Privacy Policy
Last updated 17 August 2026
The Pan-Cancer Spatial Atlas (PCSA) at pcsa.stomics.io is operated by
The Allman Institute for Personalized Medicine ("the Institute", "we", "us"). This page
explains what the platform records about you, what happens to the slides you upload, and
how to have any of it removed. Questions about it go to
support@stomics.io.
1. Information you give us
When you register we hold your email address and a bcrypt hash of your password. The password itself is never stored in readable form. If you turn on two-factor authentication, the TOTP secret is encrypted in the database and your backup codes are kept only as SHA-256 digests, so nobody at the Institute can read either of them back. API tokens you generate for pipeline access are held so that requests carrying them can be matched to your account.
Everything else you give us comes from uploads: the whole-slide image files themselves, their filenames, and any metadata you attach to them such as cancer type, cohort or free-text notes.
2. Information the platform generates
Running an analysis produces TLS counts, maturation classifications and region coordinates, all of which are stored against the slide. Tiling produces a pyramid of image tiles derived from your file so the viewer can pan and zoom. Alongside these we keep job status and error messages, and ordinary web server logs containing IP address, browser user agent, request path and timestamp. Logs are used to debug failures and to deal with abuse.
3. Patient information
PCSA is a research platform and was not built to hold identifiable patient information. The Institute has not entered into a Business Associate Agreement covering this service, and you should not treat it as HIPAA-compliant storage. Remove direct identifiers from filenames and from embedded slide metadata before you upload. If you realise that something identifiable has been uploaded, delete the slide from your dashboard and write to support@stomics.io so that copies in tile storage and in backups can be dealt with.
4. How the information is used
- Running the analyses you request and showing the results back to you.
- Sending account mail: confirmation, password reset, account unlock, and analysis completion notices if you have those switched on.
- Keeping the service secure. That covers rate limiting, blocking scanner traffic, and locking an account after repeated failed sign-in attempts.
- Improving the models and checking their quality, which section 5 covers in detail.
We do not sell personal information. The site carries no advertising and no third-party analytics trackers.
5. Anonymized slide data
Slide images, the tiles and features derived from them, and the analysis results produced from them may be retained in anonymized form and used to train, evaluate and quality-check the models behind PCSA. Anonymized means identifiers are removed from the file, its name and its embedded metadata before the material is used this way, and that results of such use are reported in aggregate or in a form that identifies neither a patient, nor a submitting account, nor a contributing institution. Section 6 of the Terms of Service sets out the licence this rests on.
Write to support@stomics.io if you would rather your material was left out. Exclusion applies to future training and evaluation sets: a model that has already been trained cannot be untrained, so tell us early if this matters to you.
6. Where the data is held
The platform runs in Amazon Web Services, in the US East (Northern Virginia) region. Slide files and tiles are stored in Amazon S3 with server-side encryption; accounts, slide records and analysis results are stored in Amazon RDS PostgreSQL. Traffic to the site is HTTPS only. Analysis runs on GPU instances inside the same AWS account, so your slides are not sent to any external model provider.
7. Who can see your data
Your slides and their results are visible to your own account. Institute staff holding administrator rights can see slide records and analysis status, and use that access to answer support requests and investigate failures. Amazon Web Services provides the hosting, storage and email delivery underneath all of this, acting on our instructions and holding no independent right to your material. Nobody else is given access.
8. Retention and deletion
A slide stays until you delete it or ask for your account to be closed. Deleting a slide removes the original file, its tile pyramid and its analysis records. Encrypted backups of the database and of storage can still contain a copy for a period after that, until those backups reach the end of their normal cycle and expire. Server logs are kept for a limited period for security and debugging, then discarded. Anonymized material already folded into a training set cannot reliably be traced back and pulled out, which is why section 5 asks you to opt out in advance if you intend to.
9. Cookies
PCSA sets a session cookie to keep you signed in and a CSRF token to protect form submissions. There are no advertising cookies and no cross-site trackers. Clearing cookies signs you out.
10. Your choices
You can read and change your account details on the Account settings page, export analysis results as JSON or CSV from any slide or through the REST API, and delete individual slides whenever you like. Account deletion, and requests to access, correct or port the information we hold, go to support@stomics.io. Statutory privacy rights vary by where you live; we handle these requests the same way for everyone rather than sorting accounts by jurisdiction.
11. Children
PCSA is built for researchers and clinicians. It is not directed at children, and accounts are not offered to anyone under 16.
12. Changes to this policy
When our practices change we update this page and move the date at the top. If a change materially affects how your data is handled, registered account holders are emailed before it takes effect.
13. Contact
The Allman Institute for Personalized Medicine, support@stomics.io.