Privacy
What leaves your browser, in full.
Last updated 28 August 2026
The screening tool has no account system, no analytics and no server of its own. It is a static page and everything below follows from that. The study board, which is a separate surface, keeps counters against public study identifiers. That is described in its own section and it involves nothing about you.
What we collect
Nothing. There is no cookie, no local storage of your answers, no session, no fingerprint and no third party tag. Close the tab and every value you typed is gone.
What the page sends, and where
- The condition name you type. Sent to the public ClinicalTrials.gov v2 API at clinicaltrials.gov, exactly as any search box on that site would send it. Your browser makes that request directly. We never see it.
- A count request on the home page. When the home page loads it asks the registry how many studies are currently recruiting, so the figure you see is real rather than a claim. That request carries no information about you.
- Two requests, only if you pay. Collecting your seat after checkout, and renewing it in the final week before it expires. Both carry the licence and nothing else. A free user never contacts that server at all.
- A font request. Geist and Geist Mono load from fonts.googleapis.com and fonts.gstatic.com, which receives your IP address the way it would for any site using Google Fonts.
- A counter, only on the study board. Opening a listing, or clicking through from one into the screener, increments a count held against that listing. The request carries a listing id and one word saying which of the two happened. No identifier, no profile, nothing that could be joined back to you. Never sent from the screening tool.
- Nothing else. There is no form anywhere on this site that collects anything about you. If a listing interests you, it shows you the study team's own address and you write to them yourself, which never touches us.
- A sentence model, only if you turn the meaning layer on. Switching that layer on in the rail downloads roughly 23 MB of weights from jsdelivr.net, once, and your browser caches them. The model then runs inside your tab. Criteria text is fed to it locally. Nothing is uploaded to run it, and leaving the layer off means the request never happens.
That is the complete list of outbound requests.
Contacting a study team
We deliberately do not sit in the middle of this. A listing shows the contact address the researcher published, and you email them yourself. We never see that message, never store it and could not produce it if anyone asked us to.
An earlier version of this site did relay your name and a note to the researcher, and kept them. We removed it. Holding identifiable health information about people, including children, arriving through listings nobody verifies, was a risk worth eliminating rather than managing. The safest version of that data is the version that was never collected.
What a researcher can see is how many people opened their listing and how many asked how to take part. Counts, never people. They cannot tell that you looked.
The study board, and what it counts
The board carries listings researchers wrote about their own studies, each anchored to a ClinicalTrials.gov identifier we check before publishing. Three counters sit behind each listing: how many times it was opened, how many times someone clicked into the screener from it, and how many asked how to take part.
What is stored is a listing id and three integers. There is no row for a person, because no identifier is ever sent, so there is nothing to profile, sell or hand over. Writes are rate limited per listing so the figures cannot be inflated by refreshing.
If you would rather not be counted, blocking the licence subdomain in your browser stops it and the board still works. Nothing in the screening tool depends on it.
Where the models run
All three reading layers execute in your browser. The rule engine and the concept model ship with the page. The sentence model is fetched on request and then runs locally like the others. None of them is an API call: no criterion, no profile and no answer is ever sent to a model hosted anywhere else. There is no prompt, and no third party sees the text being read.
What never leaves the page
Age, sex at birth, country and every answer you give the solver are held in memory in your tab and compared locally against the registry fields already downloaded. They are not transmitted, not logged, and not attached to the registry query.
Copying a search link
The copied link contains the condition name and nothing else. It never includes age, sex at birth, country, location, solver answers or screening results. Anyone you send it to can see the condition in the link and runs a fresh search in their own browser.
Your location, if you ask for distances
The tool can tell you how far each study's nearest site is. It needs a position to do that, and it gets one only when you press the button and only in one of two ways. Either your browser asks your permission and hands the page a coordinate, which no version of that flow sends to us, or you type a city name and the page matches it against the cities that arrived with the studies you have already downloaded. There is no geocoding service, no lookup by IP address, and no request leaves the tab either way. The position is held in memory, is dropped when you close or reload the page, and is never written to storage or attached to a registry query. Distances are computed here from the coordinates the registry publishes for each site.
Watching a condition
Pressing Watch keeps that run in this browser so the next search of the same condition can tell you what has changed. What is kept is the condition you typed, the age, sex at birth and country you entered, the answers you gave the solver, and the list of study numbers with the verdict each one got and its title. That is all, and it is enough to compare two runs.
It is written to this browser's local storage on your device. It is not transmitted, not logged, not attached to any registry query, and not readable by us. Stop watching deletes it, and clearing your browser's site data for inclusionhealth.xyz removes it along with everything else. Up to twelve conditions are kept, and a thirteenth pushes out the oldest.
Contacting a study
Each study that has not been ruled out shows the coordinator the registry publishes for the site nearest you, and offers to copy a short opening message. Both come from data already downloaded with the search; nothing is looked up separately and nothing is sent to us.
The two links are ordinary tel: and mailto: links, so pressing one hands off to your own phone or mail app and the page stops being involved. The pre-filled message contains the study number, the site, whatever of age, sex at birth and country you entered, and the criteria this tool could not decide. It is addressed to the study coordinator, not to us, and you can read and edit every word before you send it. Nothing is sent on your behalf, and no message is stored.
If you pay for a plan
A seat is a licence signed by our licence server and checked here in the page, so day to day the tool works offline and we learn nothing about your use. The licence and any watched conditions live in this browser's local storage, on your device, and you can clear them from the tool at any time.
There are exactly two moments a paid plan talks to that server. Once when you finish checkout, where this site swaps the Stripe session for your licence. And once inside the last week before a licence expires, where the tool asks for a fresh one using the licence itself. Neither request carries a condition, a profile, an answer, or anything else about a patient. Card details are held by Stripe, never by us.
Health information
Because Inclusion Health receives and stores no patient profile, it does not hold protected health information from the screening tool. It is not a covered entity, and using the tool is not a disclosure to us. Your clinician and the study site remain the parties who hold your record.
Children
Caregivers routinely screen on behalf of a child. Since nothing is collected, no information about a minor is gathered by us either.
Changes
If this page ever adds a server, an account or an analytics tag, this document changes first and the date above moves with it.
Contact
Questions to hello@inclusionhealth.xyz.