ReadMyReport

What happens to your lab report when you upload it

We read your report on our own server, remove your identity before anything is explained, and delete the original within seconds. Only anonymous numbers are sent over the internet to the AI, under business terms that prohibit training on your data — here is exactly how, step by step.

Exactly where your data goes

  1. 1

    Upload

    Your file arrives over an encrypted (TLS) connection into private storage. It is not public and is not shared.

  2. 2

    Reading

    Your report's text is extracted on our own server, with no third-party reading service involved. This is what turns the PDF into machine-readable values — and it means the document itself, with the name and contact details printed on it, is never sent to an outside reader.

  3. 3

    Deletion of the original

    The original file is deleted within seconds of extraction, unless you have explicitly opted into the encrypted vault to keep it.

  4. 4

    De-identification

    Before anything reaches the AI, an allowlist builder constructs the payload from scratch: an age band, sex, any conditions you typed, and the numeric values with their ranges. Names, addresses, phone numbers, doctor names, hospital IDs and dates are never included — there is no code path that copies raw report text into the AI request.

  5. 5

    Analysis

    Those anonymous numbers are sent to Google Gemini under a paid business API, whose terms prohibit using the content to train models.

  6. 6

    Storage

    If you have consented to keep history, values are stored encrypted at rest and encrypted again at the field level. If you have not, nothing is kept.

  7. 7

    Deletion, on your terms

    One click removes everything, permanently.

Why not just paste it into ChatGPT or Gemini?

A fair, factual comparison — framed as differences in design, not an attack.

What differsA consumer chatbotReadMyReport
What is sentNo guarantee

The entire document, including the name, address, doctor, hospital ID and dates printed on it.

By design

Only anonymous numbers — an age band, sex, and the values with their ranges.

Training on your contentNo guarantee

On consumer tiers, submitted content may be retained and used to improve the service, and human reviewers may see it.

By design

Paid business APIs are used, where training on the content is prohibited.

The uploaded fileNo guarantee

A general chatbot has no deletion guarantee for the uploaded file.

By design

The original is deleted within seconds by default.

Deciding a value is 'high'No guarantee

A chatbot decides whether a value is high or low from its own memory.

By design

Every flag is computed in code, against the reference range printed on your own report — the AI is never allowed to decide a range or a flag, only to explain one.

Critical-value safetyNo guarantee

A general chatbot has no critical-value safety layer.

By design

Panic values are detected deterministically in code, and the result leads with an urgent-care message.

Trends over timeNo guarantee

A chatbot has no memory of previous reports, so no trends.

By design

Values are tracked across reports over time.

Medical adviceNo guarantee

Informational only — not medical advice.

No guarantee

Informational only — not medical advice. We do not claim to be more medically accurate.

What we will never say

  • We won't tell you your report stays only on your device — its anonymous numbers are sent to Google Gemini to be explained, and that is exactly what makes the analysis possible.
  • We won't claim we cannot see your data — our servers process it to produce your results.
  • We won't claim certifications we do not hold; the certified infrastructure belongs to our providers, not to us.
  • We won't promise security that no online service can honestly guarantee — no online service can promise perfect security.

Being straight about this is the point — transparency is what makes the rest of these promises credible.

What we promise instead

  • Your name and identifying details never reach the AI — only an age band, sex, and the numeric values are sent.
  • Your original file is deleted within seconds unless you opt into the encrypted vault.
  • The AI providers operate under business API terms that prohibit training on your data.
  • Stored values are encrypted in transit, at rest, and again at the field level.
  • Your data is never sold, and never shared with advertisers or data brokers.
  • You can delete everything permanently, anytime.
  • The infrastructure our providers run on is SOC 2 Type II / ISO 27001-certified — that describes them, not a certification we claim for ourselves.
  • No online service can promise perfect security, and we won't pretend otherwise.

Frequently asked questions

Does my report go to the internet?
The anonymous numbers do. Your report's text is read on our own server, with no outside reading service, so the document itself is never sent to a third party. Then only an age band, sex and the values with their ranges are sent over an encrypted connection to Google Gemini to be explained.
Can your staff read my results?
Our servers process your report to produce your results, and access is restricted and audited. We do not sell or share your data, and identifying details are removed before analysis.
Is my name sent to the AI?
No. The payload sent to the AI is built from an allowlist — an age band, sex, any conditions you typed, and the numeric values with their ranges. Your name, address, phone number, doctor and hospital IDs are never included.
Is the AI trained on my report?
No. The analysis runs on paid business APIs whose terms prohibit using your content to train models.
What if I want nothing stored?
Storage is opt-in. If you do not consent to keep history, your values are not stored, and the original file is deleted within seconds after it is read.
How do I delete everything?
One click removes your data permanently, at any time.
Is this HIPAA compliant?
HIPAA is a United States healthcare-privacy framework; this service is built for India and operates under the Digital Personal Data Protection (DPDP) framework. We do not claim a HIPAA certification. What we can point to is concrete: de-identification before analysis, deletion by default, field-level encryption, and business API terms that prohibit training on your data.

See it on your own report

Upload a report to see the de-identified, in-code flagging in action.

Analyze a report (free)