Privacy Policy

Welcome to LocalMedAI. Protecting your personal data is very important to us. This privacy policy outlines what data we collect, how we use it, and your rights regarding your personal information when you interact with us through our website or download and use our application. Please read this policy carefully to understand our practices.

1. Scope of this Privacy Policy

This privacy policy covers two distinct aspects of our services for users of our website and our LocalMedAI application:

  • Website: Privacy information regarding how we handle data when you visit and interact with our website (www.localmedai.com).
  • Application: Privacy information regarding the standalone LocalMedAI desktop application that individual users download and install on their personal computers.

2. Definitions

The following sections detail how we handle data specifically related to your interaction with our website:

Personal Data

Personal data means any information relating to an identified or identifiable person (the "data subject"). This includes information such as a name or email address that can be linked to an individual.

Data Subject

The data subject is any identified or identifiable person whose personal data is processed. For example, this includes individuals who contact us via the contact form or email.

Processing

Processing refers to any action taken with personal data, including collecting, storing, using, and deleting it.

Controller

The controller is the entity responsible for deciding how and why personal data is processed. For this website, the data controller is 403BITS UG (haftungsbeschränkt).

Consent

Consent is the data subject's voluntary agreement to the processing of their personal data for a specific purpose. For example, by submitting an inquiry through our contact form, users consent to LocalMedAI using their personal data to respond to their inquiry.

IP Anonymization

IP anonymization means processing IP addresses in a way that removes any direct link to an individual. For Google Analytics on this site, IP addresses are anonymized, ensuring that they cannot be traced back to specific users.

3. Data Controller Information

The data controller responsible for data processing on this website is:

403BITS UG (haftungsbeschränkt)
Email: legal@403bits.com
Website: www.403bits.com

If you have any questions regarding this privacy policy, please feel free to contact us via email.

4. LocalMedAI Application Privacy

The LocalMedAI application is designed with a "privacy-by-design" approach, meaning:

  • 100% Local Processing: All data processing occurs exclusively on your local device. We do not have any capability to access, collect, or process any documents or data you create, modify, or store within the application.
  • No Remote Access: The application operates entirely offline and does not transmit any application usage data back to us or to any third parties.
  • No Logs Collection or Usage Analytics: We do not collect any logs, usage statistics, crash reports, or any other operational data from your use of the LocalMedAI application.
  • Your Data Remains Yours: Any documents, notes, or other content you create or process using LocalMedAI remains strictly under your control on your local device.

The only direct interactions we have with users of the LocalMedAI application are through initial download and voluntary customer support.

5. Personal Data Collection

5.1. Information You Provide

When you contact us through our contact form or email us directly, we collect the information you voluntarily provide (such as your name, email, and message) solely to respond to your inquiry.

5.2. Application Downloads and Marketing Communications

When you request to download our LocalMedAI application, you will be asked to provide your email address. By submitting your email, you consent to receive product updates, marketing communications, and other information related to LocalMedAI. You may opt out of these communications at any time by using the unsubscribe link provided in our emails or by contacting us directly.

5.3. Contact Form Processing

When you submit a contact form on our website, the data is initially processed by Netlify, our website hosting and form processing service. Netlify acts as a data processor on our behalf and temporarily stores your contact form submissions before forwarding them to us. The data collected through our contact forms includes your name, email address, phone number (if provided), contact reason, and message content.

Netlify's processing of your contact form data is governed by their Privacy Policy, which you can review at https://www.netlify.com/privacy/. Netlify retains form submissions for a limited period as part of their service operations, after which we delete the data from their servers.

5.4. Cookies and Website Analytics

Like most websites, our site uses cookies to enhance user experience and analyze site traffic. A cookie is a small text file stored on your device.

  • Strictly Necessary Cookies: We may use cookies that are essential for the operation of our website, such as those that manage your session.
  • Analytics Cookies: We use Google Analytics to understand how visitors engage with our site. We have enabled IP anonymization, so your full IP address is not stored. This service helps us improve our website by collecting and reporting aggregated information anonymously, such as which pages are visited most often.

You can control cookie settings through your browser preferences. However, disabling cookies may affect your experience on our site.

For more information on how Google Analytics collects and processes data, please visit the Google Privacy & Terms page at https://policies.google.com/privacy.

6. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organizational measures to protect it. While we strive to use state-of-the-art methods (such as SSL encryption) to secure data transmission, please note that internet data transfers may have security gaps.

Website Security

For our website operations, we employ industry-standard security measures to protect any data collected through your interactions with our website.

Application Security

The LocalMedAI application operates with a "zero-knowledge" approach:

  • Only Local Processing: All data processing and storage occur exclusively on your local device.
  • Complete Data Confidentiality: User conversations are protected by zero-knowledge encryption. Only the user can decrypt their data.
  • Modern Encryption: We employ best-in-class cryptographic standards: Argon2id for key derivation and AES-256 for data encryption.
  • No Logging Policy: We do not maintain servers or cloud infrastructure for application data, nor there are means to collect the information by us or send any data from the app to us.
  • No Remote Access: We have no technical capability to access any data you process within the application installed on your computer.
  • No Data Collection: We do not collect any data from the application, nor there are means to collect the information by us or send any data from the app to us.

7. Data Retention

When shared with us, we retain your personal data for as long as is necessary to fulfill the purpose for which it was collected, or as required by applicable legal regulations. Data collected via contact inquiries is retained until the inquiry is resolved unless a longer retention period is required. Anonymized data from Google Analytics is retained as per Google's default data retention policies.

For the LocalMedAI application, since it operates entirely offline and does not transmit any data to us, we do not retain any of your documents or data. All data remains on your local device, and you are responsible for managing its retention and deletion.

8. Your Rights

You have the following rights under the GDPR:

  • Right to Access: You can request information about your personal data that we process.
  • Right to Rectification: You can ask us to correct inaccurate or incomplete personal data.
  • Right to Erasure: You can request deletion of your personal data, provided no legal retention requirements exist.
  • Right to Restrict Processing: You can request a restriction on data processing under certain conditions.
  • Right to Object: You can object to our processing of your data if it is based on legitimate interest.
  • Right to Data Portability: If applicable, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.

If you would like to exercise any of these rights, please contact us at legal@localmedai.com or legal@403bits.com. Additionally, you have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR regulations.

9. Updates to This Privacy Policy

We may update this privacy policy occasionally to ensure compliance with the latest legal requirements or to reflect changes in our data processing practices. The latest version will always be available on our website.

Last Updated: August 2025