Privacy Policy
Last updated: June 27, 2026.
Doomina is a medical-imaging (DICOM) viewer. This policy explains, plainly, what data we handle, where it lives, who it is shared with and what your rights are. It covers two very different ways of using the product — read section 2 carefully, because how your data is handled depends on which one you use.
1. Who we are and our role over your data
Doomina is operated by the Doomina team (“we”). Regarding the data:
- Clinical data (DICOM studies and their metadata) you upload to the cloud: you (or your institution) are the controller of that data and Doomina acts as a processor, handling it only to provide the service, on your instructions (LGPD art. 39). You are responsible for having your own legal basis to process and upload patient data.
- Account, billing and telemetry data: here Doomina is the controller.
2. Two ways to use it — and what that means
- Local mode (no account): when you open studies straight from your device without signing in, the DICOM files are read, decoded and rendered entirely in your browser. In this mode, image pixels and patient data are not uploaded to our servers.
- Cloud features (with an account): when you create an account and use the image bank, link sharing, teaching communities, exam video recording/sharing or PACS connectors, data is sent to our servers (and to sub-processors) to power each feature. Everything below describes this mode.
3. What data we handle
- Account data: sign-in email (magic link or password) and your public nickname/avatar in communities.
- Billing data: for paid plans — name, email and subscription identifiers; and, for PIX Automático (Woovi), also tax ID (CPF) and address. We log billing events (webhooks) from the payment processors.
- Clinical data (sensitive health data): DICOM image pixels and their metadata, which may include patient name, ID, date of birth, sex, accession number, institution and referring physician, plus identifiers that may be “burned into” the image pixels.
- Exam videos: when you record an explanation, the video (screen frames + your audio narration) can be saved to the cloud.
- Ablation planning: when you mark lesions and plan ablations, only the geometry (mm coordinates) is saved to your account — the image pixels never leave your browser.
- Community content: cases, comments, posts, reactions and attachments you publish.
- Technical and usage data: IP address and approximate country (for language/currency, security and usage limits), and product telemetry (page views with a visitor identifier, error reports). See section 13.
4. Where data is stored
- On your device: studies opened in local mode are cached in the browser (IndexedDB) and, if you link a library folder, written to that real folder on your computer, under your control.
- In the cloud (Supabase): DICOM files live in private storage buckets and metadata in a database with per-user isolation (RLS), in the sa-east-1 (Brazil) region. Each user only sees their own data.
- With payment processors (Stripe and Woovi) and the host (Vercel — including request logs).
5. Anonymization and sensitive health data
Anonymization is optional and does not happen automatically when you upload to your personal bank — you must turn it on (on some plans). When you share to communities, challenges or with peers, anonymization is mandatory and applied to the file itself.
- What it does: reduces the patient name to initials (e.g.
A.J.B.N.), masks the Patient ID and accession as ******, removes the other direct identifiers (date of birth, sex, institution, physician, etc.) and remaps the unique identifiers (UIDs). - What it deliberately keeps: the exam name (study description) and dates, plus technical/private tags — useful clinically, but which in rare cases may contain re-identifying data.
- Hide on screen (paid): beyond the file anonymization, the viewer has a “Hide identity” button that masks the patient on screen only (same pattern: initials +
******), without altering the file. - Important limit: anonymization acts on metadata, not the image content. It does not remove identifiers “burned into” the pixels (common in ultrasound, screenshots and scanned documents). Before sharing, visually check that no patient data is visible in the image itself.
6. Who we share with (sub-processors)
We use providers that process data on our behalf, each for a purpose:
- Supabase — authentication, database and storage of studies/files (Brazil, sa-east-1).
- Vercel — app hosting, approximate IP geolocation and logs.
- Stripe and Woovi — payment processing (they receive no clinical data).
- Upstash — usage/abuse limits (IP-based key).
- Browser push services (e.g. Google/Mozilla) — notification delivery, if you enable it.
- Third-party PACS servers — only the ones you configure yourself; we then proxy the connection using the credentials you provide.
We do not sell your data and do not use it to train artificial-intelligence models.
7. Legal basis and purposes
- Performance of a contract: creating and running your account, storing and showing your studies, processing payments.
- Consent (art. 7 and art. 11): for processing the health data you choose to upload to the cloud, and for notifications.
- Legitimate interest: security, abuse prevention and product improvement (minimized telemetry).
- Legal obligation: retention of tax/financial records.
Because this involves sensitive health data, you should only upload patient data to the cloud if you have your own legal basis to do so (data-subject consent or another LGPD ground).
Minors (art. 14): the service is intended for healthcare professionals and students aged 18+ and is not directed at children. When the patient is a minor, processing must serve their best interest and rely on the specific consent of at least one parent or legal guardian — the controller's (your/your institution's) responsibility.
8. Link sharing, communities and videos
- Share links grant access to the study to anyone who has the link. You control expiry and a view limit, and you can revoke the link at any time. If the content is not anonymized, the recipient can see (and download) the patient data — share responsibly.
- Communities, challenges and peer sharing require file anonymization.
- Exam videos are private by default; if you create a public link, it can be revoked. A video may contain sensitive data if you choose to show patient identification.
9. Retention and deletion
- Local data: removing a study from the list deletes it from the cache and the linked folder; clearing the site data in your browser wipes the local cache (this does not delete your cloud account data).
- Cloud data: stored while your account exists. You can delete studies individually at any time.
- Account deletion: when you request deletion, there is a 30-day grace period (recoverable) before your data and files are permanently removed.
- Billing: financial records may be retained for the period required by law, even after account deletion.
10. Your rights (LGPD art. 18)
At any time you may request: confirmation and access to your data, correction, anonymization, portability, deletion, information about sharing, and withdrawal of consent. To exercise these rights, use the in-app controls or contact us (section 14).
11. Security
We use per-user data isolation (RLS) on every table, private storage buckets, short-lived signed access links, signature verification on payment webhooks, and abuse protection. No system is 100% secure, and the service is provided “as is”, without clinical validation.
12. Cookies and local storage
We use strictly necessary cookies and local storage: session cookie (login), language preference, acceptance of this notice, and session/visitor identifiers for the telemetry described below. We do not use third-party advertising cookies.
13. Telemetry and analytics
To understand usage and product stability, we log page views (the path visited, with an anonymous visitor identifier) and browser error reports (message, origin and URL). This data is minimized and is not intended to identify the patient.
14. Contact and Data Protection Officer (DPO)
To exercise your rights or ask any privacy question, contact our Data Protection Officer (DPO) at suporte@doomina.com.