Legal

Privacy policy.

Last updated:

This policy explains what personal data we process when you use HumanMetrica, why, and how you can exercise your rights. It is written in plain language on purpose.

1. Who is responsible

HumanMetrica is operated jointly by Daniel Porcelli, Nicolás Noblia and Rodrigo Cabot, based in Uruguay. For any privacy enquiry, write to nicolasnoblia@gmail.com.

Processing is governed by Uruguayan Law No. 18.331 on the Protection of Personal Data and Habeas Data. The supervisory authority is the Unidad Reguladora y de Control de Datos Personales (URCDP), with which you may lodge a complaint if you believe your rights have not been respected.

2. Radiographs are never transferred or stored

HumanMetrica does not receive, transmit or store the medical images you open with the tool.

The DICOM file is opened and decoded entirely inside your browser tab, on your own computer. It is not uploaded to any server, not written to any database, and does not pass through our infrastructure at any point. This is not a policy we promise to follow: it is a property of how the application is built.

As a result, we do not process health data or patient personal data. Any sensitive data contained in a radiographic study remains under the exclusive control of the clinician who opens it, who remains the controller of that data with respect to the patient.

You can verify this yourself: open your browser developer tools, go to the Network tab, and load a radiograph. You will see no request carrying image data.

3. What we do process

We process only what an account requires:

  • Email address, to create your account, sign you in, and contact you about the service.
  • Full name, if you choose to provide it. It is optional.
  • Tool preferences: language, default limb side, and lateral view orientation.
  • Technical operating data generated by our infrastructure providers, such as IP address, browser type and access logs, used for security and diagnostics.

If you later enable the measurement history feature, the numeric values of your measurements are stored alongside a label you choose yourself. That label is a code of your choosing: the application explicitly instructs you not to use a patient name. Images are never stored.

We use no advertising cookies, perform no cross-site tracking, and do not sell or share data with third parties for commercial purposes.

4. Purpose and legal basis

We process your data to provide the service you asked for by creating an account: to authenticate you, remember your preferences, and contact you about how the service works. The legal basis is the performance of that relationship and your consent, given at registration.

You may withdraw consent at any time by deleting your account, which removes your data as described below.

5. Cookies

We use only strictly necessary cookies to keep you securely signed in. We use no analytics, advertising or third-party cookies. If you block these cookies you will not be able to sign in.

6. Providers and international transfers

We rely on the following providers, acting as data processors:

  • Supabase — database and authentication. Account data is hosted in the São Paulo, Brazil region.
  • Vercel — web application hosting and content delivery.
  • Transactional email — account confirmation and password reset — is sent through Supabase infrastructure.

These providers may process data outside Uruguay. Where they do, we require appropriate contractual guarantees of confidentiality and security. Note that because images are never transferred, no health data crosses any border.

7. Retention

We keep your account data for as long as the account is active. If you request deletion, the data is permanently removed, except where a legal obligation requires us to retain it. Technical security logs are kept for a limited period and then deleted.

8. Security

We apply reasonable technical and organisational measures, including:

  • Encryption in transit via HTTPS across the whole service.
  • Passwords stored as hashes; nobody on the team can read them.
  • Database-level isolation: each user can only reach their own records.
  • Checks against public breached-password lists at registration.

No system is infallible. If we detect a security incident affecting your data, we will tell you and notify the supervisory authority where required.

9. Your rights

You may exercise your rights of access, rectification, update, inclusion and deletion of your personal data at any time, as well as the habeas data action provided for in Law No. 18.331. To do so, write to nicolasnoblia@gmail.com from the address associated with your account.

The right of access may be exercised free of charge at intervals of no less than six months, unless a legitimate interest justifies a shorter interval. We respond within the periods set by the applicable regulations.

The Unidad Reguladora y de Control de Datos Personales (URCDP), as the supervisory authority, is empowered to hear complaints from persons whose rights have been affected by non-compliance with data protection rules.

10. Minors

HumanMetrica is intended for healthcare professionals. It is not directed at anyone under 18, and we do not knowingly collect data from minors.

11. Changes to this policy

If we change this policy, we will update the date shown at the top. If the change is material and affects how your data is processed, we will tell you by email before it takes effect.