Legal — 01
Privacy Policy.
Last updated: May 17, 2026
This policy explains what data BINTEX collects, why we collect it, who we share it with, and what rights you have. Read it before you create an account. If you don't want the things below to happen to your data, don't use BINTEX.
01 — Who We Are
BINTEX is a research intelligence platform operated by Bintex Laboratory (the "Service", "we", "us"). For privacy questions or to exercise any right described in this policy, email ahmad@bintex.life.
If you are in the UK or EU, you can also contact us at the same address regarding your data subject rights.
02 — What We Collect
Account data. Email address, password (stored hashed, never in plain text), name and any image you provide, whether your email is verified.
Profile data. Optional fields you fill in during onboarding or on your profile page — organization, research focus, research type, preferred detail level, and data sources.
Research content. The queries you run, files and URLs you attach, the reports BINTEX generates, your saved findings, and the documents you create in /write. This content is stored so you can revisit it.
Billing data. If you upgrade to Pro, our payment processor (Lemon Squeezy) collects and handles your billing details directly. We receive limited metadata — customer ID, subscription status, renewal/end dates, last 4 digits of card. We do not see or store full card numbers.
Usage data. Per-call telemetry for every AI request — model used, token counts, cost, status, latency. Used to operate the service, bill correctly, and detect abuse.
Technical data. IP address (hashed for some features, raw for short windows for rate-limiting and abuse prevention), browser and device information, approximate country from CDN signals, request timestamps.
Sharing data. If you create a public share or view someone else's, we log the share ID, a randomly generated visitor cookie, hashed IP, referrer, user-agent, country, and any UTM parameters on the URL.
Communications. Emails you send us; emails we send you (welcome, password reset, transactional notices).
What we do not do. We do not sell your data. We do not train BINTEX's models on your queries. We do not share your content with third parties beyond the AI and infrastructure providers strictly required to run the service (listed in Section 05). We do not run ad-network trackers.
03 — Why We Process Your Data (Legal Basis)
Under GDPR/UK GDPR Article 6 and equivalent provisions in other privacy laws, we rely on the following bases:
- Contract performance — running your account, delivering research outputs, processing billing.
- Legitimate interest — security, abuse prevention, fraud detection, debugging, basic analytics that let us operate at a sustainable cost.
- Consent — non-essential cookies, optional marketing communications. You can withdraw consent at any time.
- Legal obligation — keeping records of transactions for tax, responding to lawful requests from regulators or courts.
04 — Health & Special-Category Data
BINTEX supports research across many fields. The queries you run may sometimes reference health information — your own, a patient's, or a research subject's. Under GDPR Article 9, health information is a "special category" of personal data, and this section describes how we handle it when it appears in your queries.
You are responsible for the lawful basis of any identifiable health data you submit. Typically this means: it is your own data; you have explicit consent from the data subject; or the data is properly anonymised or pseudonymised before you paste it into BINTEX.
Do not submit identifiable patient data. Do not submit data you do not have authority to process. If you must discuss a real case, anonymise first.
Where you do submit health information, we process it solely to generate the report you requested, under the legal basis of your explicit consent (GDPR Art. 9(2)(a)) implied by your decision to run the query. You can withdraw that consent by deleting the session and your account.
05 — Sub-Processors
We use the following sub-processors to operate the service. Each is contractually bound to handle your data only as we instruct. Some of these process your research queries to generate responses.
| Cloudflare Workers | United States / global edge | Hosting and request routing for the application. |
| MongoDB Atlas | United States (primary region) | Primary database — accounts, queries, reports, settings. |
| Microsoft Azure OpenAI | Configured region (Microsoft cloud) | Large-language-model inference. Your query text and attached content are transmitted for processing. |
| Cohere | Canada | Large-language-model inference for certain workloads. Query text is transmitted for processing. |
| Tavily | United States | Web search for current research evidence. The search portion of your query is transmitted. |
| Upstash (Redis) | United States | Caching, rate-limit state, ephemeral debug traces (24h TTL). |
| Resend | United States | Transactional email — welcome and password reset. |
| Lemon Squeezy | United States | Payment processing. Handles all billing data directly under their own privacy policy. |
| Vercel Analytics | United States | Aggregate, anonymous page-view analytics. |
Our sub-processor list may change as we add or replace vendors. We'll update this section when it does.
06 — International Data Transfers
Some of our sub-processors are based in the United States or Canada. By using BINTEX you understand that your personal data may be transferred to, stored, and processed in those countries.
Where required, transfers from the UK/EU are protected by Standard Contractual Clauses (SCCs) approved by the European Commission or the UK ICO, supplemented by additional safeguards where appropriate.
07 — How Long We Keep Your Data
- Account data — for as long as your account is active. Deleted within 30 days of account deletion, except where law requires longer retention.
- Research sessions, findings, write documents — for as long as your account is active. Deleted with the account.
- Stuck (in-progress >2h) research sessions — auto-deleted by a database TTL after 2 hours.
- Public shares — until you revoke them or until their explicit expiry date.
- Usage events (cost telemetry) — 13 months from collection, to support billing reconciliation and abuse investigations.
- Observability traces (Redis) — 24 hours.
- Billing records — at least 7 years where required by tax law in our operating jurisdiction.
- Backups — incremental backups may retain deleted data for up to 30 days before they roll off.
08 — Your Rights
Under GDPR/UK GDPR and equivalent laws, you have the following rights. We extend most of these to all BINTEX users regardless of location.
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — delete your account and associated data (subject to legal retention obligations).
- Restriction — limit how we process your data.
- Portability — receive a machine-readable export of your account data.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for any processing based on your consent.
- Not be subject to fully automated decisions — BINTEX outputs research reports for you to use; we do not make automated decisions with legal or similarly significant effects about you.
Most of these are available directly in your account settings (export, delete). For anything else, email ahmad@bintex.life. We respond within 30 days (one month) and may extend by two months for complex requests.
10 — Security
We encrypt data in transit (HTTPS/TLS) and at rest (provider defaults — AES-256 on MongoDB Atlas, Cloudflare, Upstash). Access to production systems is restricted. We follow the principle of least privilege.
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we'll notify the relevant supervisory authority within 72 hours and notify you without undue delay where the law requires.
No service is perfectly secure. We are a small team and we run on widely-used infrastructure. If you find a vulnerability, please report it to ahmad@bintex.life.
11 — Children
BINTEX is not directed to children under 16 (or under 13 where COPPA applies). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we'll delete it.
12 — Right to Complain
If you are in the UK/EU and believe we've mishandled your data, you can lodge a complaint with your local data protection supervisory authority. We'd prefer you contact us first at ahmad@bintex.life so we have a chance to resolve it.
13 — Changes to This Policy
We update this policy as the service evolves — new sub-processors, new features, changes to law. When we make a material change we'll update the "Last updated" date at the top and, for significant changes, notify you by email or in-app. Continued use after the effective date means you accept the updated policy.
14 — Contact
Email: ahmad@bintex.life
Site: bintex.life