Mosaic is now liveMCP tools, 760+ targets across oncology, neuro and cardio, preprint on Zenodo.See plans →
Mosaic

Privacy Policy

Last updated 2026-07-01. Mosaic is operated by Sourabh Nyalkalkar ("we", "us") as an independent developer. Questions about this policy: [email protected].

What Mosaic is

Mosaic is a pre-clinical intelligence tool over a curated biomedical knowledge graph (targets, compounds, patents, papers, clinical trials), used via a web app and an MCP (Model Context Protocol) server that AI clients like Claude can connect to. This policy covers both.

Information we collect

Connecting via Claude or another MCP client

When you add Mosaic as a connector in an AI client, that client sends tool-call requests (e.g. "look up target EGFR") directly to Mosaic's server on your behalf, authenticated by the sign-in you complete during connection. Mosaic sees only the parameters of each tool call, not your broader conversation with the AI client, and does not read or store the client's chat history, memory, or uploaded files.

How we use this information

We do not sell your personal information, and we do not use your queries to train any AI model.

Who we share data with

Mosaic uses the following service providers, each of which processes a limited slice of the data above solely to provide their service to us:

We do not otherwise sell, rent, or share your personal information with third parties, except to comply with law or to protect Mosaic's or others' rights and safety.

Data retention

Account and usage-tracking data is retained for as long as your account is active, plus a limited period afterward for legal, billing, and fraud-prevention purposes. OAuth authorization codes expire within a minute of issuance; access tokens expire within an hour and refresh automatically. You can request deletion at any time (see below).

Your rights

Email [email protected] to request a copy of your data, ask us to correct it, or delete your account and associated personal data. We'll respond within a reasonable time, generally within 30 days.

Security

Passwords aren't used at all (sign-in is via time-limited, single-use email links); API/OAuth tokens are hashed at rest; traffic is encrypted in transit (TLS). See our security & vulnerability disclosure policy for how to report a security issue.

Not medical or clinical advice

Mosaic surfaces patterns in public pre-clinical literature and patent/trial data as a hypothesis-generation aid for research use. It is not medical, clinical, diagnostic, or investment advice, and nothing in the product should be relied on as such. This is a product disclaimer, not a data-privacy term, but we restate it here because it shapes what the service does and does not do with your inputs.

Children

Mosaic is not directed at, and is not knowingly used by, anyone under 18.

Changes to this policy

If we make material changes, we'll update the date at the top of this page and, where required, notify you by email.