Privacy Policy
Last Updated
2 October 2026
Scope
This Privacy Policy applies to personal information processed through ChatIBD via our website (chatibd.com), APIs and related online offerings (collectively, “Services”). ChatIBD is operated by Dr Shaun Chuah as a University of Glasgow academic project. Data controller arrangements are described in the Supplemental UK GDPR Notice.
FOR EEA, SWITZERLAND & UK RESIDENTS: see our Supplemental GDPR Notice.
Personal Information We Collect
The categories of personal information we collect depend on how you interact with us, our Services and the requirements of applicable law. We collect information that you provide to us, information we obtain automatically when you use our Services, and information from other sources such as third-party services and organizations, as described below.
Information You Provide to Us Directly
We may collect the following personal information that you provide to us.
- Account Creation. We may collect information when you create an account, such as a unique customer ID or an email address or phone number.
- Your Communications with Us. We may collect personal information, such as email address, phone number, or mailing address when you request information about our Services, request technical support, participate in approved research or evaluation studies, or otherwise communicate with us.
- Surveys. We may contact you to participate in surveys. If you decide to participate, you may be asked to provide certain information which may include personal information.
- Chat Messages. We process chat messages submitted by users to provide responses, maintain conversation history for registered users, monitor safety, quality and performance, identify and investigate errors or failure modes, troubleshoot technical issues, and improve the Service. Chat messages may be analysed automatically for these purposes. A limited number of conversations, including responses flagged by automated monitoring or user feedback, may also be reviewed by authorised members of the ChatIBD team where necessary for safety, quality assurance, troubleshooting or investigation. Routine operational monitoring is separate from research participation. Where chat messages are used for formal academic research, this will only occur where separately consented or otherwise lawfully approved as described below.
- No Patient-Identifiable Information. Users must not submit directly identifiable patient information, including names, CHI/NHS numbers, dates of birth, addresses, contact details, hospital numbers, or free-text extracts from records that could identify an individual. If such information is submitted, we may delete, redact, or restrict processing of it where practicable.
Information Collected Automatically
We may collect personal information automatically when you use our Services.
- Automatic Data Collection When You Visit Our Website. We may collect certain information automatically when you use our Services, such as your Internet protocol (IP) address, user settings, cookie identifiers, browser or device information, approximate location derived from IP address, and Internet service provider. We may also automatically collect information regarding your use of our Services, such as pages that you visit before, during and after using our Services, information about the links you click, the types of content you interact with, the frequency and duration of your activities, and other information about how you use our Services.
- Automatic Data Collection When You Use Our Services. We may collect other types of technical information about your use of our Services, such as telemetry metrics, to help operate, secure, troubleshoot, and improve our Services.
- Cookies, Pixel Tags/Web Beacons, and Other Technologies. We and our service providers may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through your use of our Services.
Cookies
Cookies are small text files placed in device browsers that store preferences and facilitate and enhance your experience.
We use the following cookies and similar browser storage:
| Name / key | Type | Purpose | Duration |
|---|---|---|---|
| Clerk session cookies | Cookie (third party) | Authentication and account access | Set by Clerk; see Clerk privacy documentation |
guest_session_id | Cookie (first party, httpOnly) | Scope guest chat ownership to the browser | 30 days |
sidebar:state | Cookie (first party) | Remember sidebar open/closed preference | 7 days |
| Theme preference | localStorage (first party) | Remember light/dark/system theme choice | Until cleared |
| Chat draft input | localStorage (first party) | Preserve unsent message text while composing | Until cleared |
We do not use a cookie consent banner. The cookies and storage listed above are used to operate the Service, maintain your session, or remember interface preferences.
Pixel Tags/Web Beacons
A pixel tag (also known as a web beacon) is a piece of code embedded in our Services that collects information about engagement on our Services. The use of a pixel tag allows us to record, for example, that a user has visited a particular web page or interacted with a service feature. We may also include web beacons in emails to understand whether service messages have been opened or acted on.
Error and performance monitoring
We use third-party tools to monitor errors and performance in our Services.
- Sentry – We use Sentry, a service provided by Functional Software, Inc., to collect information about errors and performance issues in our Services. Sentry collects information about your device, browser, and the specific error or performance issue encountered. Sentry session replay is not enabled. Sentry’s collection and use of information about you is governed by the Sentry privacy policy available at https://sentry.io/privacy.
Information Collected from Other Sources
We may obtain information about you from third-party services that support account access, authentication, analytics, error monitoring, hosting, or other Service operations.
How We Use Your Information
We use your information to provide, secure, evaluate, and improve the Services, as described below.
Provide Our Services
We use your information to fulfill our contract with you and provide you with our Services, such as:
- Managing your information and accounts;
- Providing access to certain areas, functionalities, and features of our Services;
- Answering requests for customer or technical support;
- Communicating with you about your account, activities on our Services, and policy changes;
- Processing chat messages to generate responses and maintain conversation history where that feature is available;
- Allowing you to register for approved events or studies.
Administrative Purposes
We use your information for various administrative purposes, such as:
- Pursuing legitimate interests such as service operation, network and information security, misuse prevention, safety monitoring, quality assurance, performance monitoring, and functionality improvement;
- Detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity, and prosecuting those responsible for that activity;
- Measuring engagement in our Services;
- Improving, upgrading and enhancing our Services, including evaluating changes to models, prompts, retrieval systems, safeguards and other functionality;
- Monitoring response quality, safety and performance, including identifying errors, recurring failure modes and areas where the Service may require improvement;
- Conducting internal quality assurance, including automated evaluation and limited review by authorised members of the ChatIBD team where appropriate;
- Authenticating and verifying individual identities;
- Debugging to identify and repair errors with our Services;
- Auditing relating to interactions, transactions and other compliance activities;
- Enforcing our agreements and policies;
- Complying with our legal obligations.
Safety and Quality Monitoring
We monitor ChatIBD to understand how the Service performs in real-world use and to identify potential safety or quality issues. This may include automated analysis of chat messages and responses for characteristics such as response quality, clinical safety, citation support and potential errors.
Automated monitoring may flag particular responses for further investigation. Where appropriate, a limited number of flagged conversations may be reviewed by authorised members of the ChatIBD team. We do not routinely require every conversation to be read by a person.
Information from this monitoring may be used to investigate errors, improve prompts, retrieval systems, models, safeguards and other features, develop internal quality measures, and evaluate whether changes to ChatIBD improve its performance.
This operational monitoring forms part of running and improving the Service and is separate from formal academic research.
Service Communications
We may use personal information to send service-related communications, such as account notices, technical updates, policy changes, support responses, and information about approved research or evaluation opportunities where appropriate. We do not use ChatIBD to deliver personalised advertising.
Other Purposes
We also use your information for other purposes as requested by you or as permitted by applicable law.
- Consent. We may use personal information for other purposes that are clearly disclosed to you at the time you provide personal information or with your consent.
- De-identified and Aggregated Information. We may use information processed through the Service to create aggregated, statistical or appropriately de-identified information about the use, safety and performance of ChatIBD. This may include measures such as usage patterns, response-quality measures, citation performance, categories and frequencies of errors, and safety-monitoring metrics. We may use and publish such information to evaluate and improve the Service and to help users understand its capabilities and limitations. Published aggregate information will not be intended to identify individual users.
- Representative Examples of Failure Modes. To help explain the capabilities and limitations of ChatIBD, we may publish synthetic, reconstructed or substantially reworded examples illustrating types of errors or failure modes identified through routine monitoring. These examples may be informed by issues observed during operation of the Service but will be presented in a way designed to avoid disclosing an individual user's conversation or personal information. Where an example is synthetic or reconstructed, we will describe it as such.
- Academic Research. Routine operation, safety monitoring, quality assurance, product analytics and improvement of ChatIBD are separate from formal academic research participation. Where we wish to use conversation-level data to create a research dataset or undertake formal academic research, we will do so only under a separate approved research notice and consent process or another lawful basis approved through the relevant governance route. Routine use of ChatIBD does not by itself enrol a user into a research study.
How We Disclose Your Information
We disclose your information to third parties where needed to provide the Services, protect users and the Service, comply with law, or support approved research or formally governed evaluation, as described below.
Disclosures to Provide our Services
The categories of third parties with whom we may share your information are described below.
- Service Providers. We may share your personal information with third-party service providers who use that information to help us provide the Services. This includes service providers that support hosting, authentication, error monitoring, IT support, and related services. Our current list of subprocessors is published at chatibd.com/subprocessors.
- Model and AI Infrastructure Providers. To provide, evaluate, monitor and safeguard the Service, chat messages and model responses may be processed by third-party AI or model infrastructure providers acting as service providers or processors. This may include providers used to generate ChatIBD responses and providers used for automated safety, quality or performance evaluation. The providers we use are named in our subprocessor list. We apply contractual, technical and organisational safeguards where appropriate.
- APIs/SDKs. We may use third-party Application Program Interfaces (“APIs”) and software development kits (“SDKs”) as part of the functionality of our Services. For more information about our use of APIs and SDKs, please contact us as set forth below.
- Research Collaborators. If an approved research program is active, we may share research-eligible, minimised, or de-identified data with approved academic collaborators, ethics partners, and service providers who support the study.
Disclosures to Protect Us or Others
We may access, preserve, and disclose any information we store associated with you to external parties if we, in good faith, believe doing so is required or appropriate to: comply with law enforcement or national security requests and legal process, such as a court order or subpoena; protect your, our, or others’ rights, property, or safety; enforce our policies or contracts; collect amounts owed to us; or assist with an investigation or prosecution of suspected or actual illegal activity.
Disclosure in the Event of Service Transfer
If responsibility for operating ChatIBD transfers to the University of Glasgow, a University-approved operator, or another lawful service provider, your information may be transferred as part of that transition as permitted by law and applicable governance arrangements.
Your Privacy Choices and Rights
The privacy choices you may have about your personal information are determined by applicable law and are described below.
Email Communications.
If you receive a non-essential email from us, you may contact us to opt out of similar future messages. You will continue to receive service-related emails such as account, security, technical support, research-consent, or policy notices where appropriate.
“Do Not Track.”
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.
Cookies.
You may stop or restrict the placement of Technologies on your device or remove them by adjusting your preferences as your browser or device permits. However, if you adjust your preferences, our Services may not work properly.
Your Privacy Rights.
In accordance with applicable law, you may have the right to:
- Access Personal Information about you, including: (i) confirming whether we are processing your personal information; (ii) obtaining access to or a copy of your personal information; and (iii) receiving an electronic copy of personal information that you have provided to us, or asking us to send that information to another company (the “right of data portability”);
- Request Correction of your personal information where it is inaccurate or incomplete. In some cases, we may provide self-service tools that enable you to update your personal information;
- Request Deletion of your personal information;
- Request Restriction of or Object to our processing of your personal information; and
- Withdraw your Consent to our processing of your personal information.
If you would like to exercise any of these rights, please contact us as set forth below. We will process such requests in accordance with applicable laws.
Security of Your Information
We take steps to ensure that your information is treated securely and in accordance with this Privacy Policy. Unfortunately, no system is 100% secure, and we cannot ensure or warrant the security of any information you provide to us. We have taken appropriate safeguards to require that your personal information will remain protected and require our third-party service providers and partners to have appropriate safeguards as well. To the fullest extent permitted by applicable law, we do not accept liability for unauthorized disclosure. By using our Services or providing personal information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of our Services. If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice on our Services, by mail or by sending an email to you.
International Data Transfers
Personal information may be transferred, processed, and stored in countries outside the UK or EEA where our service providers operate, including the United States. This includes chat messages and model responses: our AI models are hosted by Microsoft Azure, which uses EU data centres by default, but we do not guarantee EU-only processing, and some models are served from deployments that may process data in the United States. We use safeguards intended to protect your information consistent with applicable data protection laws. If you are a resident of the European Economic Area, Switzerland, or the United Kingdom, please see our supplemental GDPR notice here.
Retention of Personal Information
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Service, maintaining conversation history where applicable, safety and quality monitoring, security, troubleshooting, auditing, resolving disputes and complying with legal obligations.
Retention periods may differ according to the type of information and its purpose. Where information is no longer required in identifiable or user-linked form, it may be deleted or converted into aggregated or appropriately de-identified information. Aggregated information that does not identify an individual may be retained for longer periods to measure the safety, performance and development of the Service.
Information may also remain temporarily in backups or logs in accordance with our technical and security processes.
Research Participation
Routine use of ChatIBD, including operational safety monitoring, quality assurance, service analytics and product improvement, is separate from formal research participation.
If an approved research programme is active, participation will be governed by the relevant research information, consent and privacy materials. Chat messages will only be included in a formal research dataset where the user has provided consent through an approved research consent process, or where another lawful basis has been approved through the relevant governance route.
Users may withdraw from a research programme without deleting their ChatIBD account. Withdrawal from research does not prevent continued routine use of the Service.
Children's Information
Our Services are not intended for use by children under the age of 16. If we become aware that a child has provided us with personal information in violation of applicable law, we will delete any personal information we have collected.
Supervisory Authority
If you are in the EEA, Switzerland or the UK, you have the right to lodge a complaint with your local data protection authority.
Changes to This Privacy Policy
We may update this policy from time to time. Material changes will be published on this page with an updated “Last updated” date. By continuing to use our Services after changes take effect, you accept the revised policy.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
ChatIBD
Email: privacy@chatibd.com