Privacy Policy
Sarer Health EMR Auto-fill Extension
Last updated: March 11, 2026
Overview
The Sarer Health EMR Auto-fill Chrome Extension ("Extension") is developed and operated by Sarer Health. This policy explains what data the Extension collects, how it is used, and how it is protected.
Who Can Use This Extension
This Extension is intended exclusively for healthcare professionals who have an existing account on the Sarer Health platform. It is distributed as an unlisted extension and is not publicly searchable on the Chrome Web Store.
Data We Collect
1. Authentication Credentials
When you sign in, your email address and password are transmitted securely to the Sarer Health backend API to authenticate your account.
Passwords are never stored locally. Only the resulting authentication token is saved in Chrome's local storage (`chrome.storage.local`) on your device.
2. Authentication Token & User Profile
Your JWT access token and basic user profile information (email address) are stored locally in Chrome's extension storage to keep you signed in.
This data is stored only on your device and is never shared with third parties.
Tokens expire automatically and are cleared when you log out.
3. Clinical Note Data
When you use the auto-fill feature, the Extension retrieves structured clinical notes (encounter summaries and note content) from the Sarer Health backend.
This data is fetched on demand and is not stored locally— it is used only to fill form fields in your active browser tab at the moment you trigger auto-fill.
4. Active Tab Content
When you trigger auto-fill, the Extension reads the form fields on your currently active tab to identify where to insert note content.
The Extension does notread, record, or transmit any other content from the pages you visit.
Data We Do NOT Collect
We do not collect browsing history.
We do not track which websites you visit.
We do not use analytics, telemetry, or crash reporting.
We do not sell or share your data with any third parties.
Data Transmission
All communication between the Extension and the Sarer Health backend is made over **HTTPS** to `backend-production-7e0e.up.railway.app`. No data is sent to any other server.
Data Storage Practices
When you use the extension, your privacy is prioritized by keeping sensitive information off permanent storage whenever possible. Your authentication token and user email are stored locally on your device using chrome.storage.local to keep you logged in between sessions; however, these are wiped immediately upon logout or if the token expires. Most importantly, clinical notes are never saved to your hard drive or any database. They are held in the extension's temporary memory only and are completely cleared the moment you close the popup.
Why These Permissions Are Needed
To function effectively, the extension requires a few specific permissions from your browser. We use storage simply to remember your session so you don't have to log in every time you open the tool. The activeTab and tabs permissions allow the extension to identify which EMR page you are currently using, while the scripting permission provides the "muscle" needed to actually inject the auto-fill script into those form fields. Essentially, these permissions are what allow the extension to talk to your EMR and save you the manual typing.
Your Rights
- You can log out at any time from the Extension popup, which clears all locally stored credentials.
- You can uninstall the Extension at any time, which removes all stored data.
- For questions about your data on the Sarer Health platform, contact us at the address below.
Changes to This Policy
We may update this policy as the Extension evolves. The "Last updated" date at the top will reflect any changes. Continued use of the Extension after changes constitutes acceptance of the revised policy.
Contact
For privacy-related questions, contact Sarer Health at:
Email: [your-contact-email@sarерhealth.com]
Website: [your website URL]