Privacy boundaries
We separate public contact from the authenticated project workspace.
This page explains the data boundaries of the current Chiasma site. It is not a regulatory-compliance or certification declaration.
Last updated · 4 September 2026Public contact draft
The contact form is not submitted to Chiasma servers and we do not store its contents. Your browser copies the text to the device clipboard and opens the chosen app without inserting content; you paste, review, and send it yourself.
Patient and clinical data
The public form and client panel are not clinical-record systems. Do not enter patient identifiers, health records, or sensitive clinical data. Project data requirements are considered only after purpose, contract, and secure-transfer boundaries are separately defined.
Client workspace
The panel processes account, customer membership, project metadata, and status records in D1. Access is bounded by a verified account, session, and server-side role checks.
Account security
Security records required for registration verification, two-step email codes, password reset, and passkey operations are processed. Authentication and administrative routes use private, no-store, and noindex responses.
Public client references
Client names and media are disabled by default. Only work with separately verified publication permission is served; when permission is withdrawn, its content and media requests are blocked again.
Want to discuss a project?
Please do not share patient-identifying or sensitive clinical data.
Discuss a project