# Privacy

Last updated 19 Aug 2026

What Ailio collects, who can see it, how it is protected, and how to have it deleted.

## On this page

1. Who we are
2. What we collect
3. Why we collect it
4. How it is protected
5. Who can see it
6. What we never do with insurers
7. Booking accounts we manage
8. Your location
9. Analytics
10. Ads
11. Cookies
12. Email we send you
13. How long we keep it
14. Your rights
15. Deleting your account
16. Changes to this notice
17. Contact and complaints

## Who we are

Ailio is operated by Ailio Technologies Inc., based in Victoria, British Columbia. We publish an index of clinics and practitioners across Canada — their services, prices and openings — and let you request an appointment. We are not a clinic and we do not provide care.

This notice covers personal information you give us as a patient with an Ailio account. It is written to Canada’s federal privacy law (PIPEDA) and British Columbia’s PIPA.

## What we collect

### Your account

An email address and a password. If you set up a passkey, the public part of it. We also record when you signed up and when each sign-in session was created; your active sessions are listed on your security page, where you can end them.

### Your health profile, if you fill one in

The medical profile at [/profile/medical](https://ailio.health/profile/medical) is optional and can be left blank or filled in a field at a time. When you do fill it in, it can hold: your legal and preferred name, date of birth, phone number, address and pronouns; the reasons you are booking, along with conditions, medications and allergies; whether you are pregnant, have had recent surgery, or want an area avoided, with any note you add; an emergency contact; your provincial health number and family physician; insurer, policy, member and group numbers for up to two plans; a claim number and accident date for an ICBC, WorkSafeBC or Veterans Affairs claim; and your typed consent signature.

### Insurance terms you tell us

A percentage covered, a per-visit maximum, an annual maximum and how much of it you have used, per discipline. You type these in from your own benefits booklet. They are never confirmed with anyone.

### What you are looking for

The answers you give the setup flow: a city and region, how far you will travel, which disciplines, how much notice you need, practitioner preferences, accessibility needs, and how you expect to pay.

### What you do here

Appointment requests, including the clinic, practitioner, service, time and price, and any note you write for the practitioner. Availability alerts you create, including the coordinates of the area you asked us to watch. Practitioners you save. Your notification settings.

### If we manage a booking account for you

For some clinics, Ailio books you in through the clinic’s own booking system, using an account in your name that we create and manage. Where that applies, we also hold that account’s credentials, the clinic system’s own record of a booking we placed, and mail the clinic sends to that account — each encrypted under your key. The whole arrangement is described in Booking accounts we manage.

Ailio runs no session recorder, we do not build a profile of what you browse, and we do not sell or rent personal information to anybody, for any purpose. We do use Google Analytics — by default outside Quebec, and only if you allow it there — and you can turn it off any time; we do show Google ads on some pages — those appear either way, but they are only personalized if you allow it. See Analytics and Ads below for exactly what each one receives, which is in both cases nothing from anything above.

## Why we collect it

Your account exists so your profile, bookings and alerts are yours and nobody else’s. Your health profile exists so that a clinic’s intake paperwork can be filled from it rather than typed again in a waiting room, and so a practitioner knows what matters before you arrive. Your insurance terms exist so we can estimate what a visit will actually cost you. Your search preferences exist so results are about the care you are looking for.

None of it is used to target an ad. Ailio shows Google ads on some pages, and Google chooses them from the page itself or — if you allowed it — from what it already knows about the browser you are using, never from anything you have told us. We send no advertiser your health information, your insurance terms, your searches or your account, and we do not use your health information to decide what to show you beyond the discipline you asked for.

## How it is protected

Your health profile and the note you write for a practitioner are encrypted before they reach our database, with a key that belongs to your account alone. The key itself is wrapped by a key we hold in Cloudflare’s secrets service, so the database never holds anything that can open your record on its own. Each encrypted field is bound to your account and to the exact column it belongs in, so ciphertext copied anywhere else simply fails to open rather than quietly decrypting as something it is not.

The same sealing covers everything a managed booking account touches: its password, its signed-in session at the clinic’s system, mail the clinic sends it, and the clinic system’s own record of a booking we placed are all encrypted under that same key of yours, and no screen anywhere on Ailio displays the password or the session.

Every table holding patient data enforces row-level security in the database itself, and the role our patient-facing servers connect as cannot bypass it — a query that forgot its filter returns nothing rather than somebody else’s row. A small, separately authenticated internal tool used by Ailio staff for support and moderation connects with broader read access; every use of it is by an identified staff member behind Cloudflare’s own access control, never by a patient-facing request.

Your insurance percentages and maximums are stored unencrypted, because a percentage and an annual maximum identify nobody on their own and we read them on every price estimate. They are protected by the same row-level security as everything else.

No security is absolute, and we would rather say so than imply otherwise. If we ever believe your information has been exposed, we will tell you and the relevant privacy commissioner.

## Who can see it

### Clinics

When you request an appointment, a clinic that manages its listing sees the request in its Ailio dashboard: your name, the practitioner, service, location, time and price. We do not email requests to clinic front desks, and the clinic is not given your email address at any point — when they accept or decline, we email you their answer ourselves. Clinics never see your health profile, your insurance details or your note to the practitioner — those are encrypted under your key, and the clinic side of Ailio holds no key for them.

Where we place a booking in a clinic’s own booking system, that system holds its own record of you as its patient — see Booking accounts we manage for exactly what it receives.

### Companies that run our systems

- **Cloudflare** — runs the site and the API, stores our secrets, keeps short-lived caches and sends our email. All traffic to Ailio passes through them. On the sign-in and create-account forms they also run **Turnstile**, a bot check that usually runs silently and shows you nothing; it looks at how the browser behaves, not at who you are. It is covered by Cloudflare’s [Turnstile Privacy Addendum](https://www.cloudflare.com/turnstile-privacy-policy/).
- **Neon** — hosts our Postgres database, which is where everything above is stored.
- **OVHcloud and Webshare** — booking traffic to a clinic’s own system travels through relay servers we run on OVHcloud machines and out through Webshare’s network. They carry the connection; neither stores anything or is given your account.
- **Photon (komoot)** — when you type an address into the location box, the text you typed is sent from our servers to their geocoder to turn it into suggestions. It is not sent with your account attached, and we do not log it or store it against you.
- **OpenStreetMap’s Nominatim** — when you submit an address to measure distances from, your browser contacts them directly, so they see your IP address rather than us.

Google Places, OpenStreetMap’s Overpass and the language models we use to read clinics’ published prose all receive clinic information only. No patient information of any kind is sent to a language model.

Our database and servers are operated on infrastructure that may store or process data outside Canada, which means it can be subject to the laws of the country it sits in. We may also disclose information where a Canadian law requires it.

## What we never do with insurers

We never contact your insurer, and no insurer tells us anything about you. There is no service in Canada that lets a company like ours look up what a person’s plan covers, and we are not building toward one.

Every coverage figure on Ailio is arithmetic over the terms you typed in yourself. It is an estimate you made with our help, not a number anybody confirmed. Whether a clinic bills a payer directly is that clinic’s decision, read from what they publish, and it can be out of date or wrong.

## Booking accounts we manage

For some clinics, Ailio can go further than recording your request: we place the booking in the clinic’s own booking system, through the same public booking flow you would use on their site, so the appointment exists in the clinic’s own calendar rather than waiting for someone to read a dashboard. When that happens your booking page says so — “Placed in the clinic’s own booking system” — and shows the confirmation their system returned. It is used only for appointments you asked for; nothing probes a clinic’s system on your behalf otherwise.

Doing that needs a patient account in your name at that clinic’s system, which Ailio creates and manages for you. Creating it gives the clinic’s system what its own signup asks every patient for: your name and phone number, your date of birth, and — only if you chose to put it on your profile — your provincial health number. The email address on that account is one we create and manage for you, on our own domain, rather than your real one.

Because the clinic writes to that address, its messages about your care route through us: we store each one encrypted under your key, and forward it on to your real address. Messages that could be used to take over the account — a password reset, a verification code — are held back rather than forwarded. The sorting that decides forward-or-withhold is mechanical — a fixed set of rules, not a model and not a person — and no screen on Ailio shows this mail to anyone; it is kept so that what the clinic told you is not lost, and it becomes unreadable with your key when you delete your account.

An account at a clinic is the clinic’s record as well as ours. If we have created one for you, the clinic’s system knows you as its patient from then on, under its own privacy obligations — deleting your Ailio account destroys our copy of the credentials and the mail, but does not remove you from the clinic’s system.

## Your location

When you tap “use my location” to measure distances, your browser gives the coordinate to the page and it stays there. It is not sent to us, not stored and not logged — distances are calculated in your browser against clinic coordinates the page already has. Reloading the page throws it away.

There are two deliberate exceptions. Where “use my location” is choosing a city rather than measuring a distance — in the setup flow, and in the search page’s own location box — the coordinate has to be turned into a city name, which needs a lookup: it is rounded to roughly a kilometre first, and it is sent without your account attached. And when you arrive at the search page with no city chosen, we use the rough city Cloudflare derives from your IP address as a starting point. That guess appears in the address bar where you can change it, and it is never printed as a distance — it is often the wrong town.

## Analytics

We use **Google Analytics** to see which parts of Ailio people actually use — how many visitors reach a search, how many go on to request an appointment, and where in that flow people give up. Across Canada it runs by default, the moment you land on a page, so this number reflects real traffic rather than only the visitors who happened to click through a bar. Press “No thanks” on the bar at the bottom of the page, or come back here and decline, and the Google script stops loading on every page from that point on.

In Quebec, provincial law asks for the opposite order, and this site follows it: nothing loads until you press “Allow” on the bar. We estimate which province you are in from your IP address to decide which of the two applies, the same coarse, occasionally imprecise estimate this site already uses to guess your city for a default location — see Your location.

Unless you have declined (or, in Quebec, unless you have allowed it), Google receives the pages you visit on this site, along with the usual things a web request carries: your IP address, your browser and your rough region. It also receives a running list of things you did — that a search was run, that a filter changed, that a booking was started and which step it reached, that an alert was created or paused, that a practitioner was saved, that a sign-in was attempted, that a clinic claim moved a step — and, as of 2026-08-19, real detail alongside each one rather than a bare label: the text you typed into a search box, the area of the map you dragged into view, and, if you are signed in, an account identifier that ties this activity to your Ailio account across visits until you sign out. What it still never receives, from any event, is anything from your health or insurance details, and no event can carry a session token — the credential that could sign in as you. Our test suite scans every event call for exactly that.

The identical list, gated by the same bar and built from the same code, also goes to a second analytics service, **PostHog**, hosted in the United States. Nothing above is held back from one vendor and given to the other. We use PostHog because it lets us see the flow from a search through to a booking request as one connected path rather than only separate counts — the same reason we use Google Analytics, through a second lens.

Unlike Google Analytics, PostHog also automatically records what you click anywhere on the site — the visible text and label of the button or link, not the page around it — gated by the same bar and stopped the same way a decline stops the rest of this section. On a public page that is a search result, a filter, a clinic name: information the page already showed anyone. On a signed-in page — your profile, your booking history, an alert match — it can include what that page names, such as your own display name or a detail from an appointment, because the click still carries the label on screen at the moment you made it. We are telling you this plainly rather than describing only the safer half of what this vendor does.

If you are signed in, both vendors receive the same account identifier described above, so your activity is joined up within each of them rather than staying anonymous. PostHog goes one step further and Google Analytics does not: PostHog also receives your account’s display name and email address, and attaches them to that identifier as your PostHog identity, so a name and an inbox address sit alongside the activity there. Google Analytics never receives your name or email address at any point — only the account identifier reaches it, and we do not set it in the field Google’s own systems use to build a cross-device identity graph (its reserved `user_id`), so there it stays an ordinary event property rather than feeding that graph. Signing out starts a fresh, unlinked record in PostHog for whatever happens next in that browser; Google Analytics has no comparable reset, because it was never handed a name to forget.

On the browsing pages — search, a clinic listing, a practitioner page, and similar public pages — PostHog may also record a video-like replay of how you moved through the page. Outside Quebec this follows the same default as the measurement above: it runs unless you press “No thanks”, including before you have answered at all. In Quebec, it stays off until you press “Allow”. Every box you could type into is blanked out in the recording before it ever leaves your browser, and no network request is captured. Recording never runs on your account pages or anywhere in the booking flow, whether or not you are signed in, and never depends on this bar at all — see the next paragraph.

Two things run even after you decline, and we would rather name them than let the paragraphs above overstate what “No thanks” turns off. Cloudflare, who serve every page, inject their own cookie-less page-view counter at the network edge, on every page load, whatever you answered. It sets no cookie, carries no account identifier and does not follow you across sites — it is the host counting page loads, not a profile of you — but it is a script we do not control from this site’s code, and declining Google Analytics does not stop it.

Separately, if a page breaks — an error your browser catches while using Ailio — a report of that error, including its message and where in our code it happened, reaches PostHog whatever you have answered on the bar, on every page including your account pages. So does a measure of how fast the page loaded and how stable it felt while doing so, whether or not it broke. We treat both the way we treat a server error log: something we need in order to find and fix a broken or slow page, not a measurement of you. It runs through a connection this vendor keeps separate from the one described above — nothing is written to your browser’s storage for it, it is never joined to your account even if you are signed in, and it carries nothing else: no page-visit history, no click, no replay. It is possible, though not the intent, for an error message to happen to include something you had typed on the page at the moment it broke.

To be plain about what changed: as of 2026-08-19, an account identifier reaches both Google Analytics and PostHog whenever you are signed in, and the text you type into a search box or the area of the map you drag into view reaches both vendors too, whether or not you are signed in — see above for exactly what each one does with an identifier once it has it. What neither vendor ever receives, from either, is anything from your health or insurance details, your date of birth, a note you wrote to a practitioner, or a session token that could sign in as you. That boundary is enforced the same way as everywhere else in this document: a test scans every event this app can send and fails the build if one of those appears.

The pages you visit do say something about you: a clinic page names a clinic, and a search names a kind of care. That is the part worth deciding about, and it is why you can turn this off rather than just being told about it. Press “No thanks” on the bar, or clear this site’s cookies in your browser to bring the bar back and answer again.

## Ads

**Ads appear in four kinds of place:** within a page of search results — after the twelfth result, and again after every twenty-four on a long scroll; beside or below a clinic’s or practitioner’s own details on their page; on a clinic with a long list of practitioners, once partway down that list, between two headings rather than between two people; and at the foot of a clinic’s single-column pages — its full price list, its full team list, a single treatment’s page. Nowhere else. Each one is inside a bordered box with “Advertisement” written above it.

A short page carries none of them: a clinic with only a handful of practitioners gets no ad on its team list at all, rather than one that would be most of what is on the page.

Separately from Google’s ads, Ailio sometimes promotes itself — a box suggesting a search to watch or a feature to try, on a city landing page or standing in for an ad Google left unfilled. Those are ours: no ad network is involved, nothing is requested from an ad server for them, and nobody paid for them.

Ailio shows ads from **Google AdSense**. They are how a free product that takes no commission from clinics pays for itself. What your answer to the bar changes is the KIND of ad, not whether one appears: press “No thanks”, or leave the question unanswered, and every ad on the site is a non-personalized one — Google picks it from the page it is sitting on, not from what it already knows about your browser.

It is also only loaded on a page that actually carries an ad. There is no ad on any page that shows your own information — not your profile, not your medical and insurance details, not the booking form, not your alerts — so on those pages nothing is requested from Google’s ad servers at all, whatever you answered.

Google chooses what to show from what it already knows about your browser. We tell it nothing: not your name, your email, your account, your position, what you typed into a search box, and nothing whatsoever from your health or insurance details. We do not sell or share your information with advertisers, and no advertiser learns that you visited Ailio from us.

What Google does receive is what any page you load tells it: the address of the page the ad is on, your IP address, your browser, and whatever its own cookies already say about that browser. The address of a page is not nothing here — a clinic page names a clinic and a search names a kind of care — which is why this is behind the same question rather than assumed.

Every ad is labelled as an ad, and an ad is never a search result. Nobody can pay to be listed, ranked higher, or shown as available on Ailio: clinics, practitioners, prices and openings come from what each clinic publishes, and no advertiser has any say in them.

## Cookies

These are Ailio’s own cookies — all of them. None is for advertising or measurement. We split them below into **required** — the ones that keep the site working and are never gated by the bar — and **optional** — the ones that only get set if you press “Allow”.

### Required

- **Your session** — keeps you signed in for seven days at a time, and holds who you are on Ailio — your account id, email address and display name — so the header can render without another request. Your browser cannot read it.
- **Signing in** — the sign-in and passkey flows use up to four short-lived cookies to carry a single sign-in across its steps; the longest lives ten minutes, and your browser cannot read them.
- **The last place you searched** — a city and province, for a year, so the search page opens where you left it.
- **Your language** — English or French, for a year.
- **The clinic you are managing** — only if you manage a clinic listing.
- **Your answer to the bar** — whether you allowed Google Analytics and Google ads, for a year, so we stop asking. Your browser cannot read it.
- **A share link you followed** — if you arrive through somebody’sailio.health/r/… link, the code from it, for ninety days. Nothing reads it yet: it exists so that if referral credit ever becomes real, the visit that earned it was not forgotten. Your browser cannot read it.

### Optional

Google Analytics sets two of its own (`_ga` and one beginning `_ga_`) to tell one visit from the next. Outside Quebec it sets them by default; in Quebec, only once you press “Allow”. Either way, press “No thanks” and the analytics tag stops loading on every later page, so neither is set again. PostHog, described above, sets no cookie at all — it keeps the same kind of visit identifier in your browser’s local storage instead, under the same condition: only while you have not declined, and never once you have. The ad code is the other case: on a page carrying an ad it may set or read cookies of its own for that browser, whatever you answered, and those are Google’s and are described in its own policies. Declining tells it not to use them to choose the ad.

## Email we send you

We email you to verify your address when you sign up, to sign you in by emailed link when you ask for one, to reset your password, to confirm an appointment request you made, and to pass on the answer to it. An availability alert you created emails you when an opening the crawl has just seen matches it — that is the alert working, and email is its only channel. If you asked to hear when a clinic becomes bookable through Ailio, we email you when it does. And mail a clinic sends to a managed booking account is forwarded to you, as described in Booking accounts we manage.

Each of those goes to the address on your account. One email does not: if you suggest a clinic we do not list yet, and type an email address into that form to hear the outcome, we email that address once, when the listing is live, and use it for nothing else.

Ailio sends no text messages and no push notifications. The Text and Push choices on the alert form are shown disabled because nothing behind them exists — an alert reaches you by email or not at all, and if either is ever built we will ask before using it.

A booking email names the clinic, practitioner, service and time. It deliberately leaves out the note you wrote for the practitioner, because email is not encrypted in transit end to end and that note is a health disclosure.

## How long we keep it

We keep your account and everything in it until you delete it. There is no automatic expiry today, and we would rather say that plainly than imply a schedule we do not run.

The clinic information we crawl has its own limits: published openings are dropped after 400 days; the raw pages we read are dropped after 180, except the single most recent copy of each page, which is kept so we can always show what we last read; and cached Google listing details expire after 30. Address lookups are cached for a day, keyed on the question rather than on who asked it. A signed-in session lasts seven days at a time.

When rows are deleted they are gone from our live database immediately. Our database provider keeps a short recovery history so an operational mistake can be undone, and deleted data ages out of that history after it. Write to us if you need the current window in writing.

## Your rights

You can see everything we hold about you on your own screens: [your bookings and alerts](https://ailio.health/profile), [your medical profile](https://ailio.health/profile/medical) and [your preferences](https://ailio.health/profile/preferences). You can correct any of it in place, and delete your medical profile on its own without closing your account.

Every permission you granted can be switched back off at any time, including in the middle of a booking, on the medical profile screen. Withdrawing one does not delete the record that you had granted it, which is what lets us answer a later question about what you agreed to and when.

If you would rather have a copy in writing, or want us to do any of this for you, write to [privacy@ailio.health](mailto:privacy@ailio.health).

## Deleting your account

[Delete your account](https://ailio.health/profile/delete) erases it, permanently, as soon as you confirm. There is no grace period and nothing to restore afterwards, because the key your health record was encrypted with is destroyed as part of it.

### What is deleted

Your sign-in, password, sessions and passkeys; your medical profile and everything in it; your insurance terms; your search preferences; your alerts and anything they matched; practitioners you saved; your notification settings; and your encryption key.

### What is kept, and why

- **Past appointments.** A clinic that saw you has its own record-keeping obligations and its own calendar, and deleting our row would rewrite their history of what happened. What stays is the appointment — clinic, practitioner, service, time and price. Your name, your note and every link back to you are removed, and nothing we hold can reconnect them to you.
- **The record that a permission was granted or withdrawn, and when.** This is what lets a complaint about what you agreed to be answered afterwards. It holds no name, no email and nothing about your health — only the account identifier, which after deletion refers to nothing else anywhere in our systems.
- **The record that the deletion itself happened.** The account identifier and counts of what was removed, kept so the erasure can be shown to have been carried out. Like the permission ledger, it holds no name, no email and nothing about your health.
- **Sealed rows a managed booking account left behind.** Mail a clinic sent through a managed booking account, and the clinic system’s own record of a placed booking, stay in our database as ciphertext — the key that could open them is destroyed with your account, so nothing we hold can read them again, but the rows themselves are not scrubbed, and the unencrypted envelope of a stored message (which clinic wrote, and when) remains. The account at the clinic’s own system also remains — it is the clinic’s record, not ours to erase.
- **Images you contributed to a clinic’s listing as a clinic member.** The approved public image remains part of the listing, but the link identifying you as the person who added it is removed. Pending or rejected uploads are not published.

If you have an appointment still ahead of you, deleting your account does not cancel it. We do not hold clinics’ calendars, so the clinic is still expecting you and we will have no way to reach you afterwards. Call them first — the deletion screen lists each appointment with the clinic’s number.

## Changes to this notice

When this notice changes we update the date at the top. If a change materially affects what we do with information we already hold, we will tell account holders by email rather than relying on you to re-read the page.

## Contact and complaints

Write to [privacy@ailio.health](mailto:privacy@ailio.health) with any question about this notice, to ask for a copy of what we hold, or to have something corrected or deleted. That address reaches the person responsible for privacy at Ailio Technologies Inc., Victoria, British Columbia.

If we do not resolve something to your satisfaction, you can complain to the Office of the Privacy Commissioner of Canada, or — in British Columbia — to the Office of the Information and Privacy Commissioner for BC. You do not need our permission to do so.

Source: https://ailio.health/privacy

---
- Availability here is read from clinics on a schedule, not live. A time shown may already be taken.
- "Not checked" and "no openings" are different answers and are written differently.
- Coverage is partial. A list from this site is never every clinic in an area.
- Billing lines report what a clinic published about itself. Confirm with the clinic before relying on one.
- Ailio writes no reviews and publishes no rating of its own; every rating names its source.
- Terms of use and data notes: https://ailio.health/llms.txt
