Privacy Policy

Last updated: May 9, 2026 Version 2.0 Replaces v1.0 — March 28, 2026

🔒 MyopiaTracker is operated by iCare Enterprises, LLC (Arizona, USA). This policy explains what data we collect, why, how we protect it, and your rights. Version 2.0 introduces a de-identified clinical registry. Participation is optional — see Section 6.

Contents
  1. Who We Are
  2. Who Uses MyopiaTracker
  3. Data We Collect — Clinical (Clinician App)
  4. Data We Collect — Guardian Portal
  5. Data We Do Not Collect
  6. The De-Identified Registry
  7. How We Use Your Data
  8. Third-Party Processors and Sub-processors
  9. Data Storage and International Transfers
  10. Security
  11. Data Retention
  12. Your Rights
  13. Jurisdiction-Specific Notices
  14. Breach Notification
  15. Cookies and Analytics
  16. Changes to This Policy
  17. Contact and Data Requests

1. Who We Are

MyopiaTracker is operated by iCare Enterprises, LLC, a company registered in the State of Arizona, United States. We are the Data Controller for account-level data (clinician accounts, guardian accounts) and the Data Processor for clinical patient data entered by clinicians. See our Terms of Use for the full Data Processing Agreement.

Data and privacy enquiries: support@myopiatracker.com

2. Who Uses MyopiaTracker

MyopiaTracker has two user types: Clinicians (licensed eye care professionals) and Guardians (adult parents or caregivers of paediatric patients). Children under 18 do not have accounts and do not interact directly with the platform. All data about child patients is entered by clinicians or guardians.

3. Data We Collect — Clinical (Clinician App)

3.1 Clinician Account Data

3.2 Patient Records (Entered by Clinician)

Patient records contain no direct identifiers — no patient names, exact dates of birth, addresses, or government IDs. We store:

3.3 Free and Pro/Enterprise Tiers

FeatureFree tierPro / Enterprise
Patient data storageBrowser localStorage only — never transmittedEncrypted Firestore (Google Firebase)
Registry participationNot availableOptional opt-in
AI InsightsRequires own API keyAvailable
Data on our serversNoneYes — encrypted

4. Data We Collect — Guardian Portal

Guardian accounts are for adult caregivers only. We collect:

Guardian log data is accessible to the treating clinician for compliance monitoring purposes.

5. Data We Do Not Collect

Never collected: Patient names · Exact dates of birth · Patient government IDs · Patient addresses · Guardian names or phone numbers · Clinic names in patient records · Precise geographic location (country only) · Free-text notes in registry records · Any data from children directly

We do not use behavioural tracking, advertising cookies, or sell any data about our users to advertisers.

6. The De-Identified Registry New

⚠️ Registry participation is entirely optional. The clinical service works fully without it. Both the clinician and the guardian must separately opt in for a patient's data to enter the registry.

6.1 Purpose

The registry supports epidemiological research, clinical benchmarking, and commercial analytics. De-identified aggregate data may be used to generate reports for pharmaceutical companies, medical device manufacturers, lens producers, and academic researchers. This commercial use is intentional and is disclosed here explicitly.

6.2 What Enters the Registry

Registry fields per visit: Country (ISO 2-letter) · Age band (e.g. "8–9") · Sex · Ethnicity group (jurisdiction-dependent) · Manifest refraction OD/OS · Cycloplegic refraction (where performed) · Axial length OD/OS (where measured) · Device class · Treatment modality · Parental myopia status · Estimated outdoor hours/day · Estimated near-work hours/day · Visit sequence · Months since first visit · Months on current treatment · Prior treatment (yes/no) · One-way scoped visit-linkage token (cannot identify patient)

6.3 What Never Enters the Registry

Never in registry: Names · Exact DOB · Patient or clinic identifiers · City or postcode · Exact visit dates · Guardian information · Free-text notes

6.4 Commercial Output Controls

6.5 Country Exclusions

Registry collection is not available for clinicians in the People's Republic of China or the Russian Federation.

6.6 Consent and Revocation

Both clinician and guardian consent are required. Either party may revoke at any time via the app. On revocation, no new registry records are generated. Previously submitted records are flagged for exclusion from future analyses. Historical aggregate reports already delivered are not retractable.

7. How We Use Your Data

DataPurposeLegal Basis
Clinician account dataProvide the clinical SaaS service, billing, communicationsContract performance
Patient recordsClinical service delivery on behalf of the clinician (as Processor)Clinician's legitimate interests / contract
Guardian logsCompliance monitoring, clinician reportingGuardian consent + clinician contract
Registry recordsEpidemiological research, benchmarking, commercial analyticsExplicit opt-in consent
Audit logsSecurity, legal compliance, breach responseLegitimate interests / legal obligation

8. Third-Party Processors and Sub-processors

ProcessorPurposeData SharedLocation
Google LLC (Firebase / Firestore)Cloud database, authentication, hostingEncrypted patient and account data (Pro/Enterprise)United States — Firebase DPA signed
Anthropic, PBCAI Insights (optional feature)Anonymised clinical parameters — no names, no IDs. Not used to train models per Anthropic API terms.United States
Stripe, Inc.Payment processingEmail, billing address, payment method (Stripe holds card data — we do not)United States

We do not share data with advertisers, data brokers, or any other third party not listed above, except as required by law.

9. Data Storage and International Transfers

Pro and Enterprise clinical data is stored on Google Firebase infrastructure, primarily in the United States. By using the cloud sync features, you acknowledge that data is processed in the United States.

We have signed Google's Firebase Data Processing Agreement, which incorporates Standard Contractual Clauses for international transfers and requires Google to implement appropriate security measures. A link to this agreement is in our Terms of Use.

Free tier users: All data stays in your browser's localStorage and is never transmitted to any server.

10. Security

11. Data Retention

Data TypeRetention Period
Clinical visit records7 years from last visit, then permanently deleted
Guardian daily logs2 years rolling, or deleted on account deletion request
Registry records (de-identified)7 years
Consent records10 years (legal audit requirement)
Audit logs7 years
Payment records7 years (tax and financial law)

12. Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise any right: support@myopiatracker.com. We will respond within 30 days.

13. Jurisdiction-Specific Notices

🇺🇸
United States
MyopiaTracker operates on Google Cloud/Firebase infrastructure configured for BAA-eligible services under Google's Cloud Data Processing Addendum. A clinic-facing Business Associate Agreement (BAA) is available to Enterprise plan subscribers or by separate written agreement. Free and Pro plan users are responsible for their own HIPAA compliance obligations. California residents have additional rights under CCPA including the right to know and opt out of sale (we do not sell personal data).
🇦🇺
Australia
We process data under the Privacy Act 1988 (Cth) and Australian Privacy Principles. De-identified registry data that cannot reasonably re-identify an individual is not regulated under the APPs. You may complain to the OAIC if you believe we have breached your privacy.
🇸🇬
Singapore
We comply with the Personal Data Protection Act 2012. De-identified data falling outside the definition of personal data under s.4(5) is not regulated. Data is stored on Google Firebase US infrastructure. You may contact the PDPC with complaints.
🇨🇦
Canada
We comply with PIPEDA. Data is processed in the United States by Google Firebase and Stripe. By using Pro/Enterprise features, you acknowledge cross-border transfer to the US. You may contact the OPC with privacy concerns.
🇮🇳
India
We comply with the Digital Personal Data Protection Act 2023. Ethnicity is not collected or exported for Indian clinicians in the registry. We will update this notice as DPDPA implementation rules are finalised.
🇹🇼🇭🇰
Taiwan and Hong Kong
We comply with Taiwan's Personal Data Protection Act and Hong Kong's Personal Data (Privacy) Ordinance. Ethnicity is collected where clinicians voluntarily enter it. Registry exports are transformed and aggregate only.
🇲🇽
Mexico
We process data in accordance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). You may exercise your ARCO rights (Access, Correction, Cancellation, Opposition) by emailing support@myopiatracker.com.
🇨🇳🇷🇺
China and Russia — Excluded
Clinicians in the People's Republic of China and the Russian Federation may use the clinical service, but data from these jurisdictions is not collected in the registry due to cross-border data transfer requirements that cannot currently be met on our infrastructure.

14. Breach Notification

In the event of a data breach affecting personal data, we will:

To report a suspected vulnerability: support@myopiatracker.com.

15. Cookies and Analytics

The MyopiaTracker clinical app does not use advertising cookies or third-party behavioural analytics. We use privacy-preserving analytics (no cookies, no cross-site tracking, no personal data collected) to understand aggregate usage. The landing pages and marketing site may use session cookies for functionality only. No cookie consent banner is required for the clinical app. If we add any tracking that requires consent, we will update this policy and implement appropriate notice.

16. Changes to This Policy

We will update the version number and date when this policy changes and notify registered users by email at least 14 days before material changes take effect. If changes affect registry consent, existing consents will move to Pending Re-consent and exports will pause until re-consent is given.

17. Contact and Data Requests

General enquiries: support@myopiatracker.com
Data access, deletion, or rights requests: support@myopiatracker.com
Security vulnerabilities: support@myopiatracker.com
Response time: 30 days for data requests, 2 business days for general enquiries, 24 hours for security.

← Back to MyopiaTracker