesFor the record-retention period required by the applicable clinical research regulation and the sponsor's contract
Study and imaging dataControlled by the sponsor — see Section 9

Audit trails and electronic signature records are immutable by design. Regulated clinical research requires that they remain attributable and unaltered, so they survive account deletion. This is a legal obligation under Art. 17(3)(b) GDPR and an overriding legitimate ground under Art. 17(1)(c).

8. Your rights

Where we are the controller, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase data, subject to the audit-trail limits in Section 7;
  • restrict or object to processing based on legitimate interests, including analytics and session recording;
  • portability — receive certain data in a structured, machine-readable format;
  • withdraw consent at any time, without affecting prior processing;
  • lodge a complaint with your national supervisory authority. You may do so in the country where you live, work, or where the issue arose.

To exercise any of these, use https://grc.brainstorme.com/data-request or email ryan@brainstorme.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may need to verify your identity first.

Automated decision-making: we do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you for such purposes.

Providing your data: account data is necessary to give you access to the Platform — without it we cannot provide you an account. Analytics is optional and refusing it does not affect your access.

9. Clinical trial participants and imaging data

The medical images and study records on the Platform belong to clinical research studies run by sponsors. For that data:

  • the sponsor is the controller and decides why and how it is processed;
  • Brainstorme is a processor, acting only on the sponsor's documented instructions under a data processing agreement;
  • images are expected to be de-identified by the uploading site before upload, under the site's and sponsor's trial agreements. Identifying details should not be present. Where identifiers are nonetheless found embedded in an image file, we remove them;
  • participants are identified to us only by a study-assigned code, never by name.

If you are a trial participant and want to access, correct or delete your data, or withdraw from a study, please contact your trial site or study sponsor — they hold the key linking the study code to your identity and are responsible for responding. We cannot identify you from a study code alone. If you contact us anyway, we will refer your request to the relevant sponsor and tell you we have done so.

Sponsors seeking our data processing agreement, sub-processor list or security documentation should visit https://grc.brainstorme.com/trust.

10. Security

We protect personal data with encryption in transit (TLS) and at rest, role-based access control scoped to your assigned studies and sites, multi-factor and passkey authentication options, audit logging of security-relevant actions, signed time-limited URLs for image delivery, and a documented incident response and breach notification process.

No system is perfectly secure, but we maintain a formal security programme and publish its current state at https://grc.brainstorme.com/trust.

11. Children

The Platform is a professional tool and is not directed at children. We do not knowingly create accounts for anyone under 18. Note that a trial participant whose images are processed may be a minor — that processing is governed by the sponsor's consent and ethics approvals, not by this notice.

12. Changes to this notice

We will update this notice when our practices change. The version number and effective date at the top always reflect the current version.

If a change materially affects your rights or how we use your data, we will tell you — by email or an in-Platform notice — before it takes effect, and where the change relies on your consent we will ask you again.

13. Contact

Questions, concerns or requests: ryan@brainstorme.com

To submit a formal data subject request: https://grc.brainstorme.com/data-request

Privacy Notice · version 1.0 · effective 24 July 2026