LabLucid / Privacy & data handling

Privacy & data handling

LabLucid explains lab results in plain language. We designed it to hold as little about a person as possible, and to keep it for as short a time as possible.

De-identification by design

For labs and clinics using our API, LabLucid does not need — and asks you not to send — direct patient identifiers such as name, date of birth, or medical record number. You reference each patient with your own opaque identifier; you hold the mapping between it and the person. What LabLucid stores is a set of results and an unguessable access link, not a patient’s identity.

What we store, and for how long

Security

Traffic is encrypted in transit (HTTPS), and data at rest sits on encrypted storage. Secrets and API keys are held in server-side configuration, never exposed to the browser.

AI processing

Explanations are generated by a large-language-model provider. We send the results that need explaining — not patient identifiers. For deployments handling protected health information, we use provider configurations that support a Business Associate Agreement (BAA) and zero data retention.

The boundary

LabLucid provides educational information only. It explains results and helps patients prepare questions for their clinician. It does not diagnose disease, prescribe, or replace professional medical judgment.

Contact

Questions about data handling, or need a BAA / data-processing agreement for a pilot? Email hello@lablucid.com.

← Back to lablucid.com