Privacy policy · effective August 7, 2026
Two kinds of people are on this page.
The firm using Slicefield, and the people whose medical imaging is inside the cases it holds. They are not the same people, and a privacy policy that pretends otherwise is wrong from its first sentence — so this one keeps them apart throughout. Questions are welcome at support@slicefield.com.
The short version
Case imaging lives on hardware we rent and control in Germany, on an encrypted volume that comes back locked after any restart — not in a shared consumer cloud. We process it only on the firm’s instructions: we do not read it, never use it to train anything, and never sell or share it. Sharing is off until the firm creates a link, and every access lands on an append-only ledger the firm can print. Deleting really deletes, with two honest caveats: encrypted backups expire within 30 days, and a matter under a legal hold cannot be deleted until the hold lifts.
Who we are, and which hat we wear
Slicefield is made by Oran Dynamics Ltd., Nutgrove, Tynagh, Loughrea, Ireland. For the firm’s own data — accounts, billing, site analytics — we are the data controller. For the imaging and records inside a matter, the roles reverse: the firm is the controller and we are a processor, handling that material only to run the service the firm asked for. The firm — not us — holds the legal basis for the case file, which in litigation is typically the establishment, exercise or defence of legal claims, a client authorization, or a discovery obligation. Our terms bind us to process on those instructions and no further.
If you are a person whose scan is inside a case here: the party handling your matter — the law firm — is who decides what happens to it, and requests about it should go there first. Matters on our systems are keyed by opaque identifiers, so from a name alone we usually cannot tell which firm’s matter concerns you; where we lawfully can, we will help route a request to the right controller.
The imaging in a case
A DICOM study usually carries personal details written by the hospital — a patient name, date of birth, sex, medical record and accession numbers, study dates, the institution, the referring physician — alongside the images. This is health data, the most sensitive thing we hold, and it is handled accordingly:
Where it lives. On a dedicated server we rent and control from Hetzner in Falkenstein, Germany. Study data sits on a volume encrypted with LUKS2 whose key is not stored on the machine — after any restart the volume is locked and nothing is served until an operator unlocks it by hand. To be precise rather than flattering: this covers the study data and the database; the operating-system disk is not encrypted. Everything travels over HTTPS, and Cloudflare provides DNS for this domain without proxying it — traffic carrying imaging goes straight to our server and never passes through their network.
What we do with it. An upload is converted once into a form the viewer can draw quickly, and small previews are generated. That is all. Studies are immutable once ingested, and the original files are kept byte-for-byte as received, so a production ships what arrived. We do not read scans, no employee looks at them, and they are never used to train machine-learning models — ours or anyone else’s. Server access is limited to the people who operate it, for operating it.
Accounts
An account is an email address, a random identifier, and the sign-in sessions it has open. Sign-in uses one-time emailed links and codes rather than passwords we could lose; they expire in 15 minutes and are stored only as one-way hashes. Signing in with Google gives us the identifier and email address Google releases — never a password. To make lists load quickly we keep a few fields read from each study — patient name, description, dates — in the database, which lives on the same encrypted volume as the studies.
Share links, and the people you send them to
Sharing is off until the firm mints a link, and each link carries a role — expert, recipient, or intake — plus whatever the firm chose: expiry, passcode, download permission, watermark. About the people on the other end of a link we hold what the firm gives us (a label such as a name, optionally an email address) and what using the link creates: every open is recorded on the matter’s append-only audit ledger with its time and IP address. That ledger is a legal artifact the firm can print for a court — it is the product, not a by-product — so entries are never edited or deleted by anyone, including us, and it is retained as long as the matter exists. Firms should tell their recipients that access is logged. An expert’s annotations and written report are stored beside the matter and are frozen once submitted.
An intake link works in the other direction — an outside party, such as an imaging provider or records vendor, uses it to deliver records into the matter. What they send, and when, is recorded the same way.
What stays out of our logs and URLs
Pages and studies are addressed by opaque keys, so patient names and case captions never appear in a web address — and cannot end up in browser histories or proxy logs. Search runs in your browser, over data already on the page; searching a name never becomes a network request. The web server keeps ordinary access logs for up to 30 days for security and fault-finding, and they are filtered before being written: uploaded file names (which often contain patient surnames), sign-in tokens, and cookies are all stripped. Application error logs record exception class names only — never messages, which can carry file names.
Payments
Payments are processed by Stripe. Card details go to Stripe and never reach us. When a matter is paid for, what rides to Stripe is an opaque matter identifier — never the caption, never a party’s name — so your payment records name your cases to you, not to your payment processor. The seller is Oran Dynamics Ltd.; purchase and tax records are kept as long as the law requires.
Usage analytics, and measuring our own ads
To see which features are used and where errors happen, the site sends usage events to PostHog, our analytics provider, from our own first-party script. The discipline is structural, not aspirational: DOM autocapture is off, session recording is off, event properties come from a fixed app-authored vocabulary — never file names, study titles, or free text — and URLs are scrubbed of query strings and study identifiers before anything is sent. Events are tied to the same random account identifier, never to a name.
When a visitor arrives from one of our own Google ads, the click identifier from the ad lands in a first-party cookie, and if that visitor later subscribes we report the conversion to Google server-side, with a one-way hash of the email address — never the address itself, and never anything from any case. We show no ads, set no third-party advertising cookies, and do no cross-site tracking.
Deleting things, and how long anything lasts
Deleting a study removes its files and database rows immediately; deleting an account removes everything — studies, matters, share links, sessions, the email address. What survives is a single line recording that an account was deleted, when, and how much space was freed; it contains no name and nothing from any case. The honest windows around “immediately”:
Unclaimed uploads are deleted automatically within 24 hours. Encrypted backups — made nightly, encrypted before they leave the machine, integrity-checked — expire within 30 days. Access logs: up to 30 days. Sign-in links and codes: 15 minutes, hash-only. The audit ledger lives and dies with its matter. Accounts idle for two years are deleted with their contents, after a warning email a month ahead. And the one deliberate exception: a matter under a legal hold cannot be deleted — by you or by our automation — until the hold lifts. Placing and releasing a hold are both ledger events.
If legal process is served on us
If we receive a subpoena or similar process naming a customer’s matter, our posture is notice and narrowness: we notify the firm promptly unless the law forbids it, so the firm can object in the underlying case, and we produce no more than the narrowest lawful scope. A firm’s own notes and annotations are treated as attorney work product and are not produced without a specific, contested court order naming them.
Service providers
Hetzner Online GmbH (Germany) operates the data centre our server sits in — the one provider whose hardware holds case imaging. Cloudflare provides DNS (not proxying this domain) and stores our backups, which are encrypted before they leave our machine, so it holds only unreadable data. Stripe processes payments. Postmark (ActiveCampaign) sends our emails and receives email addresses only. PostHog (US) receives the usage events described above. Google receives sign-in identity for accounts that choose Google, and the hashed ad-conversion reports described above. None of Stripe, Postmark, PostHog or Google ever receives medical imaging or anything read from inside it. Where a provider processes data outside the EEA, transfers rely on safeguards such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
Your rights
Firm users can read, export and delete their own data self-serve — studies, matters and the whole account — without asking us. Depending on where you live you may also have rights to access, correct, delete or receive a copy of your personal data, to object to or restrict processing, and to complain to a supervisory authority; we are established in Ireland, so ours is the Irish Data Protection Commission. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act. For people whose data is inside a case, those rights run first against the controller of the case — normally the firm — and we support the firm in honouring them, as a processor should.
Our legal bases, where we are the controller: performing our contract (accounts, billing), legal obligation (tax records), and legitimate interest (security, abuse prevention, and the analytics described above — which you may object to). Case imaging is processed on the firm’s documented instructions, under the firm’s own basis. If your checklist requires a business associate agreement, our BAA template is in counsel review — ask us where it stands.
Changes, and where the mechanisms are
If this policy changes, the new version appears here with a new date, and meaningful changes are called out to account holders. The security mechanisms this page leans on — the locked volume, the ledger, quarantine, holds — are described in working detail on the security page, which exists to be read.
Read the terms · Read the refund policy · support@slicefield.com