Mise à jour le 19 août 2026
Ce qu’Ailio recueille, qui peut le consulter, comment c’est protégé, et comment le faire supprimer.
Cet avis n’est disponible qu’en anglais pour le moment. Si quelque chose vous semble obscur, écrivez à privacy@ailio.health et nous vous répondrons en français.
Ailio is operated by Ailio Technologies Inc., based in Victoria, British Columbia. We publish an index of clinics and practitioners across Canada — their services, prices and openings — and let you request an appointment. We are not a clinic and we do not provide care.
This notice covers personal information you give us as a patient with an Ailio account. It is written to Canada’s federal privacy law (PIPEDA) and British Columbia’s PIPA.
An email address and a password. If you set up a passkey, the public part of it. We also record when you signed up and when each sign-in session was created; your active sessions are listed on your security page, where you can end them.
The medical profile at /profile/medical is optional and can be left blank or filled in a field at a time. When you do fill it in, it can hold: your legal and preferred name, date of birth, phone number, address and pronouns; the reasons you are booking, along with conditions, medications and allergies; whether you are pregnant, have had recent surgery, or want an area avoided, with any note you add; an emergency contact; your provincial health number and family physician; insurer, policy, member and group numbers for up to two plans; a claim number and accident date for an ICBC, WorkSafeBC or Veterans Affairs claim; and your typed consent signature.
A percentage covered, a per-visit maximum, an annual maximum and how much of it you have used, per discipline. You type these in from your own benefits booklet. They are never confirmed with anyone.
The answers you give the setup flow: a city and region, how far you will travel, which disciplines, how much notice you need, practitioner preferences, accessibility needs, and how you expect to pay.
Appointment requests, including the clinic, practitioner, service, time and price, and any note you write for the practitioner. Availability alerts you create, including the coordinates of the area you asked us to watch. Practitioners you save. Your notification settings.
For some clinics, Ailio books you in through the clinic’s own booking system, using an account in your name that we create and manage. Where that applies, we also hold that account’s credentials, the clinic system’s own record of a booking we placed, and mail the clinic sends to that account — each encrypted under your key. The whole arrangement is described in Booking accounts we manage.
Ailio runs no session recorder, we do not build a profile of what you browse, and we do not sell or rent personal information to anybody, for any purpose. We do use Google Analytics — by default outside Quebec, and only if you allow it there — and you can turn it off any time; we do show Google ads on some pages — those appear either way, but they are only personalized if you allow it. See Analytics and Ads below for exactly what each one receives, which is in both cases nothing from anything above.
Your account exists so your profile, bookings and alerts are yours and nobody else’s. Your health profile exists so that a clinic’s intake paperwork can be filled from it rather than typed again in a waiting room, and so a practitioner knows what matters before you arrive. Your insurance terms exist so we can estimate what a visit will actually cost you. Your search preferences exist so results are about the care you are looking for.
None of it is used to target an ad. Ailio shows Google ads on some pages, and Google chooses them from the page itself or — if you allowed it — from what it already knows about the browser you are using, never from anything you have told us. We send no advertiser your health information, your insurance terms, your searches or your account, and we do not use your health information to decide what to show you beyond the discipline you asked for.
Your health profile and the note you write for a practitioner are encrypted before they reach our database, with a key that belongs to your account alone. The key itself is wrapped by a key we hold in Cloudflare’s secrets service, so the database never holds anything that can open your record on its own. Each encrypted field is bound to your account and to the exact column it belongs in, so ciphertext copied anywhere else simply fails to open rather than quietly decrypting as something it is not.
The same sealing covers everything a managed booking account touches: its password, its signed-in session at the clinic’s system, mail the clinic sends it, and the clinic system’s own record of a booking we placed are all encrypted under that same key of yours, and no screen anywhere on Ailio displays the password or the session.
Every table holding patient data enforces row-level security in the database itself, and the role our patient-facing servers connect as cannot bypass it — a query that forgot its filter returns nothing rather than somebody else’s row. A small, separately authenticated internal tool used by Ailio staff for support and moderation connects with broader read access; every use of it is by an identified staff member behind Cloudflare’s own access control, never by a patient-facing request.
Your insurance percentages and maximums are stored unencrypted, because a percentage and an annual maximum identify nobody on their own and we read them on every price estimate. They are protected by the same row-level security as everything else.
No security is absolute, and we would rather say so than imply otherwise. If we ever believe your information has been exposed, we will tell you and the relevant privacy commissioner.
When you request an appointment, a clinic that manages its listing sees the request in its Ailio dashboard: your name, the practitioner, service, location, time and price. We do not email requests to clinic front desks, and the clinic is not given your email address at any point — when they accept or decline, we email you their answer ourselves. Clinics never see your health profile, your insurance details or your note to the practitioner — those are encrypted under your key, and the clinic side of Ailio holds no key for them.
Where we place a booking in a clinic’s own booking system, that system holds its own record of you as its patient — see Booking accounts we manage for exactly what it receives.
Google Places, OpenStreetMap’s Overpass and the language models we use to read clinics’ published prose all receive clinic information only. No patient information of any kind is sent to a language model.
Our database and servers are operated on infrastructure that may store or process data outside Canada, which means it can be subject to the laws of the country it sits in. We may also disclose information where a Canadian law requires it.
We never contact your insurer, and no insurer tells us anything about you. There is no service in Canada that lets a company like ours look up what a person’s plan covers, and we are not building toward one.
Every coverage figure on Ailio is arithmetic over the terms you typed in yourself. It is an estimate you made with our help, not a number anybody confirmed. Whether a clinic bills a payer directly is that clinic’s decision, read from what they publish, and it can be out of date or wrong.
For some clinics, Ailio can go further than recording your request: we place the booking in the clinic’s own booking system, through the same public booking flow you would use on their site, so the appointment exists in the clinic’s own calendar rather than waiting for someone to read a dashboard. When that happens your booking page says so — “Placed in the clinic’s own booking system” — and shows the confirmation their system returned. It is used only for appointments you asked for; nothing probes a clinic’s system on your behalf otherwise.
Doing that needs a patient account in your name at that clinic’s system, which Ailio creates and manages for you. Creating it gives the clinic’s system what its own signup asks every patient for: your name and phone number, your date of birth, and — only if you chose to put it on your profile — your provincial health number. The email address on that account is one we create and manage for you, on our own domain, rather than your real one.
Because the clinic writes to that address, its messages about your care route through us: we store each one encrypted under your key, and forward it on to your real address. Messages that could be used to take over the account — a password reset, a verification code — are held back rather than forwarded. The sorting that decides forward-or-withhold is mechanical — a fixed set of rules, not a model and not a person — and no screen on Ailio shows this mail to anyone; it is kept so that what the clinic told you is not lost, and it becomes unreadable with your key when you delete your account.
An account at a clinic is the clinic’s record as well as ours. If we have created one for you, the clinic’s system knows you as its patient from then on, under its own privacy obligations — deleting your Ailio account destroys our copy of the credentials and the mail, but does not remove you from the clinic’s system.
When you tap “use my location” to measure distances, your browser gives the coordinate to the page and it stays there. It is not sent to us, not stored and not logged — distances are calculated in your browser against clinic coordinates the page already has. Reloading the page throws it away.
There are two deliberate exceptions. Where “use my location” is choosing a city rather than measuring a distance — in the setup flow, and in the search page’s own location box — the coordinate has to be turned into a city name, which needs a lookup: it is rounded to roughly a kilometre first, and it is sent without your account attached. And when you arrive at the search page with no city chosen, we use the rough city Cloudflare derives from your IP address as a starting point. That guess appears in the address bar where you can change it, and it is never printed as a distance — it is often the wrong town.
We use Google Analytics to see which parts of Ailio people actually use — how many visitors reach a search, how many go on to request an appointment, and where in that flow people give up. Across Canada it runs by default, the moment you land on a page, so this number reflects real traffic rather than only the visitors who happened to click through a bar. Press “No thanks” on the bar at the bottom of the page, or come back here and decline, and the Google script stops loading on every page from that point on.
In Quebec, provincial law asks for the opposite order, and this site follows it: nothing loads until you press “Allow” on the bar. We estimate which province you are in from your IP address to decide which of the two applies, the same coarse, occasionally imprecise estimate this site already uses to guess your city for a default location — see Your location.
Unless you have declined (or, in Quebec, unless you have allowed it), Google receives the pages you visit on this site, along with the usual things a web request carries: your IP address, your browser and your rough region. It also receives a running list of things you did — that a search was run, that a filter changed, that a booking was started and which step it reached, that an alert was created or paused, that a practitioner was saved, that a sign-in was attempted, that a clinic claim moved a step — and, as of 2026-08-19, real detail alongside each one rather than a bare label: the text you typed into a search box, the area of the map you dragged into view, and, if you are signed in, an account identifier that ties this activity to your Ailio account across visits until you sign out. What it still never receives, from any event, is anything from your health or insurance details, and no event can carry a session token — the credential that could sign in as you. Our test suite scans every event call for exactly that.
The identical list, gated by the same bar and built from the same code, also goes to a second analytics service, PostHog, hosted in the United States. Nothing above is held back from one vendor and given to the other. We use PostHog because it lets us see the flow from a search through to a booking request as one connected path rather than only separate counts — the same reason we use Google Analytics, through a second lens.
Unlike Google Analytics, PostHog also automatically records what you click anywhere on the site — the visible text and label of the button or link, not the page around it — gated by the same bar and stopped the same way a decline stops the rest of this section. On a public page that is a search result, a filter, a clinic name: information the page already showed anyone. On a signed-in page — your profile, your booking history, an alert match — it can include what that page names, such as your own display name or a detail from an appointment, because the click still carries the label on screen at the moment you made it. We are telling you this plainly rather than describing only the safer half of what this vendor does.
If you are signed in, both vendors receive the same account identifier described above, so your activity is joined up within each of them rather than staying anonymous. PostHog goes one step further and Google Analytics does not: PostHog also receives your account’s display name and email address, and attaches them to that identifier as your PostHog identity, so a name and an inbox address sit alongside the activity there. Google Analytics never receives your name or email address at any point — only the account identifier reaches it, and we do not set it in the field Google’s own systems use to build a cross-device identity graph (its reserved user_id), so there it stays an ordinary event property rather than feeding that graph. Signing out starts a fresh, unlinked record in PostHog for whatever happens next in that browser; Google Analytics has no comparable reset, because it was never handed a name to forget.
On the browsing pages — search, a clinic listing, a practitioner page, and similar public pages — PostHog may also record a video-like replay of how you moved through the page. Outside Quebec this follows the same default as the measurement above: it runs unless you press “No thanks”, including before you have answered at all. In Quebec, it stays off until you press “Allow”. Every box you could type into is blanked out in the recording before it ever leaves your browser, and no network request is captured. Recording never runs on your account pages or anywhere in the booking flow, whether or not you are signed in, and never depends on this bar at all — see the next paragraph.
Two things run even after you decline, and we would rather name them than let the paragraphs above overstate what “No thanks” turns off. Cloudflare, who serve every page, inject their own cookie-less page-view counter at the network edge, on every page load, whatever you answered. It sets no cookie, carries no account identifier and does not follow you across sites — it is the host counting page loads, not a profile of you — but it is a script we do not control from this site’s code, and declining Google Analytics does not stop it.
Separately, if a page breaks — an error your browser catches while using Ailio — a report of that error, including its message and where in our code it happened, reaches PostHog whatever you have answered on the bar, on every page including your account pages. So does a measure of how fast the page loaded and how stable it felt while doing so, whether or not it broke. We treat both the way we treat a server error log: something we need in order to find and fix a broken or slow page, not a measurement of you. It runs through a connection this vendor keeps separate from the one described above — nothing is written to your browser’s storage for it, it is never joined to your account even if you are signed in, and it carries nothing else: no page-visit history, no click, no replay. It is possible, though not the intent, for an error message to happen to include something you had typed on the page at the moment it broke.
To be plain about what changed: as of 2026-08-19, an account identifier reaches both Google Analytics and PostHog whenever you are signed in, and the text you type into a search box or the area of the map you drag into view reaches both vendors too, whether or not you are signed in — see above for exactly what each one does with an identifier once it has it. What neither vendor ever receives, from either, is anything from your health or insurance details, your date of birth, a note you wrote to a practitioner, or a session token that could sign in as you. That boundary is enforced the same way as everywhere else in this document: a test scans every event this app can send and fails the build if one of those appears.
The pages you visit do say something about you: a clinic page names a clinic, and a search names a kind of care. That is the part worth deciding about, and it is why you can turn this off rather than just being told about it. Press “No thanks” on the bar, or clear this site’s cookies in your browser to bring the bar back and answer again.
Ads appear in four kinds of place: within a page of search results — after the twelfth result, and again after every twenty-four on a long scroll; beside or below a clinic’s or practitioner’s own details on their page; on a clinic with a long list of practitioners, once partway down that list, between two headings rather than between two people; and at the foot of a clinic’s single-column pages — its full price list, its full team list, a single treatment’s page. Nowhere else. Each one is inside a bordered box with “Advertisement” written above it.
A short page carries none of them: a clinic with only a handful of practitioners gets no ad on its team list at all, rather than one that would be most of what is on the page.
Separately from Google’s ads, Ailio sometimes promotes itself — a box suggesting a search to watch or a feature to try, on a city landing page or standing in for an ad Google left unfilled. Those are ours: no ad network is involved, nothing is requested from an ad server for them, and nobody paid for them.
Ailio shows ads from Google AdSense. They are how a free product that takes no commission from clinics pays for itself. What your answer to the bar changes is the KIND of ad, not whether one appears: press “No thanks”, or leave the question unanswered, and every ad on the site is a non-personalized one — Google picks it from the page it is sitting on, not from what it already knows about your browser.
It is also only loaded on a page that actually carries an ad. There is no ad on any page that shows your own information — not your profile, not your medical and insurance details, not the booking form, not your alerts — so on those pages nothing is requested from Google’s ad servers at all, whatever you answered.
Google chooses what to show from what it already knows about your browser. We tell it nothing: not your name, your email, your account, your position, what you typed into a search box, and nothing whatsoever from your health or insurance details. We do not sell or share your information with advertisers, and no advertiser learns that you visited Ailio from us.
What Google does receive is what any page you load tells it: the address of the page the ad is on, your IP address, your browser, and whatever its own cookies already say about that browser. The address of a page is not nothing here — a clinic page names a clinic and a search names a kind of care — which is why this is behind the same question rather than assumed.
Every ad is labelled as an ad, and an ad is never a search result. Nobody can pay to be listed, ranked higher, or shown as available on Ailio: clinics, practitioners, prices and openings come from what each clinic publishes, and no advertiser has any say in them.
These are Ailio’s own cookies — all of them. None is for advertising or measurement. We split them below into required — the ones that keep the site working and are never gated by the bar — and optional — the ones that only get set if you press “Allow”.
Google Analytics sets two of its own (_ga and one beginning _ga_) to tell one visit from the next. Outside Quebec it sets them by default; in Quebec, only once you press “Allow”. Either way, press “No thanks” and the analytics tag stops loading on every later page, so neither is set again. PostHog, described above, sets no cookie at all — it keeps the same kind of visit identifier in your browser’s local storage instead, under the same condition: only while you have not declined, and never once you have. The ad code is the other case: on a page carrying an ad it may set or read cookies of its own for that browser, whatever you answered, and those are Google’s and are described in its own policies. Declining tells it not to use them to choose the ad.
We email you to verify your address when you sign up, to sign you in by emailed link when you ask for one, to reset your password, to confirm an appointment request you made, and to pass on the answer to it. An availability alert you created emails you when an opening the crawl has just seen matches it — that is the alert working, and email is its only channel. If you asked to hear when a clinic becomes bookable through Ailio, we email you when it does. And mail a clinic sends to a managed booking account is forwarded to you, as described in Booking accounts we manage.
Each of those goes to the address on your account. One email does not: if you suggest a clinic we do not list yet, and type an email address into that form to hear the outcome, we email that address once, when the listing is live, and use it for nothing else.
Ailio sends no text messages and no push notifications. The Text and Push choices on the alert form are shown disabled because nothing behind them exists — an alert reaches you by email or not at all, and if either is ever built we will ask before using it.
A booking email names the clinic, practitioner, service and time. It deliberately leaves out the note you wrote for the practitioner, because email is not encrypted in transit end to end and that note is a health disclosure.
We keep your account and everything in it until you delete it. There is no automatic expiry today, and we would rather say that plainly than imply a schedule we do not run.
The clinic information we crawl has its own limits: published openings are dropped after 400 days; the raw pages we read are dropped after 180, except the single most recent copy of each page, which is kept so we can always show what we last read; and cached Google listing details expire after 30. Address lookups are cached for a day, keyed on the question rather than on who asked it. A signed-in session lasts seven days at a time.
When rows are deleted they are gone from our live database immediately. Our database provider keeps a short recovery history so an operational mistake can be undone, and deleted data ages out of that history after it. Write to us if you need the current window in writing.
You can see everything we hold about you on your own screens: your bookings and alerts, your medical profile and your preferences. You can correct any of it in place, and delete your medical profile on its own without closing your account.
Every permission you granted can be switched back off at any time, including in the middle of a booking, on the medical profile screen. Withdrawing one does not delete the record that you had granted it, which is what lets us answer a later question about what you agreed to and when.
If you would rather have a copy in writing, or want us to do any of this for you, write to privacy@ailio.health.
Delete your account erases it, permanently, as soon as you confirm. There is no grace period and nothing to restore afterwards, because the key your health record was encrypted with is destroyed as part of it.
Your sign-in, password, sessions and passkeys; your medical profile and everything in it; your insurance terms; your search preferences; your alerts and anything they matched; practitioners you saved; your notification settings; and your encryption key.
If you have an appointment still ahead of you, deleting your account does not cancel it. We do not hold clinics’ calendars, so the clinic is still expecting you and we will have no way to reach you afterwards. Call them first — the deletion screen lists each appointment with the clinic’s number.
When this notice changes we update the date at the top. If a change materially affects what we do with information we already hold, we will tell account holders by email rather than relying on you to re-read the page.
Write to privacy@ailio.health with any question about this notice, to ask for a copy of what we hold, or to have something corrected or deleted. That address reaches the person responsible for privacy at Ailio Technologies Inc., Victoria, British Columbia.
If we do not resolve something to your satisfaction, you can complain to the Office of the Privacy Commissioner of Canada, or — in British Columbia — to the Office of the Information and Privacy Commissioner for BC. You do not need our permission to do so.