Privacy Policy

Last updated: this policy is kept current with the data practices described on our About the Patient Experience Database page — read that page for the full technical detail on sourcing.

What we collect

Search queries. Logged for analytics (which conditions are searched most), but your IP address is one-way hashed with a salt before storage. We cannot link a search log back to you.

Site analytics. Vercel Analytics and Speed Insights, both cookieless — no personal identifiers, no cross-site tracking, no consent banner required under standard interpretations of GDPR because no cookies or device fingerprinting are used.

Indexed content. PubMed abstracts, Reddit post titles/links (never post body text or usernames), and YouTube video metadata (never descriptions). None of this is data about you — see the About page for the full source-by-source breakdown.

What we don't collect

Legal basis & retention

Hashed search logs are kept for aggregate product analytics under legitimate interest (GDPR Art. 6(1)(f)) and are never used to build individual profiles. Because the hash is one-way and unsalted-per-session data is not retained alongside it, there is no practical way to fulfil an individual erasure request against a specific log entry — the hashing itself is the privacy protection. Indexed content (research/community/video metadata) is retained indefinitely as a public search index, refreshed on a rolling weekly cycle, with every entry linking back to its original public source.

Your rights

Because we don't hold identifiable personal data on visitors, most GDPR data-subject requests (access, portability) will return nothing to provide — there is no account or profile tied to you. If you believe content indexed from your own Reddit post, YouTube video, or a paper you authored should be removed, contact us and we will action it.

Contact

Reach us via roishternin.com.