# ClinicExpander Privacy Policy

**Effective date:** July 27, 2026
**Last updated:** July 27, 2026

## 1. Introduction

This Privacy Policy describes how ClinicExpander BETA (“ClinicExpander,” “the extension,” “we,” “us,” or “our”), published by **[LEGAL PUBLISHER NAME]**, handles information.

ClinicExpander is a local-only clinical text-expansion tool designed for authorized personnel using supported OhMD and DrChrono webpages. It provides personal text shortcuts, reusable templates, and transient fill-in forms.

ClinicExpander is an independent product and is not affiliated with, sponsored by, or endorsed by OhMD or DrChrono.

## 2. ClinicExpander’s Single Purpose

ClinicExpander’s single purpose is to provide local text expansion, reusable personal templates, and transient fill-in forms within editable fields on supported OhMD and DrChrono webpages.

The extension does not make clinical decisions, automatically read patient charts, click buttons, submit forms, or provide medical advice.

## 3. Information Handled by the Extension

ClinicExpander may locally handle the following categories of information when necessary to perform its text-expansion function:

### Personally Identifiable Information

Users may enter names or other identifying information into transient fill-in forms or supported webpage fields.

### Health Information

Users may enter clinical or health-related information into transient fill-in forms or supported webpage fields.

### Personal Communications

Template text may be inserted into communication fields on supported clinical platforms.

### Website Content

ClinicExpander interacts with the editable field selected by the user. It may temporarily inspect the field’s text, cursor position, selection, and editability to recognize a shortcut, preserve surrounding text, and verify that the intended field has not changed before insertion.

### User Activity

ClinicExpander temporarily processes a limited in-memory sequence of typed characters to recognize configured shortcuts. It does not operate as a general-purpose keylogger and does not intentionally persist or transmit the keystroke buffer.

### Current Page and Origin Information

ClinicExpander checks the current webpage URL and origin to determine whether the page is an approved OhMD or DrChrono HTTPS page. It does not create, retain, or transmit a history of websites visited.

## 4. Local Storage

Personal templates, template settings, archived template records, and locally imported personal-template backups are stored using `chrome.storage.local` within the user’s Chrome profile.

ClinicExpander does not use `chrome.storage.sync`.

Saved templates remain in the user’s Chrome profile until the user deletes them, clears the extension’s storage, removes the applicable Chrome profile, or uninstalls the extension.

ClinicExpander is designed for generic reusable templates. Users are warned not to save patient-specific protected health information in templates or support reports.

If a user exports a backup file, that file is stored wherever the user chooses. The user and the user’s organization are responsible for protecting exported files.

## 5. Transient Dynamic-Form Information

Patient-specific values entered through ClinicExpander’s dynamic fill-in forms are intended to remain transient.

These values:

* Are held in application-controlled memory only while the form session is active.
* Are not intentionally written to `chrome.storage.local`, synchronized storage, cookies, browser local storage, browser session storage, IndexedDB, or Cache Storage.
* Are cleared from application-controlled references when the user inserts the completed text, cancels the form, presses Escape, starts another session, the target field becomes invalid, or the session expires.
* Are not intentionally transmitted by ClinicExpander to an external server.

The shortcut-detection buffer is limited in size and retention time and is cleared on defined lifecycle events.

JavaScript and ordinary browser software cannot guarantee physical or cryptographic erasure of data from computer memory. ClinicExpander performs best-effort clearing of application-controlled references.

## 6. Network Transmission

ClinicExpander does not contain analytics, advertising, telemetry, tracking pixels, remote scripts, or external data-processing services.

ClinicExpander does not intentionally transmit personal templates, shortcut buffers, dynamic-form values, field contents, health information, or personal communications to the publisher or to third parties.

When the user explicitly inserts text into an OhMD or DrChrono field, that text becomes part of the webpage and may then be processed, stored, or transmitted by the applicable clinical platform. Such processing is governed by the platform’s agreements, privacy practices, and the user’s organization—not by ClinicExpander.

## 7. Remote Code

ClinicExpander does not execute remotely hosted JavaScript or WebAssembly. Its program logic is packaged with the extension.

## 8. Sharing, Selling, and Human Access

We do not sell user data.

We do not transfer user data to third parties for advertising, marketing, analytics, lending, creditworthiness, or unrelated purposes.

Because ClinicExpander does not transmit locally handled information to the publisher, our personnel do not ordinarily receive or read users’ templates, patient-specific values, communications, field contents, or shortcut buffers.

## 9. Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

ClinicExpander uses locally handled information only to provide its disclosed text-expansion and template functionality.

## 10. Permissions

ClinicExpander requests only the permissions necessary for its disclosed purpose:

### Storage Permission

The `storage` permission is used exclusively for local template and configuration storage using `chrome.storage.local`.

### Host Permissions

Host permissions are limited to approved HTTPS pages on:

* `ohmd.com`
* Subdomains of `ohmd.com`
* `drchrono.com`
* Subdomains of `drchrono.com`

These permissions allow ClinicExpander to recognize shortcuts and insert user-selected template text into editable fields. ClinicExpander is inactive on other websites.

## 11. Security Measures

ClinicExpander uses technical safeguards designed to limit unnecessary access and retention, including:

* Restricted production host permissions.
* Local-only template storage.
* No synchronized extension storage.
* No extension-originated network requests.
* No analytics or telemetry.
* Extension-isolated dynamic forms.
* Cryptographically secure transient session identifiers.
* Short session expiration periods.
* Target-field integrity checks before insertion.
* Rejection of password, disabled, and read-only fields.
* No automatic form submission or button clicking.

No software can guarantee complete security. Users and organizations remain responsible for securing computers, Chrome profiles, operating-system accounts, exported backup files, and access to the underlying clinical platforms.

## 12. HIPAA and Organizational Responsibilities

ClinicExpander was designed with privacy-conscious clinical workflows in mind, but installation or use of the extension does not by itself establish, guarantee, or certify compliance with the Health Insurance Portability and Accountability Act (“HIPAA”) or any other law.

Each healthcare organization is responsible for determining whether ClinicExpander is appropriate for its environment and for implementing required administrative, physical, and technical safeguards, including workforce training, device security, access controls, risk analysis, incident-response procedures, and appropriate agreements with its clinical platform providers.

## 13. Children’s Privacy

ClinicExpander is intended for authorized workforce use and is not directed to children. The publisher does not knowingly collect information from children through the extension.

## 14. User Choices and Deletion

Users can:

* View, edit, archive, restore, or delete personal templates through the extension’s Options page.
* Remove exported backup files from locations under their control.
* Remove the extension through Chrome’s extension-management page.
* Clear extension data through applicable Chrome profile or browser controls.

Because ClinicExpander does not maintain a publisher-operated user database or server, the publisher ordinarily has no remotely stored extension data to retrieve or delete for an individual user.

## 15. Changes to This Privacy Policy

We may update this Privacy Policy if ClinicExpander’s functionality, data practices, legal requirements, or Chrome Web Store policies change.

The “Last updated” date at the top of this page will identify the latest revision. Material changes will be reflected in the policy before or when the updated extension is distributed.

## 16. Contact

Questions about this Privacy Policy or ClinicExpander’s privacy practices may be directed to:

Wonkable
Email: Dev@NewDirectionFertility.com