Privacy
What leaves your browser, in full.
Last updated 22 August 2026
The screening tool has no account system, no analytics and no server of its own. It is a static page and everything below follows from that. The study board, which is a separate surface, keeps counters against public study identifiers. That is described in its own section and it involves nothing about you.
What we collect
Nothing. There is no cookie, no local storage of your answers, no session, no fingerprint and no third party tag. Close the tab and every value you typed is gone.
What the page sends, and where
- The condition name you type. Sent to the public ClinicalTrials.gov v2 API at clinicaltrials.gov, exactly as any search box on that site would send it. Your browser makes that request directly. We never see it.
- A count request on the home page. When the home page loads it asks the registry how many studies are currently recruiting, so the figure you see is real rather than a claim. That request carries no information about you.
- Two requests, only if you pay. Collecting your seat after checkout, and renewing it in the final week before it expires. Both carry the licence and nothing else. A free user never contacts that server at all.
- A font request. Geist and Geist Mono load from fonts.googleapis.com and fonts.gstatic.com, which receives your IP address the way it would for any site using Google Fonts.
- A counter, only on the study board. Opening a listing, or clicking through from one into the screener, increments a count held against that listing. The request carries a listing id and one word saying which of the two happened. No identifier, no profile, nothing that could be joined back to you. Never sent from the screening tool.
- Nothing else. There is no form anywhere on this site that collects anything about you. If a listing interests you, it shows you the study team's own address and you write to them yourself, which never touches us.
- A sentence model, only if you turn the meaning layer on. Switching that layer on in the rail downloads roughly 23 MB of weights from jsdelivr.net, once, and your browser caches them. The model then runs inside your tab. Criteria text is fed to it locally. Nothing is uploaded to run it, and leaving the layer off means the request never happens.
That is the complete list of outbound requests.
Contacting a study team
We deliberately do not sit in the middle of this. A listing shows the contact address the researcher published, and you email them yourself. We never see that message, never store it and could not produce it if anyone asked us to.
An earlier version of this site did relay your name and a note to the researcher, and kept them. We removed it. Holding identifiable health information about people, including children, arriving through listings nobody verifies, was a risk worth eliminating rather than managing. The safest version of that data is the version that was never collected.
What a researcher can see is how many people opened their listing and how many asked how to take part. Counts, never people. They cannot tell that you looked.
The study board, and what it counts
The board carries listings researchers wrote about their own studies, each anchored to a ClinicalTrials.gov identifier we check before publishing. Three counters sit behind each listing: how many times it was opened, how many times someone clicked into the screener from it, and how many asked how to take part.
What is stored is a listing id and three integers. There is no row for a person, because no identifier is ever sent, so there is nothing to profile, sell or hand over. Writes are rate limited per listing so the figures cannot be inflated by refreshing.
If you would rather not be counted, blocking the licence subdomain in your browser stops it and the board still works. Nothing in the screening tool depends on it.
Where the models run
All three reading layers execute in your browser. The rule engine and the concept model ship with the page. The sentence model is fetched on request and then runs locally like the others. None of them is an API call: no criterion, no profile and no answer is ever sent to a model hosted anywhere else. There is no prompt, and no third party sees the text being read.
What never leaves the page
Age, sex at birth, country and every answer you give the solver are held in memory in your tab and compared locally against the registry fields already downloaded. They are not transmitted, not logged, and not attached to the registry query.
If you pay for a plan
A seat is a licence signed by our licence server and checked here in the page, so day to day the tool works offline and we learn nothing about your use. The licence and any saved cohorts live in this browser's local storage, on your device, and you can clear them from the tool at any time.
There are exactly two moments a paid plan talks to that server. Once when you finish checkout, where this site swaps the Stripe session for your licence. And once inside the last week before a licence expires, where the tool asks for a fresh one using the licence itself. Neither request carries a condition, a profile, an answer, or anything else about a patient. Card details are held by Stripe, never by us.
Health information
Because Inclusion Health receives and stores no patient profile, it does not hold protected health information from the screening tool. It is not a covered entity, and using the tool is not a disclosure to us. Your clinician and the study site remain the parties who hold your record.
Children
Caregivers routinely screen on behalf of a child. Since nothing is collected, no information about a minor is gathered by us either.
Changes
If this page ever adds a server, an account or an analytics tag, this document changes first and the date above moves with it.
Contact
Questions to hello@inclusionhealth.xyz.