Privacy Policy
Last updated: July 2026
1. Controller and Contact
MedCite is operated by Nordjysk Speciallægeklinik ApS, a Danish limited liability company (CVR 44231637). Registered address: Sct. Catharinavej 3, 9900 Frederikshavn, Denmark. We are the data controller for personal data processed through the MedCite service.
Email: privacy@medcite.eu
2. Overview
MedCite is a medical evidence search, synthesis and reference service. No account is required during public beta. We apply privacy-by-design measures, including query redaction, memory-only analytics, short answer-cache lifetimes, and anonymous session identifiers. This Privacy Policy explains what personal data we process, why we process it, and your rights.
3. Purposes and Legal Bases
We process personal data only where we have a valid legal basis under the GDPR. The table below sets out the main purposes and the basis for each.
Providing answers to your clinical questions Contract (Article 6(1)(b)) - processing necessary to deliver the service you request Yes |
Maintaining service security, availability and abuse prevention Legitimate interests (Article 6(1)(f)) - keeping the service safe and available Yes |
Product analytics and service improvement Legitimate interests (Article 6(1)(f)), with privacy-first configuration and no clinical content captured No - you can object by contacting privacy@medcite.eu |
Storing feedback and published articles you choose to submit Legitimate interests (Article 6(1)(f)) for service improvement, and your consent for public publishing No - voluntary |
4. Data Categories
We collect the following categories of personal data. We do not currently collect account data; user accounts are not active in the public beta.
- Query text - the clinical question you enter. The original query is received by our server and is redacted before evidence retrieval and synthesis.
- Redacted query - the query after automated redaction of obvious identifiers. This is used for retrieval and synthesis.
- Technical data - anonymised IP address, browser type, device type, access timestamps, and a secure anonymous session identifier (sid cookie).
- Feedback data - ratings and citation-quality feedback submitted voluntarily. We store the anonymised query text, answer identifier, rating, mode and session identifier.
- Published articles - when you choose to publish a Review answer, we store the article content, references, query text, sharing session identifier, engagement counters and timestamps.
- Analytics data - anonymised event data about feature usage, selected modes and language preferences. Clinical query text, answer text, abstracts, source URLs and arbitrary payloads are excluded by our analytics allowlist.
5. Redaction and Patient Identifiers
Do not enter identifiable patient information. MedCite applies automated redaction to obvious identifiers - such as names, email addresses, phone numbers, national identifiers, addresses, dates of birth and similar identifiers - before evidence retrieval and synthesis. However, automated redaction is pattern-based and may be incomplete. It is not a substitute for de-identification by you. We keep the original request only for the short time needed to process it; the redacted version is what flows through retrieval and synthesis.
If you believe identifiable patient information has been submitted, contact us immediately so we can assist with deletion.
6. Data Retention
We retain data for as long as necessary for the purposes described. Retention periods are summarised below. We are reviewing and implementing automatic deletion rules for persistent feedback and published-article records; until those rules are in place, we retain those records until you request deletion.
Generated answers and associated evidence 24 hours Stored in Redis with a 24-hour TTL. |
Technical logs Up to 30 days Anonymised server and access logs. |
Anonymous session identifier (sid cookie) 1 year Used to associate feedback and published articles with a session. |
Answer feedback and citation feedback Until deletion requested Stored in PostgreSQL. Automatic deletion rules are being implemented. |
Published Review articles Until deletion requested Stored publicly at a canonical URL. Automatic deletion rules are being implemented. |
GDPR request tokens 48 hours Valid for 48 hours. Contain a session identifier and may contain an IP address. |
7. Recipients and Subprocessors
We use carefully selected processors and service providers. The categories of recipients are:
- Cloud infrastructure providers - hosting the application, databases and caching layers in the EU.
- AI model providers - processing redacted queries for synthesis.
- Literature and guideline search services - receiving anonymised search queries.
- Analytics provider - PostHog, configured with memory-only persistence, autocapture disabled, session recording disabled, and a strict allowlist of safe event properties.
- Legal, regulatory and professional advisers - where required by law or to protect our rights.
Example subprocessors currently used
- Railway - application hosting and serverless infrastructure
- Neon - PostgreSQL database
- Upstash - Redis caching and rate limiting
- Mistral AI - large language model synthesis
- SearchAPI / external search services - literature and web discovery
- PostHog - product analytics
8. International Transfers
MedCite is designed to use EU-based infrastructure where possible. Some subprocessors may process data outside the European Economic Area. Where such transfers occur, we use appropriate transfer safeguards in accordance with applicable data protection law.
9. Publishing and Public Articles
Review answers can be intentionally published at a canonical public URL. Publishing is an explicit user action. Before you publish, you should understand that:
- The article and potentially the underlying clinical question become publicly accessible.
- Eligible articles may be indexed by search engines.
- Published material remains stored until removed under our deletion policy.
- You must ensure that the question, answer and article contain no patient identifiers, confidential information or third-party protected content.
- The anonymous session identifier is retained so you can exercise export or deletion rights for the content you published.
You can request removal of published articles at any time through your Privacy Settings. Removing a MedCite page does not guarantee immediate removal from search-engine caches or third-party copies.
10. Cookies and Analytics
We use PostHog for privacy-conscious product analytics. PostHog is configured with the following safeguards:
- Memory-only client persistence - no long-lived analytics cookies.
- Autocapture disabled - only explicitly captured events are sent.
- Session recording disabled.
- Strict event-property allowlist - clinical query text, answer text, source abstracts, source URLs and arbitrary payloads are excluded.
The bottom acknowledgement banner on the website is not an analytics or cookie consent control. You have the right to object to analytics processing under the GDPR by contacting privacy@medcite.eu.
We may set essential cookies required for language selection, session management and security. These do not track you for advertising purposes.
11. Your Rights
Under applicable data protection law, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Erase your personal data, subject to legal obligations
- Restrict processing of your personal data
- Object to processing based on legitimate interests
- Withdraw consent where consent is the legal basis
- Receive your data in a structured, commonly used and machine-readable format
- Complain to the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority
To exercise these rights, contact us at privacy@medcite.eu or use the Privacy Settings page. You will need your anonymous session identifier (sid) to request deletion or export of server-side data.
12. Automated Decision-Making
MedCite does not make decisions about you or any patient that produce legal or similarly significant effects. The service retrieves and synthesises published medical evidence; all clinical decisions remain with qualified healthcare professionals.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Continued use of MedCite after changes are published constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or want to exercise your data protection rights, please contact our privacy team at privacy@medcite.eu. We are not a data protection officer unless formally appointed; use the privacy contact for routine inquiries and rights requests.