clearcodeMD

Privacy Policy

Last updated: July 6, 2026

The one rule everything follows

Patient data never leaves your device. Patient stickers, health numbers, dates of birth, diagnoses, procedures, claims, and remittances are stored only in the clearcodeMD app on your phone — encrypted at rest using platform-protected key storage, and protected by your device lock. Our servers have no database fields for patient information, deliberately, and no app feature transmits it to us.

What we do collect

What we don't do

Your responsibilities as a health information custodian

Under Ontario's PHIPA, the patient information in the app remains under your custodianship. clearcodeMD gives you the tools — device encryption, an app lock, and passphrase-encrypted backups — but keeping your device secured and your backup passphrase safe is in your hands.

Data retention and deletion

Delete the app and its data is gone from the phone (keep an encrypted backup first if you need your records). You can delete your server account from the app's Account settings, or contact Support for help. We remove account records, sessions, settings, and mirrored financial claims within 30 days. To prevent repeated free-trial use after deletion, we retain a one-way, server-peppered HMAC of the normalized OHIP billing number and the date its trial was first used. This record cannot be used to recover the billing number and is not linked to a retained account profile.

Where our servers live

Account data is stored with our hosting provider. The account service is designed not to store patient information; patient identifiers and source files remain on the device. Your practice remains responsible for its own privacy, record-retention, and regulatory obligations.

Contact

Questions or concerns: Support.