What we collect
The minimum needed to run a free, anonymous service:
1.1 "Personal data" bears the meaning given in the Personal Data (Privacy) Ordinance (Cap. 486). 1.2 Per request, the service processes: (a) the IP address, for rate-limit enforcement in a cache whose entries expire within 24 hours; (b) a Cloudflare Turnstile verification token; (c) message and document content submitted during the active session. 1.3 No account credentials, names, e-mail addresses, telephone numbers, or government identifiers are requested or collected.
What we don't collect
There are no user accounts, so we never ask for or hold:
2.1 The operator maintains no user accounts and no database of user identities. 2.2 The operator runs no advertising trackers and builds no cross-session behavioural profiles of its own.
Where your conversation lives
Your conversation is held in your own browser (sessionStorage) so the site can hand it between screens. We do not store transcripts on our servers; close the tab and it is gone. Documents you upload are processed to produce the answer, then deleted.
3.1 Conversation state is persisted client-side in browser sessionStorage only and is not written to any server-side store of the operator. 3.2 Uploaded document content is processed to generate the response and then deleted.
Service providers
Handling a request touches these services, named plainly:
4.1 The operator engages the processors listed in this section solely to provide the service: a third-party AI model provider (model inference); a bot-mitigation service; a managed database provider (public-data hosting); a rate-limit cache provider; a map service provider (map embed). 4.2 The operator does not sell, rent, or transfer user data to any third party for marketing purposes.
Your rights
Under the PDPO you have rights of access and correction. Because we keep no store of identifying personal data, there is normally nothing to retrieve — but you can always ask.
6.1 Users may exercise the data access and correction rights conferred by the PDPO by writing to hello@hkgooddoctor.com. 6.2 Given the practices in §§1–3, the operator will typically hold no personal data referable to an individual user.
Changes & contact
If this policy changes, the effective date at the top changes with it. Questions or PDPO requests: hello@hkgooddoctor.com
7.1 Amendments take effect on the effective date posted on this page. 7.2 All privacy inquiries and statutory requests: hello@hkgooddoctor.com.
