Privacy Policy
Last updated: July 6, 2026
The one rule everything follows
Patient data never leaves your device. Patient stickers, health numbers,
dates of birth, diagnoses, procedures, claims, and remittances are stored only in the
clearcodeMD app on your phone — encrypted at rest using platform-protected key storage, and
protected by your device lock. Our servers have no database fields for patient information,
deliberately, and no app feature transmits it to us.
What we do collect
- Account information: your name, email address, and a cryptographic hash
of your password (we cannot see the password itself).
- Session tokens: hashed sign-in tokens with a device note (e.g. phone
model) so you can stay signed in.
- Subscription status: when paid plans begin, your plan and its status.
Payments will be processed by Stripe; card numbers go directly to Stripe and never touch
our servers.
- Optional financial claim mirror: service codes, submitted and paid amounts,
statuses, ministry claim references, and return explanations. This lets the website show
your financial dashboard and lets a blank new phone restore its ledger. It never includes
a patient name, health number, version code, sticker image, or source document.
- Security and service data: session and trusted-device tokens, email-verification
records, and—if you opt in—mobile notification delivery tokens. The apps may also send a
technical crash report to help diagnose a failure; patient information must not be included.
- Essential service providers: our hosting and email providers operate the account
service. If enabled, Google reCAPTCHA protects website registration and Stripe processes
payments. We do not provide either service with patient identifiers or source files.
What we don't do
- No patient data on our servers — ever.
- No advertising, no analytics trackers, no sale or sharing of your information.
- No patient data on our servers. The financial mirror is deliberately limited to the
non-patient fields listed above.
Your responsibilities as a health information custodian
Under Ontario's PHIPA, the patient information in the app remains under your custodianship.
clearcodeMD gives you the tools — device encryption, an app lock, and passphrase-encrypted
backups — but keeping your device secured and your backup passphrase safe is in your hands.
Data retention and deletion
Delete the app and its data is gone from the phone (keep an encrypted backup first if you
need your records). You can delete your server account from the app's Account settings, or
contact Support for help. We remove account records, sessions, settings,
and mirrored financial claims within 30 days. To prevent repeated free-trial use after deletion,
we retain a one-way, server-peppered HMAC of the normalized OHIP billing number and the date
its trial was first used. This record cannot be used to recover the billing number and is not
linked to a retained account profile.
Where our servers live
Account data is stored with our hosting provider. The account service is designed not to
store patient information; patient identifiers and source files remain on the device. Your
practice remains responsible for its own privacy, record-retention, and regulatory obligations.
Contact
Questions or concerns: Support.