Jump to a section
01Who we are and what this covers
SciVue (operated by PrecisionRx) is a scientific illustrations and life sciences analytics platform. This policy explains what personal data we process when you use scivue.live and the SciVue application, and it applies to visitors, registered researchers, and members of institutional teams.
We act as controller for account, billing, and telemetry data, and as processor for research content you upload on behalf of your institution.
02What we collect, why, and for how long
| Category | What it includes | Legal basis | Retention |
|---|---|---|---|
| Account data | Email, name, faculty, country, optional ORCID and affiliation | Contract — to create and run your account | Life of account + 30 days |
| Figures & projects | Prompts, canvases, uploaded data files, exports, version history | Contract — to store and render your work | Until you delete them |
| Usage & token logs | Tool used, tokens consumed, timestamps, job status | Contract & legitimate interest — metering and abuse prevention | 24 months |
| Billing metadata | Plan, payment reference, amount, invoice records | Contract & legal obligation | 7 years (tax law) |
| Technical logs | IP address, browser, error traces, request latency | Legitimate interest — security and reliability | 90 days |
| Support messages | Anything you send us by form, email, or WhatsApp | Legitimate interest — to answer you | 24 months |
03Your research content
- Figures, datasets, and prompts are stored under your account and are private by default — visible only to you and collaborators you invite.
- Content is encrypted in transit (TLS) and at rest, with row-level access controls that scope every read to the owning account.
- We do not train models on your content. Model training only ever uses assets we create ourselves or content you explicitly opt in per figure.
- Publishing to the gallery or marketplace is always an explicit action; nothing becomes public automatically.
- Do not upload directly identifying patient data. Pseudonymise or anonymise clinical datasets before import.
04AI and compute processing
AI tools send the minimum necessary input — your prompt and any referenced figure content — to our compute backend or, if that backend is unavailable, to a fallback model provider. Providers process the request to return a result and are contractually barred from using it for their own model training.
- We log the module name, token cost, duration, and success or failure of each call — not the scientific content of your prompt.
- Analysis modules (omics, statistics, sequence tools) run on our managed cloud compute and return results to your account only.
- You can see per-tool token usage in your dashboard at any time.
05Sub-processors and sharing
We never sell personal data and never share it for advertising. We use a short list of vetted providers:
- Managed cloud infrastructure — database, authentication, file storage, and compute.
- Managed AI providers — for illustration, legend, review, and analytics tools.
- Payment processors — subscription and token top-up handling. We receive a payment reference and amount; we never see full card numbers.
- Email and messaging providers — transactional notifications and support conversations.
We also disclose data where legally required, or to protect the rights and safety of users. An up-to-date sub-processor list is available on request from privacy@scivue.live.
06Where data lives and international transfers
You can pin storage to a specific region. Cross-border transfers rely on Standard Contractual Clauses plus supplementary technical measures. See Data Residency for the current region list and what stays in-region.
08Your rights and how to use them
You can access, export, correct, delete, restrict, or object to processing of your personal data, and withdraw consent where processing relies on it. Most of this is self-service in the Privacy Center; the GDPR page explains each right in detail.
Deleting your account cascades to your figures, jobs, projects, profile, and subscription records within 30 days, with backups cycling out within 90 days. Anonymised usage counters and legally required invoice records are retained.
09Security and breach response
- TLS 1.2+ everywhere, encryption at rest, strict access controls on every user table, and least-privilege service credentials.
- Automated dependency and security scanning, with validation on every privileged action.
- Optional multi-factor authentication and scoped, revocable access keys.
- Suspected vulnerabilities: security@scivue.live. We confirm receipt within 72 hours and notify affected users and regulators within 72 hours of confirming a qualifying breach.
10Children and changes to this policy
The platform is not directed at children under 16. If we learn that a child created an account, we delete it.
We update this policy as the platform evolves. Material changes are announced in-app and by email at least 14 days before they take effect, and the effective date at the top always reflects the current version.
11Contacting us
Privacy and data-protection requests: privacy@scivue.live. Security reports: security@scivue.live. General enquiries: the contact page.
If you are in the EEA or UK and believe we have mishandled your data, you may also complain to your local supervisory authority.
Questions about this document?
Our team replies to legal and privacy requests within 5 business days.