Astra Privacy

Astraeus Intelligence LLC

Privacy, without the fine-print fog.

This notice explains what Astra collects, why we need it, who may receive it, how long we keep it, and the choices available to you.

Effective August 13, 2026 Version 2.0 United States
01 No sale. No behavioral advertising.

We do not sell personal information or clinical content, and we do not use it for cross-context behavioral advertising.

02 Service only. No secondary use.

Prompts, notes, uploads, transcripts, generated inferences, and saved clinical work are used only to deliver, secure, maintain, and support the Service you request.

03 You can ask, access, correct, or delete.

Privacy requests and appeals can be sent to outreach@astramd.org.

Contents Scope and roles Information collected Sources of information How information is used AI and retrieval Disclosures Cookies and devices Retention Security Your rights State notices Deidentified data International transfers Children Changes Contact
01

Scope, definitions, and our role

This Privacy Policy applies to the Astra website, web application, account and subscription services, Research, Reason, Write, and Master features, QBank, referral program, support communications, and related services operated by Astraeus Intelligence LLC (collectively, “Astra” or the “Service”).

It does not govern a third-party website, scientific source, payment portal, browser service, or other service that has its own privacy notice. A link to another site does not mean Astra controls that site.

When Astra determines the purposes of processing

For an individual account that you create and control, Astra generally acts as the controller, “business,” or equivalent entity under applicable privacy law.

When an organization controls the account

If you use Astra through a hospital, clinic, university, employer, or other organization, that organization may control your account and the data submitted through it. Astra may act as its processor, service provider, or contractor. Contact the organization first for requests concerning organization-controlled data.

Contract priority

A signed Data Processing Addendum, order form, or other written agreement may impose additional or different requirements. If this Policy conflicts with such an agreement, that agreement controls to the extent of the conflict. Nothing in this Policy limits a right or obligation that cannot lawfully be limited.

This is a notice, not a blanket authorization.

We process sensitive or health-related information only as described here, as directed by an authorized organization, with consent where required, or as otherwise permitted by law.

02

Information we collect

The information collected depends on the features you use, whether you have an account, and whether an organization manages your access.

Category Examples When collected
Account and identity Name, email, authentication identifier, profile information, account status, organization affiliation, and account metadata. When you register, sign in, join an organization, or update an account.
Clinical and user content Questions, search terms, patient or case narratives, symptoms, histories, notes, differentials, plans, medications, laboratory or imaging information, feedback, and other text you submit. When you use Research, Reason, Write, support, or other content features.
Files, images, and voice Images, photographs, PDFs, document text, camera captures, audio handled by a browser speech service, and resulting transcripts. When you choose to upload, capture, dictate, or submit them.
Generated content and inferences Answers, citations, summaries, differentials, next steps, draft documentation, health-related inferences, generated questions, explanations, and tutoring responses. When Astra processes submitted content.
Learning and QBank data Selected USMLE Step exam, topics, systems, specialties, answers, scores, confidence, response time, session settings, and inferred strengths or weaknesses. When you use Master or QBank features.
Subscription and transaction data Plan, trial status, billing status, Stripe customer or subscription identifiers, transaction status, and limited payment metadata. Astra does not receive full card numbers. When you begin a trial, purchase, renew, cancel, or manage a subscription.
Referral and payout data Referral code, attribution, partner name and email, commission records, payout status, payout contact or method, and related audit history. When you use, administer, or participate in the referral program.
Communications Support requests, privacy requests, survey or feedback responses, email content, and records of our response. When you communicate with us.
Technical and usage data IP address, browser and device information, operating system, timestamps, page or feature interactions, request metadata, error and security events, usage counts, token counts, and an anonymous usage identifier. Automatically when you access or use the Service.
Preferences and local state Theme, interface state, cached usage state, session state, and other settings stored in cookies or browser storage. When needed to remember settings, maintain a session, or enforce limits.

We do not intentionally collect biometric templates, genetic test results, precise geolocation, government identification numbers, or full payment-card details through Astra’s ordinary product interfaces. Do not submit such information unless a specific feature and written agreement require it.

03

Where information comes from

  • From you, including information you type, upload, dictate, photograph, or send to us.
  • From your organization, such as account, role, entitlement, or administrative information.
  • From your browser and device, including technical, permission, cookie, local-storage, and usage information.
  • From payment and referral partners, including subscription, payment status, fraud, attribution, and payout information.
  • From public and licensed sources, such as scientific literature, clinical guidelines, registries, and regulatory sources retrieved in response to a request.
  • From our service providers, such as authentication events, delivery status, security signals, model output, search results, and operational logs.
  • From inferences generated from information you provide, including a ranked differential, draft note, or learning-strength profile.
04

How and why we use information

  • Provide the Service: authenticate users, process prompts and files, retrieve evidence, generate outputs, save conversations, and synchronize account state.
  • Personalize learning: adapt QBank content to selected exams, prior responses, confidence, timing, strengths, and weaknesses.
  • Operate subscriptions and referrals: administer trials, plans, billing, access, referral attribution, commissions, and manual payouts.
  • Communicate: send transactional messages, respond to support or privacy requests, and provide service notices.
  • Protect the Service: authenticate requests, enforce limits, prevent abuse and fraud, investigate incidents, debug failures, and maintain reliability.
  • Meet legal obligations: comply with law, respond to valid legal process, preserve records, enforce agreements, and establish or defend legal claims.
  • Complete a transaction or reorganization: conduct diligence or transfer assets in a financing, merger, acquisition, restructuring, or similar event, subject to applicable protections.
Customer Content is not a product-development asset.

Astra does not use Customer Content for advertising, marketing, behavioral profiling, benchmarking, unrelated analytics, research, model training, human evaluation, or product improvement. Technical metadata may be used only as necessary to provide, secure, maintain, support, bill for, and legally administer the Service.

Legal bases outside the United States

Where a legal basis is required, we rely as appropriate on performance of a contract, steps requested before entering a contract, our legitimate interests in providing and protecting the Service, compliance with legal obligations, consent, and the lawful instructions of an organization acting as controller. For health or other specially protected data, we rely on an additional condition required by applicable law, such as explicit consent, healthcare-related processing, substantial public interest, or the organization’s lawful basis. An organization remains responsible for identifying its own legal basis and providing required notices.

No solely automated legal or similarly significant decisions

Astra generates clinical and educational content, but Astra does not use personal information to make solely automated decisions that produce legal or similarly significant effects about you. A qualified human remains responsible for clinical, academic, employment, and other consequential decisions.

05

AI, retrieval, files, and generated inferences

Astra uses artificial intelligence and retrieval services to process content and return the feature you request. Submitted content may be transformed into model instructions, embeddings, search terms, or structured data. Outputs may infer information about a person’s health even when the inference was not explicitly stated in the input.

Model processing

Astra uses OpenAI business/API services for model inference and related processing. Under the applicable business/API terms, API data is not used to train OpenAI’s general models by default. Astra configures supported inference requests not to create provider application state. Separate abuse-monitoring, safety, and legal retention depend on Astra’s account configuration, endpoint, and contract. We do not authorize a model provider to use identifiable clinical content to train a public foundation model.

Research and web retrieval

Research mode may derive search terms from a prompt and send those terms to Tavily to retrieve public web results. Astra may then retrieve or link to medical journals, societies, government agencies, registries, publishers, and other public sources. Search providers and destination sites receive and handle data under their own contracts and notices where they act independently.

Astra applies automated identifier-reduction rules before sending a Research query to a web-search provider. Users should avoid including names, contact information, record numbers, exact dates, addresses, or other unnecessary personal identifiers in a Research query.

Images and documents

When you submit an image, the image is transmitted for model analysis. Astra is designed not to write the raw image bytes into the saved chat record after analysis; however, the generated description, response, message text, and limited metadata may be saved, and processors may retain request data under the applicable configuration and contract. Documents and extracted text may be retained with the conversation or workspace when the feature indicates that content is saved.

Human access

Astra personnel do not routinely inspect stored Customer Content and do not review it for training, evaluation, product improvement, advertising, analytics, or research. Support is designed to use technical metadata or information you choose to provide rather than opening stored clinical content.

Exceptional access may occur only when you expressly request content-level support; when strictly necessary to investigate or contain a confirmed security incident that cannot reasonably be addressed with metadata; to comply with valid legal process; or to perform a specific contractual duty. Such access must be purpose-limited, least-privilege, subject to confidentiality obligations, and logged where supported. Service-provider access remains governed by the applicable contract, account controls, safety requirements, and law; Astra cannot promise that legally required or emergency access is impossible.

06

When and with whom we disclose information

We disclose information only for the purposes described below, at your direction, or as permitted by law. A provider may act as our processor for one activity and as an independent controller or business for another activity, such as fraud prevention or its own account administration.

Supabase

Authentication, managed Postgres database, storage, server-side functions, and operational infrastructure under Astra’s configured account and contractual controls.

OpenAI

Model inference, vision, embeddings, and generated responses under applicable business/API terms, contractual protections, and retention controls.

Tavily

Web search and retrieval for Research mode. It may receive minimized search terms derived from a prompt.

Stripe

Checkout, subscriptions, billing portal, payment processing, fraud prevention, and transaction records. Stripe receives payment and device data under its own privacy terms; Astra does not send clinical prompt content to Stripe.

Vercel

Website hosting and content delivery. Vercel may receive IP address, browser, request, and security data. Astra does not intentionally route clinical prompt bodies through the static hosting layer.

Resend

Transactional email delivery. Resend may receive recipient, sender, delivery, and message data. Do not send sensitive clinical content to Astra by ordinary email unless a secure process is provided.

Browser and device providers

When you use speech recognition, camera, or file-selection features, your browser, operating system, or configured speech provider may process audio, images, permissions, or transcripts under its own terms.

Google favicon service

The Sources List may request grayscale source icons through Google’s favicon service. Google may receive technical request data and the source domain requested, but not the clinical prompt itself.

Other permitted disclosures

  • Your organization and its administrators, according to account controls and its policies.
  • People you direct us to share with, including when you export, copy, send, or open content or a citation.
  • Professional advisers and auditors under confidentiality obligations where reasonably necessary.
  • Authorities or other parties when we reasonably believe disclosure is required by law, valid process, or necessary to protect rights, safety, security, or the integrity of the Service.
  • A transaction counterparty in a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and applicable notice requirements.
  • Any other recipient with your direction or consent.

No sale or targeted advertising

Astra does not sell personal information or consumer health data for money or other valuable consideration. Astra does not share personal information for cross-context behavioral advertising, and does not use clinical content to target advertisements. We do not knowingly sell or share the personal information of anyone under 18.

07

Cookies, browser storage, permissions, and links

Astra uses cookies and browser storage that are necessary to maintain authentication, remember preferences, cache limited interface or usage state, prevent abuse, and apply account or anonymous limits. For example, Astra may set an anonymous usage identifier that remains in the browser for up to 365 days unless you clear it earlier.

We do not currently use third-party advertising cookies or cross-site advertising trackers in the Astra application. Browser privacy controls may clear or block local state, but doing so can sign you out, reset preferences, or affect usage-limit functionality.

Microphone and speech recognition

Astra requests microphone access only when you choose a voice feature. Speech recognition may be provided by the browser, operating system, or a vendor selected by those products. Astra receives the resulting transcript when you submit it. The provider may separately process audio under its own notice.

Camera, images, and files

Camera and file permissions are requested only when you choose the relevant feature. Review images and documents for identifiers before submission. Revoking a permission in the browser prevents future access but does not delete content already submitted.

External citations and links

When you open a citation, payment portal, or external link, your browser contacts that site directly. The destination may receive your IP address, browser information, referrer information, and anything you choose to provide there.

08

How long we retain information

We retain personal information only for as long as reasonably necessary for the purpose collected, the instructions of an organization, an applicable contract, security and continuity needs, legal obligations, dispute resolution, and enforcement. Retention varies by record:

  • Account and saved content: generally while the account or workspace is active and until deletion, subject to organization controls, backups, legal holds, and records we must preserve.
  • QBank and personalization records: while needed to provide history and adaptive learning, or until deletion or account closure, subject to the same exceptions.
  • Subscription, referral, commission, and payout records: for the periods required for accounting, tax, fraud prevention, contractual, and legal purposes.
  • Security, rate-limit, and operational records: for a limited period proportionate to reliability, abuse prevention, incident investigation, and legal needs.
  • Support and privacy records: while needed to resolve the request and document compliance.
  • Backups: until overwritten or deleted through the ordinary protected backup cycle, unless preservation is legally required.
  • Deidentified information: only while needed to provide, secure, maintain, support, bill for, or legally administer the Service.

Deletion removes or deidentifies information from active systems where reasonably feasible. We may retain a minimal record of a request, transaction, consent, opt-out, or legal restriction. If an organization controls the record, its instructions and legal retention duties may prevent Astra from deleting it on an individual user’s direct request.

09

Security and incident response

Astra uses administrative, technical, and organizational safeguards designed for the nature and sensitivity of the information processed. These include encrypted network transport, provider-managed encryption at rest where supported, authentication, access controls, environment separation, logging and monitoring, vendor review, secure-development practices, backups, and incident-response procedures.

Security is a shared responsibility. Users and organizations must protect credentials, enable available multi-factor authentication, use supported devices and secure networks, limit access, maintain accurate roles, and avoid copying sensitive content into unapproved systems. No internet transmission, storage system, or security control can guarantee absolute security.

We investigate suspected incidents and provide notices to affected organizations, individuals, regulators, or others when required by applicable law or contract. Notification timing and content depend on the law, our role, the facts, and the organization’s obligations.

Report a suspected privacy or security issue promptly.

Email outreach@astramd.org without including sensitive clinical content or confidential credentials in the email. We will provide a secure channel if needed.

10

Your privacy choices and rights

Depending on where you live and our role, you may have the right to confirm processing; access, correct, or delete information; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of sale, targeted advertising, or qualifying profiling; receive a list of certain third parties; and appeal a denied request. We do not discriminate for exercising a privacy right.

How to submit a request

Email outreach@astramd.org with “Privacy Request” in the subject line and describe the account, right, and jurisdiction involved. Do not include sensitive clinical content in ordinary email. We may ask for information reasonably necessary to verify identity, authority, account ownership, and the scope of the request.

An authorized agent may submit a request where permitted by law. We may require proof of authorization and may verify the request directly with the individual. If we deny a request in whole or part, you may appeal by replying with “Privacy Appeal” and explaining the basis for the appeal.

Limits and exceptions

Rights are not absolute. We may retain or decline to disclose information where permitted or required for security, fraud prevention, legal compliance, privileged material, the rights of others, transaction records, or other lawful reasons. We will explain the basis when required.

Organization-controlled accounts

For data controlled by a hospital, clinic, school, or employer, submit the request to that organization. Astra will assist it as required. Account administrators may be able to access, export, correct, retain, or delete information under the organization’s policies.

Communication choices

Astra uses account contact information for transactional, security, support, privacy, billing, and legal messages needed to administer the Service. Astra does not use Customer Content or consumer health data for marketing and does not send clinical content in ordinary email.

11

United States state privacy disclosures

The categories collected, sources, business purposes, and recipients are described in Sections 2, 3, 4, and 7. During the preceding twelve months, Astra may have collected and disclosed the categories listed there for operational purposes. Astra has not sold personal information or shared it for cross-context behavioral advertising.

California and similar comprehensive privacy laws

Where applicable, residents may exercise rights to know, access, correct, delete, port, limit certain uses of sensitive information, opt out of sale or sharing, opt out of qualifying profiling, and receive equal service. Because Astra does not sell or share personal information for targeted advertising, no sale/share opt-out is ordinarily necessary. We recognize browser-based opt-out preference signals, including Global Privacy Control, where legally required and technically applicable.

Consumer health data

Washington, Nevada, and other jurisdictions may provide specific rights concerning consumer health data. Astra’s separate notice describes the relevant health-data categories, sources, purposes, recipients, and applicable rights.

Consumer Health Data Privacy Notice

Read the separate, state-specific disclosure for consumer health information.

Read the notice
12

Deidentified information and operational metadata

Astra does not repurpose Customer Content for analytics, research, model training, human evaluation, or product improvement, even after attempting to aggregate or deidentify it. If information is transformed so it cannot reasonably be linked to an individual, Astra uses it only as necessary to provide, secure, maintain, support, bill for, or legally administer the Service. When Astra represents information as deidentified, Astra maintains it in deidentified form and does not attempt to reidentify it except as required to validate the deidentification process or comply with law.

Removing names alone may not adequately deidentify information. Unless Astra has expressly agreed to perform deidentification, the user or organization is responsible for deciding whether content is adequately deidentified before submitting it to an external retrieval workflow.

13

International processing and transfers

Astra is based in the United States, and information may be processed in the United States and other countries where our providers or their subprocessors operate. Those countries may have different data protection laws. Where required, we use an approved transfer mechanism, such as Standard Contractual Clauses, a recognized adequacy decision, or another lawful safeguard, and apply supplementary measures where appropriate.

14

Children and students

Astra is intended for adults and authorized medical, clinical, and professional education users. It is not directed to children under 13, and individual consumer accounts are not intended for anyone under 18 or the age of majority in their jurisdiction. We do not knowingly collect personal information directly from a child in violation of law.

A school or other institution that authorizes student use is responsible for required permissions, notices, age controls, and education-record obligations. If you believe a child provided information without appropriate authorization, contact us.

15

Changes to this Policy

We may update this Policy to reflect changes in the Service, law, contracts, or our practices. We will post the revised version with a new effective date. When required, we will provide additional notice or obtain consent before a material new use. We will not retroactively reduce protections for Customer Content in a manner inconsistent with an applicable contract or law.

16

Contact Astra

Questions, privacy requests, consumer health data requests, and appeals may be directed to:

Astraeus Intelligence LLC

254 Chapman Road, Suite 208 #22873
Newark, Delaware 19702, United States

outreach@astramd.org Terms of Use Consumer Health Data Notice

Do not include sensitive clinical content, passwords, secret keys, or full payment-card information in ordinary email. We will provide a more secure method when necessary.

© 2026 Astraeus Intelligence LLC

Astra Terms of Use Consumer Health Data Contact