Privacy noticePublic website and access requests only

Privacy Last updated 31 August 2026

Privacy notice.

This notice explains how SingularCell handles information submitted through the public website and enquiry form. Please use a general overview when contacting us; confidential study data belongs in a separately agreed pilot workflow.

What we collect

The enquiry form collects your email address, selected category and any optional note you add, along with your contact-consent version and submission timestamps. Existing requests may also contain a name and organization supplied through an earlier version of the form. When measurement is permitted, the request also records whether its first bounded content touch came from a recognised search-engine hostname and the applicable SingularCell article slug. The site records a small set of first-party product events—such as an article CTA click, meaningful article engagement or completed pilot request—using the page path, content slug, event label and source class.

The event table does not store the search query, full referrer, IP address, cookie or cross-site identifier. Measurement is disabled when Global Privacy Control or Do Not Track is enabled. Cloudflare may still process technical request information to deliver and protect the site.

We do not ask for raw sequences, proprietary protocols, result files, personal health information or regulated study data through the public site.

Why we use it

We use access-request information to assess fit, respond to your request, prevent abuse, maintain an audit trail and improve the onboarding workflow. We use anonymous product events to understand whether research guidance leads to a synthetic-study exploration or pilot conversation. We do not sell access-request information.

Where it is stored

Access requests and first-party product events are designed to be stored in a dedicated Cloudflare D1 database. Cloudflare Workers delivers the site. The request form uses server-side input checks and a hidden spam-trap field, without a CAPTCHA. The public site does not enable private laboratory-data ingestion.

Retention

Access requests and public product events should be reviewed at least annually and deleted when no longer needed for the request, measurement, security, legal or audit purpose. A different retention schedule must be agreed before any controlled pilot.

Your choices

You may ask to correct or withdraw an access request through the contact path. Identity may need to be confirmed before a request affecting stored information is completed.

Workspace accounts

When workspace sign-in is enabled, we store your verified email, account type, project briefs, messages, provider profile and access-sharing records in Cloudflare D1. SingularCell administrators can access these records to operate the service. Other customers cannot access your projects unless the owner or an administrator shares them with a provider. Sharing includes the full brief and earlier messages; removing access cannot recall information already seen.

Email sign-in uses Resend to send a one-time code to your address. The application stores hashes of codes and session tokens, not their readable values. Essential, secure cookies keep you signed in. Rate limits use keyed hashes derived from technical request information, including IP addresses; the workspace rate-limit table does not store raw IP addresses. Security audit records include the account, action, affected record and time. Workspace pages do not run product analytics.

Workspace records should be reviewed at least annually and deleted when no longer needed for service, security, legal or audit purposes. Expired codes, sessions and rate-limit records are cleaned up during subsequent sign-in requests. You can request correction or deletion through the contact page.

International processing

Cloud services may process information in more than one country. A controlled pilot will require separate contractual, residency, retention and deletion decisions.

Contact

Use the SingularCell contact page for privacy questions. Do not include confidential study material in the message.

Research-use boundary

The public demonstration is for research-use software evaluation only. It is not a clinical, GMP, therapeutic or regulatory system.