Legal — 01

Privacy Policy.

Last updated: May 17, 2026

This policy explains what data BINTEX collects, why we collect it, who we share it with, and what rights you have. Read it before you create an account. If you don't want the things below to happen to your data, don't use BINTEX.

01 — Who We Are

BINTEX is a research intelligence platform operated by Bintex Laboratory (the "Service", "we", "us"). For privacy questions or to exercise any right described in this policy, email ahmad@bintex.life.

If you are in the UK or EU, you can also contact us at the same address regarding your data subject rights.

02 — What We Collect

Account data. Email address, password (stored hashed, never in plain text), name and any image you provide, whether your email is verified.

Profile data. Optional fields you fill in during onboarding or on your profile page — organization, research focus, research type, preferred detail level, and data sources.

Research content. The queries you run, files and URLs you attach, the reports BINTEX generates, your saved findings, and the documents you create in /write. This content is stored so you can revisit it.

Billing data. If you upgrade to Pro, our payment processor (Lemon Squeezy) collects and handles your billing details directly. We receive limited metadata — customer ID, subscription status, renewal/end dates, last 4 digits of card. We do not see or store full card numbers.

Usage data. Per-call telemetry for every AI request — model used, token counts, cost, status, latency. Used to operate the service, bill correctly, and detect abuse.

Technical data. IP address (hashed for some features, raw for short windows for rate-limiting and abuse prevention), browser and device information, approximate country from CDN signals, request timestamps.

Sharing data. If you create a public share or view someone else's, we log the share ID, a randomly generated visitor cookie, hashed IP, referrer, user-agent, country, and any UTM parameters on the URL.

Communications. Emails you send us; emails we send you (welcome, password reset, transactional notices).

What we do not do. We do not sell your data. We do not train BINTEX's models on your queries. We do not share your content with third parties beyond the AI and infrastructure providers strictly required to run the service (listed in Section 05). We do not run ad-network trackers.

03 — Why We Process Your Data (Legal Basis)

Under GDPR/UK GDPR Article 6 and equivalent provisions in other privacy laws, we rely on the following bases:

  • Contract performance — running your account, delivering research outputs, processing billing.
  • Legitimate interest — security, abuse prevention, fraud detection, debugging, basic analytics that let us operate at a sustainable cost.
  • Consent — non-essential cookies, optional marketing communications. You can withdraw consent at any time.
  • Legal obligation — keeping records of transactions for tax, responding to lawful requests from regulators or courts.

04 — Health & Special-Category Data

BINTEX supports research across many fields. The queries you run may sometimes reference health information — your own, a patient's, or a research subject's. Under GDPR Article 9, health information is a "special category" of personal data, and this section describes how we handle it when it appears in your queries.

You are responsible for the lawful basis of any identifiable health data you submit. Typically this means: it is your own data; you have explicit consent from the data subject; or the data is properly anonymised or pseudonymised before you paste it into BINTEX.

Do not submit identifiable patient data. Do not submit data you do not have authority to process. If you must discuss a real case, anonymise first.

Where you do submit health information, we process it solely to generate the report you requested, under the legal basis of your explicit consent (GDPR Art. 9(2)(a)) implied by your decision to run the query. You can withdraw that consent by deleting the session and your account.

05 — Sub-Processors

We use the following sub-processors to operate the service. Each is contractually bound to handle your data only as we instruct. Some of these process your research queries to generate responses.

Cloudflare WorkersUnited States / global edgeHosting and request routing for the application.
MongoDB AtlasUnited States (primary region)Primary database — accounts, queries, reports, settings.
Microsoft Azure OpenAIConfigured region (Microsoft cloud)Large-language-model inference. Your query text and attached content are transmitted for processing.
CohereCanadaLarge-language-model inference for certain workloads. Query text is transmitted for processing.
TavilyUnited StatesWeb search for current research evidence. The search portion of your query is transmitted.
Upstash (Redis)United StatesCaching, rate-limit state, ephemeral debug traces (24h TTL).
ResendUnited StatesTransactional email — welcome and password reset.
Lemon SqueezyUnited StatesPayment processing. Handles all billing data directly under their own privacy policy.
Vercel AnalyticsUnited StatesAggregate, anonymous page-view analytics.

Our sub-processor list may change as we add or replace vendors. We'll update this section when it does.

06 — International Data Transfers

Some of our sub-processors are based in the United States or Canada. By using BINTEX you understand that your personal data may be transferred to, stored, and processed in those countries.

Where required, transfers from the UK/EU are protected by Standard Contractual Clauses (SCCs) approved by the European Commission or the UK ICO, supplemented by additional safeguards where appropriate.

07 — How Long We Keep Your Data

  • Account data — for as long as your account is active. Deleted within 30 days of account deletion, except where law requires longer retention.
  • Research sessions, findings, write documents — for as long as your account is active. Deleted with the account.
  • Stuck (in-progress >2h) research sessions — auto-deleted by a database TTL after 2 hours.
  • Public shares — until you revoke them or until their explicit expiry date.
  • Usage events (cost telemetry) — 13 months from collection, to support billing reconciliation and abuse investigations.
  • Observability traces (Redis) — 24 hours.
  • Billing records — at least 7 years where required by tax law in our operating jurisdiction.
  • Backups — incremental backups may retain deleted data for up to 30 days before they roll off.

08 — Your Rights

Under GDPR/UK GDPR and equivalent laws, you have the following rights. We extend most of these to all BINTEX users regardless of location.

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — delete your account and associated data (subject to legal retention obligations).
  • Restriction — limit how we process your data.
  • Portability — receive a machine-readable export of your account data.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — for any processing based on your consent.
  • Not be subject to fully automated decisions — BINTEX outputs research reports for you to use; we do not make automated decisions with legal or similarly significant effects about you.

Most of these are available directly in your account settings (export, delete). For anything else, email ahmad@bintex.life. We respond within 30 days (one month) and may extend by two months for complex requests.

09 — Cookies

We use a small number of first-party cookies. Where required by law, we ask for your consent before setting non-essential cookies.

CookieTypePurposeLifetime
bintex.session_tokenEssentialKeeps you signed in. Without it, the app cannot work.30 days
bintex_visitorAnalyticsRandom ID used to count unique visitors on public shares.1 year
bintex_refAnalyticsRecords which shared report a visitor came from, so the author can see attribution.60 days
bintex_utmAnalyticsRecords which campaign or referral link brought a visitor to the site, so we can measure that campaign’s reach.60 days

We do not use third-party advertising cookies. We do not use cross-site tracking pixels.

How to change your choice. The cookie consent banner appears on your first visit. After that, you can re-open it any time via the "Cookie preferences" link in the site footer. We re-prompt for consent at least every six months.

Global Privacy Control (GPC). If your browser sends the GPC signal, we automatically treat you as having opted out of analytics and attribution cookies — no banner interaction required. You can verify this is honoured by inspecting the cookie that is (or isn't) set after a page load.

Email open tracking. Marketing emails sent from BINTEX (announcements, product updates, never password resets or other transactional messages) embed a 1×1 invisible image hosted by Resend. When your email client loads images, Resend records that the message was opened. This is not a cookie; it is a one-time image request. To stop receiving these messages — and the open signal that comes with them — click the "Unsubscribe" link in the footer of any marketing email.

10 — Security

We encrypt data in transit (HTTPS/TLS) and at rest (provider defaults — AES-256 on MongoDB Atlas, Cloudflare, Upstash). Access to production systems is restricted. We follow the principle of least privilege.

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we'll notify the relevant supervisory authority within 72 hours and notify you without undue delay where the law requires.

No service is perfectly secure. We are a small team and we run on widely-used infrastructure. If you find a vulnerability, please report it to ahmad@bintex.life.

11 — Children

BINTEX is not directed to children under 16 (or under 13 where COPPA applies). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we'll delete it.

12 — Right to Complain

If you are in the UK/EU and believe we've mishandled your data, you can lodge a complaint with your local data protection supervisory authority. We'd prefer you contact us first at ahmad@bintex.life so we have a chance to resolve it.

13 — Changes to This Policy

We update this policy as the service evolves — new sub-processors, new features, changes to law. When we make a material change we'll update the "Last updated" date at the top and, for significant changes, notify you by email or in-app. Continued use after the effective date means you accept the updated policy.

14 — Contact