Your Privacy
How your information is collected, processed, and protected.
Effective date: July 28, 2026. Version 1.1.
Built on trust.
Privacy and security are not features of this platform. They are its foundation. Every architectural decision was made with participant protection as the first and non-negotiable requirement: how data is stored, how it is processed, who can see it, and under what conditions.
Most of this requires no AI.
The majority of participation on this platform is straightforward. You read a question, you select an answer or type a response, and your answer is stored directly. The text you enter in any field goes to a structured database exactly as you wrote it. No AI reads it, processes it, or interprets it at the point of submission.
Where AI does appear in the questionnaire experience, it is on the output side: the contextual narration and feedback you receive as you complete a module. That narration is AI-generated. Your responses are not. What you contribute is yours, stored as you wrote it. What the platform returns to you as context or feedback is AI-assisted.
Where AI is used for document processing.
The platform includes an optional capability for contributing text records you already have: radiology reports from your MRI imaging, results from ancestry services, lab results from your care team or MyChart, Epstein-Barr serology results, blood panels, and similar records. You paste the text as it appears. The platform processes it.
Processing these records into structured, queryable data requires AI assistance. Every area of the platform that uses AI is clearly labeled. Record contribution is entirely optional, as is every other area of the platform.
The AI here is not the AI you are used to.
Consumer AI tools process and may retain what you share with them. The AI on this platform is prohibited by law from doing either. A HIPAA Business Associate Agreement governs every AI interaction on this platform. That is the same legal standard that applies to your hospital's electronic health records. No data submitted here can be stored, retained, or used for any purpose beyond the moment it takes to process your request.
How AI processing is protected.
When you paste a text record for processing, it is handled by an AI model operating under a HIPAA Business Associate Agreement. This agreement is a formal legal contract that prohibits the AI provider from storing, logging, or retaining any data submitted. Your text passes through the AI layer, is processed, and is immediately discarded. It is never retained, never used to train any model, and never accessible again outside your session.
This is a fundamentally different standard from using any consumer AI tool. Most AI interfaces people encounter day to day are governed by general terms of service. This platform's AI processing is governed by a HIPAA-compliant business associate agreement, the same standard applied to any covered entity handling protected health information. Your data is protected by contract, not just policy.
HIPAA compliance across the full technology stack.
The AI layer is not the only component of this platform that operates under a formal HIPAA agreement. Every part of the technology stack that handles participant data is hosted on enterprise infrastructure operating under an executed Business Associate Agreement with WeCureUs. These agreements cover every service that touches participant data, from authentication to data storage to AI processing to email delivery.
No aspect of participant data handling takes place outside of a formal BAA framework. These agreements do not make the platform HIPAA compliant on their own. Correct configuration, access controls, encryption, and audit logging are equally required and equally in place. The BAAs establish the legal accountability. The architecture and configuration enforce it.
How contributed records are processed.
When you paste a text record, a structured extraction process classifies the document, extracts the meaningful fields, and matches the findings to a controlled vocabulary. Only the resulting structured data is stored. The text you paste is processed once and immediately discarded; it is never retained. Each stored record is version-tagged with the vocabulary version used, so researchers know exactly what process generated any record they are querying. A separate confidence-checking pass that runs after a record is stored is a planned future enhancement, not something in place today.
How your identity is protected.
Your responses are never stored alongside your name, date of birth, or any direct identifier. All data is linked to a pseudonymous code. Your account contact information, including the email address and phone number associated with your account, is stored in a completely separate system that is never joined to the research dataset. The two are architecturally designed to remain permanently separate.
No query returns results for fewer than five participants. This k-anonymity threshold is enforced at the disclosure layer before any output reaches a researcher. Individual records are never exposed.
Our commitment not to re-identify you.
We commit publicly, and not merely internally, to the following. We will process aggregate community statistics only in a de-identified form. We will not attempt to re-identify any participant from them. We will not attempt to link them back to any individual, and we will not permit anyone else to do so.
That commitment is binding on everyone who receives data from us. Every registered researcher agrees, as a condition of access, that they will not attempt to re-identify any participant, will not attempt to defeat the five-participant threshold by combining results, and will impose the same obligations on anyone they pass results to. We can revoke access, and we will.
We are stating this on a public page on purpose. A promise made only in an internal policy is worth less than one made where you can hold us to it.
Where your data is stored and processed.
All WeCureUs data is stored and processed in the United States. WeCureUs is a United States company, incorporated in Oregon, and it operates no infrastructure outside the United States.
Identity information, module responses, and contributed records are stored in databases hosted by Google Cloud Platform in the us-central1 region, in Council Bluffs, Iowa. The AI document processing described above runs on Amazon Web Services Bedrock in the us-east-1 region, in Northern Virginia. Transactional email is delivered by Paubox, and text messages, where a participant has opted in, by Twilio. All are United States companies.
If you are in Canada, this means your personal information is transferred to, stored in, and processed in the United States, and once it is there it is subject to United States law. United States government authorities may be able to compel access to it under lawful process such as a subpoena, a court order, or a warrant, and under United States national security and surveillance laws. Some of those processes can be carried out without notice to you and without notice to us. We hold Business Associate Agreements with Google Cloud Platform, Amazon Web Services, and Paubox, and those agreements bind them to protect your information, but no contract can prevent a lawful government demand in the country where data is held. We would rather tell you that plainly than imply our agreements make your data immune from legal process.
What we do about it is limit how much any single demand could reach. Identity information and health data sit in separate databases linked only by an anonymous identifier. The research query system is architecturally prevented from reaching identity information at all. Researchers never receive individual-level data, only aggregate statistics that suppress any group smaller than five people. And you can delete everything at any time, immediately and unconditionally.
How long we keep your data.
While your account is open we keep your responses and contributed records, because the scientific value of this platform is longitudinal. One answer is a data point. The same question answered over several years is evidence of how a disease actually progresses, which is the thing that has been missing from multiple sclerosis research and the reason this platform exists.
Two things we would rather state plainly than leave you to assume. First, we do not currently set a fixed maximum retention period, and we do not automatically delete or anonymise the accounts of people who stop using the platform. We consider that an open item, we intend to define maximum retention periods and an inactivity policy, and we will publish them here before we adopt them. Second, the control that matters most already works: you can delete everything at any time, immediately, with no conditions, no waiting period, and no reason required.
Deletion is complete. It removes your identity record, the link between your identity and your health data, every response, every contributed record, every consent record, and your sign-in credentials, across all three databases. One audit row survives, holding a one-way cryptographic hash of your user identifier so that we can prove the deletion happened. It contains no name, no email address, no phone number, and no health information, and because the original identifier is destroyed in the same operation the hash cannot be matched back to you.
Records of privacy or security incidents are kept for at least twenty four months under Canadian federal law, and at least five years where Quebec law applies. Researcher query logs record which queries were run and by which registered researcher; they contain no participant identity and no individual-level data.
Cookies.
WeCureUs uses cookies only where they are necessary for the platform to work and to keep your account secure. When you sign in to the participant portal, a single session cookie named __session is placed in your browser. It is marked HttpOnly, so no script running on the page can read it. It is marked Secure, so it is only ever sent over an encrypted connection. It is marked SameSite=Lax, which limits it to requests that originate from WeCureUs rather than being carried along from other websites. Its only job is to confirm that you are signed in as you move between pages. It holds no advertising identifier and builds no profile of you. It expires after at most fourteen days, and that window resets each time you return, so an inactive session ends on its own.
Two parts of the platform use security services that guard against automated abuse: the contact form on the public site, and the phone verification step during enrollment. These services may set their own strictly necessary cookies for the single purpose of telling a real person apart from an automated bot. They are not used to advertise to you and do not track you across other websites.
WeCureUs sets no advertising cookies, no analytics cookies, and nothing that profiles you or follows you across the web. We do not sell your data. You stay in control of cookies at all times. Every major browser lets you view, block, or delete cookies through its settings, and you can clear the WeCureUs session cookie at any time by signing out or by clearing your browser data. Blocking the session cookie will keep you from staying signed in to the participant portal, but the rest of the public site remains fully readable.
Your rights.
You can review, edit, or delete any response you have submitted at any time. You can stop participating at any time. You can request deletion of your entire record. None of these actions require contacting anyone. They are available directly within your account.
You also have the right to ask what we hold about you, to ask us to correct it, to withdraw a consent you previously gave, and to ask us to delete it. If you make a request in writing we will answer within thirty calendar days. If we ever need longer we will tell you before those thirty days are up, explain why, and give you the name of a person to escalate to. If we say no to any part of your request we will tell you why in writing, and we will tell you how to challenge that decision, including how to reach the regulator in your jurisdiction.
We do not treat people differently for exercising any of these rights. Using them will never affect your access to the platform.
Who is responsible, and how to complain.
Randy Strome is WeCureUs, Inc.'s Chief Privacy Officer and Chief Information Security Officer. Privacy and security questions, access and correction requests, and complaints all reach that office at hello@wecureus.com, addressed to the Privacy Officer, or by post to WeCureUs, Inc. in Hood River, Oregon, United States.
Please tell us first, and here is the practical reason why, not just the polite one. Several privacy regulators, including the commissioners in Alberta and British Columbia, will normally decline to look at a complaint until you have raised it with the company and given it around thirty business days to respond. The federal Privacy Commissioner of Canada says the same, that it may not be able to accept a complaint if you have not tried the organisation first. So going to us first is not us protecting ourselves, it is the step that keeps your regulatory options open. That is also why we commit above to answering within thirty calendar days, which is tighter than the window those regulators allow us.
You are never required to accept our answer, and more than one regulator may be able to help you. We are not going to tell you that only one office has jurisdiction, because that is frequently not true and it is not our call to make.
If you are in the United States
The Office for Civil Rights at the U.S. Department of Health and Human Services accepts health privacy complaints through its portal at ocrportal.hhs.gov, or by telephone on 1-800-368-1019, TDD 1-800-537-7697. Note the deadline carefully, because it is commonly misunderstood: a complaint must normally be filed within 180 days of when you knew or should have known about the problem, not within 180 days of the problem itself. The Secretary can waive that for good cause.
If you are in Canada
Because your information crosses the border into the United States, the federal law that applies is PIPEDA and the office that oversees it is the Office of the Privacy Commissioner of Canada. You can file at priv.gc.ca, or call 1-800-282-1376, or write to 30 Victoria Street, Gatineau, Quebec K1A 1H3. There is no fixed filing deadline; the test is a reasonable period of time.
If you live in Quebec you may also go to the Commission d'accès à l'information du Québec at cai.gouv.qc.ca, or call 1 888 528-7741. If you are contesting a refusal of access or correction, that office has a hard thirty day deadline. If you live in Alberta you may also go to the Office of the Information and Privacy Commissioner of Alberta at oipc.ab.ca, or call 1 888 878 4044. If you live in British Columbia you may also go to the Office of the Information and Privacy Commissioner for British Columbia at oipc.bc.ca, or call 250 387-5629.