What data Clinical Rx collects, what it doesn't, and exactly what happens when you use the optional AI-assist features on this Site.
Last updated: July 2026
Clinical Rx does not require an account, does not ask you to identify yourself, and does not store patient information on its own servers. Calculator inputs (doses, labs, patient parameters you type into a calculator) are processed entirely in your browser and are never sent anywhere unless you affirmatively click one of the optional AI-assist buttons described in Section 3 below. This page explains, page by page, exactly what does leave your device.
Every page on this Site loads Google Analytics (gtag.js), which collects standard, aggregate usage data — pages visited, approximate location/device type, referring site, and similar. This is used only to understand overall traffic and is not used to identify individual users. It is not linked to any patient information. The site tag disables Google signals and ad-personalization signals. Its configured page-view URL excludes query strings and fragments; its configured referrer contains only the referring origin. These application settings do not constitute an audit of Google Analytics property settings or third-party collection.
The application’s analytics calls do not include clinical calculator inputs or the Patient Identifier/MRN field in the ChemoRx regimen calculator. Our application does not add these fields to analytics events. Provider-side analytics settings are managed separately; do not place patient information in URLs or feedback forms.
Several pages include an optional, button-triggered "AI-assist" feature (drug-shortage explanations, regimen/infection search matching, calculator finder, and clinical-note context). These are opt-in only — nothing is sent unless you click the relevant button. When triggered, the request is sent to a backend we operate (Firebase Cloud Functions), which forwards a request to Google's Gemini API to generate a response, then returns it to your browser. No account or login is required to use these features.
| Feature | Where it's used | What is sent |
|---|---|---|
| Calculator finder | Homepage optional AI search box | The free-text you type into the search box |
| Regimen matching | ChemoRx | The free-text you type into the regimen search box |
| Infection matching | InfectionRx | The free-text you type into the infection search box |
| Score matching | ScoreRx | The free-text you type into the optional AI score search box |
| Shortage explainer | ShortageRx | The drug name you search for (validated server-side as a drug-name-shaped string) |
| Clinical note context | ChemoRx, InfectionRx, and AnticoagRx | Only the app's own static drug/regimen warning text — this feature cannot include anything you typed, including the Patient Identifier/MRN field, which is never part of this or any other AI request |
Important: the four free-text search features (calculator finder, regimen matching, infection matching, score matching) transmit whatever you type, up to 200 characters. Do not type patient names, MRNs, or other patient-identifying details into these search boxes — search by drug, regimen, or condition name only. As implemented today, the clinical-note feature's on-page button only ever sends this Site's own static drug/regimen warning text that's already displayed on the page — never a patient-input field. That is a design commitment we enforce through our own code and testing, not a technical restriction built into the backend endpoint itself, so treat it with the same care as the search boxes above: never rely on any AI-assist feature on this Site to keep out patient-identifying information you might type elsewhere.
Our backend code supports Google's reCAPTCHA v3 / Firebase App Check, an anti-abuse mechanism designed to confirm requests are coming from a real browser session on this Site rather than automated abuse, and a short-term per-IP rate limit runs regardless of whether App Check enforcement is turned on for a given deployment. We do not publish a live, real-time attestation of which anti-abuse layers are enforced at any given moment for this specific deployment; if App Check is active for you, it may involve Google receiving standard device/browser signals used for that verification, governed by Google's Privacy Policy.
The application uses an in-memory IP-based rate limiter and does not intentionally write search queries to an application database. Hosting and service providers may process request metadata, including IP addresses, under their own logging and retention policies. This statement is not a guarantee that provider infrastructure retains no logs.
The homepage’s ordinary calculator search runs locally. Favorites and recent tools store only allowlisted tool identifiers in this browser, not search text, clinical inputs, or results. Remove a favorite with its button or use “Clear recent tools.” Existing theme preferences, consent state, and ShortageRx watchlists may also use browser storage. The Report a problem link carries only a tool identifier and interface release; it does not attach clinical data.
This Site uses cookies set by Google Analytics to distinguish sessions/visits, and, where the AI-assist features are used, cookies/tokens associated with Firebase App Check and reCAPTCHA. These are functional/analytics cookies, not advertising cookies. You can block cookies in your browser settings; doing so will not prevent you from using the calculators, though the AI-assist features may not function correctly.
This Site links out to third-party resources (e.g., FDA labeling on DailyMed, published journal articles). Those sites have their own, independent privacy practices; this Policy does not apply to them.
We may update this Privacy Policy from time to time; the "Last updated" date above reflects the most recent revision. Material changes affecting the AI-assist data flows described in Section 3 will be reflected here.
Questions about this Privacy Policy can be sent via the Feedback & Requests page.