Legal

Privacy Policy

Effective August 18, 2026

Platelet is a data analysis tool for microplate biology experiments. We collect as little data as possible and never store your experimental files. Here is exactly what we do and don't do.

Information we collect

When you join our waitlist, we collect your email address and, if you choose to share them, your role (e.g. PhD student, PI, industry), field of study, and a short description of your research — used only to prioritize and tailor access.

When you create an account, our authentication provider, Supabase, stores your email address and account identifier. If you sign in with Google, we also receive your name and profile information from Google as part of that sign-in. If you subscribe to a paid plan (not currently available), our payment processor, Stripe, will hold your billing details and payment history — we do not store your card number ourselves.

With your consent, we collect anonymous usage analytics to understand how Platelet is used — see the Analytics section below. We never associate this data with your identity, and we never collect your lab data.

Platelet is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at the address below and we will delete it.

Your lab data

When you use Platelet, you may upload experimental files such as plate maps, readings, and feature data. This data is sent to our backend only to perform the analysis you requested. It is processed in memory and immediately discarded — we have no database of uploaded files, and nothing is written to disk on our end.

Once your results are returned to your browser, your data is gone from our systems. You retain full ownership of everything you upload.

If you connect Google Drive, you can choose to export your session data or source files to your own Drive. This is a separate, user-initiated feature — it does not change how your data is handled during analysis, described above.

Peter, our AI assistant

Platelet includes an optional AI assistant, Peter, gated behind an access flag on your account. Using Peter sends your prompts and a summary of your data's structure — not raw well-level values — to our AI provider, Anthropic. See our AI Policy for full details on how Peter handles your data.

Account authentication

Account sign-in is handled by our authentication provider, Supabase. You can sign in with a one-time code sent to your email, or with Google. We don't receive or store your password — Supabase manages credentials directly. Access to the app requires your account to be approved from our waitlist.

Billing

Paid subscriptions, when available, will be processed by Stripe. Stripe will store your payment method, billing history, and a customer record linked to your account. We only retain a reference id to that Stripe customer — we never see or store your full card details.

How we use your email

We use your email address for:

  • Sending your waitlist invite when your spot opens up.
  • Signing you in, if you use one-time-code login.
  • Account and billing notices related to your subscription.
  • Occasional product announcements, only if you remain on our list after receiving access.

We will never sell, rent, or share your email with third parties for marketing purposes. Every marketing email we send includes a clear unsubscribe link, and we honor all opt-out requests within 10 business days in accordance with the CAN-SPAM Act. Transactional emails (like sign-in codes or billing receipts) aren't affected by unsubscribing.

Unsubscribing

You can opt out of all emails from us at any time by clicking the unsubscribe link at the bottom of any email we send, or by contacting us directly at the address below. We will process your request promptly.

Error monitoring

We use Sentry to monitor application errors. When an error occurs, Sentry may collect technical information including your browser type, the actions that led to the error, and error context such as stack traces. This data is used solely to diagnose and fix bugs.

We configure Sentry to not collect your IP address, authentication credentials, or any lab data you upload. Request bodies for all data processing endpoints are explicitly stripped before error reports are sent. Error reports are only captured in production and are never used for advertising or profiling.

Analytics

We use Google Analytics to understand how visitors use Platelet — which pages are visited and which features are used — so we can improve the product. This collection is strictly opt-in: when you first visit, analytics are disabled by default (via Google Consent Mode), and nothing is collected unless you accept analytics cookies in the consent banner.

When enabled, Google Analytics records page views and basic interaction events (for example, that a file was uploaded or an analysis was run). We never send your email, any personal information, or any lab data to Google, and we keep Google's advertising and personalization signals turned off. You can change your choice at any time by clearing your browser's site data. See Google's Privacy Policy for how Google handles this data.

Cookies

We use strictly necessary cookies, set by our authentication provider Supabase, to keep you signed in while you use the app. Only if you accept analytics in the consent banner, Google Analytics also sets cookies to measure usage. We do not use advertising cookies, and analytics cookies are never set without your consent.

Other service providers

A few other providers support Platelet's infrastructure. Waitlist and feedback submissions are recorded in a private Google Sheet via a service account. Sign-in and upload requests are rate-limited using Upstash, which briefly stores a hashed identifier of your IP address or email to prevent abuse. Neither provider has access to your lab data.

International data transfers

Some of our service providers (including Supabase, Stripe, Anthropic, Google, Sentry, and Upstash) may process data outside your country of residence, including in the United States. Where we transfer personal data from the European Economic Area, United Kingdom, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards such as Standard Contractual Clauses with those providers.

Security

We use industry-standard measures to protect your information, including encryption of data in transit (TLS) and access controls limiting who can reach our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.

Data retention

Waitlist and account records are kept until you ask us to delete them or close your account. Each time you upload data, we record that you acknowledged our upload policy for 24 hours afterward, tied to your account — this record contains no data about the upload itself, only that the acknowledgment occurred. Billing records, once billing is active, will be retained by Stripe per their own retention policy. Uploaded lab data itself is never retained beyond the duration of a single analysis request. If you connect and later disconnect Google Drive, we delete your stored access tokens.

Disclosures for legal reasons or business transfers

We may disclose personal information if required to do so by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, investigate fraud, or respond to a government request. If Platelet is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction; we will notify you before your information becomes subject to a different privacy policy.

Your rights

You may request access to, correction of, or deletion of your personal data at any time. If you are located in the European Union or United Kingdom, you have additional rights under the GDPR and UK GDPR, including the right to data portability and the right to lodge a complaint with a supervisory authority.

California residents: Under the CCPA/CPRA, you have the right to know what personal information we collect, to request its deletion or correction, and to opt out of the "sale" or "sharing" of personal information as those terms are defined by California law. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals where applicable. To exercise any of these rights, contact us at the address below.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the "Effective" date above and, where required by law, notify you by email or through a notice on the app.

Contact

Questions or requests? Contact us at platelet.webapp@gmail.com.