Privacy Policy
Last updated: 29 June 2026 · Version 1.0
1. Who We Are
guidelines.doctor ("we", "us", "our") is an educational clinical reference platform operated as part of the tools.doctor family of free medical tools. We are based in the United Kingdom.
For privacy enquiries, please use our Contact page.
2. Scope of This Policy
This Privacy Policy explains what information is processed when you use guidelines.doctor, how it is used, and your rights regarding that information. It applies to all visitors worldwide and has been prepared with reference to:
- UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
- EU General Data Protection Regulation (EU GDPR) 2016/679
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- General international privacy best practice
3. Information We Process
3.1 Information you do not provide to us
guidelines.doctor requires no registration, no login, and no personal information to use. We do not collect your name, email address, IP address, device identifiers, or any other personal data through the normal use of this site.
3.2 Browser localStorage (on your device only)
With your consent, we use your browser's localStorage — a standard web technology — to store the following information locally on your device only:
- Favourites — guideline IDs you have starred, so they persist between visits
- Recently Viewed — the last 10 guidelines you have opened, for quick navigation
- Consent preferences — your cookie/storage choices, so we do not ask repeatedly
This data never leaves your device. It is not transmitted to our servers, not accessible to us, and not shared with any third party. It exists solely in your browser and you can delete it at any time by clearing your browser's site data, or via our Cookie Preferences tool.
3.3 Web server logs
Like all web servers, our hosting provider (Hostinger) automatically records standard access logs, which may include your IP address, browser type, referring URL, and pages visited. These logs are retained for security and operational purposes only, are not used to identify you personally, and are subject to Hostinger's own privacy policy. We do not process these logs for marketing or profiling.
3.4 Analytics
We do not currently use any analytics service. No third-party analytics scripts (such as Google Analytics) are loaded on this site. Any future analytics implementation will be disclosed in this policy and will require your explicit consent.
4. Legal Basis for Processing (UK/EU GDPR)
Where personal data is processed, we rely on the following legal bases:
- Consent (Article 6(1)(a) UK GDPR) — for functional localStorage (favourites, recently viewed)
- Legitimate interests (Article 6(1)(f) UK GDPR) — for server security logs, where our legitimate interest in maintaining a secure service is not overridden by your privacy interests
- Legal obligation (Article 6(1)(c) UK GDPR) — where processing is required to comply with applicable law
5. Cookies and Similar Technologies
We use no tracking cookies. We use browser localStorage with your consent as described above. For full details, including how to manage your preferences, please see our Cookie and Storage Policy.
6. Data Retention
localStorage data persists in your browser until you clear it or withdraw consent via our Cookie Preferences tool. Server access logs are retained by Hostinger according to their standard retention periods (typically 30 days). We do not maintain any centralised database of user data.
7. International Transfers
As we do not collect or store personal data on our servers beyond standard web server logs (processed by Hostinger), there are no international data transfers by us. Hostinger's data transfer practices are governed by their privacy policy and applicable data transfer mechanisms.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding personal data:
- Right of access — to request a copy of any personal data we hold about you
- Right to erasure — to request deletion of your personal data
- Right to rectification — to correct inaccurate data
- Right to restrict processing — to limit how we process your data
- Right to data portability — to receive data in a portable format
- Right to object — to object to processing based on legitimate interests
- Right to withdraw consent — at any time, without affecting prior processing
As we hold no personal data beyond standard server logs (which we do not control individually), most of these rights are effectively addressed by the fact that we do not process your personal data. For any query, please contact us.
California residents: Under CCPA/CPRA, you have the right to know, delete, opt-out of sale, and non-discrimination. We do not sell personal information. To exercise any rights, please contact us.
9. Children's Privacy
guidelines.doctor is intended for use by medical professionals and students aged 18 and over. We do not knowingly collect data from children under 13 (or under 16 where required by applicable law). If you believe a child has provided data to us, please contact us immediately.
10. Medical Disclaimer
11. Third-Party Links
This site may contain links to external websites (such as tools.doctor, NICE, ESC). We are not responsible for the privacy practices of external sites and encourage you to review their policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in an updated "Last Updated" date. Where required by law, we will seek fresh consent. Continued use of the site after changes constitutes acceptance of the updated policy.
13. Contact and Complaints
For privacy-related queries, please use our Contact page.
If you are in the UK and believe we have handled your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. If you are in the EU, you may contact your national supervisory authority.