Privacy Policy

Last updated: 3 September 2026

Template notice. This policy is a starting template, not legal advice. Have it reviewed against PIPEDA and any applicable provincial health privacy legislation before launch.

What we collect

What we do not collect

We do not collect personal health information. The Service is not designed to receive patient data, and submitting it is prohibited by the Terms & Conditions. Searches are not linked to identifiable patients.

Why we process it

To provide and secure the Service, to authenticate you, to bill for paid plans, and to meet legal obligations. We do not sell personal data and do not use it for advertising.

Cookies

We use strictly necessary cookies only: a session cookie for authentication, a CSRF token, and two preference cookies for theme and language. No third-party advertising or cross-site tracking cookies are set.

Processors we rely on

Retention

Account data is kept while your account is open and for a limited period afterwards to meet tax and accounting obligations. Server logs are rotated on a short cycle.

Your rights

You may request access to, correction of, or deletion of your personal data, and may withdraw consent to optional processing. Contact us using the details on our main company site. If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada.

Security

Traffic is encrypted in transit with TLS. Passwords are stored using a salted, computationally expensive hash. Administrative access is role-gated and audited.

Changes

We will post material changes to this policy on this page and, where required, notify you by email.