Privacy Policy

MAIND PATH™ research platform, operated by HCMA AI · Effective 28 August 2026 · Last updated 28 August 2026

This Privacy Policy explains what information HCMA AI ("HCMA AI", "we", "us") handles when you visit ai.histopathology.cloud or use the MAIND PATH research platform, and how we handle data accessed through Google APIs. We have written it to describe what the platform actually does, rather than to reserve rights we do not exercise.

Summary. MAIND PATH is an internal research platform. It does not offer public sign-up, it has no "Sign in with Google" feature, and it never requests access to the Google account of a visitor, partner or any other third party. It connects to a single Google Drive account owned by HCMA AI and uses it to store HCMA AI's own research files. We do not sell personal information and we do not use any data for advertising.

1. Who we are and how to reach us

HCMA AI is a healthcare-artificial-intelligence company established in the Kingdom of Saudi Arabia. HCMA AI is the controller of the information described in this policy.

We aim to answer any privacy request sent to that address within 30 days.

2. Information we handle

2.1 Visitors to this website

The public pages of this site (this page, the home page and the Terms of Service) do not require an account, do not use advertising or analytics trackers, and do not set cookies for tracking. Our web server keeps standard technical logs — IP address, date and time, the page requested, HTTP status and browser user-agent — which we use only to operate the service and to investigate faults and abuse. These logs are retained for up to 90 days and then deleted.

2.2 Platform users

Access to MAIND PATH is limited to accounts created by HCMA AI for our own research team. For each such account we store a name, an email address and a hashed password, together with session records and an audit trail of actions taken in the platform. Accounts are not available through public registration.

2.3 Research material

The platform processes whole-slide pathology images and their associated study metadata. Our current datasets are publicly available, de-identified research datasets — including TCGA, GTEx and BRACS — which are distributed for research use and contain no direct patient identifiers. Material contributed by a partner institution is de-identified by that institution before it reaches us and is handled under the written agreement with them. We do not seek, and do not knowingly hold, direct patient identifiers such as names, national identity numbers, contact details, or full dates of birth.

3. Data accessed through Google APIs

MAIND PATH uses Google Drive as the storage backend for the large image files and derived artefacts it produces. This section describes that use in full.

3.1 Whose Google account is used

The platform is authorised against one Google account, owned and controlled by HCMA AI. That authorisation is performed once by an HCMA AI administrator. The platform does not offer Google sign-in to anyone else, and it cannot access the Google account of a visitor, a research partner, or any other person.

3.2 Scope requested and why

Scope Why the platform needs it
https://www.googleapis.com/auth/drive The platform creates and maintains its own folder hierarchy in the HCMA AI Drive account; uploads whole-slide images, image tiles, extracted feature files and trained model checkpoints; reads those files back for processing; and deletes superseded artefacts so storage does not grow without limit. It also has to read slide files that an administrator has placed in the account manually rather than through the platform, which a create-only scope would not permit.

We request no other Google API scope. In particular, the platform does not access Gmail, Google Contacts, Google Calendar, Google Photos, or any Google account profile data beyond what is strictly required to complete the Drive authorisation.

3.3 What is stored in Google Drive

These are HCMA AI's own research assets. No personal information about website visitors or platform users is written to Google Drive.

3.4 Limited Use commitment

MAIND PATH's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Concretely, this means that data obtained through Google APIs is:

3.5 Withdrawing access and deleting data

The Google account owner can revoke the platform's access at any time from the Google account security settings, at myaccount.google.com/permissions. Revoking access stops all further reading and writing by the platform immediately; files already in the Drive account remain under the account owner's control and can be deleted there. A request to delete data we hold can also be sent to histopathology.2026.3.5@gmail.com.

4. How we protect information

No system can be guaranteed perfectly secure. We work to protect information using measures appropriate to its sensitivity, but we cannot promise absolute security.

5. Sharing and sub-processors

We do not sell personal information and we do not share it for advertising. We rely on a small number of infrastructure providers to run the platform:

These providers act on our instructions. We may also disclose information where we are legally required to do so, or to establish or defend a legal claim.

6. International transfers

The providers listed above operate data centres in several countries, so information may be processed outside the Kingdom of Saudi Arabia. Where that happens we rely on the contractual protections offered by those providers.

7. Retention

8. Your rights

Subject to applicable law, including the Saudi Personal Data Protection Law, you may ask us to confirm what personal data we hold about you, to provide a copy of it, to correct it, to delete it, or to restrict how we use it. Send any such request to histopathology.2026.3.5@gmail.com. We do not use your data for automated decision-making that produces legal effects concerning you.

9. Children

MAIND PATH is a professional research tool. It is not directed at children, and we do not knowingly create accounts for anyone under 18.

10. Changes to this policy

If we change this policy we will update the effective date shown at the top of this page and publish the revised version here. Where a change materially affects how we handle data obtained through Google APIs, we will describe that change in the updated text.

11. Contact

Questions, complaints or requests about this policy: histopathology.2026.3.5@gmail.com.