1. Introduction
This Privacy Policy describes how CenoteTracker ("Cenote," "we," "us," or "our") collects, uses, shares, and protects information when you use the CenoteTracker mobile application (the "App") and related services available at CenoteTracker.com (collectively, the "Service").
By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
2. Who We Are
CenoteTracker is a mobile application that helps licensed professionals track, store, and manage their Continuing Education ("CE") and Continuing Professional Development ("CPD") requirements. The Service is operated by CenoteTracker, a sole-proprietorship organized under the laws of Ontario, Canada, with a place of business at 48 Jenny Court, Stoney Creek, Ontario, L8G 4N8, Canada.
Contact for privacy inquiries: [email protected]
3. Information We Collect
3.1 Information You Provide Directly
When you create an account and use the Service, we collect:
- Account information: your email address, full name, and a unique account identifier issued by our authentication provider (Clerk).
- Professional profile: the U.S. state in which you are licensed, your job title or profession, your license expiration date, and your renewal deadline.
- Verified credentials: information you enter or confirm during credential verification, which may include professional license or certificate numbers (for example, NPI, PTIN, CFP, PE), specialty designations, and employer name.
- Documents you upload: certificates, transcripts, and other proof-of-completion files you choose to upload (PDF and image files up to 10 MB each).
- Communications: information you submit through support requests, feedback forms, or the "Report a Problem" / "Request a Feature" flows.
- Recipient information for "Zip & Send": when you choose to send a folder of documents to a third party, you provide that recipient's email address and optionally a recipient name and note.
3.2 Information Generated Through Your Use of the Service
- OCR-extracted document data: text and metadata automatically extracted from documents you upload (for example, course title, provider name, completion date, hours earned, certificate number, and confidence scores).
- Compliance tracking data: hours applied to specific CE categories, total completion percentages, and progress calculations derived from your documents.
- Organizational data: folder names you create and document organization choices.
- Audit logs: records of significant actions taken on your account, including action type, affected entity, and the timestamp of the action.
3.3 Information Collected Automatically
- Device and connection information: IP address, device type, operating system, app version, and user agent, recorded in our audit logs for security and debugging purposes.
- Push notification token: a device identifier issued by Apple Push Notification service or Firebase Cloud Messaging, used solely to deliver notifications you opt in to receive.
3.4 Information from Third Parties
- Authentication providers: when you sign in using a third-party authentication method (such as Sign in with Apple) via Clerk, we receive the email address and any name information that provider shares with us.
- Subscription providers: when you purchase a subscription, RevenueCat notifies us of your subscription status. We do not receive your payment card or financial account information.
3.5 Information We Do Not Collect
We do not request access to your device's location, contacts, calendar, or health data. We do not knowingly collect information from individuals under 18 years of age.
4. How We Use Your Information
We use the information described above to:
- create and maintain your account and authenticate you when you sign in;
- store and organize the documents you upload;
- automatically extract information from your documents using optical character recognition (OCR) so that you do not have to enter it manually;
- determine the CE requirements applicable to your state and profession by searching publicly available state licensing-board pages and using AI language models to structure the results;
- calculate your progress toward those requirements;
- send you notifications you have opted in to receive (for example, renewal deadline alerts);
- bundle and email your selected documents to recipients you specify through the "Zip & Send" feature;
- enforce subscription limits (for example, the free-tier upload quota);
- respond to your support requests and feedback;
- detect, investigate, and prevent fraud, abuse, and security incidents; and
- comply with legal obligations.
We do not sell your personal information. We do not use your personal information for advertising or to build advertising profiles. We do not use the content of your documents to train artificial-intelligence models.
5. Legal Bases for Processing (EEA / UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your personal information under the following legal bases:
- Performance of a contract: to provide the Service you have requested.
- Legitimate interests: to operate, secure, and improve the Service, in a manner that does not override your fundamental rights.
- Consent: for processing that requires it, such as push notifications. You may withdraw consent at any time.
- Compliance with a legal obligation: where applicable law requires it.
6. How We Share Your Information
We share information only as described below.
6.1 Service Providers (Sub-Processors)
We rely on the following sub-processors to operate the Service. Each is bound by contractual obligations to protect your information and use it only on our instructions:
| Sub-Processor | Purpose | Data Categories |
|---|---|---|
| Clerk | Authentication, account management, and session security | Email, name, password (hashed by Clerk), session tokens, login activity |
| Amazon Web Services (AWS) | Document storage (S3), automated text extraction from documents (Textract), and underlying infrastructure | Uploaded documents, file metadata |
| OpenAI | Language-model processing to extract structured CE requirements from public web pages and to interpret OCR results | Public web-page content scraped on your behalf; OCR text from your documents |
| SerpAPI | Programmatic search for official state licensing-board pages | Search queries containing your state and profession (no personal identifiers) |
| Firecrawl | Web scraping of public licensing-board pages identified through SerpAPI | URLs to public web pages (no personal identifiers) |
| SendGrid | Outgoing email delivery, including the "Zip & Send" feature and operational emails | Sender name, sender email, recipient email, message contents, ZIP archive attachments |
| RevenueCat | Subscription and entitlement management for in-app purchases | Anonymous account identifier, subscription status, product identifiers |
| Apple / Google | App distribution and in-app purchases | Information you provide to the app store; we do not receive payment-card data |
| Expo Application Services | Push notification delivery and mobile build infrastructure | Push notification tokens, notification contents |
| Supabase | Managed PostgreSQL database hosting | Account, profile, verified credentials, document metadata, OCR-extracted text, folder and progress data, notification queue, audit logs |
| Upstash | Managed Redis hosting (background-job queues for the "Zip & Send", OCR, and continuing-education-requirement workflows; short-lived cache and rate-limit counters) | Transient job payloads (file references and processing parameters), cached requirement data sourced from public web pages, per-API rate-limit counters |
| Fly.io | Application hosting — the runtime environment for the API that delivers the Service | All data described in Section 3 passes through the API at runtime; no user data is persisted on Fly's infrastructure |
We will provide notice through the App or by email before adding a new sub-processor that processes personal information.
6.2 Recipients You Choose
When you use the "Zip & Send" feature, we transmit the ZIP archive containing the documents you selected, along with your sender name and reply-to email, to the recipient email address you provide. You are responsible for ensuring the recipient is authorized to receive that information.
6.3 Legal Disclosures
We may disclose your information if we believe in good faith that disclosure is required to: (a) comply with a subpoena, court order, or other lawful request from a government authority; (b) enforce our Terms of Service; (c) protect the rights, property, or safety of Cenote, our users, or others; or (d) investigate or prevent fraud or security incidents.
6.4 Business Transfers
If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to the acquirer's agreement to honor commitments substantially similar to those in this Privacy Policy.
6.5 No Sale of Personal Information
We do not sell your personal information for monetary or other valuable consideration, and we do not engage in "sharing" of personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act.
7. Data Retention
We retain your information for as long as your account is active. When you delete your account, we delete:
- all files you uploaded to our document storage, on a best-effort basis;
- your user record and all associated rows in our database, including profile, verified credentials, documents, OCR job records, folders, trackers, notifications, and audit logs.
Some information may persist for a short time in routine system backups before those backups expire on their normal rotation schedule. Aggregated or de-identified data that cannot reasonably be associated with you may be retained for analytical purposes.
We may retain certain information for longer if required to comply with a legal obligation, resolve disputes, or enforce our agreements.
For detailed information about how long specific data categories are retained, see our Data Policy.
8. Data Security
We implement technical and organizational measures designed to protect your information from unauthorized access, alteration, disclosure, and destruction. These measures include:
- encrypted transport (TLS) for all connections between the App and our servers;
- access controls on production infrastructure, with secrets stored outside source control;
- application-layer access controls that scope every request and database query to the authenticated account, so one account cannot read or modify another account's data;
- bearer-token authentication on all API endpoints, verified against our authentication provider; and
- isolation of file storage credentials and short-lived signed URLs for document downloads.
No system is perfectly secure. You are responsible for safeguarding your account credentials and for any activity occurring under your account.
9. International Data Transfers
The Service is operated from Ontario, Canada. To deliver the Service, we transfer personal information to and process it in the United States and in other countries through the sub-processors listed in Section 6.1. Notably, documents you upload are stored in Amazon S3 in AWS's US East (Ohio) region, and certain processing — including OCR, language-model interpretation, email delivery, and subscription management — is performed by U.S.-based service providers.
When personal information is transferred outside Canada, it may be subject to lawful access by foreign governments, courts, and law enforcement under the laws of the jurisdictions in which it is processed. We require each sub-processor to provide contractual data-protection commitments designed to give your information a substantially similar level of protection wherever it is processed, and we rely on additional safeguards (such as the European Commission's Standard Contractual Clauses) for transfers from the EEA, the United Kingdom, or Switzerland.
If you would prefer not to have your personal information transferred to the United States, you should not use the Service.
10. Your Rights and Choices
10.1 Access, Correction, Deletion, and Portability
You can:
- view and edit much of your profile information directly in the App;
- delete your account from within the App, which initiates the deletion process described in Section 7;
- request a copy of the personal information we hold about you, or request correction or deletion, by contacting us at [email protected].
We will respond to verifiable requests within the timeframes required by applicable law.
10.2 California Residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- know what categories of personal information we have collected and how we use and disclose them;
- request access to the specific pieces of personal information we hold;
- request deletion of your personal information, subject to legal exceptions;
- correct inaccurate personal information;
- limit the use and disclosure of "sensitive personal information"; and
- not be discriminated against for exercising these rights.
Notice of Right to Limit Use of Sensitive Personal Information. California law treats certain categories of personal information as "sensitive personal information" ("SPI") and gives California residents the right to limit our use and disclosure of SPI to purposes necessary to provide the Service. The professional identifiers you provide or confirm during credential verification — including license, NPI, PTIN, CFP, and PE numbers — may qualify as SPI to the extent California law treats them as government-issued identifiers. We use these identifiers solely to confirm your professional identity, calculate your continuing-education obligations, and operate the Service for you. We do not use them to infer characteristics about you, to build profiles, or for advertising; and we do not sell or share them for cross-context behavioral advertising. If you would like to confirm or further limit our use of any SPI, contact us at [email protected].
To exercise these rights, email [email protected]. We will verify your request by matching the information you provide against the information associated with your account. You may designate an authorized agent to make a request on your behalf, subject to verification.
10.3 EEA, UK, and Swiss Residents (GDPR / UK GDPR)
In addition to the rights described in Section 10.1, you have the right to:
- object to processing based on legitimate interests;
- request restriction of processing;
- withdraw consent at any time (without affecting prior processing); and
- lodge a complaint with your local supervisory authority.
10.4 Canadian Residents (PIPEDA)
If you are a resident of Canada, our handling of your personal information is governed by the federal Personal Information Protection and Electronic Documents Act ("PIPEDA"). Under PIPEDA, you have the right to:
- access the personal information we hold about you;
- challenge the accuracy and completeness of that information and have it corrected where appropriate;
- withdraw your consent to our collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions and reasonable notice — withdrawing consent may mean we are unable to continue providing the Service to you; and
- file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/.
To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by PIPEDA. Because the Service is operated from Canada and routes data to U.S. sub-processors (see Section 9), your personal information will be subject to the laws of the United States during such processing.
10.5 Push Notifications
You can disable push notifications at any time in your device settings.
10.6 "Do Not Track" Signals
The Service does not respond to browser "Do Not Track" signals, as no consistent industry standard has been adopted.
11. Children's Privacy
The Service is intended for users 18 years of age or older who are pursuing or maintaining a professional credential. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at [email protected].
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you by reasonable means, which may include in-app notice or email. Your continued use of the Service after the changes take effect constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
For questions, requests, or complaints about this Privacy Policy or our information practices, please contact:
CenoteTracker Attn: Privacy 48 Jenny Court, Stoney Creek, Ontario, L8G 4N8, Canada Email: [email protected]