Legal
Privacy Policy
This policy explains what information Cell-First Clinical Analysis™ — a product of Kelly Brink LLC — collects from practitioners, how it is used and protected, and the choices available to account holders.
Effective August 24, 2026. Last updated August 24, 2026.
1. Design principle: no patient identifiers
The application is built so that patient identity is never required. A case is identified only by a system-generated Case ID together with age and biological sex. Case labels, audit records, support tickets, and billing records carry no patient name.
Practitioners must not enter patient names, dates of birth, medical record numbers, contact details, insurance identifiers, or identifiable laboratory reports anywhere in the application. Information entered in breach of this instruction remains the responsibility of the practitioner who entered it.
2. Information collected
- Account information — email address, authentication credentials managed by the authentication provider, plan and role, and account timestamps.
- De-identified case content — Case ID, age, biological sex, chief concerns, symptoms, history, medications, supplements, laboratory values, notes, and generated analysis and reports.
- Billing information — plan, subscription status, case credit balance and ledger, invoice history, and payment processor identifiers. Full card numbers are never received or stored by the application; they are handled by the payment processor.
- Support information — the content of support requests, ticket status and messages, and any screenshot attached by the sender.
- Technical information — authentication session data, application error logs, and basic request metadata used to operate and secure the service.
3. How information is used
- To provide the application: storing cases, running calculations and clinical analysis, and generating reports.
- To administer accounts, entitlements, case credits, subscriptions, invoices, and renewals.
- To send transactional messages such as purchase confirmations, low case-credit notices, billing alerts, and support responses.
- To provide support and to investigate reported problems.
- To secure the service, prevent abuse, and maintain audit records of case lifecycle actions.
- To meet legal, tax, and accounting obligations.
Case content is not sold, rented, or used for advertising, and is not used to build profiles of individuals.
3a. Product usage analytics and feedback
The application records first-party product usage events — for example that a case was created, that a reasoning screen was opened, or that a report was generated — so that the product can be measured and improved. These events describe product behavior only.
- No patient or client content is recorded in analytics: no names, dates of birth, laboratory values, symptoms, medications, narrative, reasoning text, or report content.
- The visible Case ID is not stored in analytics. Where a case must be counted, a one-way correlation code is used that cannot be reversed to the Case ID.
- No third-party advertising, tracking, or session-replay provider is used for authenticated clinical activity.
- Aggregate metrics may be reported internally or to prospective partners. Individual practitioners are not named in those summaries.
- Feedback you submit is voluntary. Contact, interview, and public-use permissions are separate and default to private; nothing is published without your explicit approval of the exact wording, and permission may be withdrawn at any time.
- Raw product events are retained for an operational period (by default approximately thirteen months) and aggregate metrics may be retained longer.
4. Case isolation
Cases belong to the account that created them. Access controls at the database level restrict each account to its own cases, entitlements, invoices, and support tickets. Administrative access is limited to designated administrator accounts and is used for support, billing correction, and clinical rule maintenance.
De-identified case content is stored server-side in the account’s own protected records, which are the authoritative copy. The browser keeps only a short-lived working cache of the case currently open; that cache is bound to the signed-in account and is cleared when the account changes or when the practitioner signs out, so case work does not persist for another user of the same device.
5. Service providers
The application relies on a small number of processors acting on documented instructions: a cloud database, authentication, and file storage provider; a payment processor for subscriptions, checkout, and invoices; an email delivery provider for transactional messages; and hosting infrastructure. These providers receive only the information needed to perform their function.
6. Retention
- Case records and analysis are retained while the account is active and until the practitioner deletes them.
- Deleted cases are removed from the working application; audit entries recording the lifecycle action are retained for integrity purposes and reference only the Case ID.
- Billing records, invoices, and the case credit ledger are retained as required for financial and tax purposes.
- Support tickets and attachments are retained while needed to resolve the request and for a reasonable period afterwards.
7. Security
Information is transmitted over encrypted connections and stored with access restricted by row-level security policies tied to the signed-in account. Support screenshots are held in private storage readable only by administrators. Privileged operations such as credit adjustment and clinical rule changes are audited. No system can be guaranteed absolutely secure; suspected unauthorized access should be reported immediately.
8. Practitioner choices and rights
- Case content can be exported through the report generator and archived or deleted from the case list.
- Billing alert emails can be turned off in the billing area; essential transactional messages such as receipts and account notices continue.
- An account holder may request access to, correction of, or deletion of their account information by contacting support.
- Depending on residence, additional rights may apply under state or national privacy law; requests are handled in accordance with applicable law.
9. Cookies and local storage
The application uses browser storage for the authentication session, interface preferences, onboarding state, and the active case workspace. These are functional and are not used for advertising or cross-site tracking.
10. Regulatory note
Because the application is designed to hold de-identified information only, it is not offered as a repository for protected health information, and no business associate agreement is implied by these terms. Practitioners subject to HIPAA or comparable obligations remain responsible for ensuring that information is appropriately de-identified before entry. See the Terms of Service for the corresponding obligations.
11. Children
The application is intended for professional use by adults. Accounts are not offered to individuals under eighteen years of age.
12. Changes to this policy
This policy may be updated as the application evolves. The effective date above reflects the current version, and material changes will be communicated to account holders.
Contact
Privacy questions and requests may be directed to:
Cell-First Clinical Analysis Support
A support request can also be submitted from the Contact & Support page. Do not include patient names, dates of birth, medical record numbers, or other protected health information in any message.

