VIEWMIUM
Back to legal information
CURRENT POLICY

Privacy Policy

What information VIEWMIUM processes, why it is used and the choices available.

Published information

This page contains the current published policy for VIEWMIUM services. Product-specific disclosures shown at sign-in, purchase or feature activation also apply.

Last updated
September 10, 2026
Version
1.0

1. Who is responsible and what this Notice covers

This Notice applies to VIEWMIUM mobile, web, desktop, contributor and public-profile surfaces that link to it. It does not cover third-party services operating under their own notices. Privacy and rights requests can be submitted through the support route linked from the VIEWMIUM site.

2. Information we process

  • Account and identity data, such as name, email, identity-provider subject, locale, roles and security events.
  • Professional-profile data, such as credentials, specialty, institution, biography, country, links and photo. Profile fields become public only through granular opt-in.
  • Restricted verification material, including credential files, status, reviewer notes and decision history.
  • Medical-content operations, including source files, quarantine records, de-identification checks, editorial history and approved attribution.
  • Study activity, including bookmarks, drawings, notes, feedback and case interactions. PHI is not allowed.
  • AI data, including the question, locale, atlas context, retrieved text, response, provider or model, and limited token or error metadata. The AI feature does not send raw image binaries.
  • Subscription data, including product, platform, transaction or entitlement identifiers, status, renewal and webhook data. VIEWMIUM does not receive full payment-card details from app stores.
  • Device and log data, including IP address, device and app version, timestamps, diagnostics, security logs and approved optional telemetry.
  • Public contributor-page view data, such as a cookie, page, daily hashed view key and timestamp.
  • Support and rights-request messages, attachments, identity verification and resolution records.

3. Why we process information

Depending on the purpose and location, processing is based on performing the service or contract, responding to a request, consent, legitimate interests, or a legal obligation. Additional regional information is provided where applicable.

  • Provide accounts, settings and product features.
  • Publish approved content and profile fields selected for public display.
  • Verify professional status and protect editorial integrity.
  • Generate an AI response and operate safety controls after required disclosure or permission.
  • Maintain Premium entitlements and store transaction records.
  • Protect accounts, prevent abuse and investigate security events.
  • Respond to support, privacy and other rights requests.
  • Run optional analytics only where configured and lawfully permitted.

4. Medical content and sensitive information

VIEWMIUM is designed to publish only de-identified educational medical content. Public users must not submit patient data. Contributor source media enters a separate quarantine and de-identification review. If identifiable patient data is detected, it is isolated, access-restricted and escalated; it is not published or treated as an ordinary user submission.

Verification documents may reveal professional status and identifiers. They are used only to assess claimed contributor status, protect editorial integrity and manage appeals. A public badge shows only the approved status and permitted fields, not the source document.

5. AI processing

When AI is enabled, VIEWMIUM may send the question, selected language, structured atlas context and retrieved published text to the provider disclosed before use. The AI feature does not send raw medical images. The in-product disclosure describes the relevant data categories, purpose and available provider information before external processing begins.

6. Recipients and processors

We disclose material providers, purposes, regions and controls as required for the features made available in the Service.

  • Cloud hosting, storage and content-delivery providers for accounts, databases, objects, backups and delivery.
  • Identity providers for sign-in identifiers, tokens and provider-selected profile fields.
  • Apple, Google and approved subscription infrastructure for purchase and entitlement events.
  • The disclosed AI provider for questions, atlas context, retrieved text, output and diagnostics.
  • Approved observability providers for limited diagnostic and security events.
  • Professional advisers, auditors and authorities where authorized or required.
  • Business-transfer counterparties under confidentiality and legal safeguards if a transaction occurs.

7. International transfers

VIEWMIUM currently focuses its service on the United States. If users in another supported market have information processed in the United States or another disclosed location, VIEWMIUM uses contractual, security and organizational safeguards appropriate to applicable law. Feature and market availability may be limited where additional transfer or representation requirements apply.

8. Retention and deletion

We keep personal information only as long as necessary for the stated purpose, security, disputes, editorial integrity and legal obligations. Retention varies by category, including accounts, verification documents, AI conversations, support cases, telemetry, public-view cookies and backups.

Account deletion must address database records, object storage, identity links, AI history, vendors, logs, caches and backup aging without restoring deleted data to production. Limited records may be retained for fraud, security, disputes, appeals, legal holds or proof of compliance where lawful.

9. Security

We use technical and organizational safeguards intended to protect information, including authenticated access, role controls, encryption in transit, protected credentials, logging and restricted quarantine. No method is completely secure. Security reports can be submitted through the support route linked from the VIEWMIUM site and should not include unnecessary personal or patient data.

10. Your choices and rights

Privacy and rights requests can be submitted through the support route linked from the VIEWMIUM site. VIEWMIUM will verify only the information reasonably necessary, respond within the applicable period and explain any denial. Authorized-agent requests require authority and identity verification where permitted.

  • Access, correct or update account and permitted profile fields.
  • Withdraw optional public-profile, search-indexing, analytics or AI permissions without affecting prior lawful processing.
  • Delete your account and associated data, subject to disclosed exceptions.
  • Request a copy, correction, deletion, restriction, objection or portability where applicable.
  • Appeal a denied privacy request where applicable and contact the relevant regulator.
  • Manage optional storage technologies and device permissions.

11. United States notice

Under the current United States baseline, VIEWMIUM does not sell personal information, share it for cross-context behavioral advertising, or use targeted advertising. If that fact changes, notices, opt-outs and Global Privacy Control handling must be implemented before the change. Applicable state rights, appeal procedures, sensitive-data rules and request records will be handled according to the user’s jurisdiction.

12. Regional launch status

Availability outside the United States may be limited while VIEWMIUM assesses local privacy, consent, complaint, cross-border processing, language, representation, cookie and AI requirements.