Privacy by design

Privacy policy for this starter build

The safest health-data strategy is not to collect information unless the product truly needs it.

Interactive tools

The screening and family-history tools in this build execute locally in the visitor’s web browser. The site code does not transmit or store the answers.

No account or patient portal

This build has no user account, no electronic health record connection, no pathology-report upload, and no database of personal medical information.

Analytics

No third-party analytics script is included in the current package. If analytics are added later, the privacy policy should identify the provider, data collected, retention period, and opt-out mechanism.

Future health-information features

Do not add pathology uploads, dates of birth, symptom histories tied to identity, reminder accounts, or referral forms until privacy, security, consent, legal, and data-retention requirements have been deliberately designed and reviewed.

Hosting logs

Hosting and network providers can maintain ordinary technical logs such as IP address, browser information, timestamps, and request paths. The production privacy notice should reflect the actual hosting configuration in use at launch.

Report explainers

Do not paste identifying information.

The colonoscopy-report and pathology-report explainers in this build process text locally in your browser. Colonoscopy.us does not need your name, date of birth, medical-record number, address, phone number, email address, or other identifiers to explain terminology.

Future changes require a privacy review. If account features, cloud AI, report uploads, reminders, analytics tied to health activity, or stored health histories are added later, this policy and the technical architecture must be updated before those features launch.