backed by Combinator

Privacy Policy

Last updated: September 1, 2026

Introduction

This policy is provided by Strand AI Bio Corp., a Delaware corporation doing business as Strand AI ("Strand AI," "we," "our," or "us"). For account, website, security, and billing information, we act as an independent controller. For personal information contained in data an organization uploads for processing (Service Data), we act as a processor or service provider on that organization's behalf and process it only to provide the services and as instructed under our agreement with that organization. This policy explains what information we collect, how we use and store it, who we share it with, how long we retain it, and how to contact us, whether you visit our website, use the Strand AI Platform, or authorize a connected application such as an AI assistant.

Information We Collect

Depending on how you use Strand AI, we may collect:

  • Contact and account information: Your name, email address, login identity, organization membership, and communications with us.
  • Service data: Biological images and related metadata you choose to upload, processing instructions, job status, generated results, and support communications.
  • Authorization and security data: Connected applications, authorization grants, scopes, device and browser information, IP address, and security and audit events.
  • Commercial records: Credit reservations, consumption, refunds, and records needed to operate and account for the service.
  • Website usage data: Pages visited, time spent, referring URLs, and interactions with website elements.

We collect this information directly from you; from your organization and connected applications you authorize; and automatically from your browser, device, and use of the Services.

Connected Applications and AI Assistants

Strand AI uses OAuth authorization so a connected application acts as your existing Strand AI identity, within an organization you explicitly select. The consent screen shows the access requested, including whether the application may create jobs that spend that organization's credits. You can revoke a connection from your Strand AI account settings. Revoking a connection stops future access; it does not retrieve or delete information the application has already received, which remains governed by that application's own terms and privacy policy.

For remote uploads, Strand AI creates an expiring, single-use browser handoff. Slide bytes are uploaded directly to Strand AI storage rather than passing through the AI assistant. Result download links are short-lived. A connected application may receive information returned by tools you invoke; its handling of that information is governed by its own terms and privacy policy.

Health Information

Upload only data that is already de-identified and that you are authorized to process. Do not upload protected health information or other regulated identifiable health information. Automated slide de-identification is off by default. When enabled for an organization, it is an optional defense-in-depth safeguard and does not replace this requirement.

How We Use Information

  • Provide, secure, support, and improve our website and services
  • Authenticate users and connected applications
  • Process requested analyses and deliver generated results
  • Respond to inquiries and send requested service communications
  • Investigate abuse and maintain security and audit records
  • Account for credit reservations and consumption
  • Analyze website usage and comply with legal obligations

Cookies and Analytics

We use cookies and similar technologies to operate our services and understand how they are used. PostHog provides product analytics, error and performance diagnostics, feature evaluation, and session replay. Cloudflare provides content delivery, network security, and performance telemetry. On our public website these load automatically and we do not display a cookie banner; in the Strand AI Platform, session replay additionally masks password and other credential fields, excludes credential-bearing elements and authorization-consent routes, and omits console output. See our Cookie Notice for the technologies, purposes, typical durations, and browser controls, and see PostHog's Privacy Policy.

AI Model Training

We do not use customer Service Data or generated results to train or fine-tune our models, create training datasets, or otherwise improve model parameters unless a separate written agreement expressly authorizes that use. We may use service telemetry that does not include uploaded content or generated results, such as job timings, error rates, and usage metrics, to operate, secure, and improve the services. If this policy changes, we will provide notice and obtain any consent required by law or contract.

Data Sharing and Service Providers

We do not sell personal information. We may disclose information to the service providers below so they can perform the listed functions for us; when required by law; to address fraud or security threats; or in connection with a corporate transaction. Connected applications receive data only when an authorized user invokes the corresponding capability.

The providers we use depend on the features involved:

Service providerPurpose
Google Cloud PlatformCloud hosting, storage, and databases
Amazon Web ServicesHosting and delivery of public 1000 Genomes explorer data
ModalGPU compute for model inference
CloudflareDNS, content delivery, network security, and performance telemetry
PostHogProduct analytics, diagnostics, feature evaluation, and session replay
Google WorkspaceBusiness email and support communications
Google FontsWebsite font delivery
SlackPartner inquiries and operational communications
NotionCustomer-relationship management for inquiries
ResendTransactional and service email

We will update this list when the service providers we use change.

Data Retention

We retain information for the following periods:

  • Service Data (uploaded slides and generated results): Retained under your organization's control. Samples do not expire unless your organization sets an expiration policy or deletes them. Expired or deleted samples are held in Trash for 7 days (during which they can be restored), then permanently deleted, including stored files and database records. Deletions are audit-logged. See our data handling documentation for details.
  • Optional automated de-identification: This safeguard is off by default. When enabled for an organization, uploads are processed in an isolated quarantine environment and originals are deleted after validation or by the quarantine lifecycle within 24 hours.
  • Account and contact information: Retained for the life of your account and deleted within 30 days of a verified deletion request or account closure.
  • Security and audit records: Infrastructure and security logs are retained for up to 400 days. Application-level audit records (for example, records of administrative actions and deletions) are retained for the life of the service.
  • Commercial records: Credit and billing records are retained for the life of your organization's account and as required by tax, accounting, and other legal obligations.
  • Analytics data: Usage analytics are retained by PostHog for up to 7 years.

Upload handoffs and signed download links expire automatically. Authorized organization users may delete eligible data in the Platform at any time or request assistance by email.

International Data Transfers

We are a United States company. The information described in this policy may be processed in the United States and other countries where our service providers operate, which may have data-protection laws different from those of your jurisdiction. Where applicable law requires a transfer mechanism, we will put that mechanism in place before making the covered transfer.

Data Security

We use technical and organizational measures designed to protect data, including encrypted transport, organization-scoped access controls, short-lived connected- application access tokens, revocation, and security logging. No system is perfectly secure; report a suspected security issue promptly.

Your Rights

You have the right to:

  • Access the personal information we hold about you and receive a copy in a portable format;
  • Correct inaccurate personal information;
  • Delete your personal information, subject to the retention periods described above;
  • Revoke a connected application's access at any time from your Strand AI account settings.

To exercise these rights, email [email protected]. We may need to verify your identity and will respond as required by applicable law. We will not discriminate against you for exercising any of these rights. Organization administrators may separately control organization data and retention under their Strand AI agreement.

If you are in the European Economic Area or the United Kingdom, you also have the rights provided by the GDPR, including the rights to object to or restrict processing, withdraw consent where applicable, and lodge a complaint with your local supervisory authority. California residents have the rights provided by the CCPA; we do not sell personal information or share it for cross-context behavioral advertising.

Children

The Services are for business and professional use and are not directed to anyone under 18. If you believe a minor provided personal information, contact us so we can evaluate and respond as required by law.

Changes to This Policy

We may update this policy and will post the revised policy with a new last-updated date. We will provide additional notice when required by law.

Contact Us

Strand AI Bio Corp. is a Delaware corporation. Contact [email protected] for security reports or [email protected] for privacy questions and requests, including data access, correction, and deletion requests.