Privacy Policy
Effective March 1, 2025
1. Overview
DiseaseDirectory (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.
2. Information We Collect
Information you provide
- Account registration: email address, name, and password
- Newsletter subscription: email address and selected health topic
Information collected automatically
- Usage data: pages visited, search queries, and general interaction patterns
- Error reports: crash and performance data collected via Sentry to help us improve reliability
- IP address: used for rate limiting and abuse prevention
3. How We Use Your Information
- To provide and maintain the Service
- To authenticate your account securely
- To send you newsletters you have subscribed to
- To diagnose technical issues and improve platform reliability
- To prevent spam and abusive behaviour
We do not sell, rent, or trade your personal information to third parties.
4. Cookies & Storage
We use HTTP-only cookies to manage authentication sessions securely. These cookies cannot be accessed by JavaScript and are essential for the Service to function. For full details, see our Cookie Policy.
5. Third-Party Services
We use the following third-party services, each with their own privacy practices:
- Vercel — hosting and infrastructure
- MongoDB Atlas — encrypted database storage
- Sentry — error monitoring and performance tracking
- Cloudflare Turnstile — bot protection on forms (privacy-friendly, no tracking cookies)
6. Data Retention
Account data is retained for as long as your account is active. Newsletter subscriptions are retained until you unsubscribe. You may request deletion of your data at any time by contacting us.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Unsubscribe from newsletters at any time using the link in any email
8. Children's Privacy
DiseaseDirectory is not directed at children under the age of 13. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by updating the effective date above.