Privacy Policy
How CellHood collects, uses, shares, retains, and protects personal data.
Last updated 28 August 20261. Scope
This policy applies when you visit a CellHood website, create or use a CellHood account or workspace, use the web application or Android application, contact support, or otherwise interact with CellHood. It covers personal data and also explains how confidential scientific workspace content is handled.
Other organizations and services linked from CellHood have their own privacy practices. This policy does not govern an external website merely because CellHood links to it.
2. Our role and workspace responsibilities
For account administration, authentication, billing, enquiries, service communications, security, and service-reliability data, CellHood determines how and why personal data is used. For scientific records entered into an organization’s workspace, the workspace owner or contracting organization normally determines the purpose of the processing and CellHood handles the information on its behalf.
Workspace administrators control membership, roles, permissions, and much of the content held in their workspace. If your request concerns records managed by an employer, university, laboratory, or research group, we may refer the request to that organization or assist it in responding.
Privacy questions and rights requests can be sent to [email protected] or submitted through the contact page.
3. Information we collect
- Account and profile information: name, username, work or academic email address, profile image, workspace, role, preferences, and account status.
- Authentication information: password hash, session and sign-in information, passkey public credential and device label, and, if you choose social sign-in, the provider name and stable account identifier it supplies. CellHood does not retain Google or GitHub access tokens after authentication. Fingerprint, face, device PIN, and other biometric or screen-lock data used with a passkey remain with your device or passkey provider and are not received by CellHood.
- Technical and security information: IP address, browser and device type, operating system, requested URL, referrer where supplied, timestamps, session identifiers, security events, request metadata, and limited diagnostic information needed to detect abuse, investigate incidents, and maintain reliability.
- Workspace and audit information: workspace membership, assigned permissions, attributable actions, approvals, changes, and other audit events needed to provide traceability and controlled collaboration.
- Scientific workspace content: culture and lineage records, protocols, schedules, media formulations, reagent details, microscopy images, notes, attachments, samples, outcomes, experiments, reports, and related metadata entered or imported by authorized users. Scientific content is not necessarily personal data, but CellHood treats it as confidential workspace information.
- Billing and entitlement information: selected plan, subscription status, billing period, transaction references, and entitlement data supplied by Stripe for website subscriptions or Google Play for Android-app subscriptions. CellHood does not receive or store full payment-card details.
- Android app and notification information: notification preferences, permission state, an Android Firebase Cloud Messaging registration token, app version, and limited device and technical diagnostic information. The token is used only to deliver notifications you enable and can be deactivated by disabling notifications or signing out.
- Enquiry and support information: contact details, organization, job title, team size, selected topic, correspondence, attachments you choose to provide, and information needed to investigate or respond.
- Service-use information: aggregate feature use, response times, error events, and performance measurements designed not to contain private scientific content.
4. How we obtain information
We obtain information directly from you when you register, configure an account, enter or upload workspace records, use a feature, make a purchase, or contact us. Other authorized workspace members may enter information about assigned researchers, owners, approvers, or collaborators. We also receive limited information from authentication providers, payment and app-store providers, notification services, and the browser or device used to access CellHood.
When information is supplied by another workspace member, that member and their organization are responsible for having authority to provide it and for giving any required notice to the person concerned.
5. Sensitive and regulated information
CellHood is designed for laboratory operations and is not intended to hold directly identifiable patient or research-participant records. Do not upload health data, genetic data linked to an identifiable person, or other special-category personal data unless the responsible organization has established an appropriate lawful basis, completed any required assessment, and confirmed that its agreement and configuration expressly cover that use.
Do not place passwords, payment-card details, government identifiers, or unrelated confidential personal information in free-text notes, images, attachments, or support messages.
6. Why we use information and our lawful bases
- Provide accounts and workspace features: to register users, authenticate access, store and synchronize records, run requested workflows, produce reports, and preserve traceability. This is normally necessary to perform the service requested or to take steps at your request.
- Administer organizations and permissions: to apply membership, role, approval, and access controls. This is necessary to perform the service and supports the legitimate interests of secure, accountable collaboration.
- Operate subscriptions and entitlements: to process purchases, renewals, cancellations, invoices, and plan access. This is necessary to perform a contract and, where applicable, comply with accounting or tax obligations.
- Send service communications: to deliver security alerts, configured reminders and notifications, operational notices, and replies to enquiries. This is necessary to provide the service or supports legitimate interests in communicating about it.
- Protect CellHood and its users: to prevent misuse, enforce access controls, investigate suspected incidents, maintain audit evidence, and establish or defend legal claims. This supports legitimate interests in security, integrity, and accountability and may also be required by law.
- Maintain and improve reliability: to diagnose faults, measure performance, understand aggregate feature use, and improve usability without analysing private scientific content for advertising. This supports legitimate interests in operating and improving the service.
- Comply with law: to meet legal, regulatory, court, accounting, and lawful disclosure requirements.
- Optional processing: where an activity relies on consent, you can withhold or withdraw consent without affecting processing that was lawful before withdrawal.
We do not sell personal data, use workspace content for third-party advertising, or make solely automated decisions about individuals that produce legal or similarly significant effects.
7. Feature-specific processing
CellHood AI. When you ask an AI question, your question, recent conversation context and relevant authorized culture records are sent to OpenAI to prepare an answer. Record search, history review and numerical comparison buttons run within CellHood without an AI request. Questions, answers and timestamped evidence snapshots are saved in your workspace and accessible through CellHood AI only to the account that created them. Saved evidence can include culture notes and original assay text. The assistant does not change culture records. AI requests disable response storage through the provider API; provider processing and retention remain subject to the applicable service terms.
Protocol and document import. When an authorized user deliberately starts an assisted import, the submitted file, extracted text, DOI or PMID, and relevant instructions are processed to produce a structured protocol draft for review. DOI and PMID lookups may use Unpaywall and NCBI PubMed to locate source material. The source file or webpage is not retained by the import feature after processing; the structured protocol and any information the user saves become workspace content.
Images and camera capture. Images selected, uploaded, or captured through the camera are validated and stored with the relevant controlled record when the user chooses to save them. Device camera permission is requested only when a camera feature is used. Users remain responsible for avoiding people, labels, screens, or documents containing unnecessary personal data in the frame.
Reports and exports. A report or export may contain the workspace data visible to the requesting user. The user and their organization are responsible for storing, sharing, and disposing of downloaded copies securely.
Notifications. Notifications may include identifiers, schedule information, and assigned actions. Users should consider whether lock-screen previews are appropriate for their environment and can change notification settings on their device or in CellHood.
8. Who can see workspace information
Authorized members and administrators of the relevant workspace may see information according to their role and permissions. Assigned researchers, owners, approvers, and administrators may receive notifications or see attributable activity. Closing or deleting an account does not necessarily remove that person’s name from controlled records where attribution is needed to preserve an accurate scientific or audit history.
Users must not share accounts, bypass access controls, or grant access to a person who is not authorized by the workspace.
9. Service providers and other recipients
We use service providers only where needed to operate CellHood. Depending on the feature and subscription route, recipients may include:
- Infrastructure, storage, delivery, and security: DigitalOcean and Cloudflare.
- Email delivery: Resend or the configured transactional-email provider.
- Payments and subscriptions: Stripe for website purchases and Google Play for Android-app purchases.
- Authentication: Google or GitHub when you choose the relevant sign-in option.
- Android notifications: Google Firebase Cloud Messaging when notifications are enabled.
- Optional product analytics: PostHog and Google Analytics, but only after you allow analytics through CellHood’s preference control.
- Scientific reference and assisted-import services: providers used to retrieve public source material and transform a submitted document into a protocol draft when an authorized user requests that feature.
- Professional and public authorities: advisers, auditors, insurers, regulators, courts, or law-enforcement bodies where access is lawful and necessary.
These recipients receive only the information reasonably needed for their function and are subject to applicable confidentiality, security, and data-protection obligations. We do not disclose personal data or workspace content to unrelated organizations for their own marketing.
10. International transfers
Some providers may process personal data outside the United Kingdom. Where UK data-protection law requires additional protection, transfers are based on an applicable adequacy regulation or an approved transfer mechanism, such as the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses, together with supplementary safeguards where appropriate. You may ask for more information about safeguards relevant to your personal data.
11. Retention
We keep information only for as long as it is needed for the purposes described above. The exact period depends on the kind of record, workspace instructions and settings, subscription and account status, security and recovery needs, legal or regulatory obligations, and the need to resolve disputes or preserve an accurate audit trail.
- Account and profile information: while the account is active and for a limited closure period, unless a longer period is required for security, disputes, or legal compliance.
- Workspace records: for the life of the workspace or the period selected by the responsible organization, subject to record-integrity, contractual, regulatory, and backup requirements.
- Audit and security records: for a period proportionate to traceability, incident investigation, fraud prevention, and legal requirements. Controlled or append-only events may outlast an individual account.
- Billing records: for the period required to administer the subscription and satisfy accounting, tax, fraud-prevention, and dispute obligations.
- Support and enquiry records: while the request is handled and for a reasonable follow-up or legal period.
- Notification tokens: while active and needed to send enabled notifications; removed on account deletion.
- Backups: until removed through the applicable scheduled rotation. A deleted item may therefore remain temporarily in a restricted backup before expiry.
12. Account deletion and controlled records
You can delete your account inside the Android app or, without using the Android app, by signing in to the CellHood web settings and selecting Delete account. If you cannot access your account, request deletion through the contact page or [email protected]. We may need to verify your identity before acting.
Account deletion removes sign-in access, linked social identities, API credentials, notification registrations, reminders, profile details, and the profile image. Personal data no longer required is deleted or anonymized. Controlled scientific records and append-only audit entries may remain in the workspace, with the account shown as closed, where this is necessary to preserve record integrity or meet the responsible organization’s legal, regulatory, or research-governance obligations.
Limited billing transaction data and a restricted closure record containing the account identifier, workspace, time, and reason may be retained where needed for fraud prevention, security, accounting, dispute handling, or legal compliance. If a deletion request cannot be fulfilled in full, we will explain the applicable reason.
13. Security
We use technical and organizational measures appropriate to the service, including encrypted HTTPS transport, password hashing, role-based access, workspace-scoped records, request protection, upload validation, audit logging, access-controlled storage, and restricted operational access. The Android application does not permit cleartext network traffic or Android backup of its application data.
No internet transmission or storage system is completely secure. Users should use a unique password or passkey, protect their device, review workspace membership, and report suspected unauthorized access promptly to their administrator and [email protected].
14. Cookies, device storage, and product analytics
CellHood uses cookies or similar browser storage that are necessary for sign-in, session security, request protection, and saved preferences. These essential functions do not depend on analytics consent. You can access and use CellHood without allowing optional analytics.
If you select Allow analytics, we use PostHog to understand account creation, sign-in, page-level use, and selected feature interactions so that we can improve reliability, usability, onboarding, and product decisions. The analytics record may include a pseudonymous CellHood account identifier, the stable internal name of the page or feature, account role, workspace plan, event type, time, and ordinary technical information supplied by the browser such as device, browser, operating system, approximate network-derived location, and referral category.
On public website and analyser pages, Google Analytics measures visits and clicks through to CellHood after you allow analytics. It receives public page addresses without query strings or fragments, a fixed public page title, the referring site’s origin, and browser/device information. We do not send CellHood account identifiers, private workspace pages, analysis data, uploaded images, results, or form contents to Google Analytics. Google signals and advertising personalisation are disabled.
CellHood’s analytics integration is deliberately restricted. It does not send your name or email address, private page URLs or query strings, record identifiers contained in URLs, scientific record content, protocol text, sample or batch details, form values, or uploaded files. Automatic interaction capture, session replay, surveys, and advertising profiling are disabled. We do not use analytics data to make solely automated decisions with legal or similarly significant effects.
PostHog and Google act as service providers for this optional processing and may process data in the region configured for CellHood’s analytics project. Where a transfer outside the United Kingdom requires safeguards, the measures described in section 10 apply. Analytics data is retained only for as long as reasonably needed for the improvement and security purposes described here, subject to the configured analytics retention period.
Your choice is stored in this browser. You can decline initially, continue using the service normally, or change your choice at any time using . If you withdraw consent, CellHood stops future analytics capture in that browser and clears the local PostHog and Google Analytics cookies and state it can access. Withdrawal does not affect processing that occurred lawfully before withdrawal.
We do not use third-party advertising cookies or sell analytics data.
15. Communications
We may send transactional or service messages about authentication, security, subscriptions, configured schedules, assigned work, support requests, or important service changes. Some messages are necessary to operate or secure an account and are not marketing. Optional reminders and device notifications can be controlled through CellHood or device settings.
CellHood does not currently use personal data for direct-marketing campaigns. If that changes, any required consent and opt-out controls will be provided before such messages are sent.
16. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- ask whether your personal data is being processed and receive a copy of it;
- have inaccurate or incomplete personal data corrected;
- ask for personal data to be erased in applicable circumstances;
- ask for processing to be restricted;
- receive personal data you provided in a structured, commonly used, machine-readable format where the portability right applies;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent where consent is the lawful basis, without affecting earlier lawful processing; and
- raise concerns about solely automated decisions that have legal or similarly significant effects. CellHood does not currently make such decisions about users.
Rights are not absolute. A request may involve the organization responsible for the relevant workspace, and information may be withheld where an exemption or another person’s rights apply. Send a request to [email protected]. We may verify your identity and will respond within the period required by applicable law or explain if more time or information is needed.
17. Children
CellHood is a professional laboratory service and is not directed to children. We do not knowingly create accounts for children or seek personal data from them. If you believe a child’s personal data has been provided to CellHood, contact us so the circumstances can be reviewed.
18. Complaints
Please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office or, where applicable, another supervisory authority in the place where you live or work or where the alleged infringement occurred.
19. Changes to this policy
We may update this policy when the service, processing activities, suppliers, or legal requirements change. The latest version will be published here with a revised date. Material changes will be communicated through the service or to relevant workspace administrators where appropriate.