Privacy Policy
Last updated: August 10, 2026
1. Introduction
인파이니(infyni) (“we,” “us,” or “our”) operates the Cura service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
2.1 Account Information
When you sign in with Google, we receive your name, email address, and profile photo from Google. We do not receive or store your Google password.
2.2 Profile Information
Depending on the features you use, profile information may include professional details, patient profile details, and consent records.
2.3 Clinical Data
Clinical and account data may be transmitted to service providers and stored to deliver Cura. This can include clinical queries, intake responses, saved cases, profile information, and consent records. Some information may also be stored on your device.
2.4 Patient Sharing
The patient portal supports manual linkage using a manually entered clinician-provided share code. A code may stop working if sharing is disabled or its configured expiration passes. Cura does not automatically match accounts using names, dates of birth, phone numbers, or hashes of those details.
2.5 Usage Data
We may collect operational data such as page views, feature usage, device or browser information, and error logs to maintain, secure, and improve the service.
3. How We Use Your Information
- To provide and maintain the Cura service
- To authenticate your identity and manage your account
- To process clinical queries and patient intake responses
- To save, synchronize, and share records when you use those features
- To prevent misuse and maintain security and audit records
- To improve and optimize the service
- To communicate important service updates
4. Data Sharing
We do not sell your personal information. We may share data with:
- AI Service Provider : Clinical data is processed by our AI engine for analysis. Provider handling follows applicable service policies.
- Firebase (Google Cloud): For authentication, hosting, and data storage services.
- Authorized Cura Users: When a user intentionally shares a record through Cura's sharing features.
- Legal Requirements: When required by law or to protect our rights.
5. Data Security
We use safeguards such as HTTPS, authentication, access controls, encrypted clinical-storage workflows, session controls, and Content Security Policy headers. These security controls reduce risk but cannot eliminate it.
6. Data Retention
Account and clinical data may be retained while needed to provide and secure the service and meet applicable obligations. Request account or data deletion by emailing infyni@infynimedical.com. Deletion requests may be subject to legal, clinical, or audit retention requirements. Clearing data from your browser or device does not necessarily delete data stored by the service.
7. Your Requests and Choices
You may contact us to:
- Ask what account information we hold about you
- Request correction of inaccurate account information
- Request deletion of your account and associated data
- Ask about available data export options
We may need to verify your identity before acting on a request, and applicable retention requirements may limit a request.
8. Clinical Data Responsibilities
Submit only clinical data that you are authorized to process and that is reasonably necessary for the feature you use. Follow your organization's policies and your applicable legal and professional obligations. Using Cura does not by itself satisfy those obligations.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of changes by posting the new policy on this page with an updated date.
10. Contact
For privacy questions or account and data deletion requests, email infyni@infynimedical.com.