Privacy Policy
1. Controller
The controller within the meaning of the GDPR is the operator, see the Legal Notice.
2. What data we store
- Account: email, password (bcrypt hash), optional display name and institution.
- Your own domains / constructs: the CAR-T sequences and metadata you create.
- API keys: if you provide your own Anthropic/OpenAI key, it is stored encrypted (Fernet) in the DB.
- Usage data: number of AI full analyses per month (for quota management).
3. Processing by third parties
For full analyses, amino-acid / DNA sequences are transmitted to the following services:
- NCBI (Bethesda, USA) — BLAST + PubMed search
- Anthropic / OpenAI / Google (depending on provider choice) — AI evaluation
- Europe PMC / Semantic Scholar — literature search
- EPO / The Lens (optional) — patent search
Important: Sequences you analyze are sent over the internet to these third parties. Do not submit confidential, patent-protected or unpublished constructs without appropriate agreements.
4. Storage location + hosting
Server hosting with Hetzner Online GmbH, data center in Germany. Database backups remain within the EU.
5. Cookies
We set a single technically necessary cookie (cartcheck_token) for the login session. No tracking, no analytics, no advertising.
6. Your rights
Under the GDPR you have the right to information, correction, deletion, restriction and data portability. Please write to admin@car-t-check.com.
7. Delete account
Upon request to admin@car-t-check.com, your account will be irreversibly deleted including all domains, groups and stored API keys.
⚠️ This text is a stub. Before go-live it must be reviewed legally (GDPR + Swiss FADP + any medical-device notices).