Privacy Policy
Effective August 2, 2026
Slicora is a DICOM viewer for looking at your own medical scans. It comes in two forms, and which one you use decides where your scans live. That difference is the most important thing on this page, so it comes first. Questions are always welcome at support@slicora.app.
Slicora for iPhone & iPad
Your scans never leave your device. There is no account, no upload, and no copy we could look at even if we wanted to.
Slicora on the web
Your scans are uploaded to our own servers in Germany, encrypted at rest, tied to an account, and kept until you delete them.
The short version
- The app keeps everything on your device. The website cannot — it is a viewer that runs in a browser, so the scan has to reach a server to be processed. We tell you plainly which one you are using.
- Web uploads go to hardware we rent and control in Germany, not to a cloud storage service. The disk holding your scans is encrypted.
- Deleting really deletes. Delete a study or your whole account and the files are removed from our servers immediately. Encrypted backups expire within 30 days.
- We never sell data, never show ads, and never use your scans to train anything.
- We collect a small amount of anonymous usage information to fix bugs, and it never includes your images, your file names, or anything read from inside your files.
Who we are
Slicora is made by Oran Dynamics Ltd., Nutgrove, Tynagh, Loughrea, Ireland, which is the data controller for the processing described here. You can reach us any time at support@slicora.app.
Slicora for iPhone and iPad
However a study reaches the app — the Files app, drag & drop, a ZIP from a patient portal, a download link, a hospital CD via Wi-Fi transfer, or a USB cable — the files are copied into the app's private storage on your iPhone or iPad and go no further.
- Never uploaded. Your studies, and the annotations, measurements, and reports you create from them, are never sent to us or to anyone else. We hold no copies and cannot access them.
- Encrypted at rest. Files live in the app's protected storage and are encrypted by iOS while your device is locked (iOS Data Protection).
- You control sharing. Exporting an image or PDF report happens only when you use the share button, through the standard iOS share sheet, to a destination you choose.
- You control deletion. Deleting a study in the app, clearing the library, or deleting the app removes the files completely — there is no server copy to chase.
This remains true and we have no plans to change it. Using the website does not change how the app behaves, and the app does not upload anything because a web account exists.
Wi-Fi transfer stays on your network
The "From a Computer" feature turns your phone into a small receiver on your own Wi-Fi network. Files travel directly from the computer to the phone; they never touch the internet. The receiver runs only while that screen is open, and connections from outside your local network are refused.
To spare you typing an IP address, the app can also show a 6-digit code for send.slicora.app. When it does, the app registers one piece of information with our pairing service: your phone's private local-network address (something like http://192.168.1.23), stored under that temporary code. The computer enters the code and is redirected to your phone on your own network — your files never pass through the service. The code and address expire within 10 minutes of leaving the transfer screen. The service runs on Cloudflare, and the IP addresses of computers using it are held briefly (about two minutes) solely to limit abuse.
Importing from a link
When you paste a download link (for example from a patient portal), your device downloads directly from that address. We never receive the link or the files. The site you download from can see the request, as it would for any browser download, under its own privacy policy.
Slicora on the web
The website is a viewer that runs in your browser, so a scan has to reach a server before it can be read. This section is what that means in practice. If you would rather nothing left your device, use the iPhone or iPad app instead — that is exactly what it is for.
What you upload, and where it goes
- Your DICOM files. These usually contain personal details written by the hospital: a patient name, date of birth, sex, a medical record or accession number, the study date, the institution, and the referring doctor — as well as the images themselves. This is health data, and we treat it as the most sensitive thing we hold.
- Where it is stored. On a dedicated server we rent and control from Hetzner in Falkenstein, Germany. Your scans are not placed in a third-party cloud storage service.
- Encrypted at rest. The volume holding all study data is encrypted with LUKS2, and the encryption key is not stored on the machine — it is supplied by hand when the server starts. (To be precise rather than flattering: this covers the study data volume and the database, which is where your scans and their details live. The operating system disk itself is not encrypted, so that the machine can boot unattended.)
- Encrypted in transit. Everything travels over HTTPS.
- Our DNS provider does not see your scans. Cloudflare provides DNS for app.slicora.app but is deliberately not proxying it, so the traffic carrying your images goes straight to our server and never passes through their network.
- What we do with it. Your upload is converted once into a format the viewer can draw quickly, and small preview images are generated so your library has thumbnails. That is all. We do not read your scans, and we never use them to train machine-learning models — ours or anyone else's.
Your account
A web account exists so that only you can reach your scans. We store your email address, a random account identifier, and the sign-in sessions you have open. If you sign in with Apple or Google we receive the account identifier they give us and the email address they release to us — never a password. Sign-in links we email you are stored only as a one-way hash, so our records cannot be turned back into a working link.
To make your library list load quickly, we also keep a copy of a few fields taken from your scans — patient name, study description and date — in our database. That database lives on the same encrypted volume as the scans, and those values are never written to our server logs.
What we deliberately keep out of our logs
Our web server keeps ordinary access logs (which pages were requested, when, from which IP address) for up to 30 days, for security and to fix faults. We have gone out of our way to keep your information out of them: studies are identified in web addresses only by a random-looking code that reveals nothing about you, and the file names you upload — which hospitals often build out of patient names — are stripped from the log before it is written. Sign-in links and session cookies are stripped too.
Deleting things, and what that actually does
- Delete a study and its files are moved out of reach immediately and then erased from the disk, along with its database rows.
- Delete your account and everything goes: your studies, your library, your tags and notes, your sign-in sessions, and your email address. What remains is a single line recording that an account was deleted, when, and how much space was freed — it contains no name, no email, and nothing from your scans.
- Backups. We keep encrypted off-site backups so a disk failure does not cost you your scans. A deleted study can still exist in a backup for up to 30 days, after which the backup expires on its own. The backups are encrypted before they leave our server, so the storage provider holds only unreadable data.
- Free uploads expire. A study uploaded on the free tier is kept for 7 days and then deleted automatically. We say so before you upload, and we email you before it happens.
Purchases and subscriptions
In the app, payments are processed by Apple and we never see your payment details. On the web, payments are processed by Paddle, who act as the merchant of record — meaning Paddle is the seller for the transaction, handles the payment and the tax, and appears on your receipt. Your card details go to Paddle and never reach us.
In both cases we use RevenueCat to keep track of whether a subscription is active. RevenueCat receives the purchase record and a random account identifier — not your name, and not your scans.
Anonymous usage statistics
To see which features are used and where errors happen, Slicora sends anonymous usage statistics to PostHog, our analytics provider. We collect:
- Screens and events — for example "study imported (import method, succeeded or failed)", "study opened (scan type, number of images)", "3D view opened", onboarding progress, subscription events, and error categories (such as "ZIP was password-protected"). Event details are chosen from fixed, app-authored labels — never file names or values read from your files.
- App and device basics — version, device or browser, operating system, language, and timezone.
- A random identifier — the same anonymous ID used for subscriptions, so we can count users and diagnose problems.
- Approximate location — a country/city estimate derived from your IP address. Slicora never asks for or collects precise location.
- Masked screen recordings — to diagnose usability problems, sessions may be replayed as screenshots in which every image, every text field, and every view that shows study content or patient details is blacked out before anything is sent. Replays show which buttons and menus are used — never your scans, never text you type, never personal details.
Usage statistics never include your images or pixel data, file names, or any patient information from inside your DICOM files.
Anonymous install statistics for our own ads
When we advertise Slicora, we need to know which ads actually brought people to the app. For this the iOS app sends an anonymous install event to Tenjin, a mobile install-measurement provider, containing basic device information (model, iOS version, language), your IP address, and Apple's anonymous per-app "vendor" identifier. Ad results are measured through Apple's privacy-preserving SKAdNetwork system. Slicora never shows ads, never asks for Apple's cross-app tracking permission, and never uses the cross-app advertising identifier (IDFA).
Support emails
If you contact us from Settings → Contact Support, the email is pre-filled with a short debug block: version and build, device, operating system, language, subscription status, the number of studies in your library, and your anonymous Support ID. It is visible and editable before you send. We use it only to help you.
What we never do
- No ads shown in Slicora, ever.
- No selling, renting, or trading of your information — to anyone, ever.
- No tracking across other companies' apps or websites.
- No training. Your scans are never used to train machine-learning models, by us or by anyone else, and they are never shared with a third party for that purpose.
- No human at Slicora looks at your scans. Access to the server is limited to the people who operate it, and is used to keep the service running, not to read your files.
Service providers
The information described above is processed by these providers on our behalf:
| Provider | What they handle | Where |
|---|---|---|
| Hetzner Online GmbH (policy) | The server your web scans are stored and processed on | Germany |
| Cloudflare, Inc. (policy) | DNS, this website, the pairing service, and storage of our encrypted backups | EU / US |
| Paddle.com Market Ltd (policy) | Merchant of record for web payments | UK / EU |
| Apple (policy) | Payments and distribution for the iOS app | US / EU |
| RevenueCat, Inc. (policy) | Subscription status | US |
| Postmark (ActiveCampaign, LLC) (policy) | Sends your sign-in emails; receives your email address only | US |
| PostHog, Inc. (policy) | Anonymous usage statistics | US |
| Tenjin, Inc. (policy) | Anonymous install measurement for our own ads (iOS only) | US |
Your scans are only ever handled by Hetzner, as the operator of the server they sit on, and by Cloudflare as the holder of backups that were encrypted before they left our machine. None of the other providers above receives your medical images or the personal details inside them.
Where a provider processes data outside the EEA or UK, transfers rely on safeguards such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
How long we keep things
| What | How long |
|---|---|
| Studies in the iPhone/iPad app | On your device, until you delete them |
| Studies uploaded to the web | Until you delete them or close your account |
| Studies uploaded on the free tier | 7 days, then deleted automatically |
| Encrypted backups | Up to 30 days, then they expire on their own |
| Web server access logs | Up to 30 days |
| Your account details | Until you delete your account |
| Sign-in links | 15 minutes, and only ever as a one-way hash |
| Pairing codes (app Wi-Fi transfer) | At most 10 minutes |
| Purchase and tax records | As long as the law requires us and Paddle to keep them |
Your rights and choices
- Delete anything, yourself, at any time. Individual studies and your entire account can be deleted from the website without asking us.
- Depending on where you live (for example the EEA, UK, or California), you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict its processing, and to complain to your local data-protection authority. We do not "sell" or "share" personal information as defined by the California Consumer Privacy Act.
- To exercise any of these rights, email support@slicora.app from the address you signed up with. For the app, which has no accounts, include the Support ID shown in Settings → Contact Support — our records there are keyed to anonymous IDs, so without it we usually cannot tell which data is yours.
Our legal basis under GDPR. Your medical scans are a special category of personal data, and we process them on the basis of your explicit consent, which you give by choosing to upload them and can withdraw at any time by deleting them or your account. We process your account details to perform our contract with you, purchase data to perform that contract and to meet tax obligations, and usage statistics and abuse prevention under our legitimate interest in running and improving Slicora — you may object to the last of these as described above.
Children
Slicora is not directed at children, and we do not knowingly collect personal information from children under 13 (or the minimum age in your country). A parent or guardian may of course use Slicora to look at their child's scan. If you believe a child has provided us personal information directly, contact us and we will delete it.
Security
Web study data sits on an encrypted volume, reachable only over HTTPS, on a server whose administrative access is restricted to a private network. Sign-in uses one-time links or Apple/Google rather than passwords we could lose. Backups are encrypted before they leave the machine. No system is perfectly secure, and we would rather say so than imply otherwise — but the most private option remains architectural, and it is the one the iPhone and iPad app gives you: data that never leaves your device cannot be taken from us.
Changes to this policy
If we change this policy, we will post the new version here and update the date at the top. For meaningful changes — particularly any change in what leaves your device — we will also call it out in the app, on the website, or in release notes.
Contact
Email support@slicora.app. We are established in Ireland, so our supervisory authority is the Irish Data Protection Commission — but if you are in the EEA or UK and think we have handled your data badly, you may complain to them or to the data-protection authority where you live, whichever you prefer.