Scope, definitions, and our role
This Privacy Policy applies to the Astra website, web application, account and subscription services, Research, Reason, Write, and Master features, QBank, referral program, support communications, and related services operated by Astraeus Intelligence LLC (collectively, “Astra” or the “Service”).
It does not govern a third-party website, scientific source, payment portal, browser service, or other service that has its own privacy notice. A link to another site does not mean Astra controls that site.
When Astra determines the purposes of processing
For an individual account that you create and control, Astra generally acts as the controller, “business,” or equivalent entity under applicable privacy law.
When an organization controls the account
If you use Astra through a hospital, clinic, university, employer, or other organization, that organization may control your account and the data submitted through it. Astra may act as its processor, service provider, or contractor. Contact the organization first for requests concerning organization-controlled data.
Contract priority
A signed Data Processing Addendum, order form, or other written agreement may impose additional or different requirements. If this Policy conflicts with such an agreement, that agreement controls to the extent of the conflict. Nothing in this Policy limits a right or obligation that cannot lawfully be limited.
We process sensitive or health-related information only as described here, as directed by an authorized organization, with consent where required, or as otherwise permitted by law.
Information we collect
The information collected depends on the features you use, whether you have an account, and whether an organization manages your access.
| Category | Examples | When collected |
|---|---|---|
| Account and identity | Name, email, authentication identifier, profile information, account status, organization affiliation, and account metadata. | When you register, sign in, join an organization, or update an account. |
| Clinical and user content | Questions, search terms, patient or case narratives, symptoms, histories, notes, differentials, plans, medications, laboratory or imaging information, feedback, and other text you submit. | When you use Research, Reason, Write, support, or other content features. |
| Files, images, and voice | Images, photographs, PDFs, document text, camera captures, audio handled by a browser speech service, and resulting transcripts. | When you choose to upload, capture, dictate, or submit them. |
| Generated content and inferences | Answers, citations, summaries, differentials, next steps, draft documentation, health-related inferences, generated questions, explanations, and tutoring responses. | When Astra processes submitted content. |
| Learning and QBank data | Selected USMLE Step exam, topics, systems, specialties, answers, scores, confidence, response time, session settings, and inferred strengths or weaknesses. | When you use Master or QBank features. |
| Subscription and transaction data | Plan, trial status, billing status, Stripe customer or subscription identifiers, transaction status, and limited payment metadata. Astra does not receive full card numbers. | When you begin a trial, purchase, renew, cancel, or manage a subscription. |
| Referral and payout data | Referral code, attribution, partner name and email, commission records, payout status, payout contact or method, and related audit history. | When you use, administer, or participate in the referral program. |
| Communications | Support requests, privacy requests, survey or feedback responses, email content, and records of our response. | When you communicate with us. |
| Technical and usage data | IP address, browser and device information, operating system, timestamps, page or feature interactions, request metadata, error and security events, usage counts, token counts, and an anonymous usage identifier. | Automatically when you access or use the Service. |
| Preferences and local state | Theme, interface state, cached usage state, session state, and other settings stored in cookies or browser storage. | When needed to remember settings, maintain a session, or enforce limits. |
We do not intentionally collect biometric templates, genetic test results, precise geolocation, government identification numbers, or full payment-card details through Astra’s ordinary product interfaces. Do not submit such information unless a specific feature and written agreement require it.
Where information comes from
- From you, including information you type, upload, dictate, photograph, or send to us.
- From your organization, such as account, role, entitlement, or administrative information.
- From your browser and device, including technical, permission, cookie, local-storage, and usage information.
- From payment and referral partners, including subscription, payment status, fraud, attribution, and payout information.
- From public and licensed sources, such as scientific literature, clinical guidelines, registries, and regulatory sources retrieved in response to a request.
- From our service providers, such as authentication events, delivery status, security signals, model output, search results, and operational logs.
- From inferences generated from information you provide, including a ranked differential, draft note, or learning-strength profile.
How and why we use information
- Provide the Service: authenticate users, process prompts and files, retrieve evidence, generate outputs, save conversations, and synchronize account state.
- Personalize learning: adapt QBank content to selected exams, prior responses, confidence, timing, strengths, and weaknesses.
- Operate subscriptions and referrals: administer trials, plans, billing, access, referral attribution, commissions, and manual payouts.
- Communicate: send transactional messages, respond to support or privacy requests, and provide service notices.
- Protect the Service: authenticate requests, enforce limits, prevent abuse and fraud, investigate incidents, debug failures, and maintain reliability.
- Meet legal obligations: comply with law, respond to valid legal process, preserve records, enforce agreements, and establish or defend legal claims.
- Complete a transaction or reorganization: conduct diligence or transfer assets in a financing, merger, acquisition, restructuring, or similar event, subject to applicable protections.
Astra does not use Customer Content for advertising, marketing, behavioral profiling, benchmarking, unrelated analytics, research, model training, human evaluation, or product improvement. Technical metadata may be used only as necessary to provide, secure, maintain, support, bill for, and legally administer the Service.
Legal bases outside the United States
Where a legal basis is required, we rely as appropriate on performance of a contract, steps requested before entering a contract, our legitimate interests in providing and protecting the Service, compliance with legal obligations, consent, and the lawful instructions of an organization acting as controller. For health or other specially protected data, we rely on an additional condition required by applicable law, such as explicit consent, healthcare-related processing, substantial public interest, or the organization’s lawful basis. An organization remains responsible for identifying its own legal basis and providing required notices.
No solely automated legal or similarly significant decisions
Astra generates clinical and educational content, but Astra does not use personal information to make solely automated decisions that produce legal or similarly significant effects about you. A qualified human remains responsible for clinical, academic, employment, and other consequential decisions.
AI, retrieval, files, and generated inferences
Astra uses artificial intelligence and retrieval services to process content and return the feature you request. Submitted content may be transformed into model instructions, embeddings, search terms, or structured data. Outputs may infer information about a person’s health even when the inference was not explicitly stated in the input.
Model processing
Astra uses OpenAI business/API services for model inference and related processing. Under the applicable business/API terms, API data is not used to train OpenAI’s general models by default. Astra configures supported inference requests not to create provider application state. Separate abuse-monitoring, safety, and legal retention depend on Astra’s account configuration, endpoint, and contract. We do not authorize a model provider to use identifiable clinical content to train a public foundation model.
Research and web retrieval
Research mode may derive search terms from a prompt and send those terms to Tavily to retrieve public web results. Astra may then retrieve or link to medical journals, societies, government agencies, registries, publishers, and other public sources. Search providers and destination sites receive and handle data under their own contracts and notices where they act independently.
Astra applies automated identifier-reduction rules before sending a Research query to a web-search provider. Users should avoid including names, contact information, record numbers, exact dates, addresses, or other unnecessary personal identifiers in a Research query.
Images and documents
When you submit an image, the image is transmitted for model analysis. Astra is designed not to write the raw image bytes into the saved chat record after analysis; however, the generated description, response, message text, and limited metadata may be saved, and processors may retain request data under the applicable configuration and contract. Documents and extracted text may be retained with the conversation or workspace when the feature indicates that content is saved.
Human access
Astra personnel do not routinely inspect stored Customer Content and do not review it for training, evaluation, product improvement, advertising, analytics, or research. Support is designed to use technical metadata or information you choose to provide rather than opening stored clinical content.
Exceptional access may occur only when you expressly request content-level support; when strictly necessary to investigate or contain a confirmed security incident that cannot reasonably be addressed with metadata; to comply with valid legal process; or to perform a specific contractual duty. Such access must be purpose-limited, least-privilege, subject to confidentiality obligations, and logged where supported. Service-provider access remains governed by the applicable contract, account controls, safety requirements, and law; Astra cannot promise that legally required or emergency access is impossible.
When and with whom we disclose information
We disclose information only for the purposes described below, at your direction, or as permitted by law. A provider may act as our processor for one activity and as an independent controller or business for another activity, such as fraud prevention or its own account administration.
Supabase
Authentication, managed Postgres database, storage, server-side functions, and operational infrastructure under Astra’s configured account and contractual controls.
OpenAI
Model inference, vision, embeddings, and generated responses under applicable business/API terms, contractual protections, and retention controls.
Tavily
Web search and retrieval for Research mode. It may receive minimized search terms derived from a prompt.
Stripe
Checkout, subscriptions, billing portal, payment processing, fraud prevention, and transaction records. Stripe receives payment and device data under its own privacy terms; Astra does not send clinical prompt content to Stripe.
Vercel
Website hosting and content delivery. Vercel may receive IP address, browser, request, and security data. Astra does not intentionally route clinical prompt bodies through the static hosting layer.
Resend
Transactional email delivery. Resend may receive recipient, sender, delivery, and message data. Do not send sensitive clinical content to Astra by ordinary email unless a secure process is provided.
Browser and device providers
When you use speech recognition, camera, or file-selection features, your browser, operating system, or configured speech provider may process audio, images, permissions, or transcripts under its own terms.
Google favicon service
The Sources List may request grayscale source icons through Google’s favicon service. Google may receive technical request data and the source domain requested, but not the clinical prompt itself.
Other permitted disclosures
- Your organization and its administrators, according to account controls and its policies.
- People you direct us to share with, including when you export, copy, send, or open content or a citation.
- Professional advisers and auditors under confidentiality obligations where reasonably necessary.
- Authorities or other parties when we reasonably believe disclosure is required by law, valid process, or necessary to protect rights, safety, security, or the integrity of the Service.
- A transaction counterparty in a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and applicable notice requirements.
- Any other recipient with your direction or consent.
No sale or targeted advertising
Astra does not sell personal information or consumer health data for money or other valuable consideration. Astra does not share personal information for cross-context behavioral advertising, and does not use clinical content to target advertisements. We do not knowingly sell or share the personal information of anyone under 18.
Cookies, browser storage, permissions, and links
Astra uses cookies and browser storage that are necessary to maintain authentication, remember preferences, cache limited interface or usage state, prevent abuse, and apply account or anonymous limits. For example, Astra may set an anonymous usage identifier that remains in the browser for up to 365 days unless you clear it earlier.
We do not currently use third-party advertising cookies or cross-site advertising trackers in the Astra application. Browser privacy controls may clear or block local state, but doing so can sign you out, reset preferences, or affect usage-limit functionality.
Microphone and speech recognition
Astra requests microphone access only when you choose a voice feature. Speech recognition may be provided by the browser, operating system, or a vendor selected by those products. Astra receives the resulting transcript when you submit it. The provider may separately process audio under its own notice.
Camera, images, and files
Camera and file permissions are requested only when you choose the relevant feature. Review images and documents for identifiers before submission. Revoking a permission in the browser prevents future access but does not delete content already submitted.
External citations and links
When you open a citation, payment portal, or external link, your browser contacts that site directly. The destination may receive your IP address, browser information, referrer information, and anything you choose to provide there.
How long we retain information
We retain personal information only for as long as reasonably necessary for the purpose collected, the instructions of an organization, an applicable contract, security and continuity needs, legal obligations, dispute resolution, and enforcement. Retention varies by record:
- Account and saved content: generally while the account or workspace is active and until deletion, subject to organization controls, backups, legal holds, and records we must preserve.
- QBank and personalization records: while needed to provide history and adaptive learning, or until deletion or account closure, subject to the same exceptions.
- Subscription, referral, commission, and payout records: for the periods required for accounting, tax, fraud prevention, contractual, and legal purposes.
- Security, rate-limit, and operational records: for a limited period proportionate to reliability, abuse prevention, incident investigation, and legal needs.
- Support and privacy records: while needed to resolve the request and document compliance.
- Backups: until overwritten or deleted through the ordinary protected backup cycle, unless preservation is legally required.
- Deidentified information: only while needed to provide, secure, maintain, support, bill for, or legally administer the Service.
Deletion removes or deidentifies information from active systems where reasonably feasible. We may retain a minimal record of a request, transaction, consent, opt-out, or legal restriction. If an organization controls the record, its instructions and legal retention duties may prevent Astra from deleting it on an individual user’s direct request.
Security and incident response
Astra uses administrative, technical, and organizational safeguards designed for the nature and sensitivity of the information processed. These include encrypted network transport, provider-managed encryption at rest where supported, authentication, access controls, environment separation, logging and monitoring, vendor review, secure-development practices, backups, and incident-response procedures.
Security is a shared responsibility. Users and organizations must protect credentials, enable available multi-factor authentication, use supported devices and secure networks, limit access, maintain accurate roles, and avoid copying sensitive content into unapproved systems. No internet transmission, storage system, or security control can guarantee absolute security.
We investigate suspected incidents and provide notices to affected organizations, individuals, regulators, or others when required by applicable law or contract. Notification timing and content depend on the law, our role, the facts, and the organization’s obligations.
Email outreach@astramd.org without including sensitive clinical content or confidential credentials in the email. We will provide a secure channel if needed.
Your privacy choices and rights
Depending on where you live and our role, you may have the right to confirm processing; access, correct, or delete information; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of sale, targeted advertising, or qualifying profiling; receive a list of certain third parties; and appeal a denied request. We do not discriminate for exercising a privacy right.
How to submit a request
Email outreach@astramd.org with “Privacy Request” in the subject line and describe the account, right, and jurisdiction involved. Do not include sensitive clinical content in ordinary email. We may ask for information reasonably necessary to verify identity, authority, account ownership, and the scope of the request.
An authorized agent may submit a request where permitted by law. We may require proof of authorization and may verify the request directly with the individual. If we deny a request in whole or part, you may appeal by replying with “Privacy Appeal” and explaining the basis for the appeal.
Limits and exceptions
Rights are not absolute. We may retain or decline to disclose information where permitted or required for security, fraud prevention, legal compliance, privileged material, the rights of others, transaction records, or other lawful reasons. We will explain the basis when required.
Organization-controlled accounts
For data controlled by a hospital, clinic, school, or employer, submit the request to that organization. Astra will assist it as required. Account administrators may be able to access, export, correct, retain, or delete information under the organization’s policies.
Communication choices
Astra uses account contact information for transactional, security, support, privacy, billing, and legal messages needed to administer the Service. Astra does not use Customer Content or consumer health data for marketing and does not send clinical content in ordinary email.
United States state privacy disclosures
The categories collected, sources, business purposes, and recipients are described in Sections 2, 3, 4, and 7. During the preceding twelve months, Astra may have collected and disclosed the categories listed there for operational purposes. Astra has not sold personal information or shared it for cross-context behavioral advertising.
California and similar comprehensive privacy laws
Where applicable, residents may exercise rights to know, access, correct, delete, port, limit certain uses of sensitive information, opt out of sale or sharing, opt out of qualifying profiling, and receive equal service. Because Astra does not sell or share personal information for targeted advertising, no sale/share opt-out is ordinarily necessary. We recognize browser-based opt-out preference signals, including Global Privacy Control, where legally required and technically applicable.
Consumer health data
Washington, Nevada, and other jurisdictions may provide specific rights concerning consumer health data. Astra’s separate notice describes the relevant health-data categories, sources, purposes, recipients, and applicable rights.
Read the separate, state-specific disclosure for consumer health information.
Deidentified information and operational metadata
Astra does not repurpose Customer Content for analytics, research, model training, human evaluation, or product improvement, even after attempting to aggregate or deidentify it. If information is transformed so it cannot reasonably be linked to an individual, Astra uses it only as necessary to provide, secure, maintain, support, bill for, or legally administer the Service. When Astra represents information as deidentified, Astra maintains it in deidentified form and does not attempt to reidentify it except as required to validate the deidentification process or comply with law.
Removing names alone may not adequately deidentify information. Unless Astra has expressly agreed to perform deidentification, the user or organization is responsible for deciding whether content is adequately deidentified before submitting it to an external retrieval workflow.
International processing and transfers
Astra is based in the United States, and information may be processed in the United States and other countries where our providers or their subprocessors operate. Those countries may have different data protection laws. Where required, we use an approved transfer mechanism, such as Standard Contractual Clauses, a recognized adequacy decision, or another lawful safeguard, and apply supplementary measures where appropriate.
Children and students
Astra is intended for adults and authorized medical, clinical, and professional education users. It is not directed to children under 13, and individual consumer accounts are not intended for anyone under 18 or the age of majority in their jurisdiction. We do not knowingly collect personal information directly from a child in violation of law.
A school or other institution that authorizes student use is responsible for required permissions, notices, age controls, and education-record obligations. If you believe a child provided information without appropriate authorization, contact us.
Changes to this Policy
We may update this Policy to reflect changes in the Service, law, contracts, or our practices. We will post the revised version with a new effective date. When required, we will provide additional notice or obtain consent before a material new use. We will not retroactively reduce protections for Customer Content in a manner inconsistent with an applicable contract or law.
Contact Astra
Questions, privacy requests, consumer health data requests, and appeals may be directed to:
254 Chapman Road, Suite 208 #22873
Newark, Delaware 19702, United States
Do not include sensitive clinical content, passwords, secret keys, or full payment-card information in ordinary email. We will provide a more secure method when necessary.