Last updated: March 15, 2026
This Privacy Policy describes how Alfi Digital SRL ("Company", "we", "us"), CUI 52377381, collects, uses, and protects your information when you use the Sanalock application ("Service"). We are committed to your privacy through our zero-knowledge architecture.
Sanalock uses client-side encryption. Your health data is encrypted in your browser using AES-256-GCM before it reaches our servers. We cannot access, read, or decrypt your health data. Your password never leaves your browser — it is used locally to derive encryption keys.
We collect minimal data necessary to operate the Service:
We never collect or have access to: your password, your encryption key, your biomarker names or values, your lab results, your reference ranges, or any other unencrypted health data.
Account data is used solely to provide the Service: authenticate you, store your encrypted data, manage your sessions, and send transactional emails (such as password reset links). We do not sell, share, or use your data for advertising. We do not use your data for AI training.
Available to Premium subscribers, the Service offers optional AI-powered features (such as lab report parsing) that use Mistral AI as a third-party processor. When you use these features, the data you submit is sent to Mistral AI for processing. Under Mistral's Zero Data Retention (ZDR) policy, your data is processed in real time and is not stored, logged, or used for model training. No health data is retained by Mistral after the request is completed. You can use the Service without the AI features — they are entirely optional.
Your encrypted data is stored on servers in the European Union. All data in transit is protected by TLS. At rest, your health data is encrypted with AES-256-GCM — even with full database access, your health data cannot be read.
Under the General Data Protection Regulation (GDPR), you have the right to:
We use only essential cookies: a session cookie (bw_session) for authentication, a language preference cookie (bw_lang) to remember your selected language, and a theme preference cookie (bw_theme) to remember your light/dark mode choice. We do not use tracking cookies, analytics, or third-party cookies.
The Service is intended for users aged 16 and older. Children under 16 may not create accounts or use the Service directly. However, parents or legal guardians may use their own account to store and track health data on behalf of their children. In such cases, the parent or guardian is the data controller for their child's data, and all data remains encrypted under their account.
We may update this Privacy Policy from time to time. We will notify you of changes by posting the updated policy on this page.
For privacy inquiries or to exercise your GDPR rights, contact us through our contact page or write to: Alfi Digital SRL, Str. Nicolae Tonitza 97, Et. 2, Ap. 8, Sat Scorteni, Bacau 607550, Romania.