Privacy
Privacy policy
Last updated: September 2026. We'll be plain about this, the same way we're plain about your reports.
What we collect
- Report text you paste in. It is sent to our servers solely to generate your explanation, processed transiently, and not stored afterward. Once your explanation is generated, the report text is discarded.
- Email address (optional). Only if you choose to have your summary emailed to you or to receive PlainScan updates. Stored so we can send what you asked for.
- Payment information. Handled entirely by our checkout provider. We never see or store your card number — we only receive confirmation that a payment succeeded.
- Basic technical data. Standard server logs (such as request times and error messages) used to keep the service running reliably.
How we use it
- To generate the plain-English explanation you requested.
- To email you your report summary and occasional PlainScan updates, if you opted in. You can unsubscribe at any time.
- To process premium and clinic purchases and unlock premium features on your device.
- To operate, secure, and improve the service.
What we never do
- We do not sell your data. Not your report text, not your email, not anything.
- We do not share your personal information with advertisers or data brokers.
- We do not use your report text to train models or for any purpose beyond generating your explanation.
Retention
Report text is processed transiently and discarded after your explanation is generated. Email addresses are kept only as long as needed to send what you asked for, and deleted when you unsubscribe or request deletion.
Security
All traffic is encrypted in transit. Access to any stored data is limited to what's needed to run the service. That said, no system is perfectly secure — if you ever spot a concern, please tell us right away.
Your choices
- You can use the Basic tier without creating an account or giving us any personal information at all.
- You can unsubscribe from emails at any time via the link in any message.
- You can ask us to delete your email address from our records at any time.
Children
HivePlainScan is intended for adults. Please don't submit a minor's report without a parent or guardian involved.
Changes to this policy
If we change this policy in a way that matters, we'll update the date above and note the change here in plain language.
Contact
Questions about privacy? Reach us at privacy@hiveplainscan.example (placeholder — final address to be confirmed). We read everything and reply as quickly as we can.
Referral codes
After a premium purchase, you may receive a referral code you can share with friends. When you share it, we store the code, the email it was issued to, and which redemptions used it — that's how we know the referral came from you. Your referral code never contains your report information or any health data.
Shareable explanation pages
If you choose to share an explanation, we create a shareable page that contains only the condition-level summary — the medical terms, their plain-English meanings, severity, and location. It never contains your raw pasted report text. The page lives behind an unguessable link: anyone with the link can view it, so only share it with people you trust.
Cloudflare Web Analytics
We use Cloudflare Web Analytics to understand aggregate usage (such as how many people visit and which pages are popular). It is cookieless and privacy-first: it does not use tracking cookies, does not track you across sites, and does not identify you personally.
Email queue and nurture
If you opt in to scan tips or PlainScan updates, we keep your email address in a mailing queue so we can send what you asked for — including your requested summary and occasional helpful emails about understanding scan results. Every email we send includes an unsubscribe link, and you can also unsubscribe anytime at plainscan.hive.baby/unsubscribe.html. Unsubscribing removes you from future marketing emails; it does not affect your ability to use the free tier.
Rate limiting
To keep the service fair and available for everyone, we limit how often the explanation endpoint can be called from a single source in a short period. The technical request data used for rate limiting (such as request counts and timestamps) is used only for security and reliability, and is not combined with your report content or email address.