Last updated: March 1, 2026

Privacy Policy

This Privacy Policy describes how ChimeStream B.V. ("LineageAI," "we," "our," or "us") collects, uses, and shares information when you use the LineageAI platform at lineageai.io.

1. Data We Collect

Account information: When you create an account, we collect your name, email address, password (hashed), and optionally your clinic or organization name.

Case data: You may enter patient identifiers (such as an internal patient ID), variant type, clinical notes, and information about family members (names, relationships, contact information). This data is stored in your account and not accessible to other users.

Usage data: We collect logs of how you use the platform — which pages you visit, what actions you take, and when. This is used to improve the product and diagnose issues.

Payment information: Payment processing is handled by Stripe. We do not store full credit card numbers. We receive a payment token and basic billing information from Stripe.

2. How We Use Your Data

  • To provide, maintain, and improve the LineageAI service.
  • To generate outreach letters based on variant data you provide.
  • To maintain your compliance audit trail.
  • To communicate with you about your account, billing, and product updates.
  • To ensure security and prevent abuse of the platform.
  • We do not use your patient data to train AI models.
  • We do not sell your data to third parties.

3. HIPAA Considerations

LineageAI is designed to support HIPAA-adjacent workflows. We are not currently a covered entity under HIPAA, but we understand our platform may be used in the context of protected health information (PHI).

Enterprise plan subscribers may enter into a Business Associate Agreement (BAA) with ChimeStream B.V. This agreement governs our handling of any PHI that may be present in your case data.

We recommend that users on the Pilot and Pro plans use de-identified patient identifiers (e.g., internal IDs rather than names and dates of birth) when entering case data, unless your institution has assessed the risk and the BAA is in place.

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.

4. Data Retention

Your account data is retained for as long as your account is active. If you close your account, your data is retained in a deactivated state for 30 days, then permanently deleted.

You can export all case data at any time from your account settings in CSV or PDF format.

Compliance logs are retained for 7 years by default to support clinical documentation requirements, unless you request earlier deletion.

5. Third-Party Services

We use the following third-party services:

  • Stripe: Payment processing. Subject to Stripe's privacy policy.
  • Vercel / cloud hosting: Infrastructure and deployment. Data is hosted in the EU or US depending on your account region.
  • OpenAI API: For generating outreach letter drafts. Data sent to OpenAI is subject to their API data usage policy. We do not send identifiable patient data to OpenAI.

6. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data. To exercise any of these rights, contact us at hello@lineageai.io.

Residents of the European Union and EEA have additional rights under the GDPR, including the right to data portability and the right to restrict processing.

7. Contact

Questions about this privacy policy? Contact us at hello@lineageai.io. Our data protection officer can be reached at the same address with the subject "DPO Request."

ChimeStream B.V., registered in the Netherlands.