1. Purpose
This Data Policy supplements our Privacy Policy with specifics about how Cenote Tracker ("Cenote") handles data within the CenoteTracker application and related services (the "Service"). It focuses on what is unique to data handling — the data categories we hold, retention windows, the "Zip & Send" mechanics, and the distinction between deleting and resetting an account. For sub-processor identities, security controls, and your rights more generally, see the Privacy Policy. In the event of any conflict between this Data Policy and the Privacy Policy, the Privacy Policy controls.
2. Data We Process
The Service processes the categories of data described below. Each row identifies the data, its source, where it lives, why we process it, and how long we retain it.
2.1 Account & Identity Data
| Information | Source | Where Held | Purpose | Retention |
|---|---|---|---|---|
| Email address | You (via Clerk) | Our database; Clerk | Authentication, account communications | Until account deletion + backup window |
| Full name | You / Clerk | Our database | Display, document attribution | Until account deletion + backup window |
| Account identifier (issued by Clerk) | Clerk | Our database | Linking your account to your data | Until account deletion + backup window |
| Subscription tier (free or premium) | RevenueCat / billing event | Our database | Feature gating, quota enforcement | Until account deletion + backup window |
| Device notification token | Your device | Our database | Delivering notifications you opted in to | Until you opt out or account deletion |
2.2 Professional Profile Data
| Information | Where Held | Purpose | Retention |
|---|---|---|---|
| State or jurisdiction code | Our database | Determining applicable CE requirements | Until account deletion |
| Job title or profession | Our database | Determining applicable CE requirements | Until account deletion |
| License expiration date | Our database | Calculating renewal deadlines | Until account deletion |
| Renewal deadline | Our database | Calculating renewal deadlines | Until account deletion |
| Verified credential records | Our database | Confirming your professional identity | Until account deletion |
Verified credential records may include professional license or certificate numbers (for example, NPI, PTIN, CFP, PE), specialty designations, and employer name, where you choose to enter or confirm them.
2.3 Documents and Extracted Data
| Information | Where Held | Purpose | Retention |
|---|---|---|---|
| Uploaded file (PDF or image) | Document storage (AWS S3, US East — Ohio) | Storing your CE evidence | Until you delete the document or your account |
| File metadata (name, size, upload date) | Our database | Indexing and organization | Until you delete the document or your account |
| File fingerprint (SHA-256 hash) | Our database | Per-user duplicate detection | Until you delete the document or your account |
| Extracted document text and fields | Our database | Auto-classification and progress credit | Until you delete the document or your account |
| Folder names and ordering | Our database | Organization | Until you delete the folder or your account |
| Progress data (hours per category, totals) | Our database | Compliance progress display | Until account deletion or recalculation |
2.4 Operational Data
| Information | Where Held | Purpose | Retention |
|---|---|---|---|
| Audit log entries (account ID, action, IP, agent) | Our database | Security, debugging, abuse investigation | 12 months, then automatically purged |
| Notification queue (scheduled and sent alerts) | Our database | Scheduling and tracking notifications | 90 days after the notification is sent |
| Cached continuing-education requirements | Temporary cache | Performance; sourced from public web pages | 7 days (cache time-to-live) |
| Transient processing data | Temporary work queue | Asynchronous OCR and notification work | Held only until the work completes |
2.5 Data We Do Not Process
We do not collect:
- precise device location;
- contacts, calendar entries, or photos beyond those you explicitly select to upload;
- health data;
- biometric data; or
- payment-card numbers or bank-account information (handled by Apple's App Store, Google Play, and RevenueCat — not by Cenote).
3. Sub-Processor Processing Regions
The full list of sub-processors, with their roles and the data categories they receive, is in Section 6.1 of the Privacy Policy. The table below identifies where each sub-processor processes data, which is the information most relevant to the cross-border transfer analysis in Section 4.
| Sub-Processor | Processing Region |
|---|---|
| Clerk | United States |
| Amazon Web Services (S3, Textract, infrastructure) | United States — US East 2 (Ohio) |
| OpenAI | United States |
| SerpAPI | United States |
| Firecrawl | United States |
| SendGrid | United States |
| RevenueCat | United States |
| Apple / Google | Global |
| Expo Application Services | United States |
| Supabase (managed PostgreSQL) | United States — US East 2 (Ohio) |
| Upstash (managed Redis) | United States |
| Fly.io (application hosting) | United States — US East (Ashburn, VA) |
We will provide notice through the App or by email before adding a new sub-processor that processes personal information.
4. Data Locations and Transfers
The Service is operated from Ontario, Canada. To deliver the Service, we transfer personal information to the United States and other countries, as shown in Section 3. Notably:
- Documents you upload are stored in AWS S3 in the US East (Ohio) region.
- Your structured account, profile, document-metadata, and progress data are stored in a managed PostgreSQL database operated by Supabase in the US East (Ohio) region.
- Background-job state and short-lived caches are held in a managed Redis service operated by Upstash in the United States.
- The API itself runs on Fly.io in the US East (Ashburn, Virginia) region; personal information passes through this runtime in memory while requests are being handled but is not persisted there.
- OCR processing (AWS Textract), language-model interpretation (OpenAI), email delivery (SendGrid), and subscription management (RevenueCat) are performed by U.S.-based service providers.
Personal information transferred outside Canada may be subject to lawful access by foreign governments, courts, and law enforcement under the laws of the jurisdictions in which it is processed. We require each sub-processor to provide contractual data-protection commitments designed to give your information a substantially similar level of protection wherever it is processed, and we rely on additional safeguards (such as the European Commission's Standard Contractual Clauses) for transfers from the EEA, the United Kingdom, or Switzerland.
5. Security Implementation Specifics
For the general security controls we apply, see Section 8 of the Privacy Policy. Implementation details that are specific to the data categories in Section 2:
- Document storage encryption at rest. Files in AWS S3 are encrypted at rest using SSE-S3 — server-side encryption with AES-256 and AWS-managed keys.
- Database encryption at rest. Structured data held in our Supabase- managed PostgreSQL database is encrypted at rest using AES-256 with AWS-managed keys (Supabase's default at-rest encryption).
- Cache and queue encryption at rest. Transient state in our Upstash- managed Redis service is encrypted at rest using AES-256.
- Encryption in transit. All connections between the App, our API, and our sub-processors use TLS, including our connections to the managed PostgreSQL and Redis services described above.
- Short-lived download links. Documents are served via temporary signed URLs rather than permanent public links, so a leaked link expires.
- Account-scoped data access. Every API endpoint is bound to the authenticated account identifier, and every database query is scoped to that identifier at the service layer, so one account cannot read or modify another account's records.
- Cleanup of orphan uploads. Upload drafts that are not confirmed are removed automatically after one hour.
6. Data Minimization and Purpose Limitation
We collect and process data only for the purposes identified in the Privacy Policy and in Section 2 above.
- We do not use Your Content to train artificial-intelligence models.
- We do not use your personal information for advertising or to build advertising profiles.
- We do not sell your personal information.
OCR processing of your documents is performed for the sole purpose of auto-populating fields you would otherwise have to enter manually. Language- model interpretation of continuing-education requirements is performed against publicly available state-licensing-board web pages, not against Your Content.
7. Document Sharing via "Zip & Send"
When you use the "Zip & Send" feature:
- You select one of your folders and provide a recipient email address (and optionally a recipient name and note).
- The Service bundles the documents in that folder into a ZIP archive and transmits it via SendGrid to the recipient you specified, with your name and email shown as the sender and reply-to.
- We retain a record that the email was sent (for delivery troubleshooting and abuse prevention), but the ZIP archive itself is not stored by Cenote after transmission.
You are responsible for ensuring that each recipient is authorized to receive the documents and personal information you transmit. Cenote has no relationship with the recipient and cannot recall or revoke a message after it has been sent.
8. Retention and Deletion
8.1 Deletion You Initiate
You can delete individual documents from within the App. When you delete an account, the Service:
- removes the underlying files from document storage on a best-effort basis; and
- deletes your user record, which cascades to your profile, verified credential records, documents, extracted document text, folders, progress data, notifications, and audit logs.
If a file deletion in document storage fails (for example, due to a transient error), we log the failure and continue with the rest of the deletion. We make reasonable efforts to retry failed deletions.
8.2 Backup Retention
Routine system backups taken before deletion may continue to contain your data for a limited period until they expire on their normal rotation schedule. Backups are restored only when needed to recover from a system incident.
8.3 Reset Without Deletion
If you choose to reset your account rather than delete it, the Service removes your stored files, document records, extracted document text, folders, progress data, and progress links, and resets your profile to the pre-onboarding state. Your account, email, and authentication credentials are preserved.
8.4 Legal Holds
We may retain certain data longer than the periods described above if required to comply with a legal obligation, resolve disputes, or enforce our agreements. In such cases, we limit access to the data placed on legal hold to personnel and counsel with a specific need to access it.
9. Your Rights
Your rights are described in Section 10 of the Privacy Policy, including jurisdiction-specific rights for residents of California (CCPA / CPRA), the EEA, the United Kingdom, Switzerland (GDPR / UK GDPR), and Canada (PIPEDA). To exercise any of those rights, contact us at [email protected].
10. Incident Response
If we determine that a security incident has resulted in unauthorized acquisition of personal information about you, we will notify you and any applicable regulators in accordance with applicable law.
If you believe your account has been accessed without authorization, please contact [email protected] immediately.
11. Changes to This Data Policy
We may update this Data Policy from time to time. Material changes will be announced by updating the "Last Updated" date and by the means described in Section 12 of the Privacy Policy.
12. Contact
CenoteTracker Attn: Privacy 48 Jenny Court, Stoney Creek, Ontario, L8G 4N8, Canada Email: [email protected]