Informativa sulla privacy
Last updated: 3 September 2026
What we collect
- Account data: email address, name if you provide it, and the identity provider you signed in with.
- Preferences: your selected theme and language, stored in cookies.
- Billing data: a Stripe customer identifier and subscription status. Card numbers are handled entirely by Stripe and never reach our servers.
- Technical data: server logs containing IP address, user agent and requested paths, retained for security and troubleshooting.
What we do not collect
We do not collect personal health information. The Service is not designed to receive patient data, and submitting it is prohibited by the Terms & Conditions. Searches are not linked to identifiable patients.
Why we process it
To provide and secure the Service, to authenticate you, to bill for paid plans, and to meet legal obligations. We do not sell personal data and do not use it for advertising.
Cookies
We use strictly necessary cookies only: a session cookie for authentication, a CSRF token, and two preference cookies for theme and language. No third-party advertising or cross-site tracking cookies are set.
Processors we rely on
- Stripe - payment processing and subscription management.
- Google, Microsoft, Facebook and LinkedIn - only if you choose to sign in with that provider.
- The U.S. National Library of Medicine Clinical Tables service - receives only the search term you type, never account or patient data.
- Our hosting provider, which operates the servers running this application.
Retention
Account data is kept while your account is open and for a limited period afterwards to meet tax and accounting obligations. Server logs are rotated on a short cycle.
Your rights
You may request access to, correction of, or deletion of your personal data, and may withdraw consent to optional processing. Contact us using the details on our main company site. If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada.
Security
Traffic is encrypted in transit with TLS. Passwords are stored using a salted, computationally expensive hash. Administrative access is role-gated and audited.
Changes
We will post material changes to this policy on this page and, where required, notify you by email.