Data handling
GaiaLab is designed to make scientific reasoning inspectable. The same standard applies to data handling: we distinguish what the platform supports today from controls still required for confidential enterprise workloads.
Do not submit protected health information (PHI), directly identifiable patient data, confidential clinical datasets, unpublished trade-secret datasets, or regulated customer information through the general public workflow. Institutional confidential-data use requires a separately approved workflow and written terms.
Public and non-confidential research inputs
Gene panels, disease context, public identifiers, and other non-confidential research prompts may be used to generate evidence-linked research hypotheses. Outputs remain research-use artifacts and are not medical diagnoses, treatment recommendations, or regulatory decisions.
Retention
Retention depends on the workflow used. Public analysis, saved workspace, shared-analysis, billing, and pilot workflows can have different persistence requirements. GaiaLab will not promise a universal deletion or retention period unless that behavior is implemented and documented for the specific workflow or contract.
Third-party scientific sources
GaiaLab retrieves or references information from external scientific data providers. Availability, licensing, credentials, and source status can vary. Source attribution and provenance are preserved where available; GaiaLab does not represent third-party source content as proprietary GaiaLab data.
AI processing
Some analyses may use configured AI model providers for synthesis. Provider configuration can vary by deployment. Confidential enterprise use must define the approved processing boundary before confidential inputs are submitted.
Enterprise readiness gate
Before GaiaLab markets general confidential-data ingestion to pharma customers, the readiness gate requires durable authenticated identity, verified tenant isolation, user-attributed audit events, documented deletion/retention behavior, and an accurate list of applicable infrastructure/model subprocessors.
Security posture · Privacy policy · Research Use Terms · Discuss a validation pilot