Official document
Privacy Policy
Last updated August 4, 2026
§1 Introduction
This policy explains what MyAllergies does with information, including the health information you record in an allergy list.
MyAllergies is free and has no business model that depends on your data. We do not sell information, we do not share it with advertisers, and there is no advertising on the site. The only routine ways information leaves us are when you deliberately share a list with someone, and when you allow us to use Microsoft Clarity to see how the site is used.
The service is operated from the United States. Writing to us at the address at the end of this document is the fastest way to reach a person about anything here.
§2 Information you give us
If you create an account we store your name, your email address and a hash of your password. We never store the password itself. We also store a hash of your account recovery key, which lets us check a key you present without being able to read or reproduce it.
An allergy list contains whatever you choose to put in it. In normal use that means the name of the person the list describes, their allergies, how severe each one is, notes about them, dietary restrictions, the names and phone numbers of emergency contacts, and free text instructions for an emergency. This is health information about a named person. Many countries treat it as a special category of personal data, and we handle it on that basis. It is stored so that we can show it to you and to anyone you share the link with, and it is used for nothing else.
If you open a support ticket we store the email address you provide together with the subject and description you write, so that a person can read the ticket and reply to you.
§3 Information collected automatically
Our server keeps ordinary web logs. Each request records the address requested, the time, the response status, the browser user agent string and the originating IP address. We use these to keep the service running and to investigate faults and abuse.
We count how many times each article in the Inspiration section has been read. That is a single number stored against the article and it is not connected to any person or session. We do not count views of allergy list pages at all.
§4 Microsoft Clarity
We use Microsoft Clarity to understand how people move around the site, which shows us where the design is confusing or broken.
Clarity records interactions such as page views, clicks, scrolling and mouse movement, and assembles them into session replays and aggregate heatmaps. It also derives an approximate location from your IP address and records the type of device and browser you are using. It stores identifiers in cookies and in your browser local storage so that it can recognise a continuing session.
Clarity is a Microsoft product. The information it gathers is sent to Microsoft and processed on Microsoft infrastructure, which may be located outside your country. Microsoft's own handling of that data is governed by the Microsoft Privacy Statement, which you can read on their website.
Two things limit what Clarity sees here. It stays switched off unless you allow analytics when the cookie banner asks, and we configure it to mask text and form input on the page, so the contents of an allergy list are not captured in a recording.
§5 Cookies and browser storage
MyAllergies sets three cookies of its own. None of them are used for advertising and none of them follow you to other websites.
A session cookie is set when you sign in. It holds a random token, and our database stores only a hash of that token, so the cookie itself is what proves who you are. It lasts thirty days and renews while you keep using the site.
A second cookie holds the secrets for lists you created without an account, which is what allows you to keep editing those lists from the same browser. It lasts a year.
A third cookie exists for a few minutes only, immediately after a recovery key is issued. It carries the key to the page that displays it, and it is cleared as soon as you confirm you have saved it.
All three are readable only by our server and are not exposed to scripts running in the page.
Your browser also keeps a small amount of information locally rather than in a cookie. That covers your cookie choices, whether you have dismissed the prompt to install the app, and whether you prefer the light or dark theme. If you have an account, your theme and language preferences are also stored with the account so that they follow you between devices. Microsoft Clarity sets its own cookies as described above, and only if you have allowed analytics.
§6 How we use information
We use what you record in a list to display that list to you and to anyone you share it with. We do not read it, analyse it, aggregate it, or use it to build a profile of anyone.
Account details identify you when you sign in and let us show you your own lists. Support tickets are used to answer your question. Logs and Clarity are used to keep the site working and to improve it.
We send no marketing. We do not send email at all, which is why account recovery depends on a key that you keep rather than on a message we send.
§7 When information is shared
A list is shared with whoever you give the link to. That is the purpose of the feature and it is the main way information leaves us. Anyone holding the public address or the permanent QR address can read the list without signing in. We ask search engines not to index those pages, but a link that has been forwarded or printed is beyond our control, so share it as carefully as you would share the information itself.
Beyond that, information reaches our hosting provider, which stores the database and serves the site, and Microsoft, through Clarity, when you have allowed analytics. We do not sell information, we do not pass it to advertisers or data brokers, and we do not use it to train machine learning models.
We will disclose information where the law requires it, or where we believe in good faith that disclosure is necessary to prevent serious harm to someone.
§8 How long we keep information
Lists remain until you delete them. Deleting a list removes it together with everything in it, including its allergens and emergency contacts, and its link stops working.
Deleting your account removes the account and every list attached to it in the same operation. Your sessions and saved preferences go with it. This happens immediately and cannot be undone.
Support tickets are stored separately from your account so that we keep a record of the conversation, which means they are not removed when an account is deleted. Ask us if you would like a ticket deleted and we will remove it. Server logs are short-lived and are rotated in the ordinary course of running the service.
§9 Security
Passwords are stored using bcrypt. Session tokens and recovery keys are stored as SHA-256 hashes rather than in any form we could read back. The cookies that matter are set so that scripts in the page cannot read them and so that they are not sent along with requests originating from other sites. In production the site is served over HTTPS.
We should be plain about the limits of this. MyAllergies is maintained by a small team, we hold no formal security certification, and no service can promise that a breach is impossible. If one occurred we would say so on the site and contact affected people by the fastest means available to us.
§10 Your choices
You can edit or delete anything in a list at any time from the list editor. In your settings you can change your name, email address, password, recovery key, theme and language, and you can delete your account outright.
If you want a copy of what we hold about you, or you want something corrected or removed that you cannot reach yourself, write to us and we will help. Depending on where you live you may have a formal right to access, correct, export, restrict or erase your personal data, and we will honour those requests regardless of where you live.
You can decline analytics when the cookie banner asks, and you can change that decision at any time afterwards through the Cookie settings link in the footer of every page. Withdrawing it stops Clarity and clears the cookies it set. Because we send no email, there is no marketing list to unsubscribe from.
§11 Children
An adult creating and managing a list for a child is a normal and expected way to use this service, and nothing here discourages it.
A child under 13 should not create their own account. We ask for as little information as possible in either case. A parent or guardian can edit or delete a child's list at any time, and can contact us about information relating to their child.
§12 Where information is held
Our database and the site itself are hosted in the United States. Microsoft Clarity processes data on Microsoft infrastructure and may move it between countries.
If you use MyAllergies from outside the United States, your information is being sent there. Please take that into account before recording anything you would not want held in that jurisdiction.
§13 Changes to this policy
We will update this page whenever what we do changes, and the date at the top records when it last changed. Since we do not send email we cannot notify you directly, so please check back if this matters to you. Where a change is significant we will say so on the site.
§14 Contact
For questions about privacy or to make a request about your information, write to [email protected]. For help with the service, open a support ticket or write to [email protected]. For legal matters, write to [email protected].
Our postal address is MyAllergies, PO Box 492, Rockwall, TX 75087.