Privacy Policy

Your privacy matters. Learn how we collect, use, and protect your data.

Privacy Policy

Last Updated: September 7, 2026

1. Introduction

SIMILIA LTD (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and application at https://www.similia.io/.

We are the data controller for the processing of personal information described in this policy. If you have any questions about this Privacy Policy or our practices, please contact us at info@similia.io.

2. Information We Collect

Personal Information: We collect information that identifies, relates to, or could reasonably be linked with you, including:

  • Email address
  • Account credentials
  • Display name (if provided)

Usage Data: We automatically collect information about your interactions with our application, including:

  • Log and usage data (IP address, browser type, referring/exit pages)
  • Device information (device type, operating system)
  • Cases and repertorizations data
  • Feature usage and interaction data

Collaborative Proving Data: When you join a proving, we collect your proving membership and the observations you submit, including typed or transcribed text and privacy-sanitized image copies derived from uploaded handwritten notes or drawings. Before a proving JPEG, PNG, or WebP image is sent for AI processing or saved to Cloud Storage, it is re-encoded server-side and its location and device metadata and embedded profiles, including EXIF, XMP, IPTC, and ICC data, are removed. The proving coordinator receives participant observations and associated privacy-sanitized image copies.

Device Fingerprint Data: We collect device-specific information including browser type, screen resolution, hardware specifications (such as CPU cores and device memory), timezone, and other technical identifiers. This data is used to detect unauthorized account sharing and improve security.

Voice and Audio Data: When you use Live Audio or upload a prerecorded proving recording, your audio is transmitted to and processed by Deepgram to create a transcript. Prerecorded proving audio is temporary and is not retained as an attachment to the proving. After transcription, it is removed from active storage and made inaccessible through the Service. The deleted Cloud Storage object can remain in a restricted soft-delete state, accessible only to authorized administrators, for up to seven days before permanent deletion from that state. Any residual backup copy, where applicable, follows a separate documented retention schedule. A Business Associate Agreement (BAA) and zero-data-retention controls apply to Deepgram processing only when they are respectively contractually applicable and configured.

AI-Processed Content: When you use our AI-powered features (such as notes analysis, image analysis, visual symptom extraction, transcription, or semantic search), your content is transmitted to and processed by third-party services that may include OpenAI, Google, OpenRouter, and Deepgram. OpenRouter acts as an AI processor and routing service and may send a request to a selected underlying model provider. Provider retention and model-training treatment vary by service and configuration. Zero-data-retention, no-training, BAA, or similar safeguards apply only where enabled for the relevant account or request and contractually applicable. Similia does not use this content to train its own AI models. This processing is necessary to provide these features.

3. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: For certain data-processing activities, we rely on your explicit consent.
  • Contractual Necessity: To perform our contractual obligations to you, including providing our services.
  • Legitimate Interests: To pursue our legitimate business interests, such as improving our services and ensuring security.
  • Legal Obligation: To comply with applicable laws and regulations.

4. How We Use Your Information

We use your information for the following purposes:

  • To provide and maintain our services
  • To personalize your experience
  • To communicate with you about your account or our services
  • To improve our application
  • To protect against fraudulent or illegal activity
  • To process payments and manage subscriptions
  • To send marketing communications (with your consent)
  • To provide customer support

5. Cookies and Similar Technologies

Similia stores information in your browser only for the purposes listed here. We do not use advertising cookies, we do not record your sessions, and we never place patient information in a cookie.

Your choice. The first time you visit, a small notice at the bottom of the page lets you allow or refuse statistics (the second group below). You can change that choice at any time under "Cookie settings" — in the footer of every public page, in the menu inside the app, or in Settings → Privacy & consent. Your choice is stored in one cookie (similia_consent) for six months and applies to the browser you made it in. If your browser sends a Global Privacy Control signal, statistics stay off until you say otherwise. Where we must obtain consent first (the EU/EEA, the United Kingdom, Switzerland, Turkey, Brazil, Israel and Canada, and whenever we cannot tell where you are), statistics stay off until you allow them; elsewhere they run until you switch them off. We keep a record of each choice — a random receipt id, the time, your choice, how you made it, whether your browser sent a Global Privacy Control signal, the version and language of the notice shown, your region as a country group (never an IP address) and, if you are signed in, your account id — for three years as proof of consent.

Strictly necessary — always on; Similia does not work without them:

  • __session, similia_has_session — keeps you signed in (Similia, 14 days).
  • NEXT_LOCALE — remembers your language (Similia, 1 year).
  • similia_consent — stores your cookie choice (Similia, 6 months).
  • theme, appZoom, similia:* browser storage — display preferences and cached prices (Similia, until you clear them).
  • Firebase Auth, rubric and offline caches (browser storage) — sign-in state and offline use (Similia, until you sign out or clear the site).
  • _vcrcs — protection against automated traffic (Vercel, 1 hour).
  • crisp-client/* — the support chat inside the app, so a conversation can continue and you can see our replies (Crisp, 6 months). It is loaded only for signed-in users inside the app, never on public pages.

Also always on: anonymous website statistics by Vercel (Web Analytics and Speed Insights). They use no cookies and store nothing in your browser; a visitor hash derived from your connection is reset daily and cannot be traced back to you. Addresses of pages inside the app are reduced to their pattern before they are sent, so no case, note or share identifiers leave your browser.

Statistics — only when you allow them:

  • _ga, _ga_* — Google Analytics: a pseudonymous visitor id so we can see how the site is used (Google, up to 2 years).
  • similia_attr — remembers how you found us (campaign parameters and the referring site) so we know which channels work (Similia, 90 days).
  • Performance timing — page-load and request timing measured in your browser and attached to our error reports, only while statistics are allowed (Sentry, EU; nothing stored in your browser). The performance of our own servers is monitored separately and involves no data from your browser.

Partner referral — only if you followed a partner link:

  • rewardful.referral — applies the partner discount and credits the partner who referred you (Rewardful, 60 days). This cookie is set only when you arrive through a partner link; it is not controlled by the statistics choice, because switching it off would cost you the discount you clicked for. You can remove it at any time with "Forget referral" in Cookie settings.

Loaded only when you use them: the feedback board (Featurebase) inside the app stores an identifier once you open it; embedded videos play through youtube-nocookie.com and load only when you press play, after which YouTube sets its own identifiers; Stripe sets its own cookies on its checkout pages.

Error monitoring (Sentry, hosted in the EU) runs on every page without cookies: when something breaks, we receive the error, the page pattern and, for signed-in users, your account id — never patient content.

Feature-usage analytics for signed-in users (Mixpanel, hosted in the EU) is not a cookie: our servers record which features you use and where they fail, under your account id, after you have accepted the data-processing notice. We rely on our legitimate interest in keeping the service working; you can object at any time with the "Feature-usage analytics" switch in Settings → Privacy & consent (with it off, we have less to go on when you ask for support) or by e-mailing info@similia.io. No health data or patient information is ever sent to Mixpanel.

You can also instruct your browser to refuse or delete cookies. If you refuse the strictly necessary ones, you will not be able to stay signed in.

6. Data Sharing and Disclosure

We may share your information with the following categories of service providers:

Analytics and Monitoring Providers:

  • Mixpanel (server-side feature-usage analytics for signed-in users, EU-hosted, legitimate interest with opt-out)
  • Google Analytics (website statistics, only while you allow statistics)
  • Vercel Web Analytics and Speed Insights (anonymous, cookieless website statistics)
  • Sentry (error tracking and monitoring, EU-hosted)

AI and Machine Learning Service Providers:

  • OpenAI (AI analysis and image processing; BAA and zero-data-retention controls where configured and contractually applicable)
  • Google Generative AI (semantic search, embeddings, and image or AI processing; privacy controls depend on the applicable account and service configuration)
  • OpenRouter (AI processing and routing for image and other AI requests; requests may be sent to selected underlying model providers)
  • Deepgram (voice-to-text transcription; BAA and zero-data-retention controls where configured and contractually applicable)
  • Pinecone (vector database for semantic search)

Payment Processors:

  • Stripe (subscription and payment processing)

Communication and Marketing Services:

  • Brevo (transactional e-mail and, if you opted in, newsletters)
  • Crisp (support chat inside the app)

Infrastructure and Hosting:

  • Firebase (authentication and database)
  • Vercel (hosting and serverless functions)
  • Upstash Redis (caching)

Other Services:

  • Rewardful (partner referrals, only if you followed a partner link)
  • Featurebase (product feedback, only when you open the feedback board)
  • YouTube / Google (embedded videos, only when you press play)

Collaborative Provings: Every proving coordinator receives the observations submitted by participants, including associated privacy-sanitized image copies of notes or drawings. The coordinator chooses whether participants are identified to one another or shown anonymously; this setting does not hide a participant's identity from the coordinator.

Legal Authorities: When required by law or to protect our rights.

7. Data Retention

We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your information to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our policies.

When account or supported content deletion completes, the affected data is immediately made inaccessible through the Service and removed from active storage. Deleted Cloud Storage objects can remain in a restricted soft-delete state, accessible only to authorized administrators, for up to seven days before permanent deletion from that state. Residual backup copies, where applicable, follow separate documented retention schedules and may be retained longer. When a proving coordinator deletes their account, the coordinator's identity, their own proving observations, and any retained uploads, stored as privacy-sanitized image copies, are removed. The proving is closed, but a de-identified proving record and content submitted by other participants may remain accessible to the remaining participants. When a proving participant deletes their account, that participant's proving membership, observations, and any retained uploads, stored as privacy-sanitized image copies, are removed. Some records may be retained longer where required by law or necessary to resolve disputes or enforce our agreements.

Billing analytics: Similia keeps a billing analytics ledger containing a pseudonymous account identifier, Stripe customer, payment, subscription and refund identifiers, transaction amounts and delivery receipts. The ledger is normally retained for 400 days to reconcile payments and later refunds, and is removed when account deletion completes. Minimal notification and retry records are normally retained for 90 days; these contain Stripe event and resource identifiers, event type, times, attempts and outcomes, but no account identifier, Stripe customer identifier, contact details or patient content. Scheduled cleanup is bounded and may take longer during a backlog. Deleting this ledger does not itself erase Stripe financial records or events previously sent to analytics providers; those records follow the applicable provider retention and data-rights processes.

Cookie choices: we keep the receipt of each cookie choice — a random receipt id, the time, the choice, how it was made, whether the browser sent a Global Privacy Control signal, the version and language of the notice, the region as a country group (never an IP address) and, for signed-in users, the account id — for three years, as proof that consent was given or refused. When an account is deleted, its receipts are kept but the account id in them is replaced by an irreversible hash.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include industry-standard security measures such as:

  • Data encryption
  • Secure authentication procedures
  • Regular security assessments

9. International Data Transfers

Your personal data may be processed outside of your jurisdiction due to our use of cloud services and third-party providers. These providers may store or process your data in the European Union, United States, or other regions where they maintain facilities.

Specifically, your data may be transferred to the United States for processing by:

  • OpenAI (AI processing)
  • Google (AI processing and cloud services)
  • OpenRouter and selected underlying model providers (AI routing and processing)
  • Stripe (payment processing)
  • Deepgram (voice transcription)
  • Pinecone (vector search)
  • Vercel Inc. (hosting, edge network and anonymous website statistics; certified under the EU-U.S. Data Privacy Framework)
  • Rewardful (partner referrals, only if you followed a partner link; standard contractual clauses)

When transferring data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, adequacy decisions, or other legally valid mechanisms to protect your data in compliance with GDPR requirements.

10. Your Rights

Under the GDPR and similar data-protection regulations, you have the following rights:

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data.
  • Right to Restrict Processing: Request limitation of processing of your data.
  • Right to Data Portability: Request transfer of your data in a structured format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time.

To exercise these rights, please contact us at info@similia.io. You can also access, download, or delete your data directly through the Settings page in your user profile.

11. Children's Privacy

Our application is not intended for use by children under the age of 16. We do not knowingly collect personally identifiable information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. Please review this Privacy Policy periodically for any changes.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

SIMILIA LTD
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
info@similia.io

14. Data Protection Authority

If you are located in the European Economic Area and believe we are unlawfully processing your personal information, you have the right to complain to your local data-protection supervisory authority.

Questions about your data?

Contact us at info@similia.io

Get in Touch