Skip to main content
Possible animal exposure? Wash the wound. Seek professional care promptly.First-aid steps
SafeRabiesRabies education

Privacy Policy

Effective date: September 16, 2026

SafeRabies limits data collection and keeps health, child, and account routes outside non-essential analytics and advertising.

Current status: advertising is off, newsletter collection is unavailable, exposure-checklist answers stay in the browser, and optional analytics requires explicit consent.

1. Information we handle

SafeRabies processes information to deliver pages and operate the features below. Requests also expose ordinary network information, such as an IP address, to the servers receiving them:

  • Accounts — name, email address, password credentials, optional profile information you supply, and session records. Passwords are stored as hashes. Session records include IP address, browser information and activity times. Account requests go to the SafeRabies account service and database; password-reset and verification emails use a configured email provider.
  • Contact — name, email address, subject and message submitted through the contact form, plus IP address, browser information and submission time. These records are stored in the SafeRabies database for staff to handle. Email sent directly to us is handled by email providers. Avoid including medical records or other unnecessary sensitive information.
  • Operational records — application errors and email-delivery diagnostics can contain personal information, including recipient email addresses. Hosting and network providers may also retain request and security logs. These records are separate from optional analytics.
  • Optional analytics — pseudonymous, limited page and interaction events only after explicit consent and only on a small set of public pages, including the homepage.

Newsletter subscriptions are temporarily unavailable. SafeRabies does not currently accept newsletter email addresses, names, or preferences.

2. Exposure checklist privacy

Answers entered into the exposure checklist are held in the page’s browser memory and are not saved as an account record. SafeRabies does not send individual answers, exposure details, scores, or results to its servers, analytics providers, or advertising providers. Copying or printing a summary happens only when the visitor chooses that action. A copied or printed summary is then handled by the visitor’s clipboard or printing system. Loading the page still makes ordinary website requests; this local-answer protection does not apply to information separately submitted through contact or account forms.

3. Clinic Finder searches

When Clinic Finder search is available, a submitted city, ZIP or address goes to our server and Mapbox to identify the location. Device location is requested only after you choose that option; its coordinates go to our server for a nearby-facility search. Search inputs and results stay in page memory and are not saved as your search history, account data, browser storage, analytics or advertising events.

Opening the optional map makes requests to OpenStreetMap that reveal the displayed area and ordinary network information. Directions and facility links open external services with their own privacy practices. Directions include the facility destination, not your device coordinates.

Finder abuse protection stores a changing, keyed IP-address identifier and request count in MongoDB with a two-minute expiry; database cleanup may happen later. It does not store the location query. These counters are separate from hosting, geocoding and map-provider logs, whose retention and processing locations require provider confirmation.

4. Storage on your device

In addition to the analytics choice, account features keep a profile cache in browser storage. Local features can save pet vaccination reminders, recent searches and game progress on this device. These stored items do not have a general automatic expiry. You can clear them through your browser’s site-data controls; doing so can remove preferences and reminders or sign you out. Clearing browser data does not delete records already stored by SafeRabies or its service providers.

5. How information is used

  • Operate accounts, protect authenticated sessions, and limit abusive requests.
  • Respond to contact and privacy requests.
  • Use consented, pseudonymous analytics on eligible trust pages to understand basic site use.
  • Meet applicable legal obligations.

6. Analytics and consent

PostHog analytics is optional and remains off until a visitor explicitly allows it. When enabled, SafeRabies limits it to the homepage, About, the author and reviewer profiles, editorial standards, disclaimer, privacy policy and terms pages. Blog articles, health pages, exposure and location tools, account pages, child and family routes, and games are excluded from analytics initialization and event capture. If the analytics library was loaded on an eligible page, moving to an excluded page stops capture; it does not unload code already in browser memory.

The analytics configuration disables autocapture, session recording, surveys, product tours, campaign storage, referrer storage, performance capture, and person profiles. A final outbound filter removes URL, query, referrer, campaign, search, identity, location, and health-related properties. PostHog may still receive a temporary pseudonymous device or session identifier and ordinary network information needed to receive the request.

The Analytics preferences control in the footer is available whether or not you have already made a choice. Choose Reject analytics to withdraw consent and stop capture by the initialized client immediately in that page. Your choice is stored in this browser until changed or site storage is cleared; it has no scheduled expiry. Set your preference separately in other browsers or devices. Withdrawal does not delete events already received by PostHog.

7. Advertising

SafeRabies does not currently serve third-party advertising or load AdSense scripts.

Exposure checklists, emergency guidance, child-directed pages, authentication pages, and private account pages remain outside the advertising boundary. This policy will be updated if advertising practices change.

8. Children's privacy

SafeRabies includes educational pages and games for children, students, parents, and families. These routes do not load non-essential behavioral analytics or advertising. Newsletter collection is unavailable. We do not knowingly collect personal information from children through these areas. A parent or guardian who believes a child submitted personal information can contact privacy@saferabies.com.

9. Sharing and service providers

The features described here send information to service providers for website operation, communications, optional analytics and requested location searches.

Information may be processed by hosting, database and email providers, PostHog after consent on eligible routes, and location providers after a visitor requests a search. External clinic, hospital, map, or public-health websites have their own privacy terms. Information may also be disclosed when required by valid legal process.

When configured, Upstash Redis receives an IP-address-based identifier and route name for request rate limiting; otherwise those counters are kept in server memory. Rate-limit windows are not a promise about provider log retention. Images may be delivered through Cloudinary or an image proxy; direct third-party image requests disclose ordinary network information to that provider. These operational services are separate from consented PostHog analytics.

10. Retention, rights, and security

Account and contact records are stored in a server database. The application does not set an automatic deletion period for these records. Administrative tools can delete individual account or contact records, but those actions do not establish deletion of related records, provider copies or backups. Signing out or revoking a session does not delete the account.

Session records have an expiry field and an automatic database-expiry mechanism configured in the application. Their expiry setting can differ from cookie lifetimes. The actual production cleanup schedule and backup retention have not been confirmed, so we do not promise deletion at an exact time.

Retention periods for server and email logs, backups and provider-held analytics have not yet been confirmed for this policy. We also have not confirmed a complete deletion process covering those copies. To request access, correction or deletion, or ask about retention, email privacy@saferabies.com. Clearing browser storage or withdrawing analytics consent does not delete previously collected server data.

The account service uses password hashing and authenticated access controls. Login cookies in the application are set to expire after 15 minutes for access and seven days for refresh; signing in or refreshing can renew them. Cookie expiry is not deletion of the account or every server record. No method of internet transmission or storage is completely secure.

11. International processing

Processing countries and international-transfer arrangements for our production hosting, database, email, logs, backups and other providers have not yet been confirmed for this policy. A provider name or service endpoint alone does not establish where all data is stored or accessed. We do not claim a particular processing country or contractual safeguard without that confirmation. For information about processing locations and arrangements, contact privacy@saferabies.com.

12. Policy changes and contact

This page will show a new effective date when the policy changes. Questions or privacy requests can be sent to privacy@saferabies.com or through the contact page.