Illnessfinder ← Back to Illnessfinder

Privacy notice

How Illnessfinder handles personal and case information

Revised July 30, 2026

1. Controller

Lundberg Selection AB, company registration no. 556448-2049, Grevgatan 15, 114 53 Stockholm, Sweden, is the controller for personal data processed to provide Illnessfinder accounts, memberships and the case tool. Privacy requests can be sent to contact@lundbergselection.com or made by post to that address.

2. Information we process

Account and security: email address, language, password hash, account status, verification and reset tokens in hashed form, session identifiers in hashed form, terms acceptance, timestamps and security audit events. Passwords and usable login tokens are not stored in readable form.

Membership and billing: selected plan, billing period, currency, amounts, invoice and subscription references, payment status, cancellation status and limited customer data returned by Stripe. Full card details are handled by Stripe and are not stored by Illnessfinder.

Case information: sex, age, blood type, height, weight, risk factors, signs, symptoms, laboratory entries, medication, supplements and diet information that a user chooses to enter. These fields may reveal health information. Do not enter names, identity numbers, contact details or other direct identifiers.

Requests and communications: information needed to process account, complaint and withdrawal requests, together with the reference and time of receipt. Sensitive request payloads are encrypted at rest in the application outbox or request store.

3. Why and on what basis

Account, membership, payment, invoice and support information is processed to enter into and perform the user agreement. Accounting and transaction records are processed to comply with legal obligations. Limited logs, rate limits, fraud prevention and audit events are processed for the legitimate interest of protecting users, the service and payment flows.

Health-related case information is processed only after the user gives explicit consent at the start of a case. It is used to generate the requested educational result. Consent can be withdrawn by leaving the tool and clearing the case with “Start new case”; no further result is then produced from the cleared case. Withdrawing consent does not affect processing that was lawful before withdrawal.

4. Temporary case processing

Case information is held in the active server-side session and browser state needed to move between the four steps. It is not written to the account database as a named or persistent case history and is not used for advertising or model training. Starting a new case clears the entered fields from the active case. Server sessions expire after inactivity and are removed through the host’s session-cleanup process.

Because a session and ordinary web logs can contain technical identifiers such as an IP address and cookie value, the instruction not to enter direct identifiers remains important even when analysing a hypothetical or third-party case.

5. Retention

Account information is retained while the account is active and for a limited period afterwards when needed for security, disputes or legal claims. Unverified accounts, expired tokens, sessions, rate-limit entries and routine audit data are subject to periodic deletion. Login sessions expire after 12 hours, or after 30 days when “keep me signed in” is chosen.

Invoices and information required for bookkeeping are retained for the period required by Swedish law, normally seven years. Withdrawal and complaint records are retained for the period needed to document consumer rights and resolve the matter. Hosting access logs are kept on a short rotating schedule for security and operations.

6. Recipients and processors

Inleed provides hosting and related infrastructure in Sweden. Stripe provides payment, subscription, invoice, tax and fraud-prevention services and receives the information required for those purposes. Transactional email is handled through the configured company mail infrastructure. Professional advisers or authorities receive information only when necessary and legally justified.

Stripe and its service providers may process data outside the EEA. Such transfers are handled under the safeguards described in Stripe’s privacy documentation, including applicable adequacy decisions or contractual safeguards. Illnessfinder does not sell personal data and does not use case information for targeted advertising.

7. Cookies and local storage

Illnessfinder uses essential cookies for the case session, CSRF protection and signed-in account access. A “keep me signed in” cookie lasts up to 30 days; otherwise the account session lasts up to 12 hours. Local browser storage remembers the current case step and whether the case-information notice has been accepted. These items are necessary for the requested service and are not advertising cookies.

8. Automated processing

The case tool ranks educational reference matches from information entered by the user. It does not make a legal, medical, employment, insurance or similarly significant decision about a person. Payment providers may perform their own fraud and payment checks under their respective notices.

9. Your rights

Depending on the circumstances, a person may request access, correction, deletion, restriction, data portability or object to processing, and may withdraw consent. Identity may need to be verified before a request is completed. Legal retention duties and the rights of others can limit deletion or access.

A complaint about personal-data processing may be made to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se, or to another competent supervisory authority.

10. Contact

Lundberg Selection AB
Company registration no. 556448-2049
Grevgatan 15
114 53 Stockholm, Sweden
Telephone +46 8 559 220 99
contact@lundbergselection.com