← Back to Mermaid Health
Legal

Privacy Policy

Last updated: 28 August 2026  ·  Version 1.1

This Privacy Policy explains how Mermaid Health ("we", "us", "our") handles information when you use our clinical document summarisation tool ("Mermaid Health"). We have written this in plain English because we believe you should be able to understand it easily.

Mermaid Health is designed specifically for clinical professionals in the UK. We take your privacy, and the privacy of your clients, extremely seriously.


1. Who we are

Mermaid Health is a clinical productivity tool operated in the United Kingdom. Our ICO registration number will be added here once registration is complete.

Contact us: hello@mermaid.health


2. What Mermaid Health does — and does not do

Mermaid Health allows clinical professionals to upload background documents (such as GP letters, school reports, EHCPs, and assessment reports) and receive an AI-generated structured summary of those documents.

We do not store your documents. Documents are processed and discarded immediately after your summary is generated. Nothing is written to a database or kept on any server we control. Your documents are never used to train AI models.

We do not share your data with third parties, except as described in Section 5 below.


3. What information is processed

3a. Documents you upload

When you use Mermaid Health, you upload clinical documents containing personal data relating to your clients. This may include special category data under UK GDPR (health and education information). This data is processed solely for the purpose of generating a summary. It is not stored, retained, or used for any other purpose.

3b. Account and usage information

We collect information when you subscribe and create an account: your name, email address, professional discipline, country, postcode, and professional registration number. We also record basic usage information, such as how many documents you have summarised. This is used to operate the service, to apply your plan's limits, and to identify accounts being shared in breach of our terms.

3c. How documents reach the AI model

Client names are removed in your browser before any document leaves your device, and are reinserted into the summary afterwards if you choose that option. The remaining document content is then sent, over an encrypted connection, to our server-side function, which passes it to the Anthropic API using our own API key. You do not need to provide an API key of your own. Document content is held only in memory for the duration of the request and is not written to disk or to any database.


4. Our role under UK GDPR

You (the clinician) are the data controller — you decide what documents to upload and are responsible for ensuring you have the right to share that information with a third-party tool.

We (Mermaid Health) act as a data processor — we process the documents on your instruction, solely to generate a summary.

By using Mermaid Health, you confirm that you have the appropriate authority, consent, or professional basis to share the documents you upload.


5. Third parties we work with

The following organisations process data on our behalf as sub-processors. We do not sell or share your data with anyone else.

Anthropic (AI processing)

Mermaid Health uses the Anthropic API to generate summaries. Document content you upload is transmitted to Anthropic's servers for processing. Anthropic operates under a zero data retention policy for API requests — your documents are not stored or used for model training. We have a Data Processing Agreement in place with Anthropic. Their privacy policy is available at anthropic.com/privacy.

Supabase (accounts and authentication)

Your account details — name, email address, professional registration number and related profile information — are stored by Supabase, in the European Union (Ireland). Supabase does not receive the documents you upload. Their privacy policy is at supabase.com/privacy.

Netlify (hosting)

Our application is hosted by Netlify. Netlify may process standard web request data (such as IP addresses) as part of hosting. Netlify does not store the documents you upload. Their privacy policy is at netlify.com/privacy.

Resend (account emails)

Transactional emails, such as your welcome email and password reset links, are sent using Resend, in the European Union (Ireland). Resend receives your email address and the content of those emails only. Their privacy policy is at resend.com/legal/privacy-policy.

MailerLite (onboarding emails)

Onboarding and product update emails are sent using MailerLite, which receives your name and email address. You can unsubscribe from these at any time without affecting your account. Their privacy policy is at mailerlite.com/legal/privacy-policy.

ThriveCart and Stripe (payments)

Subscriptions are processed by ThriveCart using Stripe. They receive your name, email address, billing country and payment details. We never see or store your card details. Their privacy policies are at thrivecart.com/privacy and stripe.com/privacy.


6. Legal basis for processing

We process personal data on the basis of legitimate interests (to provide the summarisation service you have requested) and contract (to fulfil our agreement with you as a user of Mermaid Health). You, as data controller, are responsible for identifying your own legal basis for sharing client data with Mermaid Health.


7. Data retention

We do not retain the documents you upload or the summaries generated from them. These are processed and discarded immediately.

Account-related data (such as your email address and subscription details) is retained for as long as your account is active, and for up to 12 months after account closure for legal and administrative purposes.


8. Your rights under UK GDPR

You have the right to access, correct, delete, or restrict the data we hold about you (your account information). You also have the right to data portability and to object to processing. To exercise any of these rights, contact us at hello@mermaid.health. We will respond within 30 days.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data correctly.


9. Security

All data is transmitted over encrypted HTTPS connections. Documents are never written to disk on our servers. We recommend using Mermaid Health only on secure, private networks and in accordance with your organisation's information security policies.


10. Children's data

Mermaid Health is designed for use by clinical professionals and is not intended to be accessed directly by children. Clinical documents relating to children may be uploaded by professionals as part of their work. Such documents are processed in the same way as all uploads — they are not stored or retained.


11. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "last updated" date at the top when we do. If we make significant changes, we will notify users by email where possible.


12. Contact us

If you have any questions about this Privacy Policy, please contact us:

Email: hello@mermaid.health
Website: mermaid.health

If you have a complaint, you also have the right to contact the ICO directly at ico.org.uk or by calling 0303 123 1113.