Delete your data
Ask for it to be deleted, and read exactly what that reaches.
One form, below. It also tells you the part most deletion pages leave out: in a clinical laboratory system some records are held to a legal minimum, and a request cannot shorten it. Every window is published on this page.
This page is also the address the app store listing points at, so it works without signing in.
The request form.
Three kinds of request, one form. Choosing a kind changes what is asked for below it and updates the summary beside it, so nothing is submitted on a guess.
Choose one of the three above and this panel will say exactly what it reaches, what it archives, and what it cannot touch.
If you are a patient, this is probably the wrong form. Your records belong to the laboratory that tested your sample, not to us, and only that laboratory can act on them. Section six below says how to reach it and what to ask for.
Five steps, and a person at three of them.
There is no automated pipeline behind this form, and pretending otherwise would set the wrong expectation about how quickly it moves.
The four windows, and what each one is anchored to.
A retention policy nobody can read is not a policy. These are the floors. A laboratory can set a longer window for its own tenant; it cannot go below the minimum its own regulator requires, and neither can a request from you.
| Record | Minimum | Anchored to | What a deletion request does |
|---|---|---|---|
| Results and reports | 2 years | The clinical laboratory improvement rules that set the floor for test records in the United States. Other jurisdictions set their own, and several are longer. | Archived. Removed from everyday views and kept retrievable for an assessment or a query. |
| Pathology material and slides | 10 years | Anatomic pathology retention practice, which is far longer than general chemistry because the material itself can be re-examined. | Archived. The physical material is the laboratory's; this window covers the record of it. |
| Audit trail | 6 years | The documentation-retention period under United States health-privacy law. | Nothing. It is append-only and it is the record that proves your deletion happened. |
| Specimen movement | 2 years | Chain of custody, held alongside the result it belongs to. | Archived with the result. |
| Account and profile | None | Nothing requires us to keep it. | Deleted. Genuinely removed rather than deactivated. |
| Messages you sent us | None | Nothing requires us to keep it. | Deleted, including anything sent through the contact form. |
Archived is a real state, not a euphemism. An archived record leaves worklists, searches, dashboards and exports. It is retrievable by a named person, for a stated reason, and that retrieval is itself written to the audit trail. What it is not is deleted, and this page will not use the word deleted for it.
Five things deleting your LabFlow data does not do.
Each of these has surprised somebody on some product, and each is worth knowing before you send the form rather than after.
A result delivered to a hospital record system, a clinician's inbox or a printer is that recipient's copy now. We can tell you where a report went; we cannot reach into another organisation's system.
The four in the table above are floors set by clinical rules, not preferences we chose. A laboratory can lengthen them; nobody can shorten them, including us.
The trail records that a deletion happened. An audit trail an application can rewrite proves nothing, which is exactly why it is the one table nothing can delete from.
If you are staff at a laboratory, deleting your personal account does not release the laboratory from keeping the records you produced. Those are the laboratory's, not yours.
Deleted data can persist in the database platform's own backups until they roll over on that platform's schedule. It is not restored into the product, and it ages out. Saying otherwise would be an easy sentence to write and a false one.
If you are a patient, ask the laboratory, not us.
Your test results belong to the laboratory that produced them. It decides what happens to them, and we act on its instructions rather than on ours. If we deleted a patient record because the patient asked us directly, we would be acting against the instructions of the organisation legally responsible for it.
That is not a way of avoiding the request. It is the same distinction that runs through the privacy policy, and it is what makes the rest of that document mean anything.
A deletion page that only says yes is not telling you the truth.
Most of them do. They promise erasure in a sentence, and then a laboratory discovers at its next assessment that erasure was never available for the records an assessor asks about. Publishing the windows first, and calling archiving by its own name, is slower to read and it is the version you can plan around.