**DRAFT — not legal advice; qualified counsel and privacy/security owners
must review and approve this document before publication.**
Last updated: 2026-07-26
Consent record version:
privacy_v1
PathoWish Privacy Policy — Draft
Research use only
PATHOWISH IS FOR RESEARCH USE ONLY. It is not authorized for clinical diagnosis, patient management or treatment decisions.
This draft covers account, authentication, session-security, order, subscription, support, device, local-execution and audit data. Identifiable patient data, protected health information and other sensitive research data must not be uploaded unless a separately approved workflow and all required legal, ethics, contractual and security controls exist.
Candidate data categories
- account contact details and server-generated public identifiers;
- password hashes, MFA material, session and security metadata;
- orders, payment/refund evidence, subscription and entitlement state;
- support, Finance approval and de-identified audit events;
- device, release-channel, tool authorization and run-lifecycle metadata.
The production field inventory, legal bases, retention, recipients, transfers, rights workflow and controller/operator identity remain launch blockers.
Engineering controls
Current code includes encryption for designated sensitive fields, keyed lookup projections, current-user local credential isolation, CSRF/session controls and de-identified audit events. These controls are not yet production-attested.
PRE-PUBLICATION ENGINEERING CHECK: reconcile this document against the exact production schema, logs, telemetry, backups, processors, retention jobs, support exports and local/hosted data flows. Verify deletion, access, correction, incident response, key rotation and recovery in the target environment.
Sharing and retention
No processor, recipient, retention period or cross-border transfer may be added silently. The approved policy and contracts must name them before collection or disclosure unless a documented legal exception applies.
Rights and contact
The final policy must identify the responsible legal entity, privacy contact, supported territories and verified process for applicable access, correction, deletion, restriction, objection and complaint rights.