Hans-Made Research Inc. (10257596 Manitoba Inc.), Winnipeg, Manitoba, Canada · effective 2026-08-01
This notice tells you, plainly, what we log, why, how long we keep it, and your rights. It is part of the Terms of Service. We keep this deliberately small: we collect what we need to run, secure, meter, and bill the service, and nothing we don't. We do not sell your data, and we do not use your submitted structures to train models.
The organization responsible for your personal information is Hans-Made Research Inc. (10257596 Manitoba Inc.), Winnipeg, Manitoba, Canada. The individual accountable, our Privacy Officer, is Dustin Hansley, President, reachable at dustinhansmade@gmail.com. Direct any privacy question, request, or complaint to that contact.
We are the controller of your account, technical, and usage data, and a processor acting on your instructions for the structures / sequences you submit and the deliverables we generate for you.
| Category | What | Why |
|---|---|---|
| Account | the name, email, and company you give when you request access | to create your account, contact you, and issue your key |
| Technical / connection | your IP address, timestamp, request method, and user-agent on each request | security, abuse-prevention, rate-limiting, and diagnostics |
| API keys | only a salted SHA-256 hash of your key (never the key itself), plus its prefix and last 4 characters | to authenticate you without ever storing the secret |
| Usage | which endpoint / tier you called, run IDs, number of compounds, page counts, and a content hash (Merkle root) | metering, quotas, billing, and an integrity seal you can verify |
| Audit | account and admin events (key issued/revoked, plan/status changes, quota events, auth failures) | a tamper-evident security and support trail |
| Submitted content | the structures / sequences you send, and the deliverables we generate for you | to run your job and return your report; held in your isolated tenant folder, never shared across accounts |
We use no advertising or analytics trackers. The private operator console uses one functional cookie for the operator's own device only; the client API is authenticated by key, not by cookie.
To provide the service you asked for (contract), to secure, meter, and prevent abuse of it (legitimate interest), and to meet legal and accounting obligations. Where consent is the basis, you may withdraw it at any time.
We do not sell your data and do not share it except with the infrastructure providers strictly needed to run the service, or where required by law. The sub-processors we may use are: hosting/compute, and, only if enabled, an email provider (for account notices) and a payment processor (for billing). A current list is available on request, and we will give notice before adding a new one. Aggregate, de-identified usage counts may be used to operate and describe the service.
Your data is hosted and processed in Canada. For customers in the EU / UK: Canada holds a European Commission (and UK) adequacy decision for organizations subject to PIPEDA, so EU→Canada and UK→Canada transfers require no additional transfer mechanism. If we ever engage a sub-processor outside Canada, we rely on the appropriate safeguard (e.g., the Standard Contractual Clauses).
Account, usage, and audit records are kept while your account is active and for a reasonable period afterward for security, billing, and legal purposes. Your submitted content and deliverables stay in your tenant folder until you delete them or ask us to.
If a confidentiality incident occurs that creates a real risk of significant harm (a serious injury), we will notify affected users and the relevant authority (the Office of the Privacy Commissioner of Canada and/or the Commission d'accès à l'information du Québec, and any applicable EU / UK supervisory authority) without undue delay, and we maintain a register of incidents as required by law.
You may request access to, correction of, deletion of, or a portable copy of your personal information, and you may withdraw consent or object to processing based on legitimate interest. On an erasure request we remove your tenant folder, keys, and usage-ledger rows (a minimal audit record of the deletion itself is retained for security). We respond within 30 days and may first verify your identity; we will not discriminate against you for exercising a right. Contact dustinhansmade@gmail.com. If you remain unsatisfied, you may complain to the OPC (priv.gc.ca), the CAI du Québec, your EU supervisory authority, or the UK ICO.
California residents (CCPA/CPRA): we do not sell or share your personal information and have not in the preceding 12 months, so no "Do Not Sell or Share My Personal Information" link is required. You have the rights to know, delete, correct, and non-discrimination. Categories collected: identifiers (name, email, IP address), commercial / usage information, and internet activity. Submit requests to the contact above.
Our predictions are about molecules and proteins, not about you as a person; we do not use your personal information to make automated decisions producing legal or similarly significant effects about you.
API keys are stored only as salted hashes; each account's outputs are path-isolated so one account can never read another's; requests are size- and rate-capped. No system is perfectly secure, but we design for least-exposure.
We may update this notice; material changes will be posted here with a new effective date.
Contact / Privacy Officer: Dustin Hansley · dustinhansmade@gmail.com · Hans-Made Research Inc., Winnipeg, Manitoba, Canada.