1. Purpose

This Data Policy supplements our Privacy Policy with specifics about how Cenote Tracker ("Cenote") handles data within the CenoteTracker application and related services (the "Service"). It focuses on what is unique to data handling — the data categories we hold, retention windows, the "Zip & Send" mechanics, and the distinction between deleting and resetting an account. For sub-processor identities, security controls, and your rights more generally, see the Privacy Policy. In the event of any conflict between this Data Policy and the Privacy Policy, the Privacy Policy controls.


2. Data We Process

The Service processes the categories of data described below. Each row identifies the data, its source, where it lives, why we process it, and how long we retain it.

2.1 Account & Identity Data

InformationSourceWhere HeldPurposeRetention
Email addressYou (via Clerk)Our database; ClerkAuthentication, account communicationsUntil account deletion + backup window
Full nameYou / ClerkOur databaseDisplay, document attributionUntil account deletion + backup window
Account identifier (issued by Clerk)ClerkOur databaseLinking your account to your dataUntil account deletion + backup window
Subscription tier (free or premium)RevenueCat / billing eventOur databaseFeature gating, quota enforcementUntil account deletion + backup window
Device notification tokenYour deviceOur databaseDelivering notifications you opted in toUntil you opt out or account deletion

2.2 Professional Profile Data

InformationWhere HeldPurposeRetention
State or jurisdiction codeOur databaseDetermining applicable CE requirementsUntil account deletion
Job title or professionOur databaseDetermining applicable CE requirementsUntil account deletion
License expiration dateOur databaseCalculating renewal deadlinesUntil account deletion
Renewal deadlineOur databaseCalculating renewal deadlinesUntil account deletion
Verified credential recordsOur databaseConfirming your professional identityUntil account deletion

Verified credential records may include professional license or certificate numbers (for example, NPI, PTIN, CFP, PE), specialty designations, and employer name, where you choose to enter or confirm them.

2.3 Documents and Extracted Data

InformationWhere HeldPurposeRetention
Uploaded file (PDF or image)Document storage (AWS S3, US East — Ohio)Storing your CE evidenceUntil you delete the document or your account
File metadata (name, size, upload date)Our databaseIndexing and organizationUntil you delete the document or your account
File fingerprint (SHA-256 hash)Our databasePer-user duplicate detectionUntil you delete the document or your account
Extracted document text and fieldsOur databaseAuto-classification and progress creditUntil you delete the document or your account
Folder names and orderingOur databaseOrganizationUntil you delete the folder or your account
Progress data (hours per category, totals)Our databaseCompliance progress displayUntil account deletion or recalculation

2.4 Operational Data

InformationWhere HeldPurposeRetention
Audit log entries (account ID, action, IP, agent)Our databaseSecurity, debugging, abuse investigation12 months, then automatically purged
Notification queue (scheduled and sent alerts)Our databaseScheduling and tracking notifications90 days after the notification is sent
Cached continuing-education requirementsTemporary cachePerformance; sourced from public web pages7 days (cache time-to-live)
Transient processing dataTemporary work queueAsynchronous OCR and notification workHeld only until the work completes

2.5 Data We Do Not Process

We do not collect:


3. Sub-Processor Processing Regions

The full list of sub-processors, with their roles and the data categories they receive, is in Section 6.1 of the Privacy Policy. The table below identifies where each sub-processor processes data, which is the information most relevant to the cross-border transfer analysis in Section 4.

Sub-ProcessorProcessing Region
ClerkUnited States
Amazon Web Services (S3, Textract, infrastructure)United States — US East 2 (Ohio)
OpenAIUnited States
SerpAPIUnited States
FirecrawlUnited States
SendGridUnited States
RevenueCatUnited States
Apple / GoogleGlobal
Expo Application ServicesUnited States
Supabase (managed PostgreSQL)United States — US East 2 (Ohio)
Upstash (managed Redis)United States
Fly.io (application hosting)United States — US East (Ashburn, VA)

We will provide notice through the App or by email before adding a new sub-processor that processes personal information.


4. Data Locations and Transfers

The Service is operated from Ontario, Canada. To deliver the Service, we transfer personal information to the United States and other countries, as shown in Section 3. Notably:

Personal information transferred outside Canada may be subject to lawful access by foreign governments, courts, and law enforcement under the laws of the jurisdictions in which it is processed. We require each sub-processor to provide contractual data-protection commitments designed to give your information a substantially similar level of protection wherever it is processed, and we rely on additional safeguards (such as the European Commission's Standard Contractual Clauses) for transfers from the EEA, the United Kingdom, or Switzerland.


5. Security Implementation Specifics

For the general security controls we apply, see Section 8 of the Privacy Policy. Implementation details that are specific to the data categories in Section 2:


6. Data Minimization and Purpose Limitation

We collect and process data only for the purposes identified in the Privacy Policy and in Section 2 above.

OCR processing of your documents is performed for the sole purpose of auto-populating fields you would otherwise have to enter manually. Language- model interpretation of continuing-education requirements is performed against publicly available state-licensing-board web pages, not against Your Content.


7. Document Sharing via "Zip & Send"

When you use the "Zip & Send" feature:

  1. You select one of your folders and provide a recipient email address (and optionally a recipient name and note).
  2. The Service bundles the documents in that folder into a ZIP archive and transmits it via SendGrid to the recipient you specified, with your name and email shown as the sender and reply-to.
  3. We retain a record that the email was sent (for delivery troubleshooting and abuse prevention), but the ZIP archive itself is not stored by Cenote after transmission.

You are responsible for ensuring that each recipient is authorized to receive the documents and personal information you transmit. Cenote has no relationship with the recipient and cannot recall or revoke a message after it has been sent.


8. Retention and Deletion

8.1 Deletion You Initiate

You can delete individual documents from within the App. When you delete an account, the Service:

If a file deletion in document storage fails (for example, due to a transient error), we log the failure and continue with the rest of the deletion. We make reasonable efforts to retry failed deletions.

8.2 Backup Retention

Routine system backups taken before deletion may continue to contain your data for a limited period until they expire on their normal rotation schedule. Backups are restored only when needed to recover from a system incident.

8.3 Reset Without Deletion

If you choose to reset your account rather than delete it, the Service removes your stored files, document records, extracted document text, folders, progress data, and progress links, and resets your profile to the pre-onboarding state. Your account, email, and authentication credentials are preserved.

8.4 Legal Holds

We may retain certain data longer than the periods described above if required to comply with a legal obligation, resolve disputes, or enforce our agreements. In such cases, we limit access to the data placed on legal hold to personnel and counsel with a specific need to access it.


9. Your Rights

Your rights are described in Section 10 of the Privacy Policy, including jurisdiction-specific rights for residents of California (CCPA / CPRA), the EEA, the United Kingdom, Switzerland (GDPR / UK GDPR), and Canada (PIPEDA). To exercise any of those rights, contact us at [email protected].


10. Incident Response

If we determine that a security incident has resulted in unauthorized acquisition of personal information about you, we will notify you and any applicable regulators in accordance with applicable law.

If you believe your account has been accessed without authorization, please contact [email protected] immediately.


11. Changes to This Data Policy

We may update this Data Policy from time to time. Material changes will be announced by updating the "Last Updated" date and by the means described in Section 12 of the Privacy Policy.


12. Contact

CenoteTracker Attn: Privacy 48 Jenny Court, Stoney Creek, Ontario, L8G 4N8, Canada Email: [email protected]