🔒 MyopiaTracker is operated by iCare Enterprises, LLC (Arizona, USA). This policy explains what data we collect, why, how we protect it, and your rights. Version 2.0 introduces a de-identified clinical registry. Participation is optional — see Section 6.
MyopiaTracker is operated by iCare Enterprises, LLC, a company registered in the State of Arizona, United States. We are the Data Controller for account-level data (clinician accounts, guardian accounts) and the Data Processor for clinical patient data entered by clinicians. See our Terms of Use for the full Data Processing Agreement.
Data and privacy enquiries: support@myopiatracker.com
MyopiaTracker has two user types: Clinicians (licensed eye care professionals) and Guardians (adult parents or caregivers of paediatric patients). Children under 18 do not have accounts and do not interact directly with the platform. All data about child patients is entered by clinicians or guardians.
Patient records contain no direct identifiers — no patient names, exact dates of birth, addresses, or government IDs. We store:
| Feature | Free tier | Pro / Enterprise |
|---|---|---|
| Patient data storage | Browser localStorage only — never transmitted | Encrypted Firestore (Google Firebase) |
| Registry participation | Not available | Optional opt-in |
| AI Insights | Requires own API key | Available |
| Data on our servers | None | Yes — encrypted |
Guardian accounts are for adult caregivers only. We collect:
Guardian log data is accessible to the treating clinician for compliance monitoring purposes.
✗ Never collected: Patient names · Exact dates of birth · Patient government IDs · Patient addresses · Guardian names or phone numbers · Clinic names in patient records · Precise geographic location (country only) · Free-text notes in registry records · Any data from children directly
We do not use behavioural tracking, advertising cookies, or sell any data about our users to advertisers.
⚠️ Registry participation is entirely optional. The clinical service works fully without it. Both the clinician and the guardian must separately opt in for a patient's data to enter the registry.
The registry supports epidemiological research, clinical benchmarking, and commercial analytics. De-identified aggregate data may be used to generate reports for pharmaceutical companies, medical device manufacturers, lens producers, and academic researchers. This commercial use is intentional and is disclosed here explicitly.
✓ Registry fields per visit: Country (ISO 2-letter) · Age band (e.g. "8–9") · Sex · Ethnicity group (jurisdiction-dependent) · Manifest refraction OD/OS · Cycloplegic refraction (where performed) · Axial length OD/OS (where measured) · Device class · Treatment modality · Parental myopia status · Estimated outdoor hours/day · Estimated near-work hours/day · Visit sequence · Months since first visit · Months on current treatment · Prior treatment (yes/no) · One-way scoped visit-linkage token (cannot identify patient)
✗ Never in registry: Names · Exact DOB · Patient or clinic identifiers · City or postcode · Exact visit dates · Guardian information · Free-text notes
Registry collection is not available for clinicians in the People's Republic of China or the Russian Federation.
Both clinician and guardian consent are required. Either party may revoke at any time via the app. On revocation, no new registry records are generated. Previously submitted records are flagged for exclusion from future analyses. Historical aggregate reports already delivered are not retractable.
| Data | Purpose | Legal Basis |
|---|---|---|
| Clinician account data | Provide the clinical SaaS service, billing, communications | Contract performance |
| Patient records | Clinical service delivery on behalf of the clinician (as Processor) | Clinician's legitimate interests / contract |
| Guardian logs | Compliance monitoring, clinician reporting | Guardian consent + clinician contract |
| Registry records | Epidemiological research, benchmarking, commercial analytics | Explicit opt-in consent |
| Audit logs | Security, legal compliance, breach response | Legitimate interests / legal obligation |
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Google LLC (Firebase / Firestore) | Cloud database, authentication, hosting | Encrypted patient and account data (Pro/Enterprise) | United States — Firebase DPA signed |
| Anthropic, PBC | AI Insights (optional feature) | Anonymised clinical parameters — no names, no IDs. Not used to train models per Anthropic API terms. | United States |
| Stripe, Inc. | Payment processing | Email, billing address, payment method (Stripe holds card data — we do not) | United States |
We do not share data with advertisers, data brokers, or any other third party not listed above, except as required by law.
Pro and Enterprise clinical data is stored on Google Firebase infrastructure, primarily in the United States. By using the cloud sync features, you acknowledge that data is processed in the United States.
We have signed Google's Firebase Data Processing Agreement, which incorporates Standard Contractual Clauses for international transfers and requires Google to implement appropriate security measures. A link to this agreement is in our Terms of Use.
Free tier users: All data stays in your browser's localStorage and is never transmitted to any server.
| Data Type | Retention Period |
|---|---|
| Clinical visit records | 7 years from last visit, then permanently deleted |
| Guardian daily logs | 2 years rolling, or deleted on account deletion request |
| Registry records (de-identified) | 7 years |
| Consent records | 10 years (legal audit requirement) |
| Audit logs | 7 years |
| Payment records | 7 years (tax and financial law) |
Depending on your jurisdiction, you may have the right to:
To exercise any right: support@myopiatracker.com. We will respond within 30 days.
In the event of a data breach affecting personal data, we will:
To report a suspected vulnerability: support@myopiatracker.com.
The MyopiaTracker clinical app does not use advertising cookies or third-party behavioural analytics. We use privacy-preserving analytics (no cookies, no cross-site tracking, no personal data collected) to understand aggregate usage. The landing pages and marketing site may use session cookies for functionality only. No cookie consent banner is required for the clinical app. If we add any tracking that requires consent, we will update this policy and implement appropriate notice.
We will update the version number and date when this policy changes and notify registered users by email at least 14 days before material changes take effect. If changes affect registry consent, existing consents will move to Pending Re-consent and exports will pause until re-consent is given.
General enquiries: support@myopiatracker.com
Data access, deletion, or rights requests: support@myopiatracker.com
Security vulnerabilities: support@myopiatracker.com
Response time: 30 days for data requests, 2 business days for general enquiries, 24 hours for security.