Privacy Policy
How InsilicoΣ Lab collects, uses, and protects your information.
Introduction
InsilicoΣ ("we", "our", or "the Lab") is an academic research laboratory specializing in computational drug discovery, cheminformatics, bioinformatics, and polymer science. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web platform at insilicosigma.com and our computational tools.
We are committed to protecting the privacy of our users, which include researchers, students, and professionals in the pharmaceutical and chemical sciences. By accessing or using our platform, you agree to the terms of this Privacy Policy.
Information We Collect
Account Information
When you create an account, we collect:
- Username and email address
- Password (stored using Django's secure hashing, never in plaintext)
- If you sign in with Google OAuth: your Google profile name and email
Research Data You Submit
When using our computational tools, you may submit:
- SMILES strings and molecular structures (ADMET-Σ, QSAR-X)
- Polymer SMILES (POLY-X)
- Protein/target identifiers (CRAFT, NEXUS)
- CSV or SDF files containing compound data
- Gene lists and biological datasets (APPAS)
Important: We do not claim any intellectual property rights over the molecular data, structures, or research inputs you submit to our tools. Your research data belongs to you.
Automatically Collected Information
- IP address and browser type (standard web server logs)
- Pages visited and features used (for improving our tools)
- Session cookies required for authentication
How We Use Your Information
We use the information we collect to:
- Provide and operate our computational research tools
- Process your molecular predictions, analyses, and simulations
- Manage your account and tool access permissions
- Improve our prediction models and platform performance
- Respond to your inquiries and support requests
- Send important service-related notifications
We do not use your data for advertising. We do not sell, rent, or trade your personal information or research data to third parties.
Third-Party Services
Our platform integrates with the following third-party services:
- Google OAuth — for optional "Sign in with Google" authentication. Google receives only the authentication request; we receive your name and email from your Google profile.
- Render — our hosting provider. Your data is processed on Render's infrastructure. See Render's Privacy Policy.
- Deep-PK / pkCSM API — when you use ADMET-Σ with the Deep-PK engine, your SMILES structures are sent to the Deep-PK prediction server for processing.
- ChEMBL, UniProt, PDB, IUPHAR — CRAFT queries these public scientific databases to retrieve protein and target information. Only public identifiers (e.g., UniProt IDs) are sent.
We do not share your account information with any of these services beyond what is technically necessary for the features you use.
Data Storage & Retention
- Your account information is stored securely in our database with encryption at rest.
- Prediction jobs and results are retained to allow you to revisit your analyses.
- You may request deletion of your account and all associated data at any time by contacting us.
- Server logs containing IP addresses are retained for up to 30 days for security monitoring.
- Expired or inactive data may be cleaned up automatically according to our data management policies.
Cookies
We use only essential cookies required for the platform to function:
- Session cookie (
sessionid) — maintains your login state - CSRF token (
csrftoken) — protects against cross-site request forgery attacks
We do not use tracking cookies, analytics cookies, or advertising cookies. We do not use Google Analytics or similar tracking services.
Data Security
We implement appropriate security measures to protect your data, including:
- HTTPS encryption for all data in transit
- Secure password hashing (PBKDF2 with SHA-256)
- CSRF protection on all forms
- Rate limiting on authentication endpoints
- Regular security updates to our dependencies
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we take all reasonable measures to protect your information.
Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate information
- Deletion — request deletion of your account and associated data
- Data Portability — export your prediction results and research data
- Withdraw Consent — disconnect your Google account at any time
To exercise any of these rights, please contact us at our contact page.
Children's Privacy
Our platform is designed for researchers, students, and professionals in the sciences. We do not knowingly collect information from children under 13 years of age. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify registered users of material changes via email or a prominent notice on our platform. The "Last Updated" date at the top of this page indicates when the policy was last revised.
Contact Us
If you have questions about this Privacy Policy or our data practices, please reach out:
- Contact Form: insilicosigma.com/contact
- Lab Lead: Dr. Salah Alshehade