What we store
When you use Strand AI, we store two kinds of sample data on your behalf:- Uploaded samples: the slide images you upload for prediction.
- Marker predictions: the per-marker outputs we generate from your samples, including the image pyramids served back to you.
De-identified input requirement
Slides must be de-identified before upload. Do not upload protected health information (PHI) or other regulated identifiable health information unless a separate written agreement with Strand AI expressly authorizes that processing. This requirement covers the slide pixels, embedded label and macro images, scanner metadata, and filename. Whole-slide images often carry identifiers in an embedded label image, a macro image, scanner-written metadata fields, or the filename. Remove these identifiers before upload. If identifiers are baked into the tissue region, crop or re-scan the slide before uploading.Optional de-identification at ingest
Automated slide de-identification is off by default and runs only when Strand AI enables it for your organization. When enabled, the ingest pipeline removes embedded label and macro images and known PHI-bearing metadata fields, then validates the result before permanent storage. Unsupported formats or failed validation stop that enabled path. The enabled path does not retain an unprocessed copy in permanent storage. Automated de-identification does not scan or redact identifiers in the tissue image or filename. It does not replace de-identification before upload, and it is not a representation that data satisfies HIPAA or any other legal de-identification standard.Encryption
Your data is encrypted in transit and at rest. Strand AI runs on enterprise-grade cloud infrastructure with encryption applied to stored objects and database records, and TLS protecting data moving between you and our services.Retention & deletion
Retention is under your control. Expiration is opt-in: samples never expire until an owner or admin sets a policy (see Sample expiration for how to configure it). When a sample expires, it moves to Trash, where it is held for 7 days. During that window you can restore it. After the window closes, the sample and its marker predictions are permanently deleted 7 days after expiry. Both the stored objects and the corresponding database records are removed.Deletion happens over a window rather than instantly. A sample is permanently
deleted 7 days after it expires, once it has passed through the Trash grace
period, and remains restorable until then.