Privacy Policy
Effective date: May 23, 2026 — Last updated: May 23, 2026
TrialFinder is committed to being transparent about how we collect, use, protect, and share your health information. Please read this policy carefully before using the platform.
Important Notice
This policy is provided for informational purposes only and does not constitute legal advice or create attorney-client privilege. TrialFinder recommends that this policy be reviewed by qualified legal counsel before it is relied upon for regulatory compliance purposes. If you have questions about your legal rights, please consult an attorney.
Our Approach to Health Data Privacy
TrialFinder is a clinical trial matching service. It is not a healthcare provider, health plan, or healthcare clearinghouse, and therefore may not itself be classified as a HIPAA Covered Entity under 45 CFR Parts 160 and 164. Nevertheless, we voluntarily handle your health information in accordance with HIPAA principles because we believe that is the right standard for a platform that collects sensitive patient data. The clinical trial sites and sponsors we may share your information with — only after you give explicit, affirmative consent — are typically HIPAA Covered Entities or their Business Associates and are independently bound by HIPAA.
1. What Information We Collect
When you register and use TrialFinder, we collect the following categories of information:
- Account and identity information — first name, last name, username, email address, phone number, and hashed password.
- Health and medical information (sensitive) — self-reported medical conditions (name, diagnosis date, additional notes), current medications, age, sex, height, weight, and body mass index (BMI). This information is equivalent to Protected Health Information (PHI) and is treated with the highest level of protection.
- Eligibility assessment responses — your answers to AI-generated eligibility questionnaires for specific clinical trials, the resulting qualification outcome (e.g., "Likely to Qualify", "Might Qualify", "Will Not Qualify"), and the LLM-generated explanation. These responses are among the most sensitive data we store.
- Location information — your city/region, geographic coordinates (latitude and longitude), and preferred search radius, used to find trials near you. When you search for trials, your location may be transmitted to a third-party geocoding service to convert addresses to coordinates.
- Search and activity history — the conditions and trials you search for, trials you save, and trial detail pages you view.
- Contact request records — when you submit a "Contact Trial Site" request, we store your name, email, phone number, the message you sent, the trial identifier, the recipient site, and a timestamp recording your consent to share this information.
- Notification preferences — whether you have opted in to receive alerts when new trials matching your profile become available, and records of when those notifications were sent.
- Referral and preference data — how you heard about TrialFinder, your information-release preferences regarding sponsors, and your contact preferences for our email communications.
2. How We Use Your Information
Trial Matching
- Match your health profile to trials recruiting for your conditions
- Filter trial results by proximity to your location
- Send you notifications when new trials matching your profile are added (only if you opt in)
Eligibility Assessment
- Generate trial-specific eligibility questions using an AI language model (see Section 4)
- Pre-screen your basic eligibility using your demographic and condition data
- Save your assessment results so you do not need to repeat them
- Regenerate assessments automatically when your profile is updated
Connecting You with Trial Sites
- Forward your contact request and message to the relevant trial site or our relay address, after you provide explicit consent
- Send you a confirmation email with a copy of what was forwarded
- Maintain an audit record of when consent was given and to whom your information was disclosed
Platform Operations and Security
- Authenticate your identity and protect your account
- Detect and prevent fraudulent or abusive activity
- Troubleshoot technical issues and improve platform reliability
- Comply with applicable legal obligations
3. What We Don't Do With Your Data
No Selling
We never sell your personal health information to advertisers, data brokers, or any third party for commercial purposes.
No Unauthorized Sharing
We do not share your identifiable health information with trial sponsors or sites without your explicit, affirmative consent at the time of each request.
No Unsolicited Marketing
We do not use your health data to serve you targeted advertising. Trial notification emails are sent only to users who have opted in.
4. Who We Share Your Information With
- Clinical trial sites and sponsors (with your explicit consent only) — When you complete the "Contact Trial Site" flow and confirm the consent modal, the following information is forwarded to the relevant trial site contact or, if no site contact is available, to TrialFinder's relay address for routing: your name, email address, phone number (if you provided one), the trial you are interested in, the nearest trial site to your location (facility name, city, state, and distance), and the message you wrote. This disclosure is recorded with a consent timestamp. We do not share your stored health profile, eligibility assessment results, medication list, or demographic details with sites unless you include that information in your message.
- AI language model provider (OpenAI) — To generate trial-specific eligibility questions, we transmit only de-identified information to OpenAI's API: your age, sex, and the names of your medical conditions, together with the trial's eligibility criteria text. We do not transmit your name, email address, date of birth, street address, geographic coordinates, account identifiers, or any other directly identifying information. Because the data we send is de-identified under the HIPAA Safe Harbor standard (45 CFR §164.514(b)(2)), no Business Associate Agreement with OpenAI is required for this use. You can review OpenAI's privacy policy for details on how they handle API data.
- Geocoding service — Your city, region, or address string may be transmitted to a third-party geocoding service to convert it to geographic coordinates for proximity-based trial search. We do not transmit your name, email, or health data in this request.
- Email delivery provider — Your email address and the content of confirmation and notification emails are processed by our transactional email provider to deliver messages to you and to trial sites. This provider acts as a data processor on our behalf.
- Legal and regulatory disclosures — We may disclose your information if required by applicable law, court order, or to protect the rights, safety, or property of TrialFinder or others.
5. Your Rights and Choices
Regardless of whether HIPAA formally applies to TrialFinder, we recognize the following rights with respect to your information:
- Right to access — You may view and download the personal and health information stored in your profile at any time through your account settings. For a full export of all data we hold about you (including eligibility assessments and contact records), email mail@thetrialfinder.com and we will respond within 30 days.
- Right to correction — You may update your profile information, conditions, and medications at any time through your account settings. Correcting eligibility-relevant data will automatically trigger regeneration of any saved eligibility assessments.
- Right to deletion — You may delete your account at any time through your profile settings, or by emailing mail@thetrialfinder.com. When you delete your account, the following personal data is permanently removed: your name, phone number, date of birth, height, weight, location, search radius, medical conditions, medications, eligibility assessment responses, and saved trials. We retain: (a) your email address, used as a stable identifier so we can recognize you if you choose to re-register and to support aggregate analytics; (b) records of prior "Contact Trial Site" submissions, including the consent timestamp, for at least 3 years for audit and legal-compliance purposes. If you wish your email address to also be removed, email us with that explicit request and we will process it within 30 days (note that backups may take additional time to age out).
- Right to opt out of notifications — You may opt out of trial-matching notification emails at any time by updating your notification preferences in your account settings or by clicking the unsubscribe link in any notification email.
- Right to withdraw consent — Consent to share your information with a trial site is given at the time of each "Contact Trial Site" submission. Once a contact request has been sent, we cannot recall the email already delivered to the site, but you may contact us at mail@thetrialfinder.com to request that we note your withdrawal and suppress further routing of your data to that site.
- Right to data portability — You may request a machine-readable copy of your profile data by emailing mail@thetrialfinder.com. We will provide this in a structured format (JSON or CSV) within 30 days.
- Right to complain — If you believe your privacy rights have been violated, you may file a complaint with us at mail@thetrialfinder.com. If you are a resident of the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
6. Security Safeguards
We implement the following administrative, technical, and physical safeguards to protect your information:
- Encryption in transit — All data transmitted between your browser and TrialFinder is encrypted using TLS (HTTPS).
- Encryption at rest — Your data is stored in a PostgreSQL database with encryption at rest enabled at the infrastructure level.
- Password protection — Passwords are never stored in plaintext. We use PBKDF2-SHA256 hashing with salting to protect your credentials.
- Account lockout — Accounts are temporarily locked after repeated failed login attempts to protect against brute-force attacks.
- Rate limiting — API endpoints, including eligibility assessments and contact submissions, are rate-limited to prevent abuse and unauthorized data harvesting.
- Access controls — Access to production data is restricted to authorized personnel only. Application credentials are managed via environment variables and are never hardcoded.
- Audit logging — The platform logs eligibility assessment events and contact request submissions, including user identifiers and timestamps, to support accountability and incident response.
7. Breach Notification
In the event of a security breach that compromises your personal health information, TrialFinder commits to notifying affected users without unreasonable delay and, where feasible, within 60 days of discovering the breach. Notification will be sent to the email address associated with your account and will include:
- A description of what information was involved
- The date of the breach and the date it was discovered (if known)
- Steps you can take to protect yourself
- What TrialFinder is doing to investigate and remediate the incident
- Contact information for questions
This commitment is modeled on the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). If a breach involves information you shared with a clinical trial site that is itself a HIPAA Covered Entity, that site is independently responsible for its own breach notification obligations.
8. Data Retention and Deletion
- Account and profile data — Retained for as long as your account is active. You may request deletion at any time (see Section 5).
- Eligibility assessment responses — Retained until you delete your account, or until you retake an assessment (which replaces the prior record for that trial).
- Contact request records — Retained for a minimum of 3 years to support audit and compliance purposes. The consent timestamp is a legally significant record and is retained even if you request broader data deletion. We will inform you of any such retention at the time of your deletion request.
- Search history — Records of the conditions you have searched for, along with your user identifier, are retained for up to 2 years for product analytics and to improve trial-matching quality. After 2 years they are aggregated and individual-level records are deleted.
- Other analytics and event logs — Aggregated and anonymized analytics data (such as totals, trends, and counts) may be retained indefinitely. Individual-level event logs (such as eligibility-assessment start events) are retained for up to 2 years.
9. Cookies and Session Data
TrialFinder uses session cookies to maintain your logged-in state. These cookies are essential for the platform to function and are not used for advertising or cross-site tracking. We do not currently use third-party tracking cookies or analytics pixels that transmit your health information to external advertising networks.
TrialFinder also sets a first-party tf_sid cookie (a random identifier, no personal information) so we can measure how visitors find and move through the site. This first-party analytics data is processed on our own servers and is never shared with advertising networks. Specifically, on the first page you visit during a session we record the page you landed on, the website that referred you (the standard HTTP Referer header sent by your browser), any campaign tags appended to the URL (utm_source, utm_medium, utm_campaign, utm_term, utm_content), and a coarse device category (mobile/tablet/desktop) parsed from your browser's User-Agent string. We do not store your IP address. Session-level records are retained for up to 2 years; aggregate totals (e.g. "how many visitors came from Google last month") may be retained indefinitely.
10. Users Under 18
TrialFinder is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us at mail@thetrialfinder.com and we will delete it promptly.
11. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where the changes significantly affect how we handle your health data, notify you by email. Continued use of TrialFinder after a policy update constitutes acceptance of the updated terms.
Privacy Questions or Complaints?
If you have questions about this policy, wish to exercise your rights, or want to report a privacy concern, contact us at mail@thetrialfinder.com. We aim to respond to all privacy inquiries within 10 business days.