LabLucid / Privacy & data handling
LabLucid explains lab results in plain language. We designed it to hold as little about a person as possible, and to keep it for as short a time as possible.
For labs and clinics using our API, LabLucid does not need — and asks you not to send — direct patient identifiers such as name, date of birth, or medical record number. You reference each patient with your own opaque identifier; you hold the mapping between it and the person. What LabLucid stores is a set of results and an unguessable access link, not a patient’s identity.
Traffic is encrypted in transit (HTTPS), and data at rest sits on encrypted storage. Secrets and API keys are held in server-side configuration, never exposed to the browser.
Explanations are generated by a large-language-model provider. We send the results that need explaining — not patient identifiers. For deployments handling protected health information, we use provider configurations that support a Business Associate Agreement (BAA) and zero data retention.
LabLucid provides educational information only. It explains results and helps patients prepare questions for their clinician. It does not diagnose disease, prescribe, or replace professional medical judgment.
Questions about data handling, or need a BAA / data-processing agreement for a pilot? Email hello@lablucid.com.
← Back to lablucid.com