Privacy Policy

Our privacy policy and how we use your data

Last updated: 27 July 2026

This policy explains what BlixtAI collects when you use https://www.blixtai.com, why we collect it, and what we do with it. It covers both the website and the application behind it.

Who we are

BlixtAI provides software that turns laboratory test results into written test reports. Our customers are laboratories and healthcare providers. If you are a patient and want to know how your results are handled, contact the laboratory that ordered your test — they, not we, decide what is done with your record.

What we collect

Account information. Your email address, your name, the logo you upload, and the details needed to sign you in. If you enable multi-factor authentication we store the factor, not your codes.

Order and result data. Everything you enter or upload about a laboratory order: the order identifier, the patient identifiers and demographics you choose to include, the test panel, the detected pathogens and resistance markers, and any source document you attach. This may contain health information about identifiable people.

Billing information. Which plan you are on and how many reports you have generated. Card details are handled by our payment processor and do not reach our servers.

Technical information. Sign-in events with the IP address and browser they came from, which we keep as a security audit trail, and ordinary server logs.

How we use it

  • To generate the reports you ask us to generate.
  • To operate your account, sign you in, and keep it secure.
  • To bill you and to show you your own usage.
  • To provide support when you ask for it.
  • To detect and investigate abuse and security incidents.
  • To comply with our legal obligations.

We do not sell your data, we do not share it with advertisers, and we do not use your order or result data to train our own models.

Who we share it with

We rely on a small number of service providers, each handling data only to provide their part of the service:

  • Hosting and infrastructure — to run the website and the application.
  • Database, authentication and file storage — where your account, orders and documents are held.
  • Report generation — the order details needed to produce a report are sent to a large language model provider.
  • Payments — our payment processor, which handles card details directly.
  • Email delivery — for sign-in, confirmation and notification messages.
  • Bot protection — to keep automated abuse off our sign-up and contact forms.

We may also disclose information where we are legally required to, or where it is necessary to protect our rights or someone’s safety. If our business is transferred, your data may transfer with it, and this policy continues to apply until you are told otherwise.

Where your data is held

Our infrastructure and our providers may process data in countries other than your own, including the United States. Where data leaves its country of origin we rely on the safeguards offered by those providers.

How long we keep it

Orders, reports and their attachments are kept for as long as your account is active, because they are your working records. Billing records are kept for as long as tax and accounting rules require. Security audit records are kept for a limited period and then removed. When you close your account we delete or anonymise your data, except where we are required to keep it.

How we protect it

Data is encrypted in transit. Each account’s data is isolated from every other account, and that isolation is enforced by the database itself rather than only by the application, so one customer cannot reach another’s records. Access by our own staff is limited to those who need it and is recorded.

Your choices

You can view and change your account details, replace or remove your logo, and delete your orders at any time from within the application. Depending on where you live you may also have the right to request a copy of your data, to ask us to correct or delete it, to object to certain processing, or to complain to your data protection authority. Write to us and we will help.

Where you upload health information about other people, you are responsible for having the authority to do so, and we handle it on your instructions.

Children

The service is intended for healthcare professionals and is not directed at children. We do not knowingly collect information from children as users of the service.

Changes

If we change this policy we will update the date at the top of this page, and we will tell you directly if the change is significant.

Contact us

Questions about this policy, or about your data, can be sent to us through our contact page.