Privacy Policy

Your privacy matters. Learn how we collect, use, and protect your data.

Privacy Policy

Last Updated: July 30, 2026

1. Introduction

SIMILIA LTD (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and application at https://www.similia.io/.

We are the data controller for the processing of personal information described in this policy. If you have any questions about this Privacy Policy or our practices, please contact us at info@similia.io.

2. Information We Collect

Personal Information: We collect information that identifies, relates to, or could reasonably be linked with you, including:

  • Email address
  • Account credentials
  • Display name (if provided)

Usage Data: We automatically collect information about your interactions with our application, including:

  • Log and usage data (IP address, browser type, referring/exit pages)
  • Device information (device type, operating system)
  • Cases and repertorizations data
  • Feature usage and interaction data

Collaborative Proving Data: When you join a proving, we collect your proving membership and the observations you submit, including typed or transcribed text and privacy-sanitized image copies derived from uploaded handwritten notes or drawings. Before a proving JPEG, PNG, or WebP image is sent for AI processing or saved to Cloud Storage, it is re-encoded server-side and its location and device metadata and embedded profiles, including EXIF, XMP, IPTC, and ICC data, are removed. The proving coordinator receives participant observations and associated privacy-sanitized image copies.

Device Fingerprint Data: We collect device-specific information including browser type, screen resolution, hardware specifications (such as CPU cores and device memory), timezone, and other technical identifiers. This data is used to detect unauthorized account sharing and improve security.

Voice and Audio Data: When you use Live Audio or upload a prerecorded proving recording, your audio is transmitted to and processed by Deepgram to create a transcript. Prerecorded proving audio is temporary and is not retained as an attachment to the proving. After transcription, it is removed from active storage and made inaccessible through the Service. The deleted Cloud Storage object can remain in a restricted soft-delete state, accessible only to authorized administrators, for up to seven days before permanent deletion from that state. Any residual backup copy, where applicable, follows a separate documented retention schedule. A Business Associate Agreement (BAA) and zero-data-retention controls apply to Deepgram processing only when they are respectively contractually applicable and configured.

AI-Processed Content: When you use our AI-powered features (such as notes analysis, image analysis, visual symptom extraction, transcription, or semantic search), your content is transmitted to and processed by third-party services that may include OpenAI, Google, OpenRouter, and Deepgram. OpenRouter acts as an AI processor and routing service and may send a request to a selected underlying model provider. Provider retention and model-training treatment vary by service and configuration. Zero-data-retention, no-training, BAA, or similar safeguards apply only where enabled for the relevant account or request and contractually applicable. Similia does not use this content to train its own AI models. This processing is necessary to provide these features.

3. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: For certain data-processing activities, we rely on your explicit consent.
  • Contractual Necessity: To perform our contractual obligations to you, including providing our services.
  • Legitimate Interests: To pursue our legitimate business interests, such as improving our services and ensuring security.
  • Legal Obligation: To comply with applicable laws and regulations.

4. How We Use Your Information

We use your information for the following purposes:

  • To provide and maintain our services
  • To personalize your experience
  • To communicate with you about your account or our services
  • To improve our application
  • To protect against fraudulent or illegal activity
  • To process payments and manage subscriptions
  • To send marketing communications (with your consent)
  • To provide customer support

5. Cookies and Similar Technologies

We use cookies and similar tracking technologies to track activity on our application and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

We use the following cookies and tracking technologies:

  • Session Cookies: We use a session cookie (__session) for authentication purposes, which expires after 14 days.
  • Mixpanel: For server-side analytics and feature usage tracking to help us debug issues and improve our service. Mixpanel is processed entirely server-side (no client-side cookies or localStorage), uses pseudonymized user identifiers, and data is stored in the European Union. Tracking is only active for users who have accepted our GDPR consent. No health data or patient information is ever sent to Mixpanel.
  • Google Tag Manager: For managing and deploying marketing and analytics tags.
  • Sentry: For error tracking and application monitoring.
  • Vercel Analytics: For performance monitoring and analytics.
  • Rewardful: For affiliate and referral tracking, using a referral cookie to track referral sources.

Some of these services may record user sessions, including mouse movements, clicks, and scrolling behavior, to help us understand user experience and improve our application.

6. Data Sharing and Disclosure

We may share your information with the following categories of service providers:

Analytics and Monitoring Providers:

  • Mixpanel (server-side feature usage analytics, EU-hosted)
  • Google Tag Manager (tag management)
  • Sentry (error tracking and monitoring)
  • Vercel Analytics (performance monitoring)

AI and Machine Learning Service Providers:

  • OpenAI (AI analysis and image processing; BAA and zero-data-retention controls where configured and contractually applicable)
  • Google Generative AI (semantic search, embeddings, and image or AI processing; privacy controls depend on the applicable account and service configuration)
  • OpenRouter (AI processing and routing for image and other AI requests; requests may be sent to selected underlying model providers)
  • Deepgram (voice-to-text transcription; BAA and zero-data-retention controls where configured and contractually applicable)
  • Pinecone (vector database for semantic search)

Payment Processors:

  • Stripe (subscription and payment processing)

Communication and Marketing Services:

  • Brevo/Sendinblue (email marketing and transactional emails)
  • Crisp (customer support chat)

Infrastructure and Hosting:

  • Firebase (authentication and database)
  • Vercel (hosting and serverless functions)
  • Upstash Redis (caching)

Other Services:

  • Rewardful (affiliate and referral tracking)
  • Featurebase (product feedback collection)

Collaborative Provings: Every proving coordinator receives the observations submitted by participants, including associated privacy-sanitized image copies of notes or drawings. The coordinator chooses whether participants are identified to one another or shown anonymously; this setting does not hide a participant's identity from the coordinator.

Legal Authorities: When required by law or to protect our rights.

7. Data Retention

We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your information to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our policies.

When you delete your account or supported content, the affected data is immediately made inaccessible through the Service and removed from active storage. Deleted Cloud Storage objects can remain in a restricted soft-delete state, accessible only to authorized administrators, for up to seven days before permanent deletion from that state. Residual backup copies, where applicable, follow separate documented retention schedules and may be retained longer. When a proving coordinator deletes their account, the coordinator's identity, their own proving observations, and any retained uploads, stored as privacy-sanitized image copies, are removed. The proving is closed, but a de-identified proving record and content submitted by other participants may remain accessible to the remaining participants. When a proving participant deletes their account, that participant's proving membership, observations, and any retained uploads, stored as privacy-sanitized image copies, are removed. Some records may be retained longer where required by law or necessary to resolve disputes or enforce our agreements.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include industry-standard security measures such as:

  • Data encryption
  • Secure authentication procedures
  • Regular security assessments

9. International Data Transfers

Your personal data may be processed outside of your jurisdiction due to our use of cloud services and third-party providers. These providers may store or process your data in the European Union, United States, or other regions where they maintain facilities.

Specifically, your data may be transferred to the United States for processing by:

  • OpenAI (AI processing)
  • Google (AI processing and cloud services)
  • OpenRouter and selected underlying model providers (AI routing and processing)
  • Stripe (payment processing)
  • Deepgram (voice transcription)
  • Pinecone (vector search)

When transferring data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, adequacy decisions, or other legally valid mechanisms to protect your data in compliance with GDPR requirements.

10. Your Rights

Under the GDPR and similar data-protection regulations, you have the following rights:

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data.
  • Right to Restrict Processing: Request limitation of processing of your data.
  • Right to Data Portability: Request transfer of your data in a structured format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time.

To exercise these rights, please contact us at info@similia.io. You can also access, download, or delete your data directly through the Settings page in your user profile.

11. Children's Privacy

Our application is not intended for use by children under the age of 16. We do not knowingly collect personally identifiable information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. Please review this Privacy Policy periodically for any changes.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

SIMILIA LTD
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
info@similia.io

14. Data Protection Authority

If you are located in the European Economic Area and believe we are unlawfully processing your personal information, you have the right to complain to your local data-protection supervisory authority.

Questions about your data?

Contact us at info@similia.io

Get in Touch
Privacy Policy | Similia Homeopathy Software