readmyscans

Privacy Policy

Last updated: September 2026

Who runs this

readmyscans.com is operated by an individual based in India, offered currently as a free, early-stage tool and not by a registered company.

What we do with your files

When you upload a document, your browser sends it directly to a private, encrypted storage bucket, from which our server reads it to extract lab test results and returns the results to your browser. Each uploaded file is deleted from that bucket immediately after your request completes — successful or not. As a backstop, in case that deletion step is ever skipped (a crash mid-request, for example), the bucket also automatically expires anything left in it after 24 hours. We do not write uploaded files or extracted results to a database, and nothing is retained beyond that short window.

Third-party processing

To extract lab values from your documents, we send the document content, along with any note you typed, to OpenAI's API for processing. Under OpenAI's API terms, this content is not used to train their models. OpenAI may, however, retain API inputs and outputs for up to 30 days for abuse and safety monitoring purposes — this is separate from our own servers, where nothing is retained beyond the single request. We do not send your documents to any other third party.

Looking up a reference

The results page can look things up in a library of medical reference books and show you a few paragraphs, each named to a book and a page. Nothing is generated or written for you — what you see is text from the book itself. There are three ways a lookup happens:

“What is this?” under a result, when you press it. What we send is the name of the test, whether your result was high or low, and the kind of sample it was measured in when the report says so (urine, stool, a culture). Not the value, not the date, not your name.

Questions from your note. If you typed a note when uploading, the same model that reads your documents may propose up to three general questions your note seems to be asking, and those are looked up automatically when the results page opens. The questions are checked as below before they are sent; the note itself is not.

“Ask the reference library”, a box on the results page where you type a question in your own words. What you type is what is sent, after the same checks. Leave out names, dates and the numbers themselves.

Every lookup is checked in your browser before anything leaves it. A question is refused if it contains a number that appears in your own report or its dates, any calendar date, any part of the name we found on your documents, or a run of four or more words lifted from your note; a “What is this?” question must also name a test that actually appears on your report. A refused lookup is not sent: the link does not appear, or the question box tells you which rule it met so you can rephrase. These checks are precise rather than complete — a number or a name that is not in your report is not recognised as yours — so treat the question box as you would a web search.

The lookup goes to Google, which converts the question into a form that can be searched, and to Turbopuffer, which does the search; the passages are then ranked on our own server. None of them receives your documents or your results. Your extracted results and the note you typed stay in your browser's tab storage so the results page can apply these checks, and are gone when you close the tab; we do not store either.

These references are background reading about the test, not advice about your result, and they never replace the reference range your laboratory printed. Your lab is the authority on its own ranges.

Abuse prevention

Because the service is free and requires no account, we keep a simple counter of how many documents have been submitted recently, and another of how many reference lookups have been made, so that one visitor cannot exhaust either for everybody. That counter is keyed by a one-way salted hash of your IP address, never the address itself, and each entry is automatically deleted after one hour. It records a count and nothing else — no documents, no results, and nothing that can be traced back to you.

Accounts and tracking

readmyscans.com does not require an account, does not use tracking cookies, and does not build a profile of your visits. Our hosting provider (AWS) retains standard, short-lived infrastructure logs (such as IP address and request timing) for security and abuse prevention, consistent with normal web hosting practice.

Contact

Questions or concerns about this policy can be sent to mgblr1995@gmail.com and will be addressed personally.