Privacy
Privacy policy.
NoustaView exists because a study should be readable without being sent anywhere first. This page states what that means in practice, and the few places where data does leave your device.
Studies you open
Every study opened from your own drive is decoded and rendered entirely inside this browser tab. No server is involved at any point in that, and no image data is uploaded, copied to a NoustaView system, or retained anywhere: close the tab and the study is gone. The viewer keeps working offline while the tab stays open, which is the same fact stated from the other direction.
Share Case (Supporter and Pro)
Share Case is the one feature that sends image data away from your device, and it operates only when you choose it. You select the case, review it in that feature's own preview step, and confirm. Only the de-identified copy which you have reviewed and confirmed in that step is uploaded. Nothing is sent automatically, and nothing is sent from a study which you have not explicitly shared.
That copy is hosted so a recipient can open it from a link. The link remains under your control: it can carry a password, be given an expiry, and be revoked early from your dashboard. Whoever opens it needs no account and no install.
Some ultrasound and screen-capture images carry patient text burned into the pixels, where no tag or field holds it, so identifiers alone are not the whole story. Share Case flags series likely to contain such text, based on their image type and tags, and when you open a series' review panel it looks for the text on your own device — the detection runs in your browser and uploads nothing. You review what it suggests and confirm it before the share is created. Detection can miss text, so check the preview yourself: this reduces what a recipient can see without guaranteeing the copy is fully de-identified.
Load from PACS (Supporter and Pro)
Load from PACS fetches studies directly from your own PACS into this browser tab. Requests travel from the tab straight to the PACS's own endpoint, and none of that traffic passes through a NoustaView server.
A study retrieved this way comes from a clinical system rather than a de-identified export, so it may carry patient identifiers which a de-identified copy would not. The feature is a viewing convenience for people who already have access to that PACS, not a new data flow.
The connection itself (name, address, sign-in type and username) is saved on your own device. A password or token is held for the current tab only and is gone when the tab closes, unless you tick Remember the password/token on this device.
Clinic review (clinic accounts only)
Clinic review sends the same kind of encrypted, pixel-only copy, along with coded laterality and view tags. It is opened by the reviewers that the centre has assigned, for a technical adequacy check — never for diagnosis. Their decisions are kept under the centre's own case code, and the case is deleted when it expires, at most 3 days after it was sent.
The feedback form
The feedback form routes through NoustaView's own server: a submission goes to a single endpoint there, which relays it by email through Resend.
What is sent: the category you pick, the subject, and your message. Your email address is optional, and it is used only to reply to you — it becomes the reply-to address on that email. A submission made without one is not tied to any address at all.
If the viewer has captured technical error details on this device, the form offers to attach them. That checkbox is off by default, and nothing is attached unless you tick it. What it covers is browser and application information and error messages — never patient data, and never images. On a successful send, those captured details are cleared from your device, and NoustaView's own server keeps no copy of the submission once it has been relayed.
If something here is unclear
If this page does not match what you see, or a question about your data is not answered here, raise it on the feedback page. For how the viewer itself is used, see the user guide.