# Life Analytics IAS OpenAI App Privacy Policy

Last updated: 2026-06-10

This policy describes the data practices for the Life Analytics IAS OpenAI App provided by Life Analytics K.K. The app is a ChatGPT integration for authorized IAS research workspaces and approved IAS Control Actions. It is for research use only and is not for diagnosis, treatment decisions, clinical judgment, medical advice, or emergency use.

## Scope

This policy applies only to the Life Analytics IAS OpenAI App and the separate IAS OpenAI Adapter service that connects ChatGPT to IAS research context APIs and approved IAS Control Action endpoints. It does not replace the general IAS service agreement or privacy terms that apply when a user signs in to IAS directly.

## Data Controller And Contact

The service provider is Life Analytics K.K. For privacy or support requests, contact support@life--analytics.net. Website: https://life--analytics.net/

## Data We Process

The app minimizes collection and processes only data needed to answer the specific IAS research context or approved control request.

| Category | Examples | Source |
|---|---|---|
| OAuth and account data | OAuth bearer token during request handling, token issuer, audience/resource, expiration, scopes, subject claim, IAS user/tenant mapping | ChatGPT OAuth flow and IAS identity mapping |
| Tool inputs | Search query, project ID, experiment ID, resource kind, resource ID, artifact ID, modality filter, date range, limit, include-methods flag, include-review-comments flag, requested report section, allowlisted control action name, registered operation ID, operation parameters, confirmation code, control job ID, file upload metadata such as file name, content type, size, and checksum | User prompt and model-selected tool arguments |
| IAS research metadata and control status returned by tools | Opaque experiment/project/result/resource/artifact IDs, experiment title, modality summary, method names and versions, status, short summaries, review status, report readiness, warnings, report objective, methods summary, results summary, limitations, figure summaries, approved control action catalog entries, capability registry metadata, operation plans, sanitized job status, bounded result summaries, research-use notice | Authorized IAS read-only APIs and approved IAS Control Action endpoints |
| Operational security data | Hashed user and tenant identifiers, tool name, result code, latency, aggregate metrics, circuit-breaker state | IAS OpenAI Adapter runtime |

## Tool Input And Output Coverage

The current app version exposes read-only context tools, Capability Manifest tools, direct IAS UI/viewer/task/report control tools, and approved IAS Control Action tools. Inputs may include sanitized search terms, opaque IAS entity IDs, operation IDs, viewer IDs, panel names, channel/viewer settings, analysis/report parameters, task IDs, confirmation codes, and file metadata/checksums. Outputs may include sanitized capability metadata, validation results, action IDs, correlation IDs, UI sync status, task/job status, report/artifact IDs, display/download URLs, metadata-only image/figure summaries, bounded result summaries, audit metadata, and the research-use notice.

Current tool names:

- `get_ias_capability_manifest`
- `search_ias_capabilities`
- `get_ias_capability`
- `validate_ias_action`
- `execute_ias_action`
- `plan_ias_action_from_instruction`
- `resolve_ias_entities_from_instruction`
- `plan_ias_workflow`
- `execute_ias_instruction`
- `run_ias_analysis_report`
- `execute_ias_workflow`
- `execute_ias_plan`
- `explain_ias_plan`
- `get_ias_action_status`
- `get_ias_audit_log`
- `bind_ias_ui_session`
- `get_ias_ui_session_state`
- `sync_ias_ui_state`
- `subscribe_ias_ui_events`
- `get_ias_active_view`
- `set_ias_active_view`
- `create_ias_display_url`
- `search_ias_experiments`
- `resolve_ias_entity`
- `get_ias_experiment_summary`
- `list_ias_analysis_results`
- `get_ias_report_context`
- `open_ias_experiment`
- `load_ias_image_dataset`
- `open_ias_result`
- `focus_ias_panel`
- `set_ias_viewer_state`
- `get_ias_viewer_state`
- `reset_ias_viewer_state`
- `start_ias_analysis`
- `get_ias_analysis_status`
- `list_ias_background_tasks`
- `get_ias_background_task`
- `cancel_ias_background_task`
- `generate_ias_report`
- `get_ias_report_status`
- `list_ias_reports`
- `get_ias_report_artifacts`
- `list_ias_image_assets`
- `list_ias_figures`
- `get_ias_figure_asset`
- `list_ias_control_actions`
- `execute_ias_control_action`
- `get_ias_control_job_status`
- `list_ias_capabilities`
- `get_ias_capability_schema`
- `plan_ias_operation`
- `execute_ias_operation`
- `get_ias_operation_status`
- `cancel_ias_operation`
- `search_ias_resources`
- `get_ias_resource`
- `upload_file_to_ias`
- `get_ias_artifact_metadata`
- `generate_ias_report_context`

The app does not provide arbitrary write, delete, export, publish, send-message, raw-file, direct database, shell-command, or unregistered job-running tools. Control execution is limited to the Capability Manifest, confirmation policy, IAS authorization, and named allowlisted IAS Control Action catalog. Raw images, raw files, signed URLs, storage URIs, secrets, PHI, and clinical conclusions are not returned to ChatGPT.

## Purposes Of Use

Life Analytics uses the processed data only to authenticate and authorize the requesting IAS user, run the selected IAS context tool or approved IAS Control Action, return minimized research context or bounded control status in ChatGPT, enforce access control and rate limits, maintain security audit logs and aggregate operational metrics, and investigate incidents or support requests.

The app does not use tool inputs or outputs for advertising, cross-context behavioral profiling, sale of personal data, or unrelated product analytics.

## Recipients And Sharing

Data may be processed by OpenAI/ChatGPT, Life Analytics IAS services, Life Analytics infrastructure and operations personnel, service providers that host or secure Life Analytics infrastructure, and legal, compliance, or security recipients when required by law or necessary to protect users, Life Analytics, OpenAI, or the service.

The app does not sell personal data and does not intentionally disclose IAS research data to public search engines, advertising networks, or unauthorized third parties.

## Data Not Collected Or Returned

The app is designed not to collect, request, return, or log PHI, patient identifiers, subject identifiers that can identify a person, payment card data, government identifiers, passwords, API keys, MFA/OTP codes, OAuth tokens, email addresses, phone numbers, addresses, personal names, raw chat logs, broad profile data, raw files, raw images, raw sequences, raw spectra, raw flow cytometry files, signed URLs, storage URIs, internal file paths, database primary keys, request IDs, trace IDs, session IDs, arbitrary URLs, shell commands, direct database output, publish/send results, delete results, permission-change results, diagnosis, treatment decisions, clinical judgment, or medical advice.

If a user asks for prohibited data, the app should refuse or return only sanitized research context.

## Retention

OAuth bearer tokens are used only transiently for request verification and are not stored by the Adapter. Tool inputs and raw IAS responses are not stored in Adapter audit logs. Adapter audit records contain hashed identities and non-sensitive operational metadata and are retained for no more than 90 days by default, unless a shorter deployment policy applies or a longer period is required for legal, security, or incident-response reasons. Aggregate metrics do not include raw user identifiers, tool inputs, or IAS research content. IAS workspace data remains governed by the IAS service terms and customer configuration.

## User Controls

Users can disconnect or revoke the Life Analytics IAS OpenAI App from ChatGPT, ask their IAS administrator to change or remove IAS workspace access, request deletion or correction of IAS account/workspace data where permitted by the applicable IAS agreement and law, or contact Life Analytics support for privacy, access, deletion, or support requests.

Revoking the ChatGPT app connection stops future app access but does not by itself delete IAS workspace records that are retained under the IAS customer agreement.

## Security And Data Boundaries

The IAS OpenAI Adapter is a separate service from IAS core. It verifies OAuth tokens, checks scopes, calls only approved IAS internal read-only APIs and allowlisted IAS Control Action endpoints, and sanitizes responses before returning them to ChatGPT. The Adapter does not have direct database, object-storage, or analysis job-queue credentials. The public MCP surface can be disabled independently from IAS core if an incident occurs.

## Changes

Life Analytics may update this policy to reflect new tools, data practices, or legal requirements. The published policy should be updated before any new tool collects or returns additional data categories.
