This page explains in plain English what Bactima collects, how it is protected, where it goes, and the limits of the tool. Effective 4 October 2026.
1. Who we are
Bactima (bactima.com and the installable Bactima app) is developed and operated by Madomic Kalin ("we", "us"). It offers BMQ interpretation, Batch BMQ, Auto Antibiogram, Smart Report and Bactima Bridge for microbiology laboratories.
Questions or requests about privacy: use our Contact page. Your message is emailed to the Bactima team. Effective date: 4 October 2026.
2. What we collect
- Account: name, email, hospital, role, account status and whether your email is verified. We store your password only as a one-way bcrypt hash.
- Optional profile items: a signature image, designation and registration number for Smart Reports, and letterhead logos.
- Files and reports you upload or create: antibiogram files (Excel, CSV, WHONET and other exports), their cleaned versions and results, and Smart Reports, which contain the results and any identifiers you enter or that were read from the report (for example lab ID or patient name).
- Bactima Bridge data: results that your lab system pushes to your connection. Patient names and date of birth are included only if your system sends them. API keys are stored only as a hash.
- Security records: a failed sign-in counter per email (used to lock an account after repeated failures), an audit log of actions (who, what, when and the IP address), and a log of emails sent (recipient, type and delivery status).
- Contact form: your name, email and message.
- Cookies and device storage: two sign-in cookies (httpOnly and secure: a 15-minute access cookie and a 7-day refresh cookie). The app also stores preferences, the offline breakpoint pack and unsent contact messages on your device. We set no advertising cookies.
- Analytics: the web page includes our hosting platform's script (Emergent) and the PostHog product-analytics script. These may record page views and usage events and may set their own cookie or local-storage identifier. They are not used for advertising.
3. How your data is stored and protected
- All traffic uses HTTPS. Sign-in cookies are httpOnly and secure.
- Stored files, Smart Report identifiers, Bridge data, signatures and summaries sent to admins are encrypted at rest (AES-256-GCM) with a server-held key.
- Your files and Smart Reports are private to you. Hospital admins and the super admin cannot open them.
- The super admin sees only storage totals and file metadata (file names, sizes and dates) to manage storage quotas.
- Bactima Bridge connections and their files are private to the person who set them up. Nobody else can see them, including admins.
4. Processing on your device
Reading a report from a photo or PDF (OCR) and Scan mode (page detection, flattening and filters) run entirely in your browser, and they also work offline. The photo or PDF is not uploaded.
Data leaves your device only when you go ahead with a step: when you create a Smart Report, the values that were read (and the identifiers you keep) are sent and stored encrypted. When you upload an antibiogram file, that file is uploaded.
5. AI features
- Smart Report AI comment (off by default, you can turn it on): we send a short, de-identified summary to OpenAI (GPT-4.1 mini) through Emergent's AI gateway. The summary holds the organism, specimen site, ward type, the suggested drug lists and alert codes. Names, IDs, dates and images are never sent. The comment that comes back is saved with your report.
- Optional online reader ("Read faster online (AI)"): runs only when you tap it and agree each time. It sends a cropped image of the susceptibility table and the organism line (the patient and hospital header is cut off) to Google Gemini (Gemini 3 Flash) through Emergent's AI gateway. Bactima processes the image in memory and does not store it.
- We send data to these providers only to generate the response you asked for. Their own terms govern how they process it.
6. Email
We send email through Resend: sign-in emails (verification, password reset, invitations) and account notifications (approvals, storage warnings, summaries sent to you). Contact-form messages also reach us by email. We do not send marketing email.
7. Patient privacy: your responsibilities
- Remove or de-identify patient identifiers wherever you can before uploading.
- Follow your institution's rules and the law that applies to you, for example India's Digital Personal Data Protection Act 2023, and HIPAA or GDPR where they apply.
- Upload hospital data only if you have permission to do so.
8. Hospital data
- When you send a summary to your hospital admins, they receive a copy. Your originals stay private to you.
- Antibiogram summaries are % susceptible tables and contain no patient identifiers. A Smart Report PDF you send contains whatever is printed on that report.
- If you move to another hospital, your private files, antibiograms, Smart Reports and Bridge data move with you. Summaries you already sent stay with the old hospital.
- If a hospital is deactivated or deleted, its users' private files are never deleted. After a deletion, members become independent users and keep their files.
10. Keeping and deleting your data
We keep your data while your account is open. You can delete your own data at any time:
- Files: on My Files, deleting a file erases its contents and removes it together with its clean versions, records and results. This also frees your storage quota.
- Smart Reports, Bridge files and connections, and your signature can each be deleted where they are shown.
- After a file is deleted, the audit log keeps a short record that a deletion happened (who, when, file name).
- Expired password-reset links and signed-out sessions are removed automatically.
Deleting your account: in Profile › Delete my account, enter your password and type DELETE. See our account deletion page for the steps.
- Straight away: you are signed out on all devices, your Bridge API keys stop working, and your pending join or transfer requests are cancelled. We email you the scheduled date with a single-use Cancel deletion link.
- For 7 days: signing in only shows the scheduled date with Cancel deletion and Sign out. Cancelling restores your account; Bridge keys stay revoked, so you reset them in Bridge.
- After 7 days: your account is permanently deleted. The contents of all your files and their stored copies are erased and every record of them is removed, together with your antibiograms, Smart Reports (with PDFs and AI comments), signature and letterhead, and Bridge connections and files. Your storage quota is freed.
- Kept: summaries you already sent to hospital admins (copies with no patient details), shown as from "Former member". Security, audit and email logs keep only an anonymous reference instead of your name or email.
- The only admin of a hospital with other members must transfer the admin role first. If you can't sign in, ask on the Contact page from your account's email address.
11. Clinical caution
Bactima, Smart Reports and AI comments are decision support only. They are not a diagnosis or a prescription, and they do not replace clinical judgement, the microbiologist, the infection control team or the treating physician. Always check results against the original lab report, current CLSI or EUCAST breakpoints and your local guidelines. OCR and AI can make mistakes, so check every value. Do not use Bactima in an emergency.
12. Educational content
Guides, news and resources are for education only. They may be out of date and are not medical advice.
13. Children, changes and contact
- Bactima is not intended for anyone under 18.
- If this policy changes, we will update this page and its effective date.
- Questions or requests: use our Contact page.
