Skip to main content
This page describes how Strand AI handles the data you send us: what we store, how it is protected, how long we keep it, and how it is deleted. For the mechanics of setting expiration windows and restoring from Trash, see Sample expiration.

What we store

When you use Strand AI, we store two kinds of sample data on your behalf:
  • Uploaded samples: the slide images you upload for prediction.
  • Marker predictions: the per-marker outputs we generate from your samples, including the image pyramids served back to you.
We also keep operational records (see Logs are retained separately below) that are distinct from your sample data.

De-identified input requirement

Slides must be de-identified before upload. Do not upload protected health information (PHI) or other regulated identifiable health information unless a separate written agreement with Strand AI expressly authorizes that processing. This requirement covers the slide pixels, embedded label and macro images, scanner metadata, and filename. Whole-slide images often carry identifiers in an embedded label image, a macro image, scanner-written metadata fields, or the filename. Remove these identifiers before upload. If identifiers are baked into the tissue region, crop or re-scan the slide before uploading.

Optional de-identification at ingest

Automated slide de-identification is off by default and runs only when Strand AI enables it for your organization. When enabled, the ingest pipeline removes embedded label and macro images and known PHI-bearing metadata fields, then validates the result before permanent storage. Unsupported formats or failed validation stop that enabled path. The enabled path does not retain an unprocessed copy in permanent storage. Automated de-identification does not scan or redact identifiers in the tissue image or filename. It does not replace de-identification before upload, and it is not a representation that data satisfies HIPAA or any other legal de-identification standard.

Encryption

Your data is encrypted in transit and at rest. Strand AI runs on enterprise-grade cloud infrastructure with encryption applied to stored objects and database records, and TLS protecting data moving between you and our services.

Retention & deletion

Retention is under your control. Expiration is opt-in: samples never expire until an owner or admin sets a policy (see Sample expiration for how to configure it). When a sample expires, it moves to Trash, where it is held for 7 days. During that window you can restore it. After the window closes, the sample and its marker predictions are permanently deleted 7 days after expiry. Both the stored objects and the corresponding database records are removed.
Deletion happens over a window rather than instantly. A sample is permanently deleted 7 days after it expires, once it has passed through the Trash grace period, and remains restorable until then.

Logs are retained separately

Your sample data (uploads and the predictions derived from them) is deleted according to your retention policy as described above. Operational and audit logs are kept separately and are retained beyond your sample data for security, billing, and compliance purposes. These logs do not contain your slide images or prediction outputs; billing history is preserved even after the underlying samples are deleted.

Access control & audit logging

Access to samples is scoped to your organization and governed by role-based permissions (see the permissions table in Sample expiration). Retention actions (automatic archival on expiry and permanent deletion after the grace window) are audit-logged, recording what was deleted and when.

We do not train on your data

We do not use your data to train our models. If that ever changes, we will notify you in advance, and any such use will be opt-in.