Last updated: August 2025
MedSlice (medslice.app) is a browser-based DICOM viewing and export tool. References to "we", "us" or "MedSlice" in this policy refer to the operator of medslice.app.
We never see, receive or store your medical images. All DICOM processing β parsing, rendering, converting, anonymizing β runs entirely inside your browser using WebAssembly and JavaScript. Files are read from your local disk into browser memory and are never transmitted to any server.
This architecture is not a policy choice β it is a technical constraint. There is no server endpoint that could receive your files.
localStorage. This token is validated against our server (Cloudflare KV) on each export to confirm your subscription is active. It contains no personal data.We do not set any tracking cookies. The only browser storage we write is:
medslice_pro_token β your Pro session token, stored in localStorage. You can delete it at any time via your browser's developer tools or by clearing site data.Because we process minimal personal data (IP hash for rate-limiting, Stripe customer ID for subscriptions), our legal basis is legitimate interest for rate-limiting and contract performance for subscription management.
If you are in the EU/EEA you have the right to access, rectify, erase or port any personal data we hold. Since we store only a hashed IP (not reversible to an individual) and a Stripe customer record, a practical erasure request means cancelling your subscription and clearing your browser's localStorage. Contact us if you need assistance.
MedSlice is not directed at children under 16. We do not knowingly collect data from minors.
Privacy questions: privacy@medslice.app