Summary — In Plain Language
UricAcid.online is built to be useful without knowing anything about you. There are no user accounts, no required registration, and no profile to log into.
Anything you type into the platform — your uric acid level, food searches, AI questions, symptom journal entries — lives in your own browser. None of it is sent to or stored on our servers. Close the tab, and it stops existing on the platform.
The only data we receive about you is what you choose to send us through the contact form, plus standard server logs (IP address, browser type, referring URL) generated when any web page loads. We do not sell, share, or licence this data to advertisers, pharmaceutical companies, supplement brands, or data brokers.
Data We Collect
The platform collects the following limited categories of data:
- Contact form submissions — name, email, subject, and message that you voluntarily provide. Used only to respond to your enquiry.
- Newsletter sign-ups — email address only, used to send the monthly digest. Unsubscribe at any time.
- Server access logs — IP address, browser type, requested URL, referring URL, and timestamp. Retained for 30 days for security and analytics.
- Anonymous usage analytics — aggregated, IP-anonymised page-view counts and country-level traffic data via privacy-respecting analytics.
Data We Deliberately Do Not Collect
The following are never collected, transmitted, or stored on any server we operate:
- Your serum uric acid readings or blood test history.
- Your weight, height, BMI, age, sex, or any anthropometric measurement.
- Your symptom journal entries, gout flare history, or medication list.
- Your food search history, saved foods, or meal plan customisations.
- Your geolocation, postal address, phone number, or any government identifier.
When the platform asks you to enter any of the above (for example, your uric acid level on the Diet Plan page), the value is processed in your browser only and discarded when you close the tab unless you actively choose to save it in your browser's local storage.
Browser-Side Local Storage
Several optional features (saved foods, uric acid log, symptom journal) write to your browser's local storage so they persist between visits on the same device.
Local storage is owned by your browser, not by us. We cannot read it from our servers and we cannot remotely change or delete it. You can clear it at any time:
- Chrome / Edge: Settings → Privacy and security → Clear browsing data → Cookies and other site data.
- Safari: Preferences → Privacy → Manage Website Data → uricacid.online → Remove.
- Firefox: Preferences → Privacy & Security → Cookies and Site Data → Manage Data.
Cookies & Similar Technologies
The platform uses the following minimal set of cookies:
- Strictly necessary — a WordPress security token (nonce) used for form submissions and a language-preference cookie. No tracking purpose.
- Analytics — privacy-respecting page-view analytics that do not use cross-site tracking cookies.
- Advertising — Google AdSense places its own cookies on pages where ads are displayed. See §6 for the third-party details.
You can disable cookies entirely in your browser settings, but doing so will break the contact form and newsletter signup.
Third-Party Services
The platform integrates a small number of third-party services. Each has its own privacy policy.
- Google AdSense — displays contextual programmatic ads on some pages. Google may use cookies or device identifiers to serve and measure ads. See policies.google.com/technologies/ads for details.
- Google Gemini — powers the AI clinical reasoning assistant via a server-side proxy. Prompts you submit are sent to Google's Gemini API to generate a response and are then discarded — see §7 for details.
- Google Fonts — serves the Playfair Display and Inter font files. Fonts are loaded once and cached by your browser.
- Web hosting provider — a commercial managed-WordPress host processes server logs strictly for security and infrastructure operations under their own privacy policy.
AI Clinical Assistant Privacy
When you submit a question to the AI clinical reasoning assistant, the following happens:
- Your prompt is sent through our server-side proxy. We do not log it to any persistent storage.
- The proxy forwards the prompt to Google's Gemini API. Google's standard API terms apply at that point.
- The response is returned to your browser and is not stored on our servers.
- Our Gemini API key is held server-side only — it is never exposed to the browser.
For maximum privacy, do not include real names, identifying details, or specific medical record numbers in your prompts. Describe your situation in general clinical terms instead.
Your Privacy Rights
Depending on where you live, you have one or more of the following rights regarding personal data we hold about you:
- Right of access — request a copy of personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete personal data.
- Right to erasure — request deletion of personal data we hold about you, subject to legal retention requirements.
- Right to object — opt out of marketing communications or specific processing activities.
- Right to data portability — receive a machine-readable copy of data you have provided.
- Right to opt out of sale — we do not sell personal data, so this right is permanently honoured by default.
Exercise any of these rights by emailing privacy@uricacid.online. We respond to verified requests within 30 days.
Children's Data
UricAcid.online is designed for adults managing hyperuricemia or gout. The platform is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16.
If you are a parent or guardian and believe a child has submitted personal data to the platform, please contact us and we will delete it.
International Data Transfers
The platform is hosted on infrastructure that may process server logs in the United States, the European Union, and other regions where our service providers operate. By using the platform you accept that limited transactional data (server logs and contact form submissions) may be processed outside your country of residence.
Where applicable, transfers between regions are governed by standard contractual clauses or equivalent legal safeguards.
Contacting Us About Privacy
For any privacy-related request, question, or concern — including data access, deletion, or correction requests — please contact:
- Email: privacy@uricacid.online
- Contact form: uricacid.online/contact
- Response time: within 30 days of receipt of a verified request.
We may update this policy from time to time. Material changes will be reflected in the Effective Date at the top of this page, and the prior version will be retained on request.